년 - 년
The Model to Implement the Cyber Security Policy and Strategy for Azerbaijan Information System KCI 등재
한국디지털정책학회 디지털융복합연구 제17권 제5호 2019.05 pp.23-31
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 논문은 아제르바이잔 정보 시스템에 대한 사이버보안 정책 및 전략의 우선순위를 평가하는 실행모델을 구축하는 것을 목적으로 한다. 이를 위하여 ITU 국가 이익 모델로부터 사이버보안 정책 및 전략의 4개 요인을 구성하고, 사이버보안 분야를 선도하는 8 개 선진국의 우수사례를 바탕으로 5개 사이버보안 대안을 도출한 AHP 연구모델이 제안되었다. 연구모델을 바탕으로 작성된 설문지를 사용하여 24명의 정보보안 전문가들이 각 요인 및 대안의 전략적 우선순위를 평가하였다. AHP 분석용 소프트웨어를 통해 분석한 결과 아제르바이잔 정보시스템의 사이버보안 핵심요인은 국토방위와 경제복지이지만, 이들을 구현하는 중요한 대안은 역량개발과 기반시설 분야로 판명되었 다. 본 연구는 각 요인 및 대안의 중요도 분석을 통하여 아제르바이잔 정부가 채택할 수 있는 사이버보안 정책 및 전략적 우선순위를 제시하였다. 본 연구는 아제르바이잔이 국가 사이버보안을 강화할 수 있는 실행 가이드를 수립하는데 기여할 수 있다.
This study aims to build an AHP model that evaluates the priority of cyber security policies for the Azerbaijan information system. For this, 4 factors were constructed from components of ITU National Interest Model, whereas 5 alternatives were based on the best practices of the eight developed countries leading the cyber security field. Using the questionnaire, 24 security experts evaluated the strategic priority of such factors or alternatives. The analysis results using the AHP software showed that homeland defense and economic well-being were the dominant aspects of cyber security policy, whereas capacity building and infrastructure were the main concern of cyber security elements for Azerbaijan. This study presents the strategic priority of cyber security policies that can be adopted by Azerbaijan government. This study can contribute to developing the national cyber security guide of Azerbaijan.
국방 사이버 침해 대응을 위한 전산보안점검 프로그램 및 사용자 진단항목 개선 연구(육군 중심) KCI 등재
한국융합보안학회 융합보안논문지 제17권 제2호 2017.06 pp.101-108
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 해킹, 바이러스 등 대한민국을 노린 공격이 증가하고 있다. 이와 마찬가지로 우리 군도 사이버 침해에 대한 노출이 심해지고 있으며 이를 대응하기 위해 국방부는 사이버 안보에 대한 기본절차를 규정하고 지침을 제공하고 있다. 그럼에도 불구하고 육군에서 발간하는 사이버방호작전 분석결과를 보면 침해건수는 점점 증가하고 있다. 이에 대한 문제점들을 개선하고자 사이버 침해 대응을 위해 가장 중요하면서 기본인 사용자 환경에서의 전산보안 점검항목을 재점검하여 안전하고 효율적인 전산보안 점검항목을 제시한다.
Recent cyber attacks on South Korea, including hacking and viruses, are increasing significantly. To deal with the cybe r invasion of cyber aggression, the Ministry of National Defense defined the necessary procedures for cyber security with guidelines for cyber security. In spite of, based on the analyses the cyber defense operations published, the number of viol ations are increasing. To address issues stated above, the safety check items should be reviewed and revised. This paper will revisit current safety check items and provide new guidelines to prevent cyber security breaches, which will provide more safe and efficient cyber environment.
Cyber상의 위험과 재난에 대한 제어국가의 법적 규제 - 4차산업혁명 시대의 사이버 보안을 중심으로 - KCI 등재
유럽헌법학회 유럽헌법연구 제33호 2020.08 pp.537-576
※ 기관로그인 시 무료 이용이 가능합니다.
