Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 16
No
1

5,500원

기술의 수용 과정을 이해하는 것이 경영정보학의 중요한 관심사임에도 불구하고 현재까지 해킹 기술의 수용 과정에 대해 경영정보학 분야에서 알려진 연구나 검증된 이론이 거의 없다. 본 연구는 이를 위해 세분화된 계획된 행동이론(decomposed theory of planned behavior)을 기반으로 한 동기 요인과 함께 기술 수용을 제약하 는 억제 요인을 연구에 활용해 연구 모형을 구성했다. 본 연구는 전국의 정보보호 관련 학과, 해커 양성 교육 기 관, 정보보호 관련 공공기관, 정보보호 업체 및 기업의 정보보호 및 모의 침투 업무 담당자 264명의 설문 결과를 가지고 분석했다. 본 연구의 수행 결과, 지각된 유용성과 지각된 호환성과 같은 기술 수용에서 사용하는 고전적인 변수는 물론 예상과 다르게 사회적 요인인 비해커 동료의 영향, 외적 영향도 해킹 기술의 수용에 긍정적으로 작용 하는 것으로 나타났다. 반면 지각된 위험은 물론 기술 수용의 중요한 변수인 지각된 이용 편의성은 해커의 기술 수용에 부정적으로 영향을 준다는 것으로 나타났다.

Although understanding the adoption process of technology is an important concern of management informatics, there are few known studies or verified theories about the acceptance process of hacking technology in the field of management informatics so far. To this end, in this study, a research model was constructed by using the decomposed theory of planned behavior-based motivational factors and the deterrent factors that restrict technology acceptance in the study. This study analyzed the survey results of 264 people in charge of information protection and simulation penetration of information protection-related departments, hacker training educational institutions, information security-related public institutions, information security companies and companies nationwide. As a result of this study, it was found that not only classical variables used in technology acceptance, such as perceived usefulness and perceived compatibility, but also social factors such as the influence of beaker peers and external influences, which are unexpectedly positive, act positively on the acceptance of hacking technology. appear. On the other hand, perceived risk as well as perceived ease of use, an important variable in technology acceptance, were found to negatively affect hackers' technology acceptance.

2

사회공학적 공격기법의 유형분류 KCI 등재

김도우, 이규범

한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제9권 제2호 통권 제16호 2019.12 pp.9-21

※ 기관로그인 시 무료 이용이 가능합니다.

4,500원

사회공학적 공격기법은 결코 새로운 것이 아니며 아주 오래된 수법으로서, 모든정보보안 서적들에서 이미 언급하고 있는 내용이다. 이 연구는 사회공학적 공격기법의 유형을 분류하여 이에 맞는 대응책을 구성할 수 있는 기초자료를 제공하는것을 궁극적인 목적을 두고 있다. 사회공학기법은 접근 수단을 무엇으로 하느냐에따라서 인간 기반과 컴퓨터와 웹기반 공격기법으로 나누어지며, 공격특성과 파급효과의 정도에 따라 초심자(novice), 학생(student), 여행자(tourist), 파괴자(crasher), 절도범(thief)으로 분류할 수 있다. 결과적으로 공격의 범위가 넓고 파급효과가 클수록 보안단계를 최고수준으로 올려야 할 것이며 이에 대한 철저한 대응이 필요하다. 발전된 기술적인 보안기술을 적용하고 활용하는 사람들도 사회공학적 해킹을 방어하기 위해 교육을 받아야 한다. 그렇지 않으면 우리는 계속해서 사회공학적으로 해킹을 하는 사람들에 의해 이용당하고 정보를 빼앗기고 해킹을 당하고 난 후의 모든 피해와 책임을 감내해야할 것이다. 따라서 이전에 겪었던 사례들을 분석하고 연구하여 앞의 일어날 일들을 예측하고 예방한다면 사회공학적 공격기법의 피해를 최소화할 수 있다.

Sociological engineering attack are by no means new, but very old, and are already mentioned in all information security books. The purpose of this study is to provide the basic data for classifying the types of social engineering attack techniques and constructing countermeasures. Social engineering attack are divided into human-based, computer-based and web-based attack techniques, depending on what the means of access are, and depending on the nature of the attack and the level of the ripple effect, novice, student, tourist, and destroyer. It can be classified as crasher or thief. As a result, the wider the scope of attack and the greater the ripple effect, the higher the security level should be and the thorough response is required. Those who apply and utilize advanced technical security techniques should also be educated to defend against social engineering attack. Otherwise we will have to bear all the damages and responsibilities after being hacked into, stolen and hacked by socially hacking people. Thus, analyzing and studying previous cases to predict and prevent future events can minimize the damage of social engineering attack.

