Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 39
No
1

정보유출 악성코드 분석을 통한 개선된 탐지 규칙 제작 연구 KCI 등재후보

박원형, 양경철, 이동휘, 김귀남

한국융합보안학회 융합보안논문지 제8권 제4호 2008.12 pp.1-8

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 해킹 기법들은 기존보다 정교한 기술을 바탕으로 악성화 되어 그 피해 규모가 증가하고 있으며, 인터넷 사용자의 확대와 맞물려 그 위력은 커지고 있다. 특히 정보유출을 목적으로 제작한 해킹메일에 첨부된 악성코드의 피해가 급증하고 있다. 본 논문에서 이러한 정보유출형 악성코드를 효과적으로 분석, 탐지할 수 있는 기술에 관하여 연구한다. 또한 본 연구에서는 기존 악성코드의 탐지규칙과 해킹메일 악성코드 탐지규칙을 비교하였으며 이를 통해 해킹메일 악성코드 뿐 아니라 새로운 악성코드와 변종들에 대해서도 탐지할 수 있는 기술에 대해 설명한다.

Not only the recent hacking techniques are becoming more malicious with the sophisticated technology but also its consequences are bringing more damages as the broadband Internet is growing rapidly. These may include invasion of information leakage, or identity theft over the internet. Its intent is very destructive which can result in invasion of information leakage, hacking, one of the most disturbing problems on the net. This thesis describes the technology of how you can effectively analyze and detect these kind of E-Mail malicious codes. This research explains how we can cope with malicious code more efficiently by detection method.

2

Simple Fuzzy Rule Based Edge Detection

Verma, O.P., Jain, Veni, Gumber, Rajni

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.9 No.4 2013 pp.575-591

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Most of the edge detection methods available in literature are gradient based, which further apply thresholding, to find the final edge map in an image. In this paper, we propose a novel method that is based on fuzzy logic for edge detection in gray images without using the gradient and thresholding. Fuzzy logic is a mathematical logic that attempts to solve problems by assigning values to an imprecise spectrum of data in order to arrive at the most accurate conclusion possible. Here, the fuzzy logic is used to conclude whether a pixel is an edge pixel or not. The proposed technique begins by fuzzifying the gray values of a pixel into two fuzzy variables, namely the black and the white. Fuzzy rules are defined to find the edge pixels in the fuzzified image. The resultant edge map may contain some extraneous edges, which are further removed from the edge map by separately examining the intermediate intensity range pixels. Finally, the edge map is improved by finding some left out edge pixels by defining a new membership function for the pixels that have their entire 8-neighbourhood pixels classified as white. We have compared our proposed method with some of the existing standard edge detector operators that are available in the literature on image processing. The quantitative analysis of the proposed method is given in terms of entropy value.

3

국방통합보안관제체계에서의 협업 침입탐지를 위한 탐지규칙 교환 기법 KCI 등재후보

이윤환, 이수진

한국융합보안학회 융합보안논문지 제11권 제1호 2011.02 pp.57-69

※ 기관로그인 시 무료 이용이 가능합니다.

4,500원

국방통합보안관제체계 내에는 자체 개발된 시스템을 포함하여 다양한 오용탐지 기반의 상용 침입탐지시스템들이 운용되고 있다. 오용탐지 방식에 기반해서 운용되는 침입탐지시스템의 경우 침입탐지 패턴의 업데이트 주기나 질적수준에 따라 서로 상이한 능력을 가지며, 이러한 상이성은 침입탐지시스템들 간의 통합과 협동탐지를 더욱 어렵게 만든다. 이에 본 논문에서는 국방통합보안관제체계 내에서 운용되는 이기종 침입탐지시스템들 간의 통합과 협업탐지를 위한 기반을 마련하기 위해 이기종 침입탐지시스템들이 새롭게 생성한 탐지규칙을 서로 전파하고 적용할 수 있는 기법을 제안하고, 구현 및 실험을 통해 제안된 탐지규칙 교환 기법의 국방환경 적용 가능성을 입증한다.

