Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 272
No
1

보안성 강화를 위한 블록체인기술의 활용과 개선방안 연구 KCI 등재

유승재

한국융합보안학회 융합보안논문지 제23권 제1호 2023.03 pp.63-68

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 연구에서는 블록체인 프로토콜과 네트워크 보안에 관련해서 MITM공격 및 DoS/DDoS 공격 등에 강한 대응수준 을 갖출 수 있도록 블록체인 구성과 스마트 컨트랙트 상의 암호화 키 관리 방안과 에 대해 연구한다. 암호화 통신 프로 토콜과 인증강화를 통한 중간자 공격(MITM)등의 데이터보안 위협에 대응, 노드간의 로드밸런싱과 분산화 된 방식으로 DDoS 공격 대응, 안전한 코딩과 취약점 검사, 안전한 합의알고리즘에 의한 스마트 컨트랙트 보안 강화, 사용자 인증과 권한 부여 강화를 통한 액세스 제어 및 인증, 블록체인 코어 및 노드의 보안성 강화, 기타 블록체인 프로토콜 업데이트 및 보안 강화를 위한 모니터링 시스템 구축 등을 통해 보안성이 강화된 블록체인 기술을 활용할 수 있을 것으로 기대된다.

In this study, in relation to blockchain protocol and network security, we study the configuration of blockchain and encryption key management methods on smart contracts so that we can have a strong level of response to MITM attacks and DoS/DDoS attacks. It is expected that the use of blockchain technology with enhanced security can be activated through respond to data security threats such as MITM through encryption communication protocols and enhanced authentication, node load balancing and distributed DDoS attack response, secure coding and vulnerability scanning, strengthen smart contract security with secure consensus algorithms, access control and authentication through enhanced user authentication and authorization, strengthen the security of cores and nodes, and monitoring system to update other blockchain protocols and enhance security.

2

4,800원

3

통합사례관리 개입 체계와 과정에 대한 맥락-패턴 분석 연구: 사회보장정보통합플랫폼 비정형 데이터를 활용하여

이현주, 권지성

[NRF 연계] 한국사회복지질적연구학회 한국사회복지질적연구 Vol.18 No.2 2024.07 pp.37-69

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

2012년 희망복지지원단이 공식 출범하면서 통합사례관리 사업이 수행된 후 지역사회의 많은 주민들에게 다양한 서비스를 제공하고 있으며, 사업 수행 인력은 이러한 통합사례관리의 과정과 내용을 사회보장정보통합플랫폼이라는 전산시스템에 기록해 왔다. 이에 따라 해당 전산시스템에는 매우 방대한 양의 통합사례관리 관련 데이터가 축적되어 있는데, 개인정보 보호 및 데이터 접근의 한계 등 여러 이유로현재까지 전산시스템 내 데이터 분석을 통해 통합사례관리의 개입 체계와 과정을 탐색한 연구는 없는 실정이다. 이에 본 연구에서는 통합사례관리 대상자로 선정되어 서비스를 제공받은 90명의 사례를 선정하고 그 사례들의 비정형 데이터를 활용하였으며 질적 연구방법 중 하나인 맥락-패턴 분석방법을 통해 통합사례관리의 개입 체계와 과정을 분석하였다. 또한 이러한 분석 결과에 기반하여 통합사례관리 사업의 개선을 위한 정책적, 실천적 방안을 제시하였다.

After the integrated case management project was carried out with the start of since the start of the Hope Welfare Support Group's integrated case management project, many residents have been provided with various related services. In addition, public officials and case managers record the integrated case management process and content in the computer system. Accordingly, a vast amount of integrated case management-related data has been accumulated. However, due to limitations in personal information protection and data access, no research has so far explored the intervention system and processes of integrated case management through data analysis and suggested improvement measures. In this study, the results were analyzed by extracting data from 90 people who were selected as subjects for integrated case management and received services. The unstructured data of the case were analyzed by the context-pattern analysis method, one of the qualitative research methods. And based on the analysis results, many suggestions to improve the integrated case management project were proposed.

4

빅 데이터 보안 기술 및 대응방안 연구 KCI 등재

김병철

한국디지털정책학회 디지털융복합연구 제11권 제10호 2013.10 pp.445-451

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 국내 주요 금융권 및 방송사를 타깃으로 사이버 테러가 발생하여 많은 수의 PC가 감염되어 정상적인 서비스 제공이 어려워졌으며 이로 인한 금전적 피해도 매우 큰 것으로 보고되었다. 빅 데이터의 중요성 인식과 이를 마케팅에 이용하려는 노력은 매우 활발한데 비해 빅 데이터의 보안 및 개인정보 보호에 대한 노력은 상대적으로 낮은 수준을 보이고 있다. 이에 본 연구에서는 빅 데이터 산업의 실태분석과 지능화되고 있는 빅 데이터 보안 위협과 방어 기술의 변화에 대 해 알아보고, 빅 데이터 보안에 대한 향후 대응방안을 제시한다.