3

동기적, 사회적, 그리고 환경적 요인이 해커의 기술 습득에 미치는 영향 KCI 등재

장재영, 김범수

한국경영정보학회 경영정보학연구 제18권 제1호 2016.03 pp.57-78

※ 기관로그인 시 무료 이용이 가능합니다.

5,800원

해킹은 현대의 지식기반 사회에 심각한 문제를 야기하고 있다. 해킹으로 인한 피해 규모와 피해 금액 또한 꾸준히 증가하고 있다. 따라서 현재까지 해커 또는 해킹과 관련한 많은 연구들이 진행되어 왔다. 기존 연구에 의하면 해커들은 재미와 같은 내재적 동기에 의해 해킹 기술을 습득하며, 주로 해킹 커뮤니티에서 기술을 습득하는 것으로 알려져 왔다. 또한 최근에는 재미나 흥미 등 내재적 동기는 물론 금전적 보상 등과 같은 외재적 동기도 증가하고 있다고 한다. 그러나 현재까지의 관련 연구들은 표본 수집의 한계로 인해 정성적 연구에 치우쳐 왔다. 따라서 본 연구는 기존 연구의 한계를 극복하기 위해 해킹 커뮤니티에 소속된 멤버들을 대상으로 계획된 행동이론을 기반으로 한 정량적 연구를 진행했으며, 동기적, 사회적 그리고 환경적 요인이 해커의 학습에 미치는 영향 요인을 규명하였다. 본 연구는 보안 및 해킹 기술을 습득하기 위해 결성된 대학정보보호연합 동아리를 대상으로 2015년 5월에 약 2주 간 설문을 진행했다. 회원 전체에게 이메일을 보내 응답한 215개의 설문지를 바탕으로 연구가설을 검증하고 분석했다. 연구 결과, 해킹 기술 습득자들은 해킹 기술 습득이 사회적으로 비윤리적으로 인식되고 있다는 것을 스스로 인지하고 있었으며, 재미나 흥미와 같은 내재적 동기 및 타인의 인정을 추구하는 외재적 동기 모두 학습 태도에 영향을 주었고, 온라인 해킹 커뮤니티의 접근성과 정보 품질과 같은 환경적 특성이 해킹 기술 습득에 영향을 주는 것으로 나타났다. 본 연구는 학문적으로 해킹은 사회적으로 부정적으로 인식된다는 것을 밝혀내어 비윤리적 연구의 주관적 규범의 방향성에 대한 논의를 확장시켰고, 동기 요인들이 해킹 기술 습득 태도에 영향을 미친다는 점을 실증했다. 또한, 해킹 커뮤니티의 특성이 지각된 행동통제의 선행 요건임을 밝혀내어 계획된 행동이론의 적용 범위를 확장했다. 또한, 실무적으로 해커들을 윤리적 해커(정보보호전문가)로 만들기 위한 윤리 교육의 필요성과 해킹 방지를 위한 처벌의 강화 및 과징금 부과 등이 해커의 행동 변화에 영향을 줄 수 있음을 제시했다.

Hacking has raised many critical issues in the modern world, particularly because the size and cost of the damages caused by this disruptive activity have steadily increased. Accordingly, many significant studies have been conducted by behavioral scientists to understand hackers and their practices. Nonetheless, only qualitative methods, such as interviews, meta-studies, and media studies, have been employed in such studies because of hacker sampling limitations. Existing studies have determined that intrinsic motivation was the dominant factor influencing hackers, and that their techniques were mainly acquired from online hacking communities. However, such results have yet to be causally proven. This study attempted to identify the causal factors influencing the motivational and environmental factors encouraging hackers to learn hacking skills. To this end, hacker community members using the theory of planned behavior were observed to identify the causal factors of their learning of hacking skills. We selected a group of students who were developing their hacking skills. The survey was conducted over a two-week period in May 2015 with a total of 227 students as respondents. After list-wise deletion, 215 of the responses were deemed usable (94.7 percent). In summary, the hackers were aware that hacking skills are considered socially unethical, and their attitudes toward the learning of hacking skills were affected by both intrinsic and extrinsic motivations. In addition, the characteristics of the online hacking community affected their perceived behavioral control. This study introduced new concepts in the process of conducting a causal relationship analysis on a hacker sample. Moreover, this research expanded the discussion on the causal direction of subjective norms in unethical research, and empirically confirmed that both intrinsic and extrinsic motivations affect the learning of hacking skills. This study also made a practical contribution by raising the educational and policy response issues for ethical hackers and demonstrating the necessity to intensify the punishment for hacking.