Many heterogeneous Intrusion Detection Systems(IDSs) based in misuse detection technique including the self-developed IDS are now operating in Defense-ESM(Enterprise Security Management System). IDS based on misuse detection may have different capability in the intrusion detection process according to the frequency and quality of its signature update. This makes the integration and collaboration with other IDSs more difficult. In this paper, with the purpose of creating the proper foundation for integration and collaboration between heterogeneous IDSs being operated in Defense-ESM, we propose an effective mechanism that can enable one IDS to propagate its new detection rules to other IDSs and receive updated rules from others. We also prove the performance of rule exchange and application possibility to defense environment through the implementation and experiment.

4

보안관제 위협 이벤트 탐지규칙 표준 명명법 연구 KCI 등재

박원형, 김양훈, 임영환, 안성진

한국융합보안학회 융합보안논문지 제15권 제4호 2015.06 pp.89-96

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 해킹과 악성코드 등 사이버 공격기법은 매우 빠르게 변화 발전하고 있으며 그에 따른 사이버공격 기법이 다양해지고 지능화된 악성코드의 수가 증가하고 있다. 악성 코드의 경우 악성 코드의 수가 급격하게 증가함으로 서 분류나 이름의 모호함으로 인해 악성코드에 대처함에 있어 어려움이 있다. 본 논문은 이러한 문제점을 해결 하기 위해서 국내에 있는 백신업체들의 명명규칙을 조사․분석하고 이를 기반으로 현재까지 나온 탐지규칙의 패 턴을 비교 분석해 보안관제 이벤트 탐지규칙에 적합한 명명규칙을 제안 한다.

Recent, Cyber attacks such as hacking and malicious code techniques are evolving very rapidly changing cyber a ttacks are increasing, the number of malicious code techniques vary accordingly become intelligent. In the case of m alware because of the ambiguity in the number of malware have increased rapidly by name or classified as maliciou s code may have difficulty coping with. This paper investigated the naming convention of the vaccine manufacturer s in Korea to solve this problem, the analysis and offers a naming convention for security control event detection r ule analysis to compare the pattern of the detection rule out based on this current.

5

Enhance Rule Based Detection for Software Fault Prone Modules SCOPUS

Hassan Najadat, Izzat Alsmadi

보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.6 No.1 2012.01 pp.75-86

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Software quality assurance is necessary to increase the level of confidence in the developed software and reduce the overall cost for developing software projects. The problem addressed in this research is the prediction of fault prone modules using data mining techniques. Predicting fault prone modules allows the software managers to allocate more testing and resources to such modules. This can also imply a good investment in better design in future systems to avoid building error prone modules. Software quality models that are based upon data mining from previous projects can identify fault-prone modules in the current similar development project, once similarity between projects is established. In this paper, we applied different data mining rule-based classification techniques on several publicly available datasets of the NASA software repository (e.g. PC1, PC2, etc). The goal was to classify the software modules into either fault prone or not fault prone modules. The paper proposed a modification on the RIDOR algorithm on which the results show that the enhanced RIDOR algorithm is better than other classification techniques in terms of the number of extracted rules and accuracy. The implemented algorithm learns defect prediction using mining static code attributes. Those attributes are then used to present a new defect predictor with high accuracy and low error rate.

6

A Semantic Rule-based Detection Scheme against Flooding Attacks on Cloud Environment SCOPUS

Chu-Hsing Lin, Chen-Yu Lee, Shin-Pin Lai, Wei-Shen Lai

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.6 No.2 2012.04 pp.341-346

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

With the progress the Internet, more and more applications provide Web services. The presentation of web page has evolved to be dynamic. You also can interact with the web page. Some malicious users have malicious browsing behaviors, such as flooding attack, to waste the resources and bandwidth of the host for web page. Nowadays, more and more web services are developed on cloud computing. Flooding attack on the application layer has no ability to cause denial of service to a Web server on cloud computing. But resources on cloud mean cost. Any waste of resource will cause unnecessary cost. Therefore, in this paper we analyze PHP dynamic pages. According to analysis, we propose a method based on semantic concept to formulate rules to indentify malicious browsing behaviors in order to slice the cost.

