Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 66
No
1

4,000원

국가는 전통적으로 국토를 방위하고 국민의 생명과 재산을 보호하는 사명을 가지고 있으며, 이러한 방위의 범위는 지상, 공중, 바다, 우주에 이어 제5의 영역인 사이버 영역을 포함한다. 사이버 영역으로 국가 방위의 범위가 확대 되었지 만, 사이버 영역에 있어서는 국가보다는 민간이 더 많은 사이버 관련 출처와 수집수단을 보유하는 정보역전 현상 때문에 정부 주도의 사이버 영역 방위에 어려움을 겪고 있다. 이를 해결하기 위해, 본 논문에서는 먼저 사이버위협정보를 정의하고 그 특성을 분석하였다. 다음으로 정보역전 현상을 극복하기 위한 각국의 노력과 우리나라의 현 주소를 조사하였고, 그 결과 를 바탕으로 정부 주도의 사이버 방위를 위한 국가정보기관의 역할과 사이버위협정보의 민간 공유 모델을 제안하였다. 제 안된 모델을 국가정보기관에서 활용한다면 사이버위기에 보다 효과적으로 대응할 수 있는 기반 체계가 마련될 것을 기대해 볼 수 있다.

The role of government is to defend its lands and people from enemies. The range of that defense has now extended into the cyber domain, regarded as the fourth domain of the conventional defense domains (i.e., land, sea, sky, and universe). Traditionally, a government’s intelligence power overrides that of its civilians, and government is exclusively responsible for defense. However, it is difficult for government to take the initiative to defend in the cyber domain because civilians already have a greater means for collecting information, which is known as being “intelligence inverse” in the cyber domain. To this end, we first define the intelligence inverse phenomenon and then analyze its main features. Then we investigate foreign countries’ efforts to overcome the phenomenon and look at the current domestic situation. Based on these results, we describe the appropriate role of the National Intelligence Agency to handle cyber threats and offer a cyber threat intelligence model to share with civilians to help protect against these threats. Using the proposed model, we propose that the National Intelligence Agency should establish a base system that will respond to cyber threats more effectively.

2

빅데이터/클라우드 기반 미래 C4I체계 사이버위협 관리체계 적용 방안 연구 KCI 등재

박상준, 강정호

한국융합보안학회 융합보안논문지 제20권 제4호 2020.10 pp.27-34

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 4차 산업혁명 기술은 기술발전을 통해 일상생활을 크게 바꾸고 있을 뿐 아니라 국방정책 수립에 있어서도 주요 키워드가 되어 가고 있다. 특히 ICBMS라 불리는 사물인터넷, 클라우드, 빅데이터, 모바일, 사이버보안 기술은 인공지능 과 더불어 국방정보화정책의 핵심선도기술로 선정되었다. 4차 산업혁명 기술의 중요성이 증대되는 가운데 현재 KJCCS, ATCIS, KNCCS, AFCCS 등 합참 및 각 군 기능별로 분리 운용되고 있는 C4I체계를 미래전에 대비하는 하나의 체계로 개발하기 위한 연구가 추진되고 있다. 이는 C4I체계를 각 도메인별로 운용함에 따라 정보교환 등 합동작전을 위한 상호 운용성이 저하되는 문제를 해소하기 위함이다. 또한 각종 무기체계들이 초연결 및 초지능화 체계로 개발이 추진되고 있 어 이들을 효율적으로 통제하고 안전하게 운용하기 위해 통합C4I체계 구축과 미군의 RMF(Risk Management Framewo rk) 같은 체계의 도입이 필수적이다. 따라서 본 논문에서는 빅데이터/클라우드 기반의 미래 C4I체계의 사이버위협 지능 화 탐지 및 사용자 정보 접근권한 관리, 사이버위협의 지능화 관리 및 가시화 방안을 제시한다.

Recently, the fourth industrial revolution technology has not only changed everyday life greatly through technological development, but has also become a major keyword in the establishment of defense policy. In particular, Internet of Things, cloud, big data, mobile and cybersecurity technologies, called ICBMS, were selected as core leading technologies in defense information policy along with artificial intelligence. Amid the growing importance of the fourth industrial revolution technology, research is being carried out to develop the C4I system, which is currently operated separately by the Joint Chiefs of Staff and each military, including the KJCCS, ATCIS, KNCCS and AFCCS, into an integrated system in preparation for future warfare. This is to solve the problem of reduced interoperability for joint operations, such as information exchange, by operating the C4I system for each domain. In addition, systems such as the establishment of an integrated C4I system and the U.S. military's Risk Management Framework (RMF) are essential for efficient control and safe operation of weapons systems as they are being developed into super-connected and super-intelligent systems. Therefore, in this paper, the intelligent cyber threat detection, management of users' access to information, and intelligent management and visualization of cyber threat are presented in the future C4I system based on big data/cloud.