4

리눅스 커널 백도어 침입자 추적대응시스템 설계 및 구현 KCI 등재후보

전완근

한국융합보안학회 융합보안논문지 제5권 제2호 2005.06 pp.43-50

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 논문에서는 리눅스 커널 백도어 침입자에 대한 추적과 커널 백도어의 공격에 대한 대응방법을 다룬다. 해커는 일반적으로 시스템에 침입하여 접속로그파일을 지우거나 위조된 주소정보를 사용하기 때문에 현재 로그기반의 침해사고 분석방법으로는 침입자를 추적하는데 한계가 있다. 이에 대한 해결책으로 DeFor 시스템을 제안한다. 이 시스템은 삭제된 로그복구와 전체 하드디스크 이미지 증거 분석을 통하여 침입자 위치를 추적하고, 신속하게 대응함으로써 해킹 피해를 최소화할 수 있다.

This paper is about the method that chases the Linux kernel backdoor intruder and copes with the kernel backdoor attack. We have a limit to trace the hacker with the current log analysing method because the hacker generally removes the log file and use the forge IP information. I propose the solution to solve the problem with the DeFor system. Through the restoration of the deleted log file, analysis of it and full HDD image, promptly quick response, it is possible to trace hacker spot and reduce hacking damage.

5

Public common happiness and hacker ethics

Niina Isokoski, Jenna Mäki

한국윤리교육학회 한국윤리교육학회 학술대회 동서양의 공공행복과 윤리교육 2012.11 pp.231-241

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

6

이중 MCU를 활용한 IoT 보안 교육용 하드웨어(해커보드) 설계 KCI 등재

김동원

한국융합보안학회 융합보안논문지 제24권 제1호 2024.03 pp.43-49

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

교육(education)과 기술(technology)의 융합이 강조되면서 에듀테크가 교육 현장에 적용되어 다양한 매체와 학습 상황 속에 서 학습자 중심의 맞춤형 교육환경을 제공하고 있다. 본 논문에서는 사이버보안 교육 현장에서 사물인터넷 보안 교육을 위한 에듀테크 기반의 교육용 교구를 제작하기 위하여 하나의 보드(Board) 내에서 이중 MCU를 기반으로 공격과 방어가 각각 수행 될 수 있도록 하드웨어를 설계하였으며, 사물인터넷의 다양한 센서를 활용하기 위하여 모듈형으로 설계하여 제시하였다. 교육 측면에서 에듀테크를 활용한 사이버보안 교육은 실제 물리적인 교구를 활용함으로써 교육에 대한 호감을 키우고, 임베디드 하 드웨어와 소프트웨어, 센서 네트워크 등 기존 교육에서 다루기 어려운 분야에 대한 보안 교육 환경을 간단하게 구성하기 위하 여 IoT 보안 교육용 하드웨어 설계시 참고가 될 수 있도록 연구 제안한다.

The convergence of education and technology has been emphasized, leading to the application of educational technology (EdTech) in the field of education. EdTech provides learner-centered, customized learning environments through various m edia and learning situations. In this paper, we designed hardware for EdTech-based educational tools for IoT security edu cation in the field of cybersecurity education. The hardware is based on a dual microcontroller unit (MCU) within a single board, allowing for both attack and defense to be performed. To leverage various sensors in the Internet of Things (IoT), the hardware is modularly designed. From an educational perspective, utilizing EdTech in cybersecurity education enhances engagement by incorporating tangible physical teaching aids. The proposed research suggests that the design of IoT secur ity education hardware can serve as a reference for simplifying the creation of a security education environment for embe dded hardware, software, sensor networks, and other areas that are challenging to address in traditional education..

7

4,000원

기존의 강의식 사이버보안 교육은 이론 중심으로 실무역량 배양에 한계를 보인다. 본 연구에서는 하드웨어(해커보드)를 활 용한 플립러닝 기반 Bloom’s Taxonomy 교수학습 모형을 개발하여, 실습 중심 학습 환경이 학습자의 만족도, 흥미도, 참여도 에 미치는 영향을 분석하였다. Bloom의 교육 목표 분류(Bloom’s Taxonomy)를 적용하여 단계적 학습설계를 도입하였으며, 혼 합 연구 방법(Mixed-Method Approach)을 활용해 3년간(2022~2024) 학습자 데이터를 수집하였다. 연구 결과, 하드웨어 기반 실습 교육이 학습 몰입도를 높이고, 신기술에 대한 흥미를 유발하며, 진로 탐색 및 실무능력 향상에 긍정적인 영향을 미치는 것으로 나타났다. 특히, 사이버공격 및 방어 실습을 직접 수행하는 과정이 학습 효과를 극대화하는 핵심 요인으로 작용하였다. 본 연구는 에듀테크를 활용한 실습형 교수학습 모형이 기존 교육의 한계를 극복하고 실무역량 배양에 효과적임을 실증적으로 제시하였다.