7

In the field of network security, researchers have implemented different models to secure the network. Intrusion Detection System is also one of them and Snort is an open source tool for Intrusion Detection and Prevention System. Today intrusion Detection System is a growing technology in network security and mostly researchers have focused in this field, some of them used signature or rule-based technique and some are anomaly based techniques to improve security of network. In this paper we propose a rule-base Intrusion Detection System with our self generated new Efficient Port Scan Detection Rules (EPSDR). These rules will be used to detect naive port scan attacks in real time network using Snort and Basic Analysis Security Engine (BASE). BASE is used to view the snort results in font-end web page because Snort has no graphic user interface. In This rule-based Intrusion Detection System we will match the signature with our Efficient Port Scan Detection Rules (EPSDR) from captured packet. As a definition of signature based IDS this new EPSDR based IDS will be useful to reduce the false positive alarm.

8

Nucleus Detection of Uterine Cervical Pap-Smears using Contour Trucking Method and Fuzzy Reasoning Rule SCOPUS

Hyunjun Woo, Young Woon Woo, Kwang-Baek Kim

보안공학연구지원센터(IJBSBT) International Journal of Bio-Science and Bio-Technology Vol.5 No.6 2013.12 pp.123-136

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we apply a set of algorithms to classify normal and cancer nucleus from uterine cervical pap-smear images. First, we use lightening compensation algorithm to re- store color images that have defamation through the process of obtaining 400x microscope magnification. Then, we remove the background from images with the histogram distribu- tions of RGB regions. We extract nucleus areas from candidates by applying histogram brightness, Kapur method, and our own 8-direction contour tracing algorithm. Various bi- narization methods, cumulative entropy, masking algorithms are used in that process. Then, we are able to recognize normal and cancer nucleus from those areas by using three mor- phological features - directional information, the size of nucleus, and area ratio - with fuzzy membership functions and deciding rules we devised. The experimental result shows our method has low false recognition rate.

9

취약성 룰 기반의 소프트웨어 취약성 탐지 시스템

조성훈, 장창복, 이무훈, 최의인

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.1 No.1 2005.08 pp.36-41

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

10

CA(Cellular Automata)와 ARD(Automatic Rule Detection)를 이용한 제주도 도시 스프롤의 시공간적 변화 예측 모델링

정고은, 김영호

[NRF 연계] 한국지리학회 한국지리학회지 Vol.10 No.1 2021.04 pp.139-152

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 연구의 목적은 제주도 도시 스프롤의 시공간적 변화를 예측하는 것이다. 본 연구는 크게 세 단계로 나뉜다. 첫 번째로 스프롤 예측의 기반이 되는 토지피복 변화를 예측하기 위해 2009년과 2019년의 예측변수로 사용될 사회・환경데이터를 구축한다. 두번째로 네이버후드 테스트 모델(ARD)을 이용하여 모델에 적합한 네이버후드를 선정한 후 이를 적용하여 2019년과 2029년의 토지피복 변화를 예측한다. 세번째로 2009년에서 2019년, 2019년에서 2029년의 사이의 스프롤을 측정 및 유형을 분류한 후 시공간적 변화를 확인한다. 연구 결과, 2009년에서 2019년 사이에는 대규모의 개발로 Leapfrog와 Edge-expansion이 두드러지게 나타났으며, 2029년에는 이와 대조적으로 Infilling의 형태가 활발한 것으로 해석되었다. 본 연구는 국내 최초로 CA기반의 SIMLANDER모형을 이용하여 도시 스프롤의 시공간적 변화를 예측하고 유형별로 분석함으로써 난개발의 방지와 국토의 효율적인 관리를 위한 새로운 유형의 기초자료로 사용될 수 있다는 점에서 의의를 갖는다.