3

효과적인 데이터 공유를 위한 계층적 구조를 갖는 사이버 보안 데이터 공유시스템 모델 연구 KCI 등재

유호제, 김찬희, 조예림, 임성식, 오수현

한국융합보안학회 융합보안논문지 제22권 제1호 2022.03 pp.39-54

※ 기관로그인 시 무료 이용이 가능합니다.

4,900원

최근 지능화·고도화되는 사이버 위협에 효과적으로 대응하기 위해 다양한 사이버 보안 데이터의 수집, 분석, 실시간 공유의 중요성이 대두되고 있다. 이러한 상황에 대응하기 위해 국내에서는 사이버 보안 데이터 공유시스템의 확대를 위해 노력하고 있지만, 많은 민간 기업들은 사이버 보안 데이터를 수집하기 위한 예산과 전문 인력의 부족으로 인해 사이버 보안 데이터 공 유시스템에 참여가 어려운 상황이다. 이러한 문제를 해결하기 위해 본 논문에서는 현존하는 국·내외 사이버 보안 데이터 공유 시스템의 연구·개발 동향을 분석하고 이를 기반으로 조직 규모를 고려하여 계층적 구조를 갖는 사이버 보안 데이터 공유시스 템 모델과 해당 모델에 적용할 수 있는 단계별 보안정책을 제안한다. 본 논문에서 제안하는 모델을 적용할 때 다양한 민간 기 업들이 사이버 보안 데이터 공유시스템에 참여하는 것을 확대할 수 있으며, 지능화되고 있는 보안 위협에 신속하게 대처할 수 있는 대응체계 마련에 활용할 수 있을 것으로 기대한다.

Recently, the importance of collecting, analyzing, and real-time sharing of various cybersecurity data has emerged in order to effectively respond to intelligent and advanced cyber threats. To cope with this situation, Korea is making efforts to expand its cybersecurity data sharing system, but many private companies are unable to participate in the cybersecurity data sharing system due to a lack of budget and professionals to collect cybersecurity data. In order to solve such problems, this paper analyzes the research and development trends of existing domestic and foreign cyber security data sharing systems, and based on that, propose a cybersecurity data sharing system model with a hierarchical structure that considers the size of the organization and a step-by-step security policy that can be applied to the model. In the case of applying the model proposed in this paper, it is expected that various private companies can expand their participation in cybersecurity data sharing systems and use them to prepare a response system to respond quickly to intelligent security threats.

4

4,000원

제4차 산업혁명 시대가 진전되어 정보통신기술이 획기적으로 발전하면서 사이버위협은 점점 더 지능적이고 고도화될 것이다. 그렇기 때문에 그 위협에 대한 대비책을 마련하면서 사고가 발생할 경우에도 체계적이고 신속한 조치를 취하기 위해서는 정보기관의 역할이 중요하다고 할 것이다. 그러나 우리나라는 이와 관련된 ‘국가사이버안보법안’ 제정이나 「국가정보원법」개정에 대한 논의가 지지부진하여 사이버위협을 대응하는데 어려움이 있는 실정이다. 이에 본 논문에 서는 현행 법 체계상 정보기관의 사이버안보 기능, 최근의 법 제ㆍ개정 논의 동향과 우리 실정에 맞는 정보기관의 역할 에 대한 시사점을 살펴본 후 향후 사이버안보 수행체계 보강을 위한 정보기관의 역할 정립 방안으로 사이버안보에 관한 첩보수집․분석 집중, 사이버위협 예측ㆍ대응역량 제고, 법과 원칙 준수를 위한 법적 토대 구축 등을 제시하고자 한다.

As the era of the 4th Industrial Revolution has progressed and the information and communication technologies have developed dramatically, the cyber threats will gradually become more intelligent and sophisticated. Therefore, in order to take systematic and prompt action in case of an accident while preparing measures against the threat, the role of intelligence agency is important. However, Korea is having difficulty in responding to the threats due to the lack of support for the national cybersecurity bill or the amendment bill of the National Intelligence Service. In this paper, I examine the cybersecurity function of the intelligence agency, the recent debate trends, and implications for the role of intelligence agency in our current situation. And then I intend to suggest some measures such as concentration on information gathering and analysis, enhancement of cyber threat prediction and response capacity, and strengthening of legal basis as a way to establish the role of intelligence agency for reinforcement of cybersecurity performance system.