Traditional lecture-based cybersecurity education focuses on theoretical learning, limiting the development of practical skills. This study developed a Flipped Learning-Based Bloom’s Taxonomy Instructional Model Using Hardware (Hacker Board) and analyzed the impact of a hands-on learning environment on learners’ satisfaction, interest, and engagement. The study applied Bloom’s Taxonomy to implement a step-by-step learning structure and adopted a Mixed-Method Approach to collect learner data over three years (2022–2024). The results demonstrated that hardware-based practical education enhances learning immersion, stimulates interest in new technologies, and positively influences career exploration and practical skill development. In particular, the process of directly performing cyberattack and defense exercises was identified as a key factor in maximizing learning effectiveness. This study empirically verifies that a hands-on instructional model utilizing EduTech can overcome the limitations of traditional education and effectively cultivate practical competencies in cybersecurity.

8

8,800원

본 논문은 미국 뉴딜 시기 사회입법에서 재계가 수행한 역할에 관해 제이콥 해 커 및 폴 피어슨과 피터 스웬슨이 벌인 논쟁을 분석적으로 재구성하고 그 한국적 함의를 검토한다. 먼저 논쟁에 대한 검토에 앞서 미국 초기 복지국가 형성에 관한 네 가지 설명을 제시함으로써 논쟁의 의미와 위상을 이론사적 맥락에 위치시킨다. 검토의 대상이 되는 이 논쟁에서, 해커와 피어슨은 1935년 사회보장법의 통과를 재계권력의 쇠퇴와 노동을 포함한 아래로부터의 압력에 의한 것으로 파악한다. 반 면 스웬슨은 뉴딜 개혁가들에게 개혁에 대한 지지 신호를 보냈던 자본가와 이같은 “예상된 이해관계”에 대한 정치인들의 전략적 대응이라는 양자의 상호작용(“조정 동맹”)에 주목했다. 따라서 해커와 피어슨이 1930년대의 경제위기와 민주당의 집 권에 따른 연방정부의 권한 증대가 사회보장법의 통과에 결정적이었다고 보는 데 반해, 스웬슨은 경제 환경의 변화로 인한 노동시장 거버넌스 제도의 변화에 따라 자본가의이해관계 역시 변화했다고 주장한다. 또한 스웬슨에 따르면, 이러한변화 는 자본가의 이해관계를 예측한 뉴딜 개혁가들의 전략적 역할을 고려하지 않고서 는 이해될 수 없다. 요컨대, 전체적인 권력 지형의 변화를 중시하느냐 또는 자본가 의 이해관계의 변화 양상을 강조하느냐에 따라 뉴딜 사회입법의 역사는 매우 상이 한 방식으로 해석된다. 우리는 양측의 주장을 구체적으로 살펴보기 위해 노령보험의 사례에 대한 해석을 간략히 검토함으로써 양측이 동일한 사안을 어떻게 다른 방식으로 해석하는지 제시한다. 논쟁을 평가하면서, 우리는 방법론적 측면에서 자본가의 이해관계 분석과 권력 분석의생산적 결합을 제안한다. 주목하는대상의 차이에도 불구하고, 권력지형에 대한 탐색과 자본가의 전략적 행동의 원인에 대한 분석이 결합한다면, 역사에 대 한보다 풍부한 해석이 가능할 수 있기때문이다. 끝으로 결론에서는 이논쟁이 한 국사회에 가질 수 있는 두 가지 함의를 지적한다. 첫째, 1976년의 의료보험법 개정 사례가 한국의 건강보험 발전에서 재계의 이해관계가 어떻게 관여했는지 분석할 수 있는 단초가 될 수 있다는 점을 제시한다. 둘째, 최근 논의되고 있는 ‘복지국가 논쟁’의 일부를 살펴봄으로써 복지국가 건설에 대한 재계의 기여를 주장하는 입장 들을 비판적으로 검토한다.

This article aims to analytically reconstitute a controversy over the role of business in initiating and supporting the social legislation in the era of New Deal in the United States, which is carried out by Jacob S. Hacker & Paul Pierson (hereafter H&P) and Peter Swenson in distinct ways. By doing so, we also consider its implications for the Korean counterpart. First of all, we place this debate on the theoretical context of American political development by suggesting four accounts of how the early American welfare state was formed. In this controversy, H&P see the passage of Social Security Act (hereafter SSA) in 1935 as a result of combination of decline of business power and increased pressure from below including labor. On the other hand, Swenson focuses on the "arranged alliance" between business which signalled its support for social reform which New Dealers pursued, and the latter who anticipated interests of business for regulatory merits which the reform could have. Therefore, while H&P argue that the increase of federal government's power caused by the economic crisis and the electoral victory of the Democratic party in 1930s was critical for the passage of the SSA, Swenson disputes that with the change of institutions of the labor market governance which was caused by the economic fluctuation, capitalists' interests also transformed. Also, according to him, this transformation cannot be understood without considering the strategic role of New Dealers who expected the interests of capitalists. In sum, relying on whether emphasizing the change of the power configuration among social actors or weighting on the variation of the capitalists' interests determines one to interpret the New Deal history in quite different ways. In order to see both arguments in more detail, we briefly deal with the interpretation of the case of Old Age Insurance and discuss how both of them look the same issue disparately. Assessing the controversy, we suggest a productive incorporation of analysis of capitalists' interests with that of their power. In spite of distinct dimensions on which they focus, combining an exploration on the power configuration among social actors with an analysis on strategic behavior of capitalists can make one to understand the history of the New Deal in more fertile fashion. In conclusion, we present two implications of this controversy for Korean society. First, we suggest that the case of revision of medical insurance in 1976 may be an important clue to analyze how business' interests involved in the development of Korean health insurance. Second, considering a part of the recent debate on 'the welfare state', we make a critical examination of how the business can encourage a formation of welfare state in Korea.

