년 - 년
한국경영정보학회 한국경영정보학회 정기 학술대회 소통과 동반성장을 위한 ICT 비즈니스 혁신 2011.11 pp.497-500
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Most of business activities are performed on the basis of information assets in cyberspace. However, assets are exposed to threats that cause information security incidents. In order to cope with increasing security incidents, companies has invested to information security measures such as policies and procedures, access control mechanisms, anti-virus software, encryption, digital signatures, monitoring and analysis tools, backup copies of information, and security awareness and training programs. Nonetheless, security incidents have significantly increased. The objective of this paper is to investigate the relationship between information security measures and security incidents that decrease production efficiency. For this purpose, this study analyzes a survey data from finance and insurance companies by using negative binomial regression model. Our results could be utilized to establish a guideline about which security measures should be improved to reduce security incident.
IoT 사용자의 빅데이터 정보를 안전하게 보호하기 위한 IoT 정보 보안 모델 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제9권 제11호 2019.11 pp.8-14
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
컴퓨터 기술의 발전으로 인하여 IoT 기술은 산업, 경제, 의료서비스 및 교육 분야에서 다양하게 사용되고 있다. 그러나, IoT 장비를 통해 처리되는 멀티미디어 정보는 아직까지 애플리케이션 분야에서 무결성과 기밀성 문 제가 큰 이슈 중 하나로 손꼽히고 있다. 본 논문에서는 IoT 장비를 통해 처리되는 사용자의 빅데이터 정보에 안전 성을 보장하기 위한 스테가노그래피 기반의 IoT 사용자의 빅데이터 보호 모델을 제안한다. 제안 모델은 사용자의 동의 없이 IoT 장비를 통해 수집된 사용자의 빅데이터 정보를 불법적으로 악용되는 것을 예방하는 것이 목적이다. 제안 모델은 IoT 사용자의 빅데이터에 서명과 인증 정보를 하이브리드 암호 방식으로 사용한다. 제안 모델은 IoT 를 통해 수집된 사용자의 빅데이터에 대한 무결성 및 기밀성을 보장하는 특징이 있다. 또한, IoT 사용자의 빅데이 터는 스테가노그래피 기반의 암호 처리 기법을 사용하여 사용자의 서명 정보를 암호화하였기 때문에 제 3자가 사 용자의 정보를 악의적으로 사용되지 못한다.
Due to the development of computer technology, IoT technology is being used in various fields of industry, economy, medical service and education. However, multimedia information processed through IoT equipment is still one of the major issues in the application sector. In this paper, a big data protection model for users of IoT based IoT is proposed to ensure integrity of users' multimedia information processed through IoT equipment. The proposed model aims to prevent users' illegal exploitation of big data information collected through IoT equipment without users' consent. The proposed model uses signatures and authentication information for IoT users in a hybrid cryptographic method. The proposed model feature ensuring integrity and confidentiality of users' big data collected through IoT equipment. In addition, the user's big data is not abused without the user's consent because the user's signature information is encrypted using a steganography-based cryptography-based encryption technique.
미래 정보전에 대비한 육군전술지휘정보체계(C4I) 정보보호대책 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제9호 2012.10 pp.1-13
※ 기관로그인 시 무료 이용이 가능합니다.
4,500원
본 연구는 현재운용중인 국방정보통신망의 운용실태와 시스템의 구조·관리, 통신선로, 선로용 보안장비, 네트워크 및 소프트웨어의 관리, 보관중인 자료와 전송자료, 우리 군(軍)의 C4I체계에 대한 전반적인 취약점에 대해 분석을 실시하였다. 특히, 이중에서도 차후 전장에서 정보전의 핵심이 될 수 있는 육군전술지휘정보체계(C4I)에 대해 중점적으로 분석을 실시하여, 제시된 취약요소를 토대로 정보보호 적용방안을 제시하였다. 첫째, C4I 체계의 취약요소에 실질적으로 적용될 수 있는 보안운용체제, 인증제도, 바이러스 및 악성소프트웨어에 대한 대비, 가상사설망(VPN), 침입차단·탐지시스템, 방화벽 등 다양한 정보보호 요소기술을 제시함으로써 네트워크, 하드웨어(컴퓨터보안), 통신측면(통신보안)에서 강구될 수 있는 방안을 마련하였다. 둘째, 최근 사회적으로 이슈가 되고 있는 해커전에 대비하기 위해 해킹수법의 분석을 통한 위협을 살펴봄으로써 육군전술지휘정보망에 대한 대응책을 수립할 수 있도록 방안을 제시하였음. 셋째, 합리적인 국방정보보호체계를 구축하기 위해서 정보보호 관련된 제도 및 규정, 조직의 정비와 보완 등 여러 가지 선행되어야 할 요인들을 제시함으로써 효율성 높은 국방정보보호 체계를 구축할 수 있는 기반을 마련하였다. 본 연구의 결과를 바탕으로 얻어진 결론을 제시하면 성공적인 정보보호체계의 구축을 위해서는, 여러 기종의 다양한 보안시스템을 통하여 침입행위를 실시간으로 탐지하고 신속한 대응을 수행하며 침입관련 정보를 수집·분석하여 적절한 구성정보를 유지하여 주는 효율적인 ‘통합보안시스템’의 구성·운영이 필수적임을 강조한다.