8,500원
코로나 바이러스 감염증 사태(Corona, Covid-19)로 인하여 인류는 대면사회에서 점차 비대면사회로 변화해 가고 있다. 국가는 인간의 자유를 제한할 수 있는 질서유지와 공공복리에 대한 명분과 설득력을 더욱 가지게 되었다. Cyber세계는 4차산업혁명으로 인하여 더욱 비약적으로 발전되어 가고 있다. 이제 전통적인 시민사회의 헌법적 가치는 점차 평가절하 되어 가고 있다. Cyber상의 위험과 재난은 사물인터넷과 빅데이터 및 인공지능, 클라우드 등 4차산업혁명기술들을 통하여 더욱 광범위하고도 다양하게 오프라인상의 위험과 결합하기 시작하고 있다. 사이버상의 위험의 범위를 확대해서 접근해야만 한다. 기존의 시민사회에서 성립된 전제가 무너진 4차산업혁명시대에서는 기본권침해와 관련하여 정부와 시민 및 제3세력(해킹관련)으로 법률관계를 구성하여야 한다. 자유세계의 국가들이 빅 브라더 사회로 가지 않기 위해서는 헌법에서 보장하는 개인과 기업의 행동의 자유와 직업의 자유, 경쟁의 자유를 최대한 보장하면서도 사이버와 연결된 시장이 안전하게 잘 돌아갈 수 있도록 탄력적이고도 유연한 개입을 최소한도로 하는 것이다. 우리는 이를 제어국가라고 부를 수 있다. 제어국가는 사이버상의 시장과의 거리를 적절하게 유지할 수 있어야 하는데, 시장질서가 위기에 있을 때에는 거리를 좁혔다가 질서를 회복하면 다시 거리를 넓혀야 하는 동적인 거리를 조절하여야 한다. 동적인 거리 조절이 합헌적이고 합법적인지 여부는 비례의 원칙으로 판단할 수 있다고 생각한다. 제어국가에서는 사이버 안보뿐만 아니라 개인정보의 중요성을 인식하고, 정보자기결정권과 각종 기본권을 최대한 존중할 수 있도록 노력하여야 한다. 거버넌스와 관련하여 정부조직 내부는 전문화되면서도 외부적으로는 민간과의 협력을 강하하여 공사협동(PPP)을 활용하여야 한다. 민간 부분의 자율적인 대응도 더욱 전문적이 될 수 있도록 교육과 과학기술을 강화하는 방향으로 법정책을 추진하여야 한다. 이를 위한 민간분야에서 요구되는 점들을 고찰하였다. 앞으로도 등장하게 되는 불확실하고도 다양한 사이버상의 위험에 대한 판단은 기밀성, 무결성, 가용성 등으로 판단하면 될 것이다. 이는 정보 자체에 대한 기본권 뿐만 아니라 사이버 사스템에 대한 기본권인 IT기본권까지 보호하는 요건들로 작용한다. 우리 헌법하에서 이론과 실무의 관점을 수정하여 수정하여야 하며, 법률과 하위 법령에도 입법의 변화를 반영하여야만 한다. 이와 관련하여 각론적으로 애플리케이션 보안, 클라우드 보안, 사물인터넷 보안, 인공지능 보안, 전자서명제도와 인증기관의 강화 등에 대하여 논의하여 보았다.
Because of the corona virus infection (Corona, Covid-19), human society is gradually changing from face-to-face transactions to non-face-to-face transactions. The state has become more and more justified and persuasive about public welfare and maintaining order, which can limit human freedom. The cyber world is developing more rapidly due to the 4th industrial revolution. Now, the constitutional value of traditional civil society is gradually devalued. Cyber risks and disasters are starting to combine with a wider variety of offline risks through the 4th industrial revolution technologies such as IoT and big data and artificial intelligence. We need to expand the scope of cyber risk. In order to ensure that the countries of the free world do not go to the Big Brother Society, flexible and proportionate interventions are needed to ensure that cyber-connected markets run safely while ensuring maximum freedom of action, freedom of trading, and competition for individuals and businesses guaranteed by the Constitution. We can call this the Steering State. The Steering State must be able to maintain a proper distance from the cyber market, and when the market order is in crisis, the distance should be narrowed, and if the order is restored, the dynamic distance that needs to be increased again must be adjusted. I think it can be judged by the principle of proportionality whether dynamic distance control is constitutional and legal. In the Steering State, not only cyber security, but also the importance of personal information should be recognized and efforts should be made to respect information self-determination and various basic rights as much as possible. In relation to governance, the government organization should be specialized, but externally, cooperation with the private sector should be reduced to utilize the PPP. Legal policy should be promoted to strengthen education and science and technology so that the private sector's autonomous response can become more professional. Judgment on uncertain and diverse cyber risks that will emerge in the future will be judged by confidentiality, integrity, and availability. In this regard, we discussed and discussed application security, cloud security, IoT security, artificial intelligence security, digital signature system, and strengthening of certification bodies etc.
UAM 항공교통관리 인프라의 사이버보안 고려사항 및 대응방안
한국정보기술응용학회 JITAM Vol.30 No.6 2023.12 pp.17-29
※ 기관로그인 시 무료 이용이 가능합니다.
4,500원
In this paper, we aim to propose cyber security considerations and countermeasures for infrastructure and services in the UAM(Urban Air Mobility) Air Traffic Management field, which is one of the key elements of the UAM market that has not yet bloomed. Air traffic management is an important factor for safe navigation and social acceptance of UAM. In order to realize air traffic management, infrastructure and services based on solid network connectivity must be established. And for industries where connectivity is the core component, it can become an infiltration route for cyber threats. Therefore, cyber security is essential for the infrastructure and services. In detail, we will look into the definition of the existing air traffic management field and the cyber threats. In addition, we intend to identify cyber security threat scenarios that may occur in the newly designed UAM air traffic management infrastructure. Moreover, in order to study the cyber security countermeasures of the UAM air traffic management infrastructure, there will be analysis of the UAM operation concept. As a result, countermeasures applicable to the infrastructure and service fields will be suggested by referring to the cyber security frameworks.
일본의 사이버 안보전략 - 양자주의의 강화인가 다자주의로의 전환인가? - KCI 등재
동국대학교 일본학연구소 일본학 제56집 2022.04 pp.159-182
※ 기관로그인 시 무료 이용이 가능합니다.