9

해커의 유비쿼터스 홈 네트워크 공격에 대한 정보보호 기술

천재홍, 박대우

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.12 No.5 2007 pp.145-154

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 유비쿼터스 홈 네트워크에서의 개인정보보호를 위해 유비쿼터스와 홈 네트워크의 보안을 위협하는 다양한 보안 위협사항과 요구사항에 대해 분석하고 연구하였다. 보안기능을 강화한 유비쿼터스 홈 보안 게이트웨이를 설계를 통해 외부에서의 정당한 사용자 접근 시, 인증절차와 검증절차를 마련함으로써 홈 네트워크의 보호를 강화하였다. 또한 DoS, DDoS, IP Spoofing 공격을 실시하여 홈 네트워크 보안 게이트웨이에서의 방어실험을 함으로써 해커의 공격에 대한 보안이 이루어졌음을 확인하였다. 공격 실험을 통해 유비쿼터스 홈 네트워크에서의 기기와 사용자에 대한 보안을 강화하고, 외부 공격에 대한 방어를 확인함으로써 본 논문의 홈 네트워크 보안 모델을 유비쿼터스 홈 네트워크에서의 개인정보보호를 강화할 수 있는 방안으로 제시한다.

Analyzed about a matter and requirements to intimidate security of ubiquitous and home network threatening various security for personal information protection in ubiquitous home networks at this paper, and studied. Got authentication procedures and verification procedures acid user approach to be reasonable through designs to the home security gateway which strengthened a security function in the outsides, and strengthened protection of a home network. Also, execute a DoS. DDoS, IP Spoofing attack protective at home network security gateways proved, and security regarding against the Hacker's attack was performed, and confirmed. Strengthen appliances and security regarding a user, and confirm a defense regarding an external attack and present a home network security model of this paper to the plans that can strengthen personal information protection in ubiquitous home networks in ubiquitous home networks through experiment.

10

화이트 해커 양성 및 활성화 방안에 대한 연구

홍준호, 유현우

[NRF 연계] 한국법학회 법학연구 Vol.17 No.4 2017.12 pp.463-515

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 IT 기술이 비약적으로 발전하면서 인터넷을 기반으로 하는 사이버 공간은 국가의 활동은 물론 기업의 비즈니스와 국민들의 일상생활에서도 중요한 영역으로 자리매김하고 있다. 사이버 공간에 대한 중요성과 이에 대한 의존이 커지면서 사이버 공간에서의 공격, 테러, 해킹 등 잠재적인 위협과 위험 역시 함께 증대되고 있는데 특히 제4차 산업혁명 시대가 본격화되고 전 세계가 인터넷을 통해 연결되는 초 연결 사회로 진입하면서 사이버 공간에서의 공격 및 위협은 전 세계적으로 확대되고 있다. 점차 지능화·고도화·대규모화 되고 있는 사이버 위협 및 공격은 단순한 경제적 피해는 물론 사회적인 혼란과 더 나아가 국가 안보에 대한 위협까지 되고 있는 실정이다. 이처럼 지능화되고 대규모화 되고 있는 사이버 공간에서의 공격 및 테러에 대응하기 위한 근본적인 대책을 요구하는 목소리가 높아지고 있으며, 이와 함께 사이버 안보 및 보안에 대한 관심 또한 높아지고 있다. 이에 세계 각국은 국가의 사이버 안보 및 보안 수준을 높이기 위해 정보보호 분야 투자촉진, 전문 인력 양성 등의 정책을 적극적으로 추진하고 있다. 화이트 해커는 모의 해킹이나 다른 취약점 점검 등의 기법을 통해 취약점을 식별하거나 취약점 패치에 주력하는 윤리적 성향의 전문적인 보안전문가로서 사이버 공간에서의 공격 및 침해, 더 나아가 국가 간 전쟁의 위협이 도사리고 있는 오늘날 국가 간 전쟁을 위한 수단이자 국가의 중요한 자산으로 인식되고 있으며, 실력과 윤리의식을 겸비한 유능한 화이트 해커의 확보는 곧 국가 안보를 강화하는 수단으로 여겨지고 있다. 화이트 해커는 사이버 안보 및 보안의 전문가이자 첨병 역할을 할 수 있기 때문에 전국가적 차원에서 화이트 해커를 양성하고 활용 및 관리해야 할 필요성이 있다. 이에 본 논문에서는 법·제도적 차원과 교육적 차원, 지원·관리적 차원에서 화이트 해커 양성 및 활성화 방안에 대해 고찰해 보았다.