5

Context-aware cyber-threat attribution based on hybrid features

Irshad Ehtsham, Siddiqui Abdul Basit

[NRF 연계] 한국통신학회 ICT Express Vol.10 No.3 2024.06 pp.553-569

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

With the rapid technological development, identifying the attackers behind cyber-attacks is getting more sophisticated. To cope with this phenomenon, the current process of cyber-threat attribution includes features like tactics techniques and procedures (TTP), tools, target country/ company and application. They do not include attacker context and motives; thus, they demand more refined traits. Adding behavioral features to this process is essential to better understand the attacker’s context, motivations and goals. This research study accentuates the impact of adding behavioral features with existing technical features in determining the actual actor. The behavioral features are extracted from Threat actor encyclopedia, a dataset published by Thai CERT. This research investigation also analyzes the impact of hybrid features (technical & and behavioral). For this procedure, the best features are chosen by implementing feature selection techniques. For empirical results, we use the threat actor encyclopedia, a data set published by Thai Cert, for extraction of behavioral attributes. With this augmentation, we achieve elevated results of 97%, 98.8%, 97%, and 97.2% in terms of accuracy, precision, recall and F1-measure using machine/deep learning algorithms.

6

Multi-stage crypto ransomware attacks: A new emerging cyber threat to critical infrastructure and industrial control systems

Aaron Zimba, Zhaoshun Wang, Hongsong Chen

[NRF 연계] 한국통신학회 ICT Express Vol.4 No.1 2018.03 pp.14-18

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The inevitable integration of critical infrastructure to public networks has exposed the underlying industrial control systems to various attack vectors. In this paper, we model multi-stage crypto ransomware attacks, which are today an emerging cyber threat to critical infrastructure. We evaluate our modeling approach using multi-stage attacks by the infamous WannaCry ransomware. The static malware analysis results uncover the techniques employed by the ransomware to discover vulnerable nodes in different SCADA and production subnets, and for the subsequent network propagation. Based on the uncovered artifacts, we recommend a cascaded network segmentation approach, which prioritizes the security of production network devices.

7

4,000원

With the increase in cyber data attacks, the manual method of investigating cyber-attacks is more prone to errors and is time consuming. With the increase in advanced cyber threat attacks with the same patterns, timely investigation is not possible. There are many systems proposed which analyse and predict threats using various machine learning methods. In this various models apply machine learning algorithms to analyse and predict cyber-attacks.

8

The use of social engineering has become the primary cause of security breaches in the digital world, where it takes advantage of human nature instead of the weaknesses in technology. Social engineering, unlike a normal hacker, uses charm, lies, and psychological stress on the victim to get him/her to reveal confidential information. This research uncovers deceiving tactics used in social engineering to examine the main attack vectors like phishing, pretexting, quid pro quo, baiting, and tailgating, and to show the effect of these tactics on companies. It cites examples of the past to convince the reader to resort to the solution of awareness programs, well-structured security policies, and staff training to counter the threat.

9

5,500원

Is cyber terrorism the threat to modern society? Not only has the socio- and geo-political climate changed dramatically in the last decade, but there has also been a technological change with the advent of the ‘information revolution’. Governments all over the world are trying to protect critical national infrastructure from a new apolitical threat, yet they are not able to agree upon a common cyber-threat vocabulary. This paper compares two different approaches to combatting the cyber threat and underlines their common understanding yet different articulation of what constitutes cyber terrorism. The central argument of the paper is that cyber terrorism against critical national infrastructure is not presently a great threat but perceptions of it make it a useful tool in securing financial interests and controlling domestic populations.

10

사이버 위협 중심의 국방 사이버 방호수준 분석에 관한 연구 KCI 등재

최세호, 오행록, 윤주범

한국융합보안학회 융합보안논문지 제21권 제4호 2021.10 pp.77-85

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

사이버 방호란 사이버 공격 및 위협으로부터 우리가 운영하는 정보시스템을 보호하는 활동[1]이다. 현재 운영중인 사이버 방호체계의 방호수준을 알기 위해서는 시시각각 새롭게 발전하고 있는 사이버 위협을 반영하여 공격기술 현 황을 최신화하고 방호기능으로 대응이 가능한지 분석할 필요가 있다. 이에 본 논문에서는 사이버 킬 체인의 공격절 차와 방어유형으로 분류한 공격기술을 MITRE의 방어기술(Mitigation ID)과 연관 관계를 분석하고 방어적 사이버활 동 중심으로 군 부대 유형별 사이버 방호수준을 제시하고자 한다. 향후 국방영역에서 운영중인 사이버 방호체계의 대응역량을 실시간 분석하여 부대별 방호수준을 가시화하고 알려지지 않은 사이버 위협에 대한 조사 및 적극적인 취약점 보완을 통해 사이버 방호수준이 향상되길 기대한다.