6,100원
이 연구는 2021년에 개정된 일본의 사이버 안보전략(サイバーセキュリティ戦 略)을 양자주의와 다자주의에 기반해 분석하고자 했다. 기존 연구의 대다수가 해 당 전략의 근간인 사이버시큐리티기본법(サイバーセキュリティ基本法)에 대한 해 석 및 시사점 도출에만 주목했을 뿐, 동북아 안보에서 중요한 위치를 점유하는 사이버 안보전략에 대한 분석이 부족했기 때문이다. 이러한 공백을 보완하기 위 해, 양자주의 및 다자주의 요소와 관련한 분석 틀에 입각해 일본이 구체화하는 사이버 안보를 분석했다. 연구 결과, 일본은 사이버 안보전략에서 양자주의와 다자주의적 관점을 모두 취하며 수준을 더욱 격상하고 있다. 이와 같은 특징은 일본의 아시아 안보 구조 재정립 구상에 근거한다. 양자주의적 운영 원리로 변함없는 미・일 동맹의 중요성 에 근거해 사이버 영역에서도 협력과 발전을 지속하고자 하며, 다자주의적 운영 원리로써 국제적 협력을 더욱 강화할 것으로 보인다. 더불어, 일본이 핵심적으로 추진하는 ‘인도태평양 전략’과의 연계 속에서 사이버 안보는 중국을 견제하는 측면에서 강화될 가능성이 높다. 양자주의와 다자주의라는 국제정치학 관점에 입 각한 이 연구는 대내적 차원에서의 조망을 넘어 대외적 역학관계를 반영해 일본 의 사이버 안보를 분석한 의의가 있다.
This research analyzed Japan's cyber security strategy(サイバーセキュリティ戦略) revised in 2021 based on bilateralism and multilateralism. Because many studies focused only on the interpretation of the Basic Act on cyber security(サイバーセキュリ ティ基本法) and its implication, there was a lack of analysis on cyber security strategy, which occupies an important position in Northeast Asian security. I examined Japan's cyber security by applying an analytical framework related to bilateral and multilateral factors to compensate for this research gap. The result shows that Japan takes both perspectives in its cyber security strategy and raises those levels further. These characteristics depend on Japan's plan of reestablishing the Asian security structure. Japan intends to continue cooperation and development in cyberspace based on the unchanging importance of the U.S.-Japan alliance with the principle of bilateralism. At the same time, Japan expects further to strengthen international cooperation with the basis of multilateralism. In addition, cyber security is likely to be reinforced to keep China in check in connection with Japan's core “Free and Open Indo-Pacific Strategy.” This paper, which combines the international politics approach from bilateral and multilateral elements, is meaningful since it inspects Japan's cyber security by considering interstate dynamics beyond the domestic level.
지능정보사회를 대비한 일본의 사이버 보안 정책동향 분석연구
한국정보통신설비학회 한국정보통신설비학회 학술대회 2016년도 정보통신설비 학술대회 2016.09 pp.145-150
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Japan has recently enacted the Fundamental Act on Cyber Security, taking prompt actions to reinforce the status of the cyber security policy and to organize the implementation system. This kind of change in policy indicates that cyber space does not remain as a field of information restricted to Internet but has become an international field of discussion about economy, society and politics. This study summarizes the change of cyber security policy of Japan, and analyzes the recent changes.
통합 사이버 보안 상황분석을 통한 관제 상황인지 기술 KCI 등재
한국디지털정책학회 디지털융복합연구 제13권 제1호 2015.01 pp.313-319
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷을 이용하는 응용의 수가 급격히 증가함에 따라 인터넷 상에서 이루어지는 사이버 공격의 발생 빈도는 점점 증가하고 있다. 전 세계적으로 L3 DDoS 공격 탐지 중비의 장비에서 응용계층 기반의 지능형 DDoS 공격에 대한 탐지가 미비하다. 차세대 네트워크 보안솔루션의 다양한 요구사항을 충족할 수 있는 고성능 유무선 네트워크 위협대응 기술에 있어서 국내제품은 외국제품에 비해 기능면에서는 근접하나 성능은 미비한 상황에 있으며, 악성코드 탐지 및 시그니쳐 생성연구 관련하여 주로 Window OS에서 동작하는 악성코드 탐지 및 분석 연구 중심으로 진행하고 있다. 본 논문에서는 최신 사이버 보안 상황 침해 공격 분석을 통한 최신 다양한 신종 공격 기법 및 분석 기술의 현황 조사, 분석등을 기술한다.
As the number of applications using the internet the rapidly increasing incidence of cyber attacks made on the internet has been increasing. In the equipment of L3 DDoS attack detection equipment in the world and incomplete detection of application layer based intelligent. Next-generation networks domestic product in high-performance wired and wireless network threat response techniques to meet the diverse requirements of the security solution is to close one performance is insufficient compared to the situation in terms of functionality foreign products, malicious code detection and signature generation research primarily related to has progressed malware detection and analysis of the research center operating in Window OS. In this paper, we describe the current status survey and analysis of the latest variety of new attack techniques and analytical skills with the latest cyber-attack analysis prejudice the security situation.