This study aims to analyze actual conditions of the present national defense information network operation, the structure and management of the system, communication lines, security equipments for the lines, the management of network and software, stored data and transferred data and even general vulnerable factors of our army tactical C4I system. Out of them, by carrying out an extensive analysis of the army tactical C4I system, likely to be the core of future information warfare, this study suggested plans adaptive to better information security, based on the vulnerable factors provided. Firstly, by suggesting various information security factor technologies, such as VPN (virtual private network), IPDS (intrusion prevention & detection system) and firewall system against virus and malicious software as well as security operation systems and validation programs, this study provided plans to improve the network, hardware (computer security), communication lines (communication security). Secondly, to prepare against hacking warfare which has been a social issue recently, this study suggested plans to establish countermeasures to increase the efficiency of the army tactical C4I system by investigating possible threats through an analysis of hacking techniques. Thirdly, to establish a more rational and efficient national defense information security system, this study provided a foundation by suggesting several priority factors, such as information security-related institutions and regulations and organization alignment and supplementation. On the basis of the results above, this study came to the following conclusion. To establish a successful information security system, it is essential to compose and operate an efficient 'Integrated Security System' that can detect and promptly cope with intrusion behaviors in real time through various different-type security systems and sustain the component information properly by analyzing intrusion-related information.
U-사회에서의 한국과 일본의 정보보호정책 추진방안― 한국과 일본의 정책비교를 통한 국가협력을 중심으로 ― KCI 등재
한국일본학회 일본학보 제64권 2005.08 pp.375-390
※ 기관로그인 시 무료 이용이 가능합니다.
4,900원
In ubiquitous society(u-Society) the information technology forces the changes of public service and citizen's needs. Each country has been implementing National Informatization Plan(NIP) based on information security policy, because the information security is a part of major issues to be resolved to construct secure u-Government. In case of Korea and Japan, both try to overcome the problem of informatization risks by containing them as one of NIP initiatives. So this study analyzes information security policy from political, technical, and administrative perspectives. After then the study tries to make a plan for the information security through the cooperation of both countries. Therefore, the study suggests an effective cooperating method to realize u-Society.
지식정보보안 산업의 현황과 전망 KCI 등재
한국보안관리학회(구 한국경호경비학회) 시큐리티 연구 제39호 2014.06 pp.269-294
※ 기관로그인 시 무료 이용이 가능합니다.
6,400원
최근 우리나라는 카드3사의 개인정보 유출 등으로 보안 산업에 대한 관심이 높아지고있다. 경영자들은 개인 정보 유출 등 보안 사고에 의한 피해가 어떠한 재무적 위험보다도더 위험한 요소로 인식하고 있다. 지식정보 보안 산업은 과거 물리보안 및 네트워크 보안에서 최근에는 사회 안전 및 시설보안 등 융합 산업 보안으로 진 화하고 있다. 관심분야도방화벽이나 Anti-virus 등에서 스마트폰보안 및 지능형영상보안 등 융합보안 산업으 로 변해가고 있다. 융합보안은 시설경비나 출입통제 중심에서 최근에는 공공기관 및 대기업을 중심으로수요가 확대되고 있다. 금융, 교육, 유통, 국방, 의료, 자동차산업에 이르기까지 범위가 빠르게 증가하고 있다. 융합보안시장은 지능 형차량 보안, U-헬스케어 보안, 금융 보안, 스마트그리드 보안, 주력산업 보안 등 다양한 분야에서 제품 및 서 비스가 개발되고 있으며 시장이 확대되고 있다. 지식정보보안 산업의 발전을 위해 시장중심의 인재를 육성하고 학계와 연계하여 교육과정의 신설 및 강화가 요구된다. 글로벌 기업과의 경쟁력 강화를 위해 교육의 질적 수준을향상시키고 동시에 대국민 보안의식을 높 이기 위한 노력이 병행되어야 할 것이다.
Korea is concerned with information security industry due to recent leak-out privateinformation of 3 card companies. Executives are aware of damage from breach of securitysuch as personal data spill, is more dangerous than any other financial risks. The information security industry, which was limited in physical security and networksecurity formerly, is evolving into convergence security of public and facility security industry. The field of interest has also been changed into security of smart phone and intelligenceimage recently, from firewall or Anti-virus. The convergence security is originally about access control of facility, but recently itsdemand has been increased mostly by public institutions and major companies. The scopeof the industry also varies from finance, education, distribution, national defense, medicalcare to automobile industry. The market of convergence security has been expanded and new various products andservices of security of intelligent vehicle, ‘U’ healthcare, finance, smart grid and key industriesare also developed. It is required to create and enhance of new curriculum and cultivate human resourcesfor the development of knowledge information security industry. Raising standