Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 166
No
1

국가중요시설 방호를 위한 안티드론 시스템 구축 방안 연구 KCI 등재

황순필, 김두환

한국디지털정책학회 디지털융복합연구 제18권 제11호 2020.11 pp.247-257

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

본 연구는 범죄 집단이나 테러리스트 등 악의적 의도로 사용되는 드론으로부터 국가중요시설 방호를 위한 효과 적인 안티드론 시스템 구축 방안을 제시하는 데 목적이 있다. 연구목적 달성을 위해 안티드론 시스템에 관한 기술 및 정책 보고서, 제조업체의 공개 자료, 학술 연구논문을 검토하고, 드론 관련 분야의 전문가를 대상으로 안티드론의 복합 적인 대응체계 구축과 관련한 인터뷰를 실시하였다. 연구결과, 탐지체계는 다양한 센서의 장단점을 보완하여 탐지율을 향상시킬 수 있도록 중첩·혼합운용하는 것이 효과적이며, 무력화 수단은 소프트킬 방식과 하드킬 방식을 배비하여 작전 환경에 맞게 선택적으로 사용할 수 있도록 융통성을 확보하는 것이 효과적인 것으로 나타났다. 다시말해 불법드론 사전 관리체계 정립, 탐지자산 혼합 및 중첩운용, 적합한 대응방안 결정, 무력화 수단 다중배비 등이다. 이러한 중첩·복합적 안티드론체계 운용을 통한 국가중요시설에 대한 방호체계 구축이 무엇보다 시급한 과제라 할 수 있다.

The Purpose of this study is to present effective Anti-Drone systems to protect national important facilities against drones that are illegally used by crime groups and terrorists with malicious intents. In order to accomplish the purpose of the study, technical and policy reports regarding Anti-Drone systems, open documents from manufacturers and various research papers are reviewed, and in-depth interviews with experts were conducted. Studies have shown that it is effective to overlay and mix different detection systems so that they can improve detection rates by supplementing each other's advantages and disadvantages, and that the means of incapacitation need to acquire flexibility by using both soft-kill and hard-kill methods in accordance with operational environment for the effective usage. In other words, the establishment of an illegal drone pre-management system, mixed and overlapping detection assets, determining appropriate countermeasures, and multiple distribution of means of incapacitation. The establishment of a protection system for important national facilities through the operation of overlapping and complex anti-drone systems is the most urgent task.

2

연구배경: 우리나라를 포함한 중국, 대만, 북한, 일본 등에서 원전, 재처리시설과 같은 원자력시설의 증가에 따라 주변국 핵활동 분석의 종합적 대책이 필요하다. 우리나라와 포괄적핵실험금지조약기구(Comprehensive Nuclear-Test-Ban Treaty Organization, CTBTO)는 동북아시아 지역에서 핵종 탐지소를 운영 중으로, 핵종탐지 장비에서 특이 값 측정시 모니터링 자료의 분석과 더불어 배출원 탐색모델을 이용하여 핵종의 기원이 어디인지 추정하고 평가하는 것은 주변국 핵활동에 대한 감시 및 안전성 확보 측면에서 중요하다. 재료 및 방법: 주변국의 은밀한 핵활동 시 방사성핵종의 기원을 추정하기 위하여 3차원 전진/후진형 궤적모델을 개발하였다. 개발된 궤적모델은 궤적 미분방정식을 유한차분법을 이용한 방법으로 주어진 바람자료를 이용하여 방사성핵종의 방출지점으로부터 입자의 궤적을 순차적으로 찾아가는 전진형 모델과 시간 역산으로 방출기원을 추정하는 후진형 모델로 구성되었다. 결과 및 논의: 개발된 궤적모델의 검증을 위하여 체르노빌 사고 당시 측정된 농도자료를 이용하였다. 검증결과 관측지점의 농도가 높게 측정된 지점과 방출기원에서 가까운 지역으로부터 시간 역산의 방출지점을 추정한 결과의 정확도가 높았다. 3차원 궤적모델은 방출시간, 방출높이, 방출간격 등의 변수에 의해 계산결과가 달라지는 불확도를 내포하고 있는데, 이러한 궤적모델의 불확도를 최소화하기 위해 한국원자력연구원에서 개발한 대기확산모델(long-range accident dose assessment system, LADAS)를 이용하여 fields of regards (FOR) 기법에 의해 오염물 방출영역을 추정한바 신뢰성 있는 결과를 얻었다. 결론: 본 연구를 통하여 개발된 배출원 탐색모델은 주변국의 은밀한 핵활동 시 핵종 탐지장비와 연계하여 방사성핵종의 방출지역과 기원을 파악하여 우리나라의 핵종탐지 능력을 향상하고 핵활동 및 방사선 안전 분야에서 주도적 역할을 할 수 있을 것으로 생각된다.