This study aims to predict the spatio-temporal change of the urban sprawl in Jeju isalnd. This study consists of three stages. First, we construct 2009 and 2019 social-environment data for 2009 and 2019, which are the basis for the sprawl prediction. Second, the Neighborhood test model (ARD) is used to select a suitable Neighborhood. Using the selected Neighborhood and 2009 predictor variables, we predict 2019 and 2029 landcover map. Third, after measuring and classifying the sprawl between 2009 to 2019 and 2019 to 2029, the spatiotemporal changes are analyzed. The result show that, Leapfrog and Edge-expansion appeared noticeably due to large-scale development between 2009 and 2019, and in contrast to this, there are more Infilling in 2029. This study is meaningful in that it can be used as a new basic data for preventing ineffective development and efficient management of the land by predicting spatio-temporal changes of urban sprawl and analyze by type using the Cellular Automata (CA) based SIMLANDER model for the first time in Korea.

11

Rule-Based Anomaly Detection Technique Using Roaming Honeypots for Wireless Sensor Networks

Gowri, Muthukrishnan, Paramasivan, Balasubramanian

[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.38 No.6 2016 pp.1145-1152

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Because the nodes in a wireless sensor network (WSN) are mobile and the network is highly dynamic, monitoring every node at all times is impractical. As a result, an intruder can attack the network easily, thus impairing the system. Hence, detecting anomalies in the network is very essential for handling efficient and safe communication. To overcome these issues, in this paper, we propose a rule-based anomaly detection technique using roaming honeypots. Initially, the honeypots are deployed in such a way that all nodes in the network are covered by at least one honeypot. Honeypots check every new connection by letting the centralized administrator collect the information regarding the new connection by slowing down the communication with the new node. Certain predefined rules are applied on the new node to make a decision regarding the anomality of the node. When the timer value of each honeypot expires, other sensor nodes are appointed as honeypots. Owing to this honeypot rotation, the intruder will not be able to track a honeypot to impair the network. Simulation results show that this technique can efficiently handle the anomaly detection in a WSN.

12

Network Anomaly Detection using Association Rule Mining in Network Packets

오상현, 장중혁

[Kisti 연계] 한국산업정보학회 한국산업정보학회논문지 Vol.14 No.3 2009 pp.22-29

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

컴퓨터를 통해서 들어오는 다양한 형태의 침입을 효과적으로 탐지하기 위해서 이전에는 오용탐지 기법이 주로 이용되어 왔다. 오용탐지 기법은 이전에 알려지지 않은 침입 방법들을 효과적으로 탐지할 수 있기 때문이다. 하지만, 해당 기법에서는 정상적인 네트워크 접속 형태가 몇 가지 패턴으로 고정되어 있다고 가정한다. 이러한 이유 때문에 새로운 정상적인 네트워크 연결이 비정상행위로 탐지되기도 한다. 본 논문에서는 연관 마이닝 기법을 활용한 침입 탐지 방법을 제안한다. 논문에서 제안되는 방법은 패킷내 마이닝 단계와 패킷간 마이닝 두가지 단계로 구성된다. 제안된 방법의 성능은 대표적인 네트워크 침입 탐지 방법인 JAM과의 비교 실험을 통하여 평가하였다.

In previous work, anomaly-based intrusion detection techniques have been widely used to effectively detect various intrusions into a computer. This is because the anomaly-based detection techniques can effectively handle previously unknown intrusion methods. However, most of the previous work assumed that the normal network connections are fixed. For this reason, a new network connection may be regarded as an anomalous event. This paper proposes a new anomaly detection method based on an association-mining algorithm. The proposed method is composed of two phases: intra-packet association mining and inter-packet association mining. The performances of the proposed method are comparatively verified with JAM, which is a conventional representative intrusion detection method.

13

Implementation of Rule-based Smartphone Motion Detection Systems

Lee, Eon-Ju, Ryou, Seung-Hui, Lee, So-Yun, Jeon, Sung-Yoon, Park, Eun-Hwa, Hwang, Jung-Ha, Choi, Doo-Hyun

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.26 No.7 2021 pp.45-55

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

스마트폰에 내장된 각종 센서를 통해 획득할 수 있는 정보는 사용자의 움직임, 상황 등을 파악하고 분석하는데 유용하게 활용될 수 있다. 본 논문에서는 스마트폰의 가속도 센서와 자이로스코프 센서에서 얻은 정보를 분석하여 'I', 'S', 'Z' 모션을 인식하는 두 가지 규칙기반 시스템을 제안한다. 먼저, 각 모션에 대한 가속도 및 각속도의 특성을 분석한다. 이를 기반으로 두 가지 종류의 규칙기반 모션 인식 시스템을 제안하고 이를 안드로이드 앱으로 구현하여 각 모션에 대한 성능을 비교한다. 두 가지 규칙기반시스템은 각 모션에 대해서 90% 이상의 인식률을 보이며 앙상블을 이용한 규칙기반 시스템은 다른 시스템보다 향상된 성능을 보인다.