Recently IT technology has developed dramatically and cyberspace based on the Internet is an important area not only in the activities of the state but also in the business of the company and daily life of the people. But, the importance and dependency on cyberspace are growing, potential threats and dangers such as attacks, terrorism and hacking in cyberspace are also increasing. Especially, as the era of the 4th Industrial Revolution started and the world entered into the hyper-connected society where the whole world is connected through the Internet, attacks and threats in cyberspace are spreading all over the world. Cyber threats and attacks that are gradually becoming more intelligent, advanced and larger have become simple threats as well as social turmoil and even a threat to national security. Like this, there is an increasing demand for fundamental countermeasures to cope with attacks and terrorism in cyberspace that has become more intelligent and large scale. Interest in cyber security and security is also growing. In order to increase the level of cyber security and security, each country in the world actively promotes policies such as promoting investment in the field of information protection and training specialized human resources. White hackers are ethical professional security experts who try to identify vulnerabilities or patch vulnerabilities through techniques such as mock hacking or other vulnerability checks. Today, with attacks and infringements in cyberspace, and even threats of war between nations, They are perceived as an important asset of the state and a means for war between nations. And securing a competent white hacker who combines skills and ethical awareness is now seen as a means to strengthen national security. Since white hackers are experts in cyber security and could play the role of advance guard, it is necessary to nurture, utilize and manage white hackers at the state level. Thus, we examined white hacker training and activation plan in terms of law·Institutional perspective, educational perspective, support·administrative perspective in this paper.

11

WiBro에서 공격 이동단말에 대한 역추적기법 연구

박대우, 임승린

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.12 No.3 2007 pp.185-194

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

WiBro가 IEEE802.16e로 국제 표준화 되었다. 국내뿐만 아니라 세계에서도 휴대인터넷으로 WiBro 서비스를 시작하고 있다. 본 논문에서는 불법 공격자인 해커가 휴대인터넷 WiBro의 이동단말을 이용하여 자신의 위치추적을 피하기 위하여, 피해 시스템을 직접 공격하지 않고 우회 공격을 수행한다. 현재 인터넷망에서 침입 기술에 적극적인 보안을 위한 진보된 알고리즘을 응용하여 효과적인 역추적 기법 등을 연구한다. 공격자인 이동단말에 대한 역추적을 할 때, 실시간 네트워크 로그 감사기록을 이용하고, TCP/IP와 네트워크 기반에서는 Thumbprint Algorithm, Timing based Algorithm, TCP Sequence number 등을 이용한 알고리즘 및 SWT 기법 등을 이용한 역추적 기법 등을 설계하고, 역추적을 실시하였다. 또한 트래픽 폭주 공격에 대해 AS시스템을 이용한 네트워크 트래픽 관리와 통제 및 실시간으로 역추적을 하였다. 본 논문의 연구 결과는 유비쿼터스 환경에서의 WiBro 인터넷에서의 역추적을 실시하고 포렌식 자료를 확보하는데 이바지 할 수 있을 것이다.

WiBro has become intentionally standardize as IEEE 802.16e. This WiBro service has been started by a portable internet at home as well as abroad. In this paper, an offender hacker do not direct attack on system on system that It marched an attack directly in damage system because a place oneself in mobile station of portable internet WiBro and avoid to attack hacker's system. At this time, a mobile make use of network inspection policy for back-tracking based on log data. Used network log audit, and presented TCP/IP bases at log bases as used algorithm, the SWT technique that used Thumbprint Algorithm. Timing based Algorithm, TCP Sequence number. Study of this paper applies algorithm to have been progressed more that have a speed to be fast so that is physical logical complexity of configuration of present Internet network supplements a large disadvantage, and confirm an effective back-tracking system. result of research of this paper contribute to realize a back-tracking technique in ubiquitous in WiBro internet network.