Background: It is necessary to consider the overall countermeasure for analysis of nuclear activities according to the increase of the nuclear facilities like nuclear power and reprocessing plants in the neighboring countries including China, Taiwan, North Korea, Japan and South Korea. South Korea and comprehensive nuclear-test-ban treaty organization (CTBTO) are now operating the monitoring instruments to detect radionuclides released into the air. It is important to estimate the origin of radionuclides measured using the detection technology as well as the monitoring analysis in aspects of investigation and security of the nuclear activities in neighboring countries. Materials and methods: A three-dimensional forward/backward trajectory model has been developed to estimate the origin of radionuclides for a covert nuclear activity. The developed trajectory model was composed of forward and backward modules to track the particle positions using finite difference method. Results and discussion: A three-dimensional trajectory model was validated using the measured data at Chernobyl accident. The calculated results showed a good agreement by using the high concentration measurements and the locations where was near a release point. The three-dimensional trajectory model had some uncertainty according to the release time, release height and time interval of the trajectory at each release points. An atmospheric dispersion model called long-range accident dose assessment system (LADAS), based on the fields of regards (FOR) technique, was applied to reduce the uncertainties of the trajectory model and to improve the detective technology for estimating the radioisotopes emission area.Conclusion: The detective technology developed in this study can evaluate in release area and origin for covert nuclear activities based on measured radioisotopes at monitoring stations, and it might play critical tool to improve the ability of the nuclear safety field.

3

Research on Password Detection Technology of IoT Equipment Based on Wide Area Network

Jia Qu

[NRF 연계] 한국통신학회 ICT Express Vol.8 No.2 2022.06 pp.213-219

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

At present, while the Internet of Things (IoT) devices bring convenience to people, security issues have led to an increasing number of threats to IoT security. Since IoT devices have a Web application system for device managers to operate, the system can view device information, control and configure device status, and its security is of great significance. Among the various authentication methods provided by IoT devices, the password information authentication mechanism is still a critical method for Web login. If the IoT device has a weak Web password, once a hacker discovers the device, it is straightforward to be attacked and implanted with malicious code to control the device and attack other devices in the network. In response to this problem, this paper designs a set of automatic detection frameworks for weak passwords for web application systems of IoT devices. Based on this framework, an automated weak password detection system was developed to detect weak Web passwords on IoT devices on the wide-area networks of Beijing, Shandong Province, and Zhejiang Province. A total of 12,179 devices with weak Web passwords were found, accounting for all discovered IoT devices of 7.58%, verifying the effectiveness of the proposed framework.

4

Study of Danger-Theory-Based Intrusion Detection Technology in Virtual Machines of Cloud Computing Environment

Zhang, Ruirui, Xiao, Xin

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.14 No.1 2018 pp.239-251

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In existing cloud services, information security and privacy concerns have been worried, and have become one of the major factors that hinder the popularization and promotion of cloud computing. As the cloud computing infrastructure, the security of virtual machine systems is very important. This paper presents an immune-inspired intrusion detection model in virtual machines of cloud computing environment, denoted I-VMIDS, to ensure the safety of user-level applications in client virtual machines. The model extracts system call sequences of programs, abstracts them into antigens, fuses environmental information of client virtual machines into danger signals, and implements intrusion detection by immune mechanisms. The model is capable of detecting attacks on processes which are statically tampered, and is able to detect attacks on processes which are dynamically running. Therefore, the model supports high real time. During the detection process, the model introduces information monitoring mechanism to supervise intrusion detection program, which ensures the authenticity of the test data. Experimental results show that the model does not bring much spending to the virtual machine system, and achieves good detection performance. It is feasible to apply I-VMIDS to the cloud computing platform.