Cyber protection is an activity that protects the information systems we operate from cyber attacks and threats. To know the level of protection of the currently operating cyber protection system, it is necessary to update the current state of attack technology by reflecting the constantly evolving cyber threats and to analyze whether it is possible to respond with the protection function. Therefore, in this paper, we analyze the relationship between the attack procedures and defense types of the cyber kill chain with the defense technology(Mitigation ID) of MITRE and present the cyber protection level for each military unit type with a focus on defensive cyber activities. In the future, it is expected that the level of cyber protection will be improved through real-time analysis of the response capabilities of cyber protection systems operating in the defense sector to visualize the level of protection for each unit, investigate unknown cyber threats, and actively complement vulnerabilities.

11

순환형 사이버 위협 생애주기를 반영한 LLM 기반 RMF 위협 시나리오 생성 모델 연구 KCI 등재

신수철, 김민정, 서용석

한국융합보안학회 융합보안논문지 제25권 제5호 2025.12 pp.21-28

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

현대 사이버 환경에서 위협은 기술 및 운영 환경의 변화와 결합하며 소멸되지 않고 잠복과 재등장을 반복하는 순환형 생애 주기 구조를 보인다. RMF(Risk Management Framework)는 전통적으로 공격표면을 중심으로 위협을 식별·관리해 왔으나, 생 성형 AI의 등장으로 위협의 생성·변형·확산 속도와 규모가 급격히 증가하면서 기존의 정적·문서 기반 위협 시나리오 관리 방 식은 한계에 직면하고 있다. 생성형 AI는 위협 생애주기 단계와 공격표면 간 전이를 반영한 시나리오 생성, 환경 변화에 따른 공격표면 재구성, 반복적 위험 평가의 자동화를 가능하게 한다. 이에 본 연구는 순환형 사이버 위협 생애주기를 반영한 AI 적 합형 RMF 위협모델링 구조를 재정의하고, 생성형 AI 기반 Threat Scenario Generation Pipeline을 제안함으로써 보다 신속하 고 일관된 위협 관리 프레임워크를 제시하고자 한다.

In modern cyber environments, threats do not simply disappear but instead persist through cycles of dormancy and re-emergence as they interact with evolving technologies and operational conditions. The Risk Management Framework (RMF) has traditionally managed threats by focusing on the attack surface; however, the advent of generative AI has dramatically increased the speed, scale, and variability of threat generation, transformation, and propagation. As a result, conventional static and document-centric threat scenario management approaches face significant limitations. Generative AI enables the automated generation of threat scenarios that reflect transitions across threat lifecycle stages and attack surfaces, dynamic reconfiguration of attack surfaces in response to environmental changes, and iterative risk assessment automation. Accordingly, this study redefines an AI-adaptive RMF threat modeling structure that incorporates a cyclic cyber threat lifecycle and proposes a generative AI-based Threat Scenario Generation Pipeline, providing a more timely and consistent framework for cyber threat management.

12

네트워크 분석을 활용한 복합체계 사이버 위협 영향성 평가 방안 KCI 등재

김대환

한국융합보안학회 융합보안논문지 제25권 제1호 2025.03 pp.259-268

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

2024년에도 다양한 사이버 위협이 급증하였다. 다수의 사이버 위협이 동시다발적으로 발생하면 사이버 보안관제를 담당하 는 부서 및 담당자, 그리고 의사결정권자는 사이버 위협의 영향성을 검토·평가하고 대응 우선순위 수립하여 대응계획을 조치 한다. 사이버 위협의 영향성을 검토하고 평가하는 방법론은 다양하게 개발되어 적용되고 있다. 대부분 사이버 위협이 발생한 정보체계만을 대상으로 영향성 분석·평가를 수행하고 있다. 하지만 최근 정보체계는 다수 정보체계를 연동 및 상호운용하는 복합체계(System of Systems, SoS)로 개발 및 운영한다. 이에 대한 반영이 제한되어 복합체계를 구성하는 특정 체계에 대한 사이버 위협의 영향성을 과대 또는 과소 평가되는 문제가 있다, 그러므로 전체 복합체계 관점에서 사이버 위협이 미치는 영향 성 분석·평가하는 방법론이 요구되어, 본 논문은 MND-AF를 참조하여 복합체계를 구성하는 체계 간 연동 및 상호운용 관계 를 식별하고, 네트워크 분석을 적용하여 가용성, 무결성, 기밀성 측면에서 사이버 위협의 영향성을 정량적으로 분석·평가하는 방법을 제안한다.