Information obtained through various sensors embedded in a smartphone can be used to identify and analyze user's movements and situations. In this paper, we propose two rule-based motion detection systems that can detect three alphabet motions, 'I', 'S', and 'Z' by analyzing data obtained by the acceleration and gyroscope sensors in a smartphone. First of all, the characteristics of acceleration and angular velocity for each motion are analyzed. Based on the analysis, two rule-based systems are proposed and implemented as an android application and it is used to verify the detection performance for each motion. Two rule-based systems show high recognition rate over 90% for each motion and the rule-based system using ensemble shows better performance than another one.

14

Framework for False Alarm Pattern Analysis of Intrusion Detection System using Incremental Association Rule Mining

Chon, Won Yang, Kim, Eun Hee, Shin, Moon Sun, Ryu, Keun Ho

[Kisti 연계] 대한원격탐사학회 대한원격탐사학회 학술대회논문집 2004 pp.716-718

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The false alarm data in intrusion detection systems are divided into false positive and false negative. The false positive makes bad effects on the performance of intrusion detection system. And the false negative makes bad effects on the efficiency of intrusion detection system. Recently, the most of works have been studied the data mining technique for analysis of alert data. However, the false alarm data not only increase data volume but also change patterns of alert data along the time line. Therefore, we need a tool that can analyze patterns that change characteristics when we look for new patterns. In this paper, we focus on the false positives and present a framework for analysis of false alarm pattern from the alert data. In this work, we also apply incremental data mining techniques to analyze patterns of false alarms among alert data that are incremental over the time. Finally, we achieved flexibility by using dynamic support threshold, because the volume of alert data as well as included false alarms increases irregular.

15

Network Intrusion Detection Based on Directed Acyclic Graph and Belief Rule Base

Zhang, Bang-Cheng, Hu, Guan-Yu, Zhou, Zhi-Jie, Zhang, You-Min, Qiao, Pei-Li, Chang, Lei-Lei

[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.39 No.4 2017 pp.592-604

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Intrusion detection is very important for network situation awareness. While a few methods have been proposed to detect network intrusion, they cannot directly and effectively utilize semi-quantitative information consisting of expert knowledge and quantitative data. Hence, this paper proposes a new detection model based on a directed acyclic graph (DAG) and a belief rule base (BRB). In the proposed model, called DAG-BRB, the DAG is employed to construct a multi-layered BRB model that can avoid explosion of combinations of rule number because of a large number of types of intrusion. To obtain the optimal parameters of the DAG-BRB model, an improved constraint covariance matrix adaption evolution strategy (CMA-ES) is developed that can effectively solve the constraint problem in the BRB. A case study was used to test the efficiency of the proposed DAG-BRB. The results showed that compared with other detection models, the DAG-BRB model has a higher detection rate and can be used in real networks.

16

커널 수준의 침입탐지를 위한 동적 침입탐지 규칙 변경기법의 설계

정보흥, 김정녀

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2002 pp.1031-1034

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 커널수준의 침입탐지를 위한 동적 침입탐지 규칙 변경 기법을 제안한다. 제안하는 기법은 침입탐지 규칙은 규칙타입 프로토콜 타입, 패킷 헤더와 패킷 페이로드에 대한 검사를 수행하기 위한 규칙들로 세분화하여 LVR로 표현하고 이들 LVR이 계층적으로 구성된 IDRL로 관리한다. 침입탐지는 IDRL을 이용하여 수행하며, 규칙에 대한 변경은 변경된 규칙에 대한 LVR을 구성하고 LV를 이용한 포인터 변경을 이용하여 IDRL에 반영하는 방법이다. 제안하는 기법은 IDRL을 이용한 침입탐지와 탐지규칙의 변경을 IDRL에 최소한의 비용으로 수행하고, LVR을 이용하여 침입탐지 규칙을 디스크와 메모리에 동일한 형태로 저장 및 관리하여 탐지규칙 초기화 비용과 변경 비용을 최소화할 수 있다. 이를 통하여 보다 안전한 커널 수준에서의 네트워크 보안을 위한 효율적인 동적 침입탐지 규칙 변경을 지원할 수 있다는 장점을 가진다.