Cyber terrorism has lately aimed at major domestic financial institutions and broadcasters. A large number of PCs have been infected, so normal service is difficult. As a result, the monetary damage was reported to be very high. It is important to recognize the importance of big data. But security and privacy efforts for big data is at a relatively low level, therefore the marketing offort is very active. This study concerns the analysis of Big Data industry and Big data security threats that are intelligent and the changes in defense technology. Big data, security countermeasures for the future are also presented.

5

4,000원

군의 음성 통신망에서 음성 통신 내용의 보안은 필수적일 것이다. 군 통신망의 음성 데이터 보안에 대해 제안된 연구는 없 으나 통신 시에 음성 데이터의 보안은 필수적으로 요구될 것이다. 본 논문은 군내 통신망에서 음성 통화 시 보안을 제공하기 위한 디지털 음성 데이터의 암호화/복호화 기법에 관한 것이다. 또한 AES를 이용한 대칭키 알고리즘을 사용함으로써 비밀 키 가 필요한 데 이 키를 음성 통화로 설정 전에 수신단으로 송신하는 기능을 가져 비밀 키 분배의 어려움을 해결하였다. 본 논 문에서는 스트림 암호화 기법 중에서도 동기 상실 시에도 동기 복원이 비교적 용이한 동기식 스트림 암호화 방식을 적용한 디지털 음성 데이터의 보안 기법을 제안한다.

Security of voice communication content in the military's voice communication network will be essential. There i s no proposed study on voice data security of military communication networks, but security of voice data will be e ssential when communicating. This paper is about to an encryption/decryption technique of digital voice data to pro vide security in case of voice calls in a military communication network. In addition, by using a symmetric key alg orithm using AES, a secret key is required, and it has the function of transmitting this key to the receiving end bef ore setting it as a voice call, solving the difficulty of distributing the secret key. This paper proposes a security tec hnique for digital voice data that applies a synchronous stream encryption method that is relatively easy to restore synchronization even in the event of loss of synchronization among stream encryption techniques.

6

4,000원

현대 사회에서 배터리는 전기자동차, 공유형 모빌리티, 모바일 기기 및 다양한 IoT 기기에 필수적인 요소로 자리 잡고 있다. 이러한 배터리의 성능, 안정성 및 수명 정보를 기록하고 관리하는 배터리 이력 시스템은 중요한 역할을 한다. 하지만 이러한 배터리 정보는 민감한 데이터로, 무단 접근이나 변조로부터 보호할 필요성이 있다. 따라서 데이터 전송 시 안전한 암호화 기술을 선택하는 것이 필수적이다. 본 논문에서는 배터리 이력 시스템에 서의 데이터 교환 시 AES, RSA, Salsa20, ChaCha20 블록 암호의 적합성을 비교하고, 각 기술의 성능과 보안성 을 분석한다.

In modern society, batteries are becoming an essential element in electric vehicles, shared mobility, mobile devices, and various IoT devices. Battery history systems that record and manage information on the performance, stability, and lifesp an of these batteries play an important role. However, such battery information is sensitive data and needs to be protecte d from unauthorized access or tampering. Therefore, it is essential to select a secure encryption technology when transmi tting data. In this paper, we compare the suitability of the AES, RSA, Salsa20, and ChaCha20 block ciphers when exchan ging data in the battery history system and analyze the performance and security of each technology.

7

데이터보안인증을 위한 DSMS 프레임워크 구축 연구 KCI 등재

유승재

한국융합보안학회 융합보안논문지 제19권 제4호 2019.10 pp.107-113

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

데이터보안(Data Security)이란 데이터 및 정보자산의 접근, 활용에 대한 적절한 인증과 권한의 감사를 위하여 보안 정책 및 절차를 기획, 구축, 실행하는 것이다. 또한 내・외부 네트워크, 서버, 어플리케이션 등을 통해 서비스되는 데이 터는 정보보호의 핵심 대상으로서 데이터베이스와 데이터의정보보안의 범주에서 DB와 DB내에 저장된 데이터의 보호에 특화하여 집중하는 것이라 할 수 있다. 이 연구에서는 데이터보안 인증체계와 미국의 연방보안관리법(FISMA)을 기반으로 한 적절한 데이터보안관리체계(DSMS, Data Security Management System) 모델 설계를 위한 기초연 구를 진행한다. ISO27001, NIST의 Cybersecurity Framework 등 주요보안인증 제도를 살펴보고 또한 현재 개인 데이터 유출방지와 기업보안강화를 위한 보안플렛폼으로 구현된 데이터보안매니저 솔루션에 구현된 상태를 연구한다.