12

해커의 공격에 대한 실시간 보안공조시스템 연구

박대우

[Kisti 연계] 한국정보통신학회 한국정보통신학회 학술대회논문집 2010 pp.285-288

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

중국의 해커가 제3국으로 한국IP를 우회 접속하여 전자상거래사이트를 해킹하여, 대포계좌로 금융피해를 입히는 한 침해사고가 났었다. 7.7 DDoS공격은 국가의 주요사이트를 마비시킨 해커의 공격사건이었다. 본 논문에서는 해커의 침해사고와 DDoS공격에 취약점 분석을 한다. 해커의 공격에 대한 전조 증상 및 공격 연관성 분석을 통하여 실시간으로 Red, Orange, Yellow, Green에 속하는 위험등급을 나눈다. 해커에 대한 블랙리스트를 작성하여 실시간으로 공격을 차단 방어하는 보안공조시스템을 연구한다. 침해사고 후 패킷에 대한 역추적과 탐지를 통해 포렌식 자료를 생성하고 법정에서 책임소재의 증거로 확정하는 연구를 하여 국가 침해사고 대응과 포렌식 기술 발전에 기여한다.

Chinese hackers hack the e-commerce site by bypass South Korea IP to connect to the third country, finance damaging a violation incident that fake account. 7.7.DDoS attack was the case of a hacker attack that paralyzed the country's main site. In this paper, the analysis is about vulnerabilities that breaches by hackers and DDoS attacks. Hacker's attacks and attacks on the sign of correlation analysis is share the risk rating for in real time, Red, Orange, Yellow, Green. Create a blacklist of hackers and real-time attack will be studied security and air conditioning systems that attacks and defend. By studying generate forensic data and confirmed in court as evidence of accountability through IP traceback and detection about packet after Incident, contribute to the national incident response and development of forensic techniques.

13

해커의 공격에 대한 지능적 연계 침입방지시스템의 연구

박대우, 임승린

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.11 No.2 2006 pp.351-360

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

기존의 침입차단시스템과 침입탐지시스템의 단점을 개선할 수 있는 지능적 연계 침입방지시스템을 제안한다. 제안된 보안 시스템은 공격 검출, 공격 우회로 설정 및 통신량 대역 확보, 다른 연계 보안 시스템에 공격 정보 홍보, 내부 IPS에서의 필터 생성, 차단 필터링의 즉각적인 업데이트, 공격 패킷 차단 및 서비스와 포트 차단 설정이다. 스위치 타입 구현과 동적 재설정 메모리들을 통해 새로운 보안 규칙과 패킷 필터링을 실시간으로 교환하고 패킷을 처리한다. 네트워크 성능 실험에서 해커의 공격인 2.5 Gbs의 DDoS, SQL Stammer, Bug bear, Opeserv worm 등에 대한 공격검출이 실시간으로 이루어졌다. 이를 갱신하는 보안 정책 알고리즘의 즉각적인 갱신의 결과로 정상적인 패킷 외에 해커의 공격으로 인한 패킷은 차단되었고, 트래픽은 감소되어, 정상적인 내부와 외부 네트워크 트래픽의 잔여 대역폭을 확보하였다.

Proposed security system attacks it, and detect it, and a filter generation, a business to be prompt of interception filtering dates at attack information public information. inner IPS to attack detour setting and a traffic band security, different connection security system, and be attack packet interceptions and service and port interception setting. Exchange new security rule and packet filtering for switch type implementation through dynamic reset memory by real time, and deal with a packet. The attack detection about DDoS, SQL Stammer, Bug bear, Opeserv worm etc. of the 2.5 Gbs which was an attack of a hacker consisted in network performance experiment by real time. Packet by attacks of a hacker was cut off, and ensured the normal inside and external network resources besides the packets which were normal by the results of active renewal.

14

사인의 컴퓨터 해킹에 의한 증거수집과 증거배제법칙 - 미국의 United States v. Jarret 사건과 관련하여 -

김종구

[NRF 연계] 한국형사법학회 형사법연구 Vol.21 No.3 2009.09 pp.291-314

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In the United States v. Jarret, the hacker, who claimed to be from Istanbul, Turkey, gained entry to Jarret's computer who lived in the US through the use of a Trojan Horse program and found child pornography on Jarret's personal computer hard drives. After finding the pornography, the Turkish hacker contacted with the US law enforcement to inform them of the child pornographer, the defendant Jarret. The child pornography found by the Turkish hacker was admitted by the US court, and the defendant Jarret was convicted of producing and possessing child pornography. In the United States v. Jarret, the defendant Jarret claimed that the hacker's actions and his close relation with the FBI made the hacker the equivalent of a government agent. The defendant argued that searches conducted by the hacker should be covered under the Fourth Amendment, and the evidence obtained by the hacker should be excluded from the trial, based on the principle of agency. However, the Fourth Circuit Court of Appeals rejected Jarrett's claim that the hacker was a government agent subject to Fourth Amendment restrictions. The court asserted that mere acquiescence was insufficient, rather, the government must affirmatively support the search. A hacker can conduct efficient and anonymous electronic searches of vast amounts of information stored on personal computers. Consequently, personal computers are vulnerable to warrantless searches by private parties doing the work of law enforcement. In the digital era, the invasion of privacy on the internet by a private party could be more dangerous than the invasion of privacy by the government. Although, society must protect its children by ensuring that men like Jarret are imprisoned for many years, individuals are entitled to a reasonable expectation of privacy in their computer files. Thus the author of this article agrees with the argument that the traditional position of the US courts, applying the exclusionary rule only to governmental activity, is outdated and should be modified especially in the era of computer technology.