사이버 안보 전문인력 양성을 위한 교육시스템 개선 방안 KCI 등재
한국경찰연구학회 한국경찰연구 제20권 제1호 2021.03 pp.409-426
※ 기관로그인 시 무료 이용이 가능합니다.
5,200원
정보통신 기술의 발전으로 인하여 현대 인간들은 생활의 편리함을 더욱 누리면서 삶을 영위하고 있지만 반대급부로 이러한 편리한 기술들로 인하여 가상현실에서의 악 의적 위협을 받고 있다. 현재 한국은 미·중 무역전쟁으로 인하여 주변국들에게 많은 안 보적 위협에 노출되어 있으며, 전통적인 물리적 안보위협뿐만 아니라 가상공간에서의 위협도 나날이 증가하고 있어 사이버 위협에 대한 심각성이 고조되고 있다. 그러나 우 리나라는 사이버 안보에 관련된 기본법도 제정이 되어 있지 않은 상태이므로 오랜 시 간과 비용이 투자되어야 하는 사이버 안보 전문인력 양성에 대하여서는 정보보호 분야 에 치중하여 교육이 운용되고 있다. 현재까지 많은 사이버 안보 관련 법안이 발의 되었 지만 아직 제정이 되고 있지 못하고 있다. 이에 따라 본 연구는 사이버 안보관련 대학 교육과 국가기관에서의 전문인력 양성과 관련하여 사이버 안보 법제 마련과 교육시스 템 개선을 목적으로 하며, 사이버 안보를 담당하기 위한 전문 인력 양성을 위한 교육 인프라가 확충되어야 함과 동시에 지도자 양성과 공신력 있는 자격검증 제도가 마련되 어야 한다. 또한 수도권 중심으로 편중된 교육환경 제약을 극복하고, 대학 역할의 강화 와 더불어 관련 정부기관과 연계된 교육사업이 전국적으로 강화되어야 한다.
With the development of information and communication technology, modern humans are living their lives while enjoying the convenience of life more, but as a counter benefit, these convenient technologies are threatened with malicious in virtual reality. Currently, Korea is exposed to many security threats to neighboring countries due to the US-China trade war, and the seriousness of cyber threats is increasing as threats in virtual space as well as traditional physical security threats are increasing day by day. However, since the basic laws related to cybersecurity in Korea have not been enacted, education is being operated with a focus on the field of information protection for the training of cybersecurity professionals that require a long time and cost. And until now, many cybersecurity related laws have been proposed, but they have not been enacted yet. Accordingly, this study aims to prepare cybersecurity legislation and improve the education system accordingly in relation to cybersecurity-related university education and training of professional manpower in national institutions. At the same time, the infrastructure must be expanded and a system for training leaders and credible qualifications must be established. In addition, concrete measures to overcome the constraints of the educational environment concentrated in the metropolitan area must be realized. To this end, the role of universities must be reinforced and educational projects linked with related government agencies must be strengthened nationwide.
7,800원
인공지능(AI) 시대의 도래로 인하여 전통적·비전통적인 안보 위협이 복잡하게 얽히게 되었고, 간첩행위 주체의 다양화 및 행위영역이 확대되었다. 이와 같은 변화에 대응하기 위해 중국은 2014년 제정된 구(舊) 반간첩법을 개정하였다. 2023년 7월부터 시행 중인 개정법은 ‘데이터’를 규율 대상으로 명시하고, ‘사이버 공격’도 간첩행위로 규정 하는 등 ‘사이버 안보’를 강조하였다. 중국은 2014년 ‘총체적 국가안전관’에 기반하여 국가안전 법률체계 를 구축하였으며, 이 과정에서 ‘국가안전법’과 ‘반간첩법’이라는 두 가 지 방향으로 입법이 진행되었다. 국가안전법은 네트워크안전법·데이터 안전법·개인정보보호법과 함께 기술의 발전에 따른 사이버 안보 이슈를 지속적으로 규율해 왔으나, 반간첩법은 개정을 통해 비로소 4차 산업혁명 시대의 총체적 국가안전관의 확장을 이루었다. 우리나라는 사이버 안보에 관한 기본법 제정시도가 있었으나, 기본권 침해 이슈와 민간 사찰 우려가 제기되어 현재까지도 입법이 이루어 지지 않고 있다. 또한 AI 법제 입법방향에 관하여 ‘규제와 진흥’을 중 심으로 논의가 진행되고 있으나, ‘사이버 안보’는 핵심적인 논의 대상 으로 부각되진 못하였다. AI 기술이 국가안보의 본질에 근본적 변화를 가져올 수 있다고 평가받고 있는바, 반간첩법에서 나타난 중국의 사이버 안보관을 바로 이해하여, AI 법제 입법과정에서 ‘사이버 안보’ 관한 심도 있는 논의가 진행되어야 한다.