Data security is the planning, implementation and implementation of security policies and procedures for the proper audit and authorization of access to and use of data and information assets. In addition, data serviced through internal / external networks, servers, applications, etc. are the core objects of information protection and can be said to focus on the protection of data stored in DB and DB in the category of information security of database and data. This study is a preliminary study to design a proper Data Security Management System (DSMS) model based on the data security certification system and the US Federal Security Management Act (FISMA). And we study the major security certification systems such as ISO27001 and NIST's Cybersecurity Framework, and also study the state of implementation in the data security manager solution that is currently implemented as a security platform for preventing personal data leakage and strengthening corporate security

8

6,400원

본 연구는 드론이 국가 핵심 인프라로 확산되는 환경에서, 드론 부품 공급망의 구조적 취약성과 시스템 보안의 결함이 국가 데이터 주권에 미치는 복합적 위협을 분석하고 정책적 개선 방향을 도출하는 데 목적이 있다. 연구 방법으로는 문헌분석과 비교 법제 분석을 병행하였다. 선행 연구를 통해 공급망 내 신뢰되지 않은 부품이 데이터 유출로 이어지는 경로를 분석하고, 미국(NDAA・Blue UAS)과 유럽(EASA・CRA)의 보안인증 체계를 국내 법제와 비교해 분석하였다. 분석 결과, 국내 드론 보안 정책은 하드웨어 기반 신뢰점(RoT) 검증 부재, 공급망 투명성 결여, 분산된 거버넌스 체계라는 세 가지 한계를 지닌다. 개선방안으로 드론 특화 보안인증 제도의 법제화, SBOM 기반 공급망 관리 체계 도입, 데이터 국외 이전 통제 강화, 범정부 통합 거버넌스 구축을 제안하였다. 본 연구는 드론 보안 담론을 공급망・시스템의 신뢰 구축을 통한 국가 데이터 주권 수호라는 안보 정책 과제로 재구성하였다는 점에서 정책적 의의를 가진다.

This study analyzes the complex threats that drone supply chain vulnerabilities and system security deficiencies pose to national data sovereignty, as drone operations become essential national infrastructure. Rather than treating drone security as a purely technical issue, this research examines it from policy, institutional, and governance perspectives. The study employs content analysis to trace the pathways by which untrusted supply chain components lead to unauthorized data exfiltration, and comparative legal analysis to assess the security certification frameworks of the United States (NDAA, Blue UAS) and the European Union (EASA, CRA) against South Korea's current legal framework. The analysis identifies three critical gaps in South Korea's drone security policy: the absence of hardware-based Root of Trust (RoT) verification, a lack of supply chain transparency, and a fragmented governance structure. In response, the study proposes legislating a drone security certification system, mandating SBOM-based supply chain management, strengthening controls over cross-border data transfers, and establishing an integrated government-wide governance body. This research holds policy significance by reframing drone security as a national security governance challenge centered on safeguarding data sovereignty through trusted supply chains and system integrity.

9

본 논문에서는 한국의 물리 및 사이버 보안 시장 동향과 데이터 센터의 보안 중요성을 다룹니다. 물리적 보안 방안과 디지털 보안 방안을 제시하여 데이터 센터를 보호하고, 기업의 핵심 자산과 비즈니스 연속성을 유지하는 데 필요한 다양한 기술적 해결 책을 모색합니다.