In 2024, various cyber threats will continue to increase rapidly. When multiple cyber threats occur simultaneously, departments and personnel in charge of cyber security control and decision makers will review and evaluate the impact of cyber threats, establish response priorities, and take action on response plans. Methodologies for reviewing and evaluating the impact of cyber threats have been developed and applied in various ways. Most of the time, impact analysis and evaluation are conducted only on the information system where the cyber threat occurred. However, recent information systems are developed and operated as a System of Systems (SoS) that interconnects and interoperates multiple information systems. There is a problem that the impact of cyber threats on specific systems that make up the complex system is overestimated or underestimated due to limited reflection of this. Therefore, a methodology for analyzing and evaluating the impact of cyber threats from the perspective of the entire complex system is required. This paper proposes a method to identify the interconnection and interoperability relationships between systems that make up the complex system by referring to MND-AF, and to quantitatively analyze and evaluate the impact of cyber threats in terms of availability, integrity, and confidentiality by applying network analysis.

13

정보보안 위험관리를 활용한 사이버 위협 군사 대응 전략 KCI 등재

유진철

한국융합보안학회 융합보안논문지 제23권 제5호 2023.12 pp.173-179

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

제4차 산업혁명 기술은 현재 우리 군이 처한 병력 감축과 국방예산 감소라는 장애물을 넘어 초연결 초지능화된 네트 워크 중심 작전 환경을 구축하는 해결책으로 대두되고 있다. 그러나 최신 정보기술에 대한 복잡성 증대와 기 운용중인 정보시스템과의 영향성 검증을 포함한 전체적인 위험관리가 미흡하여 시스템 무결성과 가용성에 심각한 위협을 초래하 거나 시스템 간 상호운용성에 부정적 영향을 끼침으로서 임무 수행을 저해할 수 있다. 본 논문에서 우리는 정보기술의 발전에 따라 발생할 수 있는 사이버 위협으로부터 군 정보화 자산을 보호하기 위해 미국의 정보보안 위험관리에 대한 내용의 고찰을 통해 우리 군이 사이버 위협에 대비하기 위한 사이버 위협 대응 전략을 제시하고자 한다.

The 4th Industrial Revolution technology has emerged as a solution to build a hyper-connected, super-intelligent network-oriented operational environment, overcoming the obstacles of reducing troops and defense budgets facing t he current military. However, the overall risk management, including the increase in complexity of the latest inform ation technology and the verification of the impact with the existing information system, is insufficient, leading to s erious threats to system integrity and availability, or negatively affecting interoperability between systems. It can be inhibited. In this paper, we suggest cyber threat response strategies for our military to prepare for cyber threats by examining information security risk management in the United States in order to protect military information assets from cyber threats that may arise due to the advancement of information technology.

14

국내 사이버위협 정보공유 확산 방안에 관한 연구 - 국내 정보보호 산업 생태계 활성화를 중심으로 - KCI 등재

윤준희, 허지용, 김화경, 신용태

한국융합보안학회 융합보안논문지 제23권 제5호 2023.12 pp.35-43

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

디지털 인프라가 증가하면서 모든 영역에서 연결과 융합이 빠른 속도로 진행되고 있는 가운데 국가 성장 지속을 위해 사이버 침해, 즉 해킹으로부터 안전을 담보하는 것이 무엇보다 중요하다. 이에 사이버침해 대응의 기본이 되는 사이버위협 정보공유에 있어서 저해 요인들을 살펴보고 효율성을 제고할 수 있는 방안을 제시한다. 우선 정보공유에 있어서 정부, 정보보호업체, 중소 기업‧개인 3개 분야로 구분하고 분야별의 입장에서 요구사항을 확인한다. 이를 보완하고 상호 간에 사이버 보안 강화 및 경제적 이득이 될 수 있는 방안을 모색해본다. 그리하여 정부는 사이버위협 정보 출처 다변화, 중소기업‧개인은 사이버보안의 강화, 정보 보호업체는 수요가 창출되는 ‘사이버위협 정보공유 → 중소기업‧개인 사이버보안 강화 → 정보보호 산업 수요창출’로 이어지는 선순환 구조의 정보보호 산업 생태계가 조성되도록 정책을 제안하고자 한다. 연구결과는 국가 사이버안보 강화를 위한 정책 수립에 도움이 되기를 기대한다

As digital infrastructure increases connections and convergence progress rapidly in all areas, and it is most important to ensure safety from cyber infringement or hacking to continue national growth. Accordingly, it examines the obstacles to cyber threat information sharing, which is the basis for responding to cyber infringement, and suggests ways to improve efficiency. First of all, information sharing is divided into three areas: the government, cyber security companies, small and medium-sized enterprises and individuals and the requirements are checked from their respective positions. We will supplement this and explore ways to strengthen cybersecurity and provide economic benefits to each other. Therefore, national and public organizations will propose policies to create an cybersecurity industry ecosystem with a virtuous cycle that leads to diversification of cyber threat information sources, strengthening cybersecurity for general companies and individuals, and creating demand for the cybersecurity industry. The results of the study are expected to help establish policies to strengthen national cybersecurity.