With the advent of the AI era, traditional and non-traditional security threats have become complex. The subject of espionage has diversified, and the scope of espionage has expanded. In response to these changes, China has amended its Anti-espionage Law. The amended law, which has been in force since July 2023, specified data as a subject of regulation, and cyber attacks are also defined as espionage in order to emphasize cyber security. In 2014, China established a national security legal system based on the Comprehensive National Security. In this process, legislation was carried out in two directions: the National Security Law and the Anti-espionage Law. The National Security Law has been regulating cyber security issues along with the Cyber Security Law, Data Security Act, and Personal Information Protection Law. It was only after the Anti-espionage Law was amended that the Comprehensive National Security in the era of the 4th Industrial Revolution was expanded. Korea also attempted to enact a basic law on cyber security. However, it was not legislated due to risks of breach of fundamental rights and concerns about private inspections. In addition, cyber security did not become a key subject in the progress of AI legislation. It is evaluated that AI technology can bring about a fundamental change in the nature of national security. In-depth discussions on cyber security should proceed with a understanding of China's cyber security perspective as revealed in the Anti-espionage Law.
사이버보안 인력의 효율적 관리를 위한 자격등급 모델 설계 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제1호 2022.03 pp.61-69
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
대규모 사이버공격이나 테러가 발생하여 국가가 막대한 피해를 보거나 안보에 치명적인 위협이 되었을 때에서야 비 로소 사이버보안 인력 양성에 대한 사회적 관심은 높아진다. 또한, 정부에서는 사이버보안 인력 양성과 확보 정책을 제 시하곤 한다. 하지만, 양성된 사이버보안 인력이 관련 기관이나 기업에 취업한 이후에 이들을 체계적으로 관리할 수 있 는 시스템은 아직 미약하다. 소프트웨어 인력은 표준화된 자격등급 모델이 있어서 각 등급별로 적합한 직무를 설정하여 관리하고 있다. 사이버보안 인력도 경력, 학력, 교육훈련 실적 등을 고려한 특화된 자격등급 모델이 필요하다. 자격등급 을 부여함으로써 각 등급별로 수행할 수 있는 직무를 설정하고 부서의 직책과 직위도 등급을 고려하여 부여해야 한다. 따라서 본 논문에서는 사이버보안 인력의 효율적으로 관리하기 위한 자격등급 모델을 제안한다.
When a large-scale cyber attack or terrorism occurs and the country suffers enormous damage or poses a fatal t hreat to security, social interest in nurturing cybersecurity workforce increases. In addition, the government often su ggests policies and guideline to train cybersecurity workforce. However, the system that can systematically manage trained cyber workforce after they are employed in related organizations or companies is still weak. Software workf orce has a standardized qualification level model, so appropriate jobs are set and managed for each level. Cyber wor kforce also need a specialized qualification level model that takes into account their career, academic background, an d education&training performance. By assigning a qualification level, the duties that can be performed for each level should be set, and the position and duty of the department should also be assigned in consideration of the level. Th erefore, in this paper, we propose a qualification level model for cyber security workforce.
국내 관련 법과 비교 분석을 통한 국가사이버안보법안의 제정 필요성 연구 KCI 등재
한국보안관리학회(구 한국경호경비학회) 시큐리티 연구 제54호 2018.03 pp.9-35
※ 기관로그인 시 무료 이용이 가능합니다.
6,600원
제 4차 산업혁명이 도래하고 있는 오늘날, 사이버공격은 초국가적인 형태로 민간과 공공 구분 없이 동시다발적으로 일어나고 있으며, 지난 2009년의 DDOS 사건을 포함하여 청와대, 언론, 금융기관 전산 시스템 마비 등 사이버 위협은 갈수록 심각성을 더하고 있다. 그러나 현재 우리나라는 사이버안보와 관련된 기본법이 존재하지 않고, 국내의 여러 법률에 관련 내용이 산재되어 있는 형편이다. 이는 사이버안보와 관련된 내용의 법 적용 및 판단 근거에 혼선을 초래할 수 있다. 이러한 상황을 극복하기 위해 2006년 ‘사이버위기 예방 및 대응에 관한 법률안’이 발의되었지만 폐기되었고, 이후 꾸준히 발의되었지만 기존 법률과의 중복문제 및 개인정보침해우려 등으로 번번이 통과가 무산되었다. 가장 최근 발의안은 ‘국가사이버안보법안’으로 2017년 1월 정부가 발의하였다. 이 법안은 사이버안보와 관련된 기본법의 부재를 해결하고, 사이버안보위기시의 대응 능력 강화 및 안보력 함양 등을 주요 내용으로 하고 있다. 따라서 본 연구는 ‘국가사이버안보법안’을 사이버안보와 관련된 국내의 기존법과 비교 분석을 통해 그 필요성을 고찰하고, 개선점을 제언함으로써 사이버안보 기본법으로서의 ‘국가사이버안보법안’의 올바른 제정에 기여하고자 한다.