10

U-Healthcare 기기에서 DRDoS공격 보안위협과 Big Data를 융합한 대응방안 연구 KCI 등재후보

허윤아, 이근호

한국융합학회 한국융합학회논문지 제6권 제4호 2015.08 pp.243-248

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

U-Healthcare는 언제, 어디서나 환자의 건강을 검사하고 관리하며 유지할 수 있도록 하는 의료와 IT가 융합된 서비스이다. U-Healthcare 서비스에서 이루어지는 통신은 검진한 분석 결과나 긴급 데이터를 무선 통신방식을 이용하여 병원 서버에 전송하는 방식이 활용되고 있다. 이 때 악의적인 접근을 수행하는 자(공격자)가 U-Healthcare기기나 BS(Base Station)에 DRDoS(Distributed Reflection DoS)공격을 하면 위급한 환자의 상황정보가 병원 서버까지 전송되지 않는 다양한 피해가 예상된다. 이를 대응하기 위해 DRDoS 공격 시나리오와 DRDoS에 대한 대응방안을 제안하고 대량의 패킷을 처리할 수 있는 빅데이터와 융합한다. 공격자가 U-Healthcare기기나 BS(Base Station)를 공격 시 DB와 연동하여 일치하면 공격을 막는다. 본 논문은 원격의료 서비스인 U-Healthcare기기나 BS에서 나타날 수 있는 공격방법을 분석하고, 빅데이터를 활용하여 보안 위협에서의 대응방안을 제안한다.

U-Healthcare is a convergence service with medical care and IT which enables to examine, manage and maintain the patient’s health any time and any place. For communication conducted in U-Healthcare service, the transmission methods are used that patient’s medical checkup analysis results or emergency data are transmitted to hospital server using wireless communication method. At this moment when the attacker who executes the malicious access makes DRDoS(Distributed Reflection DoS) attack to U-Healthcare devices or BS(Base Station), various damages occur that contextual information of urgent patients are not transmitted to hospital server. In order to deal with this problem, this study suggests DRDoS attack scenario and countermeasures against DRDoS and converges with Big Data which could process large amount of packets. When the attacker attacks U-Healthcare devices or BS(Base Station), DB is interconnected and the attack is prevented if it is coincident. This study analyzes the attack method that could occur in U-Healthcare devices or BS which are remote medical service and suggests countermeasures against the security threat using Big Data.

11

정보보호 공시 데이터를 이용한 정보보호 관리체계 인증과 조직의 특성 분석 KCI 등재

김선주, 김태성

한국경영정보학회 경영정보학연구 제25권 제4호 2023.11 pp.205-231

※ 기관로그인 시 무료 이용이 가능합니다.

6,600원

정보보호 관리체계(Information Security Management System, ISMS)는 정보 자산의 기밀을 유지하고 결함이 없게 하며 언제든 사용할 수 있게 하는 보호 절차와 과정이고, 국내의 ISMS-P와 국외의 ISO/IEC 27001이 가장 대표적인 ISMS 인증제도이다. 본 논문에서는 ISMS 인증과 조직의 특성과의 관계를 파악하기 위해서 한국인터넷진흥원(KISA), 과학기술정보통신부 전자공시시스템(ISDS), 금융감독원 전자공시시스템(DART)로부터 데이터를 수집하고, Probit 회귀 분석을 실시하였다. Probit 분석 시 ISMS-P 취득여부, ISO/IEC 27001 취득여부, ISMS-P와 ISO/IEC 27001 모두 취득여부의 세 가지 경우에 대해 독립변수 4개와의 관련성을 확인하였다. 분석 결과, ISMS-P, ISO/IEC 27001 모두 취득한 기업은 총 임직원 수와는 양의 상관관계, 업력과는 음의 상관관계가 있음을 알 수 있었다. 이외에도 ISMS-P 인증제도와 정보보호 공시제도의 개선방향에 대해서도 확인할 수 있었다.

The Information Security Management System (ISMS) is a protection procedure and process that keeps information assets confidential, flawless, and available at any time. ISMS-P in Korea and ISO/IEC 27001 overseas are the most representative ISMS certification systems. In this paper, in order to understand the relationship between ISMS certification and organizational characteristics, data were collected from Korea Internet & Security Agency (KISA), Ministry of Science and ICT, Information Security Disclosure System (ISDS), Financial Supervisory Service, Data Analysis, Retrieval and Transfer System (DART), and probit regression analysis was performed. In the probit analysis, the relationship with four independent variables was confirmed for three cases: ISMS-P acquisition, ISO/IEC 27001 acquisition, and both ISMS-P and ISO/IEC 27001 acquisition. As a result of the analysis, it was found that companies that acquired both ISMS-P and ISO/IEC 27001 had a positive correlation with the total number of employees and a negative correlation with business history. In addition, the improvement direction of the ISMS-P certification system and information security disclosure system could also be confirmed.