15

실시간 침입자 행동양식 파악 시스템의 설계 및 구현

서동일, 최양서, 이상호

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2003 pp.1941-1944

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷이 생활의 한 부분이 되면서 인터넷 사용자가 급증함에 따라 각종 사이버 범죄의 발생 건수 역시 크게 증가하고 있다 이러한 각종 사이버 범죄에 대응함에 있어서 가장 심각한 문제 중의 하나는 해커가 어떤 기술을 이용하여, 어떠한 방식으로 해킹을 진행하는지에 대한 정보가 매우 부족하다는 것이다. 현재 해커들은 해킹에 성공하기 위해 고도의 해킹 기법과 새로운 취약점을 이용하고 있는 반면, 해킹 방지를 위해 사용되고 있는 보안 강화 시스템들은 새로운 방식을 이용하는 해킹 시도를 효율적으로 방어하지 못하고 있는 것이 현실이다. 이와 같은 문제점을 해결하기 위해 제안된 것이 해커의 행동 양식에 대한 정보를 얻기 위한 침입유도 시스템(Honeypot)이다. 그러나 기존의 침입유도 시스템은 해커의 행동 양식 파악에 전문적인 기술이 필요하여 실시간 정보분석이 용이하지 못했다. 이에 본 논문에서는 해커의 행동양식을 실시간으로 파악하고 분석하는 허니넷(Honeynet) 형태의 침입자 행동양식 파악 시스템(Honeypot)을 설계하고 개발하였다.

16

신경과학이 철학적 반성을 필요로 하는 까닭은? - ‘신경적 유물론’에 대한 베넷과 해커의 비판 -

이을상

[NRF 연계] 새한철학회 철학논총 Vol.81 No.3 2015.07 pp.169-196

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

신경과학은 심리학적 술어들이 뇌의 활동으로 설명될 수 있다고 본다. 이 지점이야말로 신경과학이 철학적 반성을 필요로 하는 대목이다. 여기서 철학은 다음과 같은 사실을 상기시킨다. 우선 심리학적 개념(속성)들은 인간 전체에 귀속시켜야만 비로소 의미를 얻는다. 그럼에도 불구하고 이를 뇌나 뇌의 부분들에 귀속시키는 것은 전혀 ‘무의미’하다는 점이다. 이러한 무의미가 만들어지는 논리적 오류를 ‘부분-전체의 오류’라 한다. 이렇게 오류가 생겨나는 까닭은 일찍이 데카르트가 인간을 마음과 신체로 구분하고, 심리적 속성을 마음에 배타적으로 귀속시켰는데, 이러한 데카르트의 오류를 신경과학자들이 무비판적으로 답습했기 때문이다. 이러한 논리적 오류로 인해 신경과학자들의 언어 사용 및 심리학적 용어는 논리적-문법적 분석을 필요로 한다. 이때 언어 분석의 틀을 제공해 주는 것이 비트겐슈타인의 일상 언어에 대한 의미론적 해석이다. 이러한 철학적 해석과 달리 과학에서는 ‘환원’이 필수적인데, 철학은 또한 과학의 환원적 방식이 신경과학에서 이념화되는 것에 반대한다. 이렇게 신경과학에서 이념화된 환원주의가 일종의 ‘환상’임을 들어 우리는 신경과학의 인식론적 반성을 촉구한다.

Neuroscience believes that psychological attributes can be well explained by neural activities of brain. This belief meets with strong philosophical criticism. In this regard philosophy reminds us of the following; A psychological concept(attributes) can only have a meaning when we ascribe it to man himself, but ascribing it to brain or a part of brain results 'nonsense'. This nonsense is called a mereological fallacy. This is originated from neuroscientist's uncritical reception of Descartes's error, which is consisted in body-mind dualism, ascribing psychological attributes to mind. For such logical fallacy are language-usages of neuroscience and psychological terms needed logical-grammatical analysis. Here L. Wittgenstein's semantic interpretation of ordinary languages supplies a frame of analysis. Unlike philosophical interpretation, 'reduction' is requisite for science, but philosophy also objects to be idealized reductional method of science in neuroscience. Such a idealized reductionism in neuroscience can cause a kind of 'illusion'. This is why we ask neuroscience to reconsider a philosophical(especially epistemological) reflection.

 
페이지 저장