7

API 호출 구간 특성 기반 악성코드 탐지 기술

김동엽, 최상용

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.32 No.4 2022 pp.629-635

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 사회적 변화와 IC T 기술의 발전에 따라 사이버 위협 또한 증가되고 있으며, 사이버위협에 사용되는 악성코드는 분석을 어렵게 하기 위해 분석환경 회피기술, 은닉화, 파일리스 유포 등 더욱 고도화 지능화되고 있다. 이러한 악성코드를 효과적으로 분석하기 위해 머신러닝 기술이 활용되고 있지만 분류의 정확도를 높이기 위한 많은 노력이 필요하다. 본 논문에서는 머신러닝의 분류성능을 높이기 위해 API호출 구간 특성 기반 악성코드 탐지 기술을 제안한다. 제안하는 기술은 악성코드와 정상 바이너리의 API 호출 순서를 시간을 기준으로 구간으로 분리하여 각 구간별 API의 호출특성과 바이너리의 엔트로피 등의 특성인자를 추출한 후 SVM(Support Vector Mechine) 알고리즘을 이용하여 제안하는 방법이 악성바이너리를 잘 분석할 수 있음을 검증하였다.

Cyber threats are also increasing with recent social changes and the development of ICT technology. Malicious codes used in cyber threats are becoming more advanced and intelligent, such as analysis environment avoidance technology, concealment, and fileless distribution, to make analysis difficult. Machine learning technology is being used to effectively analyze these malicious codes, but a lot of effort is needed to increase the accuracy of classification. In this paper, we propose a malicious code detection technology based on API call interval characteristics to improve the classification performance of machine learning. The proposed technology uses API call characteristics for each section and entropy of binary to separate characteristic factors into sections based on the extraction malicious code and API call order of normal binary. It was verified that malicious code can be well analyzed using the support vector machine (SVM) algorithm for the extracted characteristic factors.

8

콘텐츠 보호를 위한 경량화 침입탐지 기술

박성준, 김봉한

[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회지 Vol.14 No.1 2016 pp.38-43

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

9

시나리오 기반 상·하수도 관로의 실시간 결함검출 기술 개발

박동채, 최영환

[Kisti 연계] 한국수자원학회 한국수자원학회 논문집 Vol.55 No.suppl1 2022 pp.1177-1185

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

상·하수도 시스템은 사람들에게 안전하고 깨끗한 물을 공급해주는 사회기반시설이며, 특히 상·하수도 관로는 지중에 매설되어 있기 때문에 시스템의 결함검출이 매우 어렵다. 이러한 이유로 상·하수도 관로의 진단은 관로 내부에 카메라 및 드론을 통한 촬영을 하여 사후에 촬영된 영상을 바탕으로 시스템 진단하는 등의 사후 결함검출로 제한되기 때문에, 작업자의 업무 효율 증대와 진단의 신속성을 위해서는 관로의 실시간 탐지기술이 필요하다. 최근 첨단장비 및 인공지능 기법을 활용한 시설물 진단 기술이 개발되고 있지만, 인공지능기반 결함검출 기술은 결함 데이터의 종류 및 형태, 수가 검출 성능에 영향을 주기 때문에 다양한 학습데이터가 필요하다. 따라서, 본 연구에서는 상·하수도 관로의 결함검출 시 탐지 성능 향상을 위해 다양한 결함 시나리오를 3D 프린트를 이용하여 구현하고 이를 수집된 결함 데이터와 함께 학습데이터로 사용한다. 이후 수집된 이미지는 위험도에 따른 분류 및 객체의 라벨링 등의 전처리 작업이 수행되고 실시간 결함탐지를 수행한다. 제안된 기법은 상·하수도시스템 결함검출 시 실시간 피드백을 제공함으로써, 작업자의 진단 누락 가능성을 최소화하며 기존의 상·하수도관 진단업무 처리능력을 향상할 수 있다.