15

사이버 위협정보 공유체계 구축방안에 관한 연구 - 미국 사례를 중심으로 - KCI 등재

김동희, 박상돈, 김소정, 윤오준

한국융합보안학회 융합보안논문지 제17권 제2호 2017.06 pp.53-68

※ 기관로그인 시 무료 이용이 가능합니다.

4,900원

오늘날 정보공유는 점차 지능화, 고도화되어 나타나고 있는 사이버공격을 효과적으로 예방할 수 있는 수단으로 인식되어 미국, EU, 영국, 일본 등 전세계적으로 국가적 차원의 사이버 위협정보 공유체계를 구축하고 있다. 특히 미국은 지난 2015년 12월 사이버위협정보공유법(CISA) 을 제정하는 등 오래전부터 위협정보 공유를 위한 법 제도 기반 마련, 수행체계 구축 이행을 추진해오고 있다. 우리나라는 국가사이버안전센터와 한국인터넷진흥원을 중심으로 각각 공공, 민간분야에서 사이버 위협정보를 수집, 공유하고 있으며 관련 법 제도의 도입 시행을 통한 일원화된 정보공유 절차의 마련과 수행체계 구축을 추진 중에 있으나, 사이버 위협정보 공유 과정에서 발생할 수 있는 기업 또는 개인의 민감정보 유출문제, 정보수집 관리 주체에 대한 신뢰, 효용성 등의 문제의 우려도 제기되고 있는 실정이다. 본 논문에서는 미국과우리나라의 사이버 위협정보 공유 현황의 비교 분석을 통해 향후 우리나라의 성공적인 사이버 위협정보 공유 체계정착이 이루어지는데 필요한 요구사항 및 시사점을 도출해보고자 한다.

Today, information sharing is recognized as a means to effectively prevent cyber attacks, which are becoming more intelligent and advanced, so that many countries such as U.S., EU, UK, Japan, etc. are establishing cyber threat information sharing system at national level. In particular, the United States has enacted the "Cyber Threat Information Sharing Act (CISA)" in December 2015, and has been promoting the establishment of a legal and institutional basis for sharing threat information and the implementation of the system. Korea is sharing cyber threat information in public and private sectors mainly through the National Cyber Security Center(NCSC) and the Korea Internet & Security Agency(KISA). In addition, Korean government is attempting to strengthen and make legal basis for unified cyber threat information sharing system through establishing policies. However, there are also concerns about issues such as leakage of sensitive information of companies or individuals including personal identifiable information that may produced during the cyber threat information sharing process, reliability and efficiency issues of the main agents who gather and manage information. In this paper, we try to derive improvement plans and implications by comparing and analyzing cyber threat information sharing status between U.S. and Korea.

16

5,800원

4차 산업혁명 시대를 맞이하면서 ICT의 발전과 함께 지능적이고 고도화된 새로운 공격 이 증가하고 있다. 사이버 위협 인텔리전스 시스템은 사이버 위협에 대한 정보를 수집하고 이를 통해 능동적인 대응을 위한 분석 및 정보 공유를 하는 시스템이다. 사이버 위협 인텔 리전스 공유는 사이버 보안 공격에 대응하는 데 도움이 되는 중요한 자원으로 간주한다. 하지만 프라이버시, 법 정책적 과제 및 공유 비용에 대한 문제들과 같이 효과적인 사이버 위협 인텔리전스 공유를 개선해야 할 많은 과제가 존재한다. 이러한 문제를 해결하기 위해 수해 된 최근 추세 중 하나는 블록체인 기반의 공유 아키텍처를 사용하는 것이다. 하지만 이러한 플랫폼은 공유 효율성을 높이는 데 도움이 될 수 있지만, 위의 모든 문제를 완전히 해결하지는 못한다. 특히 신뢰와 관련된 문제는 현재의 접근 방식으로 만족스럽게 해결되 지 않는다. 이에 본 논문에서는 기존 방식과 다르게 사이버 위협 인텔리전스 공유의 신뢰 문제를 해결하기 위해 블록체인 기술 적용 방안을 연구하였다. 이를 통해 이에 국내 사이 버 위협 인텔리전스의 블록체인 기술 활용 가능성을 확인한다. 특히 새로운 공유 프로세스 를 통해 신뢰성 향상 가능성을 제공하면서 블록체인 기술의 특징을 통해 공유 시스템의 신뢰성 향상을 위한 방향성을 제시하고자 한다.