12

빅 데이터를 이용한 호텔기업 CRM 및 보안에 관한 연구 KCI 등재

공효순, 송은지

한국융합보안학회 융합보안논문지 제13권 제4호 2013.09 pp.69-75

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

기업에 있어 고객은 수입의 원천으로 기업의 발전을 위해서는 효과적인 고객관계관리(CRM: Customer Relationship Management)가 매우 중요하다. 이를 위해서는 고객의 요구를 파악하고 실제 고객이 필요로 하는 제품이나 서비스를제공해야 한다. 그러나 점점 고객의 요구가 다양해지고 복합적인 형태를 갖게 되어 이를 파악하는 것이 어려워지고 있다. 최근 스마트 폰의 출현과 트위터, 페이스북과 같은 SNS의 발달로 실시간으로 다양한 고객의 목소리가 증가하고 있는 가운데 효율적인 CRM을 위해 이러한 빅 데이터를 이용 하는 것이 매우 효율적인 방법으로 부상하고 있다. 본 연구에서는 고객자체가 기업의 자산이며 서비스 산업의 대표라 할 수 있는 호텔기업의 CRM을 위해 빅 데이터를 활용하는방법을 제안한다. 또한 빅 데이터 서비스를 이용하는데 있어 보안에 대한 문제점을 논의하고 대책을 강구한다

Customer is the base factor of income for some corporations, so that effective CRM (Customer Relationship Management) is very important to develop the business. In order to use CRM efficiently, we should figure out customers’ demands and provide services or products that the customers want. However, it is getting difficult to comprehend customers’ demands because they have complicated form and getting more diverse. Recently, social media like Twitter and Facebook let customers to express their demands, and using big data is a very effective method for efficient CRM. This research suggests how to utilize big data for hotel CRM, which considers customer itself as asset of business. In addition, we discuss security problems of big data service and propose the solution for that.

13

6,600원

기술적·국제적 우위에 서기 위한 국가 간 기술 패권 경쟁이 가속화되면서 산업보안의 중요성 이 대두되고 있다. 국내에서는 산업보안의 중요성을 인식하여 한세대학교를 기점으로 중앙대학 교, 단국대학교 등에서 산업보안학과가 설립되었으며 정부 소관의 관련 사업 등이 실시되고 각 종 세미나 및 학술대회가 개최되었다. 이처럼 산업보안과 관련된 사업은 점차 확대되고 있는 추 세이나, 학술적인 관점에서 산업보안 분야의 정체성 확립과 연구 활성화를 위한 노력은 아직 부 족한 것이 현실이다. 따라서 본 연구에서는 산업보안 분야의 대표 학술지인 한국산업보안연구의 발전을 위해 과거의 논문 게재 데이터를 바탕으로 발전방안을 제시한다. 이를 위해 한국학술지 인용색인(www.kci.go.kr) 사이트에서 제공하는 분석 정보 서비스와 한국산업보안연구의 2009년 학술지 발간호부터 ‘2020 온라인 학술대회’가 개최되기 이전인 2020년 8월까지 게재된 모든 연구 논문들을 체계적으로 분석하였다. 특히 그동안 학술지에 게재되었던 논문들을 법/제도 분 야, 범죄 분야, 기술 분야, 관리 분야, 융합 분야, 기타 분야로 세부 분야로 분류하면서 앞으로의 발전 방향과 연결 지었고 네트워크 분석 툴(Gephi)를 사용하여 주제어와 저자별로 네트워크 하 여 시각화하였다. 따라서 본 연구는 산업보안의 추후 연구 방향을 제시하고, 산업보안 활성화에 기여한다는 점에서 의의가 있다.

With the fourth industrial revolution and the spread of new COVID-19 infections, key bio technologies, including science and technology, are drawing global attention. Amid this interest, the importance of industrial security is emerging as competition for technological supremacy accelerates. Recognizing the importance of industrial security in Korea, the Department of Industrial Security was established at Chung-Ang University and Dankook University starting from Hanse University, and related projects under the jurisdiction of the government were conducted, and various seminars and academic conferences were held. As such, the business related to industrial security is gradually expanding, but there is a lack of research on industrial security itself academically. Therefore, all research papers published from the issue of publication until recently were systematically analyzed for the development of industrial security and the development of the Korean Industrial Security Research Journal. In particular, the papers that have been published in academic journals have been grouped into detailed fields in law/system, crime, technology, management, convergence and other fields, linking them to the future direction of development. In addition, a network tool called Gephi was used to network and visualize them by subject language and author. Therefore, this study is meaningful in that it presents the direction of further research in industrial security and contributes to the vitalization of industrial security.