The water and sewage system is an infrastructure that provides safe and clean water to people. In particular, since the water and sewage pipelines are buried underground, it is very difficult to detect system defects. For this reason, the diagnosis of pipelines is limited to post-defect detection, such as system diagnosis based on the images taken after taking pictures and videos with cameras and drones inside the pipelines. Therefore, real-time detection technology of pipelines is required. Recently, pipeline diagnosis technology using advanced equipment and artificial intelligence techniques is being developed, but AI-based defect detection technology requires a variety of learning data because the types and numbers of defect data affect the detection performance. Therefore, in this study, various defect scenarios are implemented using 3D printing model to improve the detection performance when detecting defects in pipelines. Afterwards, the collected images are performed to pre-processing such as classification according to the degree of risk and labeling of objects, and real-time defect detection is performed. The proposed technique can provide real-time feedback in the pipeline defect detection process, and it would be minimizing the possibility of missing diagnoses and improve the existing water and sewerage pipe diagnosis processing capability.

10

SDP 환경에서 SVDD 기반 이상행위 탐지 기술을 이용한 디바이스 유효성 검증 방안

이희웅, 홍도원, 남기효

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.31 No.6 2021 pp.1181-1191

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

팬데믹 현상은 원격으로 문제를 해결할 수 있는 비대면 환경을 빠르게 발전시켰다. 하지만 급작스러운 비대면 환경으로 전환은 다양한 부분에서 새로운 보안 이슈들을 발생시켰다. 새로운 보안 이슈들 중 하나가 내부자에 의한 보안 위협이었고 이를 방어하기 위한 기술로 제로 트러스트 보안 모델이 다시 주목받게 되었다. SDP(Software Defined Perimeter) 기술은 다양한 보안 요소로 이루어져 있는데 이 중 디바이스 유효성 검증이라는 기술이 내부자의 사용 행위를 모니터링 하여 제로 트러스트 보안 모델을 실현할 수 있는 기술이다. 하지만 현재 SDP 명세서에는 디바이스 유효성 검증을 수행할 수 있는 기술이 제시되어 있지 않다. 따라서 본 논문에서는 SDP 환경에서 사용자 행위 모니터링을 통한 SVDD 기반 이상행위 탐지 기술을 이용해 디바이스 유효성 검증 기술을 제안하고 성능 평가를 진행하여 SDP 환경의 디바이스 유효성 검증 기술을 수행할 수 있는 방안을 제시한다.

The pandemic has rapidly developed a non-face-to-face environment. However, the sudden transition to a non-face-to-face environment has led to new security issues in various areas. One of the new security issues is the security threat of insiders, and the zero trust security model is drawing attention again as a technology to defend against it.. Software Defined Perimeter (SDP) technology consists of various security factors, of which device validation is a technology that can realize zerotrust by monitoring insider usage behavior. But the current SDP specification does not provide a technology that can perform device validation.. Therefore, this paper proposes a device validation technology using SVDD-based abnormal behavior detection technology through user behavior monitoring in an SDP environment and presents a way to perform the device validation technology in the SDP environment by conducting performance evaluation.

12

Since 1990s, some events - detection of a dirty bomb in a Russian nation park in 1995, 9/11 terrorist attack to WTC in 2001,discovery of Al-Qaeda’s experimentation to build a dirty bomb in 2003 etc - have showed that nuclear or radiological terrorism relatingto radioactive materials (hereinafter “radioactive materials” is referred to as “nuclear material, nuclear spent fuel and radioactive source”)isnot incredible but serious and credible threat. Thus, to respond to the new threat, the international community has not only strengthenedsecurity and physical protection of radioactive materials but also established prevention of and response to illicit traffickingof radioactivematerials. In this regard, our government has enacted or revised the national regulatory framework with a view to improving security ofradioactive materials and joined the international convention or agreement to meet this international trend. For the purpose of preventionofnuclear/radiological terrorism, this paper reviews physical characteristics of nuclear material and existing detection instruments used forprevention of illicit trafficking. Finally, national detection regime against nuclear/radiological terrorism based on paths of the smuggledradioactive materials to terrorist’s target building/area, national topography and road networks, and defence-in-depth concept is suggestedin this paper. This study should contribute to protect people's health, safety and environment from nuclear/radiological terrorism.