During the recent years, cyber attacks have been increasing both in the private sector and the government. Those include the DDOS cases in 2009, the Blue House cyber attack, bank hackings etc. Cyber threats are becoming increasingly serious. However, there is no basic law related to cyber security at present, and regulations related to cyber security are scattered in various domestic laws. This can lead to confusion in the application of the law and difficult to grasp the regulations related to cyber security. In order to overcome this situation, the bill on the prevention and countermeasures against cyber crisis was initiated in 2006, but it has been abrogated. Since then, it has been repeatedly proposed, but it has been abrogated repeatedly due to the overlapping of existing laws and concerns about infringement of personal information. The most recent initiative was the National Cyber Security Act, which was initiated by the government in January 2017. The act focuses on resolving the absence of a basic law related to cyber security, strengthening its responsiveness in the event of a cyber security crisis, and fostering security strength. Therefore, this study seeks to contribute to the establishment of National Cyber Security legislation as a basic law of cyber security by examining the necessity of National Cyber Security legislation through comparative legal analysis with existing domestic laws related to cyber security and suggesting policy implications.
직무별 특성을 고려한 대학 정보보호 학과의 교육분야 선정 및 운영에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제15권 제4호 2015.06 pp.105-111
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
사이버 공격의 지능화, 조직화로 몇몇 소수의 정보보호 전문가만으로 사이버 위협에 대응할 수 없는 시대가 되었다. 이에 따라 대학의 정보보호 관련학과가 2013년에 비해 17%나 증가했다. 하지만 대학의 교육은 실제 산업현장에 필요한 인력을 양성하는데 한계를 노출하고 있다. 본 연구에서는 이를 개선하기 위해 정보보호 직무체계 및 분야별 필요 교육 내용에 대한 연구를 조사하였다. 이후 이를 바탕으로 대학에서 학습되어야하는 정보보호 분야를 도출하였다. 그리고 도 출된 분야의 교육과정을 운영하기 위한 방안으로 교육내용 선정 및 인증에 대한 방안을 제시하고 있다. 본 연구를 국가 정보보호백서에서 조사되는 정보보호 인력 현황과 연계해 대학 정보보호 관련학과의 분야를 조절할 수 있을 것으로 기 대된다. 그리고 실 현장의 수요를 반영한 인력을 배출할 수 있는 정보보호 인력 중장기 계획의 기초 연구로 활용되고자 한다.
Because intelligent and organized cyber attack, It is difficult to respond to cyber threats with only a small number of information security experts. Accordingly, information security department compared to 2013 it increased by 17%. But there was a problem that cannot train appropriate students for companies. This research examined the Workforce Framework and Knowledge Units for improving this situation. Based on this, educational department in cyber security major was selected to be learning at the university. And it proposed a plan for a managing course to operate. And the result will be utilized as fundamental research of human resources medium- and long-term demand and supply planning in cyber security department.
사이버공간에서의 거부적 억제를 위한 사이버보안 대응전략 연구 : 베트남전 한국군의 대게릴라전술을 중심으로 KCI 등재
한국융합보안학회 융합보안논문지 제26권 제3호 2026.06 pp.237-246
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
현대 사이버위협은 고도화된 지능형 지속 위협의 형태로 진화함에 따라, 기존의 경계기반 보안모델의 한계가 드러나고 있다. 특히 공격자는 저비용ㆍ고효율의 비대칭성을 활용하여 장기간 은밀히 침투하며, 내부 이동과 권한 상승을 통해 핵심 자산에 접근함으로써 방어자의 대응을 무력화한다. 이는 현대 사이버공격이 비정규전, 특히 게릴라전과 전략적·전술적 유사성을지님을 보여준다. 본 연구는 게릴라전과 사이버전의 공통 특성을 분석하고, 베트남전에서 한국군이 운용한 대게릴라전술인 중대전술기지와 민사심리전을 각각 제로트러스트 아키텍처와 조직 내부 보안 거버넌스와 연계하여 사이버공간에서의 거부적 억제 전략을 제시하였다.
As modern cyber threats evolve into sophisticated Advanced Persistent Threats, the limitations of traditional perimeterbased security models are being revealed. In particular, attackers exploit the asymmetry of low-cost and high-efficiency to infiltrate covertly over a long period, and neutralize the defender's response by accessing core assets through lateral movement and privilege escalation. This shows that modern cyberattacks possess strategic and tactical similarities with irregular warfare, especially guerrilla warfare. This study analyzes the common characteristics of guerrilla warfare and cyber warfare, and presents a deterrence-by-denial strategy in cyberspace by linking the “Company Tactical Base” and “Civic Psychological Warfare”—which are counter-guerrilla tactics employed by the Korean military during the Vietnam War—with Zero Trust Architecture and organizational internal security governance, respectively.
해상 사이버 위협에 대비한 해양경찰의 대응 방안 KCI 등재
한국해양경찰학회 한국해양경찰학회보 제16권 제1호 통권 제48호 2026.02 pp.153-177
※ 기관로그인 시 무료 이용이 가능합니다.