14

5,700원

민간경비산업은 국가 성장과 함께 급속한 양적 성장을 이루었지만, 4차 산업혁명 시대에 따른 과학기술 발전으로 인해 과거 전통적인 형태에서 탈피하여 시대적인 흐름을 반영한 민간경비산업 구축이 필요한 현실이다. 이에 따라, 이 연구에서는 시설경비 및 물리보안 용어에 대한 사람들의 인식 및 정서 형태, 2012년과 2021년의 인식 및 정서 형태 변화, 인식 및 정서 차이에 대해 파악하여 향후 보안산업이 발전할 수 있는 기초자료를 제공하고 자 한다. 이를 위해 텍스톰 6.0을 활용하여 크롤링 방식을 통해 국내 주요 웹사이트에서 ‘시설경비’, ‘물리보안’이 언급된 게시물을 수집하였다. 이후 LDA 토픽 모델링, 오피니언 마이닝 등의 빅데이터 분석을 통해 2012년과 2021년에 시설경비, 물리보안 용어별 주요 키워드 및 토픽을 파악하고, 이에 대한 사람들의 2012년과 2021년 인식 및 정서 형태가 어떻게 변화하였는지 살펴보았으며, 사람들의 인식 및 정서가 어떠한 차이를 보이는지 분 석하였다. 연구 결과, 시설경비 용어에 대한 인식은 시간이 흐르며 부정적인 측면으로 변했 지만, 물리보안 용어에 대한 인식은 과거에도 긍정적인 부분이 컸고, 시간이 흐르며 더욱 긍정적으로 변했다. 또한, 융합보안에 대한 필요성 및 관심 증가와 보안 시장의 확대 등으 로 물리보안에 대한 사람들의 인식 및 정서는 더욱 좋아질 것으로 예상된다. 그러므로 시 설경비라는 용어 대신 물리보안이라는 보다 확장된 의미를 가진 용어를 사용하는 것이 차후 보안 관련 학계와 산업 발전에 더욱 큰 도움을 줄 수 있을 것이라는 시사점을 제시하였다.

The private security industry has achieved rapid quantitative growth with national growth, but due to the development of science and technology in the era of the 4th Industrial Revolution, it is necessary to build a private security industry that reflects the stream of the times. Accordingly, this study aims to provide basic data for future development of the security industry by grasping people's awareness and emotional forms of facility security and physical security, changes in awareness and emotional forms in 2012 and 2021, and grasping the differences in awareness and sentiment. To this end, posts mentioning facility security and physical security were collected from major domestic websites by using Textom 6.0’s crawling function. After that, major keywords and topics for the term facility security and the term physical security in 2012 and 2021 were identified through big data analysis such as LDA topic modeling and opinion mining. In addition, we looked at how people's perceptions and emotions changed in 2012 and 2021 and analyzed the differences in people's perceptions and emotions. As a result of the study, the perception of facility security changed negatively over time, but the perception of physical security changed more positively over time. In addition, people's perception and sentiment of physical security are expected to improve due to the need for convergence security, increased interest, and the expansion of the security market. Therefore, the use of the term physical security instead of the term facility security will help further develop security-related academia and industry in the future.

15

4,000원

사물인터넷 기반의 헬스케어 서비스는 다양한 사물인터넷 디바이스를 통해서 사용자의 생체신호 측정, 질병 진단 및 예방을 포함한 건강관리 및 의료 서비스를 제공하고 있다. 그러나, 사물인터넷 기반의 헬스케어 서비스는 여러 가지 요소 기술들이 통합되어 서비스를 제공하기 때문에 각 요소 기술 자체의 보안 취약성과 연동 시 새로운 보안 취약성이 발생할 수 있는 문제점이 존재한다. 본 논문에서는 모바일 환경에서 IoT 기반의 웨어러블 장비를 이 용한 사용자의 헬스케어 정보를 서버에 전달할 때 제 3자로부터 사용자의 헬스케어 정보를 안전하게 처리할 수 있 는 사용자 프라이버시 보호 모델을 제안한다. 제안 모델은 사용자의 헬스케어 정보를 안전하게 처리, 보관, 저장할 수 있도록 헬스케어 센서 정보 별로 속성 값을 부여하여 사용자의 프라이버시를 계층적으로 통합 관리한다. 성능평 가 결과, 제안모델은 기존모델보다 IoT 장치의 처리율은 평균 10.5% 향상되었고, 서버의 오버헤드는 기존 모델에 비 해 평균 9.9% 낮은 결과를 얻었다.