13

MITRE ATT&CK 및 Anomaly Detection 기반 이상 공격징후 탐지기술 연구 KCI 등재

황찬웅, 배성호, 이태진

한국융합보안학회 융합보안논문지 제21권 제3호 2021.09 pp.13-23

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

공격자의 무기가 점차 지능화 및 고도화되고 있어 기존 백신만으로는 보안 사고를 막을 수 없으므로 endpoint까지 보안 위협이 검토되고 있다. 최근 endpoint를 보호하기 위한 EDR 보안 솔루션이 등장했지만, 가시성에 중점을 두고 있 으며, 이에 대한 탐지 및 대응 기술은 부족하다. 본 논문에서는 보안 관리자 관점에서 효과적인 분석과 분석 대상을 선 별하기 위해 실 환경 EDR 이벤트 로그를 사용하여 지식 기반 MITRE ATT&CK 및 AutoEncoder 기반 Anomaly Detection 기술을 종합적으로 사용하여 이상 공격징후를 탐지한다. 이후, 탐지된 이상 공격징후는 보안 관리자에게 로그 정보와 함께 alarm을 보여주며, 레거시 시스템과의 연계가 가능하다. 실험은 5일에 대한 EDR 이벤트 로그를 하루 단위 로 탐지했으며, Hybrid Analysis 검색을 통해 이를 검증한다. 따라서, EDR 이벤트 로그 기반 언제, 어떤 IP에서, 어떤 프로세스가 얼마나 의심스러운지에 대한 결과를 산출하며, 산출된 의심 IP/Process에 대한 조치를 통해 안전한 endpoint 환경을 조성할 것으로 기대한다.

The attacker's techniques and tools are becoming intelligent and sophisticated. Existing Anti-Virus cannot prevent security accident. So the security threats on the endpoint should also be considered. Recently, EDR security solutions to protect endpoints have emerged, but they focus on visibility. There is still a lack of detection and responsiveness. In this paper, we use real-world EDR event logs to aggregate knowledge-based MITRE ATT&CK and autoencoder-based anomaly detection techniques to detect anomalies in order to screen effective analysis and analysis targets from a security manager perspective. After that, detected anomaly attack signs show the security manager an alarm along with log information and can be connected to legacy systems. The experiment detected EDR event logs for 5 days, and verified them with hybrid analysis search. Therefore, it is expected to produce results on when, which IPs and processes is suspected based on the EDR event log and create a secure endpoint environment through measures on the suspicious IP/Process.

14

본 연구는 열악한 작업환경과 위험성이 산재해 있는 폐기물 처리 현장에서의 작업자 안전사고를 분석하여 작업자의 사고 예방과 안전을 확보할 수 있는 기술을 연구하고자 한다. 이를 위해 객체 탐지 기술을 활용한 지능형 안전 관리 기술을 개발하여 작업자의 사고감소 및 산업재해율감소, 안전한 작업 환경 조성 등 작업장의 안전관리 효율성을 향상시키는데 기여하고자 한다.

15

본 연구는 지하공간 내에서 발생하는 화재나 테러와 같은 재난상황을 인지하고 IoT 시스템을 통해 승객이 현재 위치에서 최 적의 경로로 대피를 유도하기 위한 시스템으로 CCTV를 통한 지능형 영상감지 기술을 적용하여 지하공간 내 밀집도를 분석한 데이터를 바탕으로 단위공간별 노드에서 밀집공간을 우회하여 안내할 수 있는 시스템으로 개발되었다. 배경차(Background Extraction) 감지 기법을 사용하여 분석하였으며 분석된 밀집도 값이 분할된 공간에 입력하여 우회 경로를 실시간으로 분석을 통해 승객의 대피의 의사결정과 골든타임 확보를 통하여 신속한 대피 의사결정을 지원할 수 있는 기술로 개발하였다. 이와 같은 시스템은 실제 지하공간인 지하철 역사에 테스트베드를 구축하여 성능을 확인하였다.

16

암호화폐 트랜잭션의 실증적 분석을 통한 자금세탁 탐지 기술 KCI 등재

신미진, 유민정, 정윤영, 김성민

한국융합보안학회 융합보안논문지 제25권 제1호 2025.03 pp.105-116

※ 기관로그인 시 무료 이용이 가능합니다.