With the coming of the fourth industrial revolution, new threats using advanced intelligence are increasing due to ICT development. Cyber threat intelligence systems collect, analyze and share the information about cyber threats for an active response. The initial role of cyber threats intelligence systems is to maximize each node's threat response capabilities through information sharing. Because of this approach, the cyber threat intelligence system is considered as a crucial factor for the next-generation security strategy to respond to advanced cyber threats effectively. However, many problems need to be addressed to operate cyber threat intelligence systems effectively. In particular, trust-related issues are not satisfactorily solved by current approaches. Thus, this paper will investigate how to apply blockchain technology to solve cyber threat intelligence sharing's trust problem, unlike conventional methods. Through this approach, it will discuss the possibility of using blockchain technology cyber threat intelligence. In particular, we want to present directions for improving the reliability of shared systems through blockchain technology's characteristics while providing the possibility of enhancing reliability through the new sharing process.

17

주요국의 사이버위협정보 공유체계 분석을 통한 국내 적용모델 연구 KCI 등재

윤오준, 조창섭, 박정근, 배선하, 신용태

한국융합보안학회 융합보안논문지 제16권 제7호 2016.12 pp.101-111

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

최근 정부 주요인사 대상 스마트폰 해킹과 인터파크사 고객정보 탈취 등 사이버위협은 이제 우리에게 현실적인 위협 으로 다가오고 있고 이러한 위협은 사물인터넷 시대 도래로 인해 더욱 고도화될 것이며 이에 대응하기 위해 민·관간 사이 버위협정보 공유에 대한 체계 정립은 반드시 필요하다. 미국·일본·영국 등 주요국은 공유기구를 설치하고 관련대책을 수 립·시행하는 등 사이버위협정보 공유제도를 정착시켜 나가고 있으나, 우리나라는 몇 개 기관이 공유센터를 자체 구축하여 운영하고 있고 참여기관간 정보의 제공과 공유에 있어 불균형이 존재하는 등 제도적인 미흡으로 활성화가 되지 못하고 있는 실정이다. 이에 나날이 진화하는 사이버위협에 효과적으로 대응하기 위해 정보공유체계 운영주체의 명확한 설정, 민 간·공공간 협업체계 운영, 통합적이고 자동화된 시스템 구축, 면책권 부여 등 법·제도 보완 등 국내에 적용 가능한 모델을 제시하고자 한다.

The recent cyber threats are becoming real threats to our lives. This gloomy situation from cyber threats necessarily demands the establishment of the cyber threat information sharing system between the public and private area. Key countries, like the US, Japan and the UK, are stabilizing the cyber threat information sharing systems by founding exclusive organizations for sharing information and setting up and implementing relevant measures. In this thesis, I would like to propose the model for cyber threat information sharing in order to cope efficiently with the ever-intensifying cyber threats. My model would include key elements for the efficient information sharing, such as the clear designation of main operator of information sharing system, the management of collaboration system between the public and private sector, the build-up of the integrated and automated system and the supplementation of legal system including the grant of privilege, and so on.

18

북한의 사이버전 위협에 대한 분석과 전망 KCI 등재

이대성, 안영규, 김민수

한국융합보안학회 융합보안논문지 제16권 제5호 2016.09 pp.11-16

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

현대사회에서 정보통신기술의 발달은 인류에게 많은 기회를 제공하고 있지만, 그 이면에는 사이버 공격으로 인한 막대한 손해도 발생하고 있다. 최근 한국도 사이버 공격의 대상이 되었고, 그 위협의 범위도 점차 확대되고 있다. 특히 북한은 한국을 대상으로 한 적대행위를 지속적으로 자행하고 있으며, 최근에는 국가중요시설 등의 전산망을 공격하는 사이버 공격을 감행하고 있다. 이러한 북한의 사이버 공격 유형으로는 소프트웨어(Software) 측면에서 인터넷 내부를 파괴하거나 조정하는 컴퓨터 바이러스(Virus)와 웜(Worms), 트로이 목마(Trojan Horse), 분산서비스 거부공격(Distributed Denial of Service) 등이 있다. 이를 해결하기 위해 다음과 같은 제언을 하고자 한다. 첫째, 북한은 사이버 공격을 위하여 일원화된 조직체계를 갖추고 있으므로, 한국도 효과적인 대처를 위해 일원화된 대응조직체제로 전환할 필요성이 있다. 둘째, 소프트웨어 측면의 공격에 체계적으로 대응하기 위해서는 가칭 『사이버테러리즘방지법』의 제정을 적극 검토하여야 한다.

In modern society, the development of Information and Communication Technology has given people a lot ofopportunities. But on the other side cyber attack also gives enormous damage to people. Recently Korea has becomethe target of cyber attack. The threat of it is growing. Especially North Korea has committed hostile actions againstSouth Korea. North Korea has recently attacked the computer networks of South Korea’s important nationalfacilities. The types of North Korea’s cyber attacks include the followings. First, if we see it with the viewpoint ofsoftware, it tries to destroy or control the Internet, infects the networks with viruses, worms, Trojan Horse andDistributed Denial of Service. I suggest the following to solve the problem. First, South Korea should unify theorganizations to respond to the attacks of North Korea, as North Korea has a unified organization for the cyberattack. Second, they should think about the establishment of 『Cyber Terrorism Prevention Act』to systematicallyrespond to the software attacks.