Objects Internet-based healthcare services provide healthcare and healthcare services, including measurement of user's vital signs, diagnosis and prevention of diseases, through a variety of object internet devices. However, there is a problem that new security vulnerability can occur when inter-working with the security weakness of each element technology because the internet service based on the object Internet provides a service by integrating various element technologies. In this paper, we propose a user privacy protection model that can securely process user's healthcare information from a third party when delivering healthcare information of users using wearable equipment based on IoT in a mobile environment to a server. The proposed model provides attribute values for each healthcare sensor information so that the user can safely handle, store, and store the healthcare information, thereby managing the privacy of the user in a hierarchical manner. As a result of the performance evaluation, the throughput of IoT device is improved by 10.5% on average and the server overhead is 9.9% lower than that of the existing model.

16

5,800원

경호 및 경비산업이 민간분야에서 급격하게 성장하면서 경호학 역시 큰 성장을 하였지만, 최 근 전통적인 경호학은 시간이 지남에 따라 상대적으로 쇠퇴하고 있는 현실이다. 이에 따라, 경호 학이 시대적인 변화에 적응하여 향후 발전할 수 있는 방향성을 제시하기 위해 이 연구에서는 ‘경 호’ 및 경호 관련 용어(‘보안’, ‘시큐리티’)에 대한 사람들의 인식 및 정서를 파악하고자 한다. 이를 위해 텍스톰 5.0의 웹 크롤러 기능을 활용해 국내 주요 포털사이트에서 ‘경호’, ‘보안’, ‘시큐리티’ 가 언급된 게시물을 수집하였다. 이후 빈도 분석, 토픽 모델링, 감성분석 등의 빅데이터 분석을 통해 2012년과 2022년에 경호 관련 용어별로 인터넷 포털과 SNS(Social Networking Service)상 에서의 주요 키워드 및 토픽은 무엇이 있었는지 파악하고, 이에 대한 사람들의 인식 및 정서가 10년을 주기로 어떻게 변화하였는지 살펴보았으며, 경호 관련 용어별로 사람들의 인식 및 정서 는 어떠한 차이를 보이는지 분석하였다. 연구 결과, 경호라는 용어는 대중들이 인식하기에 다소 고전적이고 그에 대한 관심도도 낮으며, 용어 자체가 경호학 관련 학과에서 가르치는 교육과정 을 전부 포함하고 있다기엔 무리가 있다. 그러므로 경호라는 용어 대신 그 개념을 적절하게 확장 할 용어로 현재 대중에게 가장 긍정적인 인식을 보이는 동시에 학계 연구 또한 활발하게 이루어 지고 있는 ‘보안’이라는 용어를 사용해 시대적인 변화를 반영하여 대중들의 관심을 증가시킨다면 향후 경호학이 더욱 혁신적으로 발전할 수 있을 것이라는 시사점을 제시하였다.

As the security industry grew rapidly in the private sector, personnel protection also grew significantly. However, in recent years, a school related to personnell protection also called ‘Gyeonghohak’ has been relatively declining over time. Accordingly, in order to present the direction in which ‘Gyeonghohak’ can adapt to the changes of the times and develop in the future, this study attempts to understand people’s awareness of and sentiment toward security-related terms such as ‘Gyeongho,’ ‘Boan,’ and ‘security.’ To this end, the researcher used the web crawler function of Textom 5.0 to collect posts mentioning ‘Gyeongho,’ ‘Boan,’ and ‘Security’ from major domestic portal sites. Afterward, the researcher used big data analysis such as word frequency analysis, topic modeling, and sentiment analysis to determine what major keywords and topics were on the Internet portal and social networking service (SNS) by security-related terms in 2012 and 2022. In addition, the researcher examined how people’s awareness and sentiment changed over the past 10 years, and analyzed how people’s awareness and sentiment differ by security-related terms. As a result of the analysis, the term ‘Gyeongho’ is somewhat old for the public to recognize and has low interest in it, and the term itself cannot be considered to include all the curriculum taught in the department related to security. Therefore, instead of the term ‘Gyeongho,’ it is appropriate to use the term ‘Boan’ that properly expands the concept of ‘Gyeongho’ and at the same time shows the most positive perception to the current public. Currently, academic research on ‘Boan’ is also being actively conducted, and if the public’s interest in security increases by reflecting the changes of the times, ‘Gyeonghohak’ can develop more innovatively in the future.