6,300원
해양 공간의 디지털화와 정보시스템 의존도의 증가는 해상 안전과 질서 유지에 새로운 위험 요인으로서 사이버 위협을 증가시키고 있다. 해상 사이버 위협은 선박 운항·관리 시스템, 해상 정보·통신 인프라, 항만 운영 시스템 등 해상 운용 구조 전 반과 연계되어 발생하며, 그 영향은 개별 침해 사건을 넘어 해양치안의 대상과 작동 방식에 구조적 변화를 초래하고 있다. 이러한 변화는 해양치안을 기존의 물리적 공 간 중심 관리에서 정보·시스템 환경을 포괄하는 관리 체계로 확장시키고 있다. 이 연구는 해상 사이버 위협을 해양치안의 핵심 과제로 인식하고, 해상 사이버의 개념과 기술적 특성, 침해 사례 및 위협 유형을 분석하였다. 나아가, 해양경찰 조직 의 운영 실태와 해외 대응 동향을 종합적으로 검토하여 해양경찰의 대응 역량 강화 방안을 제시하는 것을 목적으로 한다. 이를 위해 문헌 분석과 정보공개청구 자료 분 석을 병행하였으며, 국내외 해상 사이버 침해 사례와 국제기구 및 주요 국가의 대응 체계를 비교·분석하였다. 연구 결과, 해양경찰은 해상 사이버 위협에 대한 제도적 대응을 시작한 단계에 있 으나, 조직체계, 전문 인력, 예산, 수사·예방 역량 측면에서 보완이 필요한 것으로 나 타났다. 이에 이 연구는 조직체계의 정비, 전문 인력 및 예산 기반 확충, 수사·예방 역량 강화, 다기관 협력 거버넌스 구축이라는 네 가지 측면에서 해양경찰 조직 차원의 대응 방안을 제시하였다. 이 연구는 해상 사이버 위협을 기술적 문제에 국한하지 않고 해양치안의 구조적 변화로 분석함으로써, 향후 해양경찰의 역할 정립과 해상 사이버 보안 정책 수립을 위한 기초 자료를 제공한다는 점에서 의의를 가진다.
The increasing digitalization of the maritime domain and the growing reliance on information systems have highlighted cyber threats as a significant risk to maritime safety and order. Maritime cyber threats are closely linked to ship operation and management systems, maritime information and communication infrastructures, and port operation systems, and their impact extends beyond individual incidents to bring about structural changes in the scope and functioning of maritime security. These changes call for an expansion of maritime security from a physical-space-centered approach to a comprehensive management framework that includes information and system environments. This study aims to examine maritime cyber threats as a core issue of maritime security and to propose measures to strengthen the response capacity of the maritime police. To this end, the study analyzes the concept and technical characteristics of maritime cyber threats, examines cyber incident cases and threat types, and reviews the operational status of the maritime police along with overseas response trends. The research employs a combination of literature review and analysis of information disclosed through official information requests, as well as a comparative analysis of international organizations and major countries’ response frameworks. The findings indicate that while the maritime police have begun to establish institutional responses to maritime cyber threats, there remain limitations in organizational structure, specialized personnel, budget allocation, and investigative and preventive capabilities. Accordingly, this study proposes organizational-level response measures focusing on four aspects: restructuring the organizational framework, strengthening personnel and budgetary foundations, enhancing investigative and preventive capacities, and establishing multi-agency cooperative governance. By approaching maritime cyber threats as a structural transformation in maritime security rather than a purely technical issue, this study provides foundational insights for future policy development and the role of the maritime police in addressing maritime cyber security.
PDCA 방법론을 활용한 인공지능 기반 피싱탐지 및 차단에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제25권 제5호 2025.12 pp.145-150
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
디지털 환경의 확산과 함께 피싱 및 스미싱 공격이 지능화·고도화되면서 개인정보 유출과 금전적 피해가 지속적으로 증가 하고 있다. 기존의 피싱 사이트 차단 방식은 신고 기반 또는 규칙 기반의 수동적 대응에 의존하고 있어, 신규 및 변종 피싱 공 격에 효과적으로 대응하는 데 한계가 있다. 이에 본 연구는 능동적인 피싱 사이트 탐지 및 차단을 위해 PDCA(Plan–Do– Check–Act) 방법론을 적용한 인공지능 기반 피싱 탐지 방법을 제안한다. 본 연구에서는 앙상블 학습 기반의 XGBoost 머신 러닝 알고리즘을 활용하여 정상 사이트와 피싱 사이트를 분류하였다. URL 구조, 도메인 및 보안 설정, 콘텐츠 특성 등을 반영 한 37개의 특징을 선정하여 총 20,171개의 데이터셋을 학습에 활용하였다. PDCA 방법론을 통해 모델 설계, 학습, 성능 검증 및 개선 과정을 체계적으로 수행한 결과, 학습 데이터에 대해 97.2%의 정확도를 보였으며, 학습에 사용되지 않은 20,417개의 피싱 사이트 데이터에 대해 98.1%의 차단률을 기록하였다. 본 연구는 머신러닝 기반 탐지 모델에 PDCA 기반의 지속적 개선 구조를 결합함으로써, 실제 운영 환경에서 변화하는 피싱 공격에 효과적으로 대응할 수 있는 실용적인 피싱 탐지 및 차단 방 법을 제시한다.