4,300원

암호화폐는 중앙화된 시스템 없이 신뢰성을 갖춘 탈중앙화 금융서비스 및 전자상거래를 위한 핵심 기술로 주목받아왔으나, 암호화폐가 보장하는 익명성을 바탕으로 다크웹 시장에서 불법 거래, 사기, 랜섬웨어를 통한 자금 도난 등의 범죄에 악용되고 있다. 불법 거래된 암호화폐는 주로 믹싱 서비스를 통해 자금 출처를 은닉했지만, 믹서의 불법 사용 증가로 인해 규제가 강화 되면서 새로운 트랜잭션 기법들이 등장하고 있어 기술적 대응 연구가 시급하다. 하지만 불법 자금세탁 탐지의 정확도를 평가 할 실측자료가 부족할 뿐만 아니라, 기존 불법 자금세탁 탐지기법들은 수사를 통해 불법으로 식별된 지갑을 대상으로만 세탁 여부를 탐지할 수 있어 수사 내역이 공개되지 않은 트랜잭션에 대한 실효성 검증이 미흡하다는 한계가 있다. 이에 본 연구에 서는 체이널리시스 사의 암호화폐 분석 도구(Reactor)를 사용하여 실측자료 기반으로 복합적인 자금세탁 패턴을 분석하고, 수 사 중인 주소에서 발생한 자금세탁 기법을 분석하였다.

Cryptocurrencies have been attracting attention as a core technology for decentralized financial services and e-commerce without a centralized financial authority system, but they are being exploited for crimes such as illegal transactions, fraud, and ransomware theft in dark web markets based on the anonymity guaranteed by cryptocurrencies. Most illegally traded cryptocurrencies concealed the source of funds through mixing services, but as service sanctions continue due to the increase in the illegal use of mixers, new transaction techniques are emerging, and money laundering trends are rapidly changing, making technological response research urgent. However, not only is there a lack of actual data to evaluate the accuracy of illegal money laundering detection, but the illegal money laundering detection techniques proposed so far can only detect laundering for wallets identified as illegal through investigations, so there is a limitation in that the effectiveness of transactions for which the investigation details have not been properly evaluated exists. Therefore, in this study, we used the cryptocurrency analysis tool (Reactor) provided by Chainalysis to analyze complex money laundering patterns that could not be confirmed in previous studies based on actual data, and analyzed money laundering techniques that occurred for addresses under investigation.

17

랜섬웨어에 의한 피해 규모는 매년 급증하고 있으며 이와 함께 랜섬웨어 탐지 기술에 대한 연구도 함께 발전되어왔다. 기존의 악성코드 탐지 기법에서 보다 랜섬웨어의 특징을 가지고 이를 탐지하는 기술들이 연구되어졌다. 본 논문에서는 기존의 악성코드 탐지 기법들에 대해 간략하게 서술하고 랜섬웨어의 특징과 함께 그 특징들을 통한 다양한 탐지 기법들에 대해 서술한다. 그리고 본 논문의 결론에서 랜섬웨어 탐지 기법의 시사점에 대해 서술한다.

18

머신러닝과 딥러닝을 활용한 악성 패킷 탐지 기술 연구 KCI 등재

안병욱, 이중찬, 최재성, 박원형

한국융합보안학회 융합보안논문지 제21권 제4호 2021.10 pp.109-115

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

현재, 5G 및 IoT 기술의 발달함에 따라 실생활에 사용하는 사물들에 네트워크로 연결되어 사용되고 있다. 하지만, 네트워크로 연결된 컴퓨터를 악의적인 목적으로 사용하려는 시도가 증가하고 있으며, 사용자 정보의 기밀성 및 무결성 을 침해하는 악성코드를 이용한 공격은 더욱 지능화되고 있다. 이에 대응하기 위한 방안으로 보안관제 시스템과 AI 기술인 지도 학습을 이용한 악성 패킷 탐지 방법에 대한 연구가 진행되고 있다. 사이버보안 관제 시스템 운영상 인력 및 비용 측면에서 비효율적으로 운영되고 있다. 또한, 코로나19 팬데믹 시대에 원격 근무가 증가하여 즉각적인 대응에 어려움이 있다. 그리고 기존 AI 기술인 지도 학습을 이용한 악성코드 탐지에는 변종 악성코드를 탐지하지 못하고 데 이터의 양과 질에 따라 부정확한 악성코드 탐지율을 가진다. 따라서, 본 연구에서는 다양한 머신러닝과 딥러닝 모델을 통해 악성 패킷 탐지 기술을 융합하여 악성 패킷 탐지 정확도를 높이고 오탐률과 미탐률을 감소시키며 새로운 유형의 악성 패킷이 침입시 이를 효율적으로 탐지 할 수 있는 악성 패킷 탐지 기술을 제안 한다.