17

미정부의 빅데이터를 위한 보안정책 KCI 등재

홍진근

한국디지털정책학회 디지털융복합연구 제11권 제10호 2013.10 pp.403-409

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 논문은 미국 정부의 빅데이터 정책과 보안 이슈에 관해 고찰하였다. 빅데이터 R&D 이니셔티브 전략과 계획, NITRD 프로그램, 정부기관의 빅데이터 전략을 소개하였고, 또한 미군에서 빅데이터 운용환경, 군사 작전에 사 용되는 빅데이터 정보, 주요 연구기관과 주제, 보안가이드라인 등에 대해 살펴보았다.

This paper review about big data policy and security issue of US government. It is introduced Big data R&D initiative strategy and plan, NITRD program, and big data strategy of government. It is presented operation environment of big data in US government, big data information for military operation, major research organization and topic, security guideline and so on.

18

4,000원

최근, 정보화 시대의 수많은 서비스 제공을 통해 재택근무, 원격근무 등의 다양한 업무 형태가 도입되어 운영되고 있다. 기존의 정보망은 내부 경계 중심의 사용자 인가를 통해 접근한 반면, 현재는 물리적 위치에 관계 없이 네트워킹 서비스가 가능하다면 어느 곳이든 외부로부터 접근이 가능하다. 보안 영역의 확장으로 인해 외부 위협요소에 노출되고 이를 위한 다각적 보안 연구가 진행되고 있다. 그러나 분산 서비스 공격(Distributed Denial of Service, DDoS), 페이로드 삽입 공격이 지능화되면서 이에 상응하는 보안 기술이 요구된다. 따라서 외부로부터 접근되는 다양한 용도의 패킷을 분석하여 비정상행위 여부를 판단하고 배제하는 Abnormal Packet Filtering Mechanism (APFM)을 제안한다. APFM은 사용자 패턴 중심, 시스템 패턴 중심, 시계열 중심 등의 패킷을 분석 하여 비정상행위를 판단하였으며, 93%이상의 비정상행위 탐지의 정확도가 측정되었다.

Recently, various types of work such as work from home and remote work have been introduced and operated through the provision of numerous services in the information age. Existing information networks were accessed through user authorization centered on internal boundaries, but currently, access from the outside is possible anywhere as long as networking services are available regardless of physical location. Due to the expansion of the security area, it is exposed to external threats, and multilateral security research is being conducted for this purpose. However, as Distributed Denial of Service (DDoS) and payload injection attacks become more intelligent, corresponding security technologies are required. Therefore, we propose an Abnormal Packet Filtering Mechanism (APFM) that analyzes packets for various purposes accessed from the outside to determine and exclude abnormal behavior. APFM analyzed packets centered on user patterns, system patterns, and time series to determine abnormal behaviors, and the accuracy of detecting abnormal behaviors was over 93%.

19

4,000원

미래 국방은 세계 안보정세의 불확실성 가속화, 국내 사회․경제적 여건 제한 등 다양하고 도전적인 환경에 직면하고 있다. 이에 우리 국방부는 인공지능, 드론, 로봇 등 과학기술 기반의 국방혁신으로 당면한 문제점과 위협요인에 대응하려 하고 있다. 인공지능 기반의 첨단과학기술 도입을 위해서는 클라우드, 5G와 같은 IT기반 환경 위에 데이터를 융합하고 활용하는 것이 필 수적이다. 하지만 기존의 전통적인 보안 정책은 주로 시스템 중심의 보안으로 일률적인 보안 통제수단을 적용하는 등 데이터 공유 및 활용에 어려움이 있다. 본 연구는 데이터 가치 평가 및 데이터 수명주기 관리에 대한 이론적 배경을 바탕으로 데이터 가치 기반의 국방 보안정책으로 패러다임 전환을 제안한다. 이를 통해 데이터 기반의 업무 활성화 및 AI기반 과학기술중심의 국방혁신 구현에 도움이 될 것으로 기대한다.

The future outlook for defense faces various and challenging environments such as the acceleration of uncertainty in the global security landscape and limitations in domestic social and economic conditions. In response, the Ministry of National Defense seeks to address the problems and threats through defense innovation based on scientific and technological advancements such as artificial intelligence, drones, and robots. To introduce advanced AI-based technology, it is essential to integrate and utilize data on IT environments such as cloud and 5G. However, existing traditional security policies face difficulties in data sharing and utilization due to mainly system-oriented security policies and uniform security measures. This study proposes a paradigm shift to a data value-based security policy based on theoretical background on data valuation and life-cycle management. Through this, it is expected to facilitate the implementation of scientific and technological innovations for national defense based on data-based task activation and new technology introduction.

20

3,000원

 
1 2 3 4 5
페이지 저장