As digital services continue to expand, phishing and smishing attacks have become increasingly sophisticated, resulting in a steady rise in personal data breaches and financial losses. Conventional phishing website blocking methods primarily rely on manual or rule-based approaches, which are insufficient for detecting newly emerging and evolving phishing attacks. To overcome these limitations, this study proposes an artificial intelligence-based phishing detection and blocking approach incorporating the PDCA (Plan–Do–Check–Act) methodology. An ensemble learning-based XGBoost machine learning algorithm was employed to classify phishing and legitimate websites. A total of 37 features related to URL structure, domain and security configurations, and content characteristics were selected, and a dataset of 20,171 samples was used for model training. By applying the PDCA methodology, the processes of model planning, training, performance evaluation, and continuous improvement were systematically managed. Experimental results showed an accuracy of 97.2% on the training dataset and a blocking rate of 98.1% on an unseen dataset consisting of 20,417 phishing websites. The key contribution of this study lies in integrating a machine learning-based detection model with a PDCA-driven continuous improvement framework, enabling sustainable performance enhancement and effective adaptation to evolving phishing attack patterns in real-world environments.
항공정비 인력의 보안역할과 주요 리스크 대응에 관한 연구 KCI 등재
한국항공보안학회 항공보안·안전 거버넌스(구 한국항공보안학회지) Vol. 7 No. 2 2025.12 pp.143-159
※ 기관로그인 시 무료 이용이 가능합니다.
5,100원
항공기 정비 인력은 항공기의 감항성을 보장하는 데 핵심적인 역할을 수행하는 동시에 정비 오류, 사이버 위협, 규정 준수 문제 등 다양한 위험에 직면한다. 본 논 문은 항공기 정비 분야의 항공 안전 및 보안에 대해 논의하고, 항공 보안 분야에서 정비 인력의 핵심적인 역할을 제시한다. 또한, 정비 인력의 항공 보안 강화를 위한 지침으로 "항공기 정비 보안 5계명"을 제안하고, 그 중요성과 실제 적용 방안을 강 조한다. 본 연구는 각 계명의 실질적인 의미를 분석하고 실제 정비 업무와 연관시켜 정비 품질 향상 및 항공 보안 강화를 위한 실행 가능한 전략을 제시한다.
Aviation maintenance personnel play a critical role in ensuring the airworthiness of aircraft, while also facing various risks such as maintenance errors, cyber threats, and compliance issues. This paper discusses aviation safety and security in the aircraft maintenance field, and shows the key role of maintenance personnel in aviation security. In addition, it lists the “Five Commandments for Aviation Maintenance Security” as a guideline for enhancing aviation security for maintenance personnel, and emphasizes their importance and practical application. This study examines the practical meaning of each commandment and connects it to actual maintenance work, thereby suggesting actionable strategies to improve maintenance quality and enhance aviation security.
Non-invasive BCI-powered adaptive authentication system impediment for HMDs
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 학술대회 ICNGC 2025 The 11th International Conference on Next Generation Computing 2025 2025.12 pp.303-306
Metaverse, our virtual reality, is traversed via an Avatar linked to a user profile through Personal Identifiable Information (PII). To secure this PII from causing attacker infiltration, only authorised users should access these avatars permitted by the authentication systems. The authentication systems are researched to be resilient against attackers’ manipulations. These systems rely on dynamic and real-time sensor data rather than static information from the user for authentication. Dynamic sensor data captured through Head Mounted Displays (HMDs) is highly classifiable with Machine learning (ML) and Deep Learning (DL) algorithms. Over time, the model training requires an upgrade through evolution in data processing and learning. Self-learning —Adaptive learning can lead this system to transform with its learn-evolve-adapt learning strategy. Therefore, our study attempts to explore authentication systems developed for HMDs, capturing realtime dynamic sensor data. With its results, we concluded that these systems are highly sensitive while processing the sensor data. We list out the risk factors of utilising adaptive learning for an authentication system based on neurometric data combined with biometric data. This study will be the state of the art for the self-learning algorithms for biometric and neurometric data-based authentication systems.
Neurometric Authentication System : Limitless Adaptability for Avatars in Metaverse Environment
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 학술대회 ICNGC 2025 The 11th International Conference on Next Generation Computing 2025 2025.12 pp.274-277
In the metaverse-- the threat verse, the user identity security is not suffice. The user identities linked to the traversing avatars utilize biometric authentication to authenticate and dictate their actions in the metaverse. Biometric authentication demands input in the form of facial, voice, iris/gaze, and physiological behavioural patterns for its user. Additionally, combining these biometrics with neurometrics for enhanced authentication is being explored. These Neurometric-based authentication systems are less discovered due to their complexity and practicality. However, these systems are stabilized by consuming the Artificial Intelligence (AI) Model Fusion. These systems are unprobed towards their sustainability, security, and usability. Therefore, we attempted to explore the Neurometric-based authentication systems stabilized with AI model fusions. We acutely examined these systems’ infrastructure and its susceptibility to existing threats. This led us to introduce the absent components to be included in the system infrastructure to increase its potential towards probable threats. However, we conclude our study exploring this new direction of possibilities for a Neurometricbased authentication system for the virtual world environment.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.