17

효율적인 자동화 코드 인스펙션(Automated Code Inspection)을 위한 필수 결함 검출 규칙 수립

곽수정, 최진영

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2009 pp.811-812

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

프로젝트 개발에서 소프트웨어의 품질을 높이기 위한 방법 중 하나는 소스코드에 대한 잠재적인 결함을 초기에 발견하는 것이다. 이를 실현하기 위해 정형화된 기법으로 코드 인스펙션을 자동화하였으며, 개발자들이 ACI 규칙을 수립하였다. 논문에서는 실제 진행 중인 프로젝트를 기반으로 하여 결함 점검 수행에 따른 결함 발견 건수와 결함밀도가 감소되는 증명을 다룬다.

18

효율적인 자동화 코드 인스펙션(Automated Code Inspection)을 위한 필수 결함 검출 규칙 수립

곽수정, 최진영

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2009 pp.811-812

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

프로젝트 개발에서 소프트웨어의 품질을 높이기 위한 방법 중 하나는 소스코드에 대한 잠재적인 결함을 초기에 발견하는 것이다. 이를 실현하기 위해 정형화된 기법으로 코드 인스펙션을 자동화하였으며, 개발자들이 ACI 규칙을 수립하였다. 논문에서는 실제 진행 중인 프로젝트를 기반으로 하여 결함 점검 수행에 따른 결함 발견 건수와 결함밀도가 감소되는 증명을 다룬다.

19

N-code를 이용한 규칙 기반 침입 탐지 시스템

빙영태, 차병래, 서재현

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2001 pp.919-922

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 인터넷의 확산에 따라 여러 가지 침해사고 발생이 증가하고 있어서 시스템을 안전하게 관리하기 위한 노력들이 행해지고 있다. 본 논문에서는 NFR의 N-code언어를 이용하여 Shieh 모델의 침입패턴을 탐지할 수 있는 규칙 기반 침입 탐지를 설계 및 구현한다. 제안하는 침입 탐지는 웹 기반에서 Shieh 침입 탐지 모델을 N-code 언어로 변환하여 침입 탐지여부를 쉽게 발견한다. 그리고 다양한 규칙들을 정의하고 이를 바탕으로 하여 취약점을 보완할 수 있도록 침입 탐지 시스템을 구현한다.

20

규칙기반 다단계 침입 탐지 시스템

민욱기, 최종천, 조성제

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2005 pp.965-968

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 보안 정책 및 규칙에 기반을 둔 네트워크 포트 기반의 오용침입 탐지 기능 및 센서 객체 기반의 이상침입 탐지 기능을 갖춘 리눅스 서버 시스템을 제안 및 구현한다. 제안한 시스템은 먼저 시스템에 사용하는 보안 정책에 따른 규칙을 수립한다. 이러한 규칙에 따라 정상적인 포트들과 알려진 공격에 사용되고 있는 포트번호들을 커널에서 동적으로 관리하면서, 등록되지 않은 새로운 포트에도 이상탐지를 위해 공격 유형에 대하여 접근제어 규칙을 적용하여 이상 침입으로 판단될 경우 접근을 차단한다. 알려지지 않은 이상침입 탐지를 위해서는 주요 디렉토리마다 센서 파일을, 주요 파일마다 센서 데이터를 설정하여 센서 객체가 접근될 때마다 감사로그를 기록하면서, 이들 센서 객체에 대해 불법적인 접근이 발생하면 해당 접근을 불허한다. 본 시스템은 보안정책별 규칙에 따라 다단계로 구축하여 특정 침입에 대한 더욱 향상된 접근제어를 할 수 있다.

 
1 2
페이지 저장