Currently, with the development of 5G and IoT technology, it is being used in connection with the things used in real life through a network. However, attempts to use networked computers for malicious purposes are increasing, and attacks using malicious codes that infringe the confidentiality and integrity of user information are becoming more intelligent. As a countermeasure to this, research is being conducted on a method of detecting malicious packets using a security control system and AI technology, supervised learning. The cyber security control system is being operated inefficiently in terms of manpower and cost. In addition, in the era of the COVID-19 pandemic, remote work has increased, making it difficult to respond immediately. In addition, malicious code detection using the existing AI technology, supervised learning, does not detect variant malicious code, and has an inaccurate malicious code detection rate depending on the quantity and quality of data. Therefore, in this study, by converging malicious packet detection technologies through various machine learning and deep learning models, the accuracy of malicious packet detection is increased, the false positive rate and the false positive rate are reduced, and a new type of malicious packet can be efficiently detected when intrusion. We propose a malicious packet detection technology.

19

4,000원

Currently, Korea government is pushing to reduce the energy of various building to meet GHG(Greenhouse Gas) reduction target. There are various methods to save energy in order to fulfill this reduction obligation. One of the ways is detection of spaces using IoT environment sensors to save energy on buildings based on monitoring. Some spaces waste the energy to meet thermal comfort level even when there is no people. In this paper, we show the practical results of our occupancy detection algorithm using IoT environment sensors to find the wasted space on the building.

20

N-gram을 활용한 DGA 기반의 봇넷 탐지 방안 KCI 등재

정일옥, 신덕하, 김수철, 이록석

한국융합보안학회 융합보안논문지 제22권 제5호 2022.12 pp.145-154

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 봇넷의 광범위한 확산과 고도의 정교함은 기업과 사용자뿐만 아니라 국가 간 사이버전에도 심각한 결과를 초래하고 있다. 이 때문에 봇넷을 탐지하고자 하는 연구는 꾸준히 되고 있다. 하지만, DGA 기반의 봇넷은 기존의 시그니처 및 통계 기 반의 기술로는 탐지율은 높지만, 오탐율 또한 높은 한계가 있다. 이에 본 논문에서는 DGA 기반의 봇넷을 탐지하고자 문자 기 반의 n-gram을 활용한 탐지모델을 제안한다. 제안한 모델을 통해 기존의 탐지 기술의 한계인 탐지율을 높이고 오탐율을 최소 화할 수 있다. 다양한 DGA 봇넷에서 사용하는 대규모의 도메인 데이터셋과 정상 도메인에 대한 실험을 통해 기존의 모델보 다 성능이 우수함을 확인하였다. 제안된 모델의 오탐율은 2~4% 미만이며 전체 탐지 정확도와 F1 점수는 모두 97.5%임을 확 인하였다. 이처럼 본 논문에서 제안한 모델을 통해 DGA 기반의 봇넷에 대한 탐지 및 대응 능력이 향상될 것을 기대한다.

Recently, the widespread proliferation and high sophistication of botnets are having serious consequences not o nly for enterprises and users, but also for cyber warfare between countries. Therefore, research to detect botnets is steadily progressing. However, the DGA-based botnet has a high detection rate with the existing signature and st atistics-based technology, but also has a high limit in the false positive rate. Therefore, in this paper, we propose a detection model using text-based n-gram to detect DGA-based botnets. Through the proposed model, the detecti on rate, which is the limit of the existing detection technology, can be increased and the false positive rate can als o be minimized. Through experiments on large-scale domain datasets and normal domains used in various DGA b otnets, it was confirmed that the performance was superior to that of the existing model. It was confirmed that the false positive rate of the proposed model is less than 2 to 4%, and the overall detection accuracy and F1 score are both 97.5%. As such, it is expected that the detection and response capabilities of DGA-based botnets will be improved th rough the model proposed in this paper.

 
1 2 3 4 5
페이지 저장