19

사이버위협정보 공유 활성화를 위한 관리적ㆍ기술적 개선모델 연구 KCI 등재

윤오준, 조창섭, 박정근, 서형준, 신용태

한국융합보안학회 융합보안논문지 제16권 제4호 2016.06 pp.25-34

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

정부 주요인사의 스마트폰을 대상으로 한 해킹과 인터넷뱅킹 보안소프트웨어 제작업체의 내부 전산망 장악시도 및방글라데시 중앙은행의 계좌 이체 등에서 보듯이 최근의 사이버공격은 국내외는 물론 공공과 민간영역을 구분하지 않고동시다발적으로 발생하고 있다. 이에 본 논문에서는 이러한 사이버위협에 대처하기 위한 관계기관간의 사이버위협정보공유 필요성을 제기하면서 법ㆍ제도 미흡, 통합된 정보시스템 미비, 민ㆍ관의 공동 협의기구 부재 등 현실태를 지적하였다. 이를 해결하기 위해 정보공유 가이드라인 제정 등 법ㆍ제도 개선, 국가정보공유센터 설립 및 통합정보시스템 구축ㆍ운영, 사이버위협정보 수집ㆍ분석ㆍ검증 등 전 과정 자동처리기술 개발, 민ㆍ관 합동 정보공유협의체 구성 등 사이버위협 정보공유 활성화를 위한 관리적ㆍ기술적 개선모델을 제시함으로써 사이버위협을 사전 차단하고 사이버공격 발생 시에도 피해의 확산을 방지하고자 한다.

This paper shall suggest the improvement model for invigorating cyber threat information sharing from the national level, which includes, inter alia, a comprehensive solutions such as the legislation of a guideline for information sharing, the establishment of so-called National Center for Information Sharing, the construction and management of a integrated information system, the development of techniques for automatizing all the processes for gathering, analyzing and delivering cyber threat information, and the constitution of a private and public joint committee for sharing information, so much so that it intends to prevent cyber security threat to occur in advance or to refrain damage from being proliferated even after the occurrence of incidents.

20

지식기반 실시간 사이버위협 조기 예ㆍ경보시스템 KCI 등재후보

이동휘, 이상호, 김귀남

한국융합보안학회 융합보안논문지 제6권 제1호 2006.03 pp.1-11

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

최근 사이버테러의 급증은 정보사회의 근간을 위협하고 있고, 특히 악성 트래픽에 의한 네트워크 마비는 단 시간 내에 국가적인 손실을 초래할 수 있어 이에 대한 대비책이 시급히 요구되고 있다. 이와 관련, 국가사이버안전 위협에 대한 신속한 대처능력확보를 위해 국가사이버위협 조기 예경보시스템에 대해 많은 연구가 이루어지고 있으나, 기술적인 문제와 함께 시스템의 효용성에 대한 한계 때자료수집분석을 통하여 보안관리자가 개개인의 경험을 바탕으로 예경보 판단을 내려왔다. 이러한 판단은 상황에 따라 극히 위험한 결과를 초래 할 수도 있다. 이러한 문제점을 방지하기 위해 본 논문에서는 “지식기반을 이용한 실시간 사이버위협 조기 예경보시스템”을 제안하였다. 제안된 시스템은 향후 사이버공격에 대해 체계적이고 보다 정확한 예경보 판단을 내리는데 사용할 수 있다.

The exponential increase of malicious and criminal activities in cyber space is posing serious threat which could destabilize the foundation of modern information society. In particular, unexpected network paralysis or break-down created by the spread of malicious traffic could cause confusion and disorder in a nationwide scale, and unless effective countermeasures against such unexpected attacks are formulated in time, this could develop into a catastrophic condition. As a result, there has been vigorous effort and search to develop a functional state-level cyber-threat early-warning system: however, the efforts have not yielded satisfying results or created plausible alternatives to date, due to the insufficiency of the existing system and technical difficulties. The existing cyber-threat forecasting and early-warning depend on the individual experience and ability of security manager whose decision is based on the limited security data collected from ESM (Enterprise Security Management) and TMS (Threat Management System). Consequently, this could result in a disastrous warning failure against a variety of unknown and unpredictable attacks. It is, therefore, the aim of this research to offer a conceptual design for “Knowledge-based Real-Time Cyber-Threat Early-Warning System” in order to counter increasing threat of malicious and criminal activities in cyber space, and promote further academic researches into developing a comprehensive real-time cyber-threat early-warning system to counter a variety of potential present and future cyber-attacks.

 
1 2 3 4
페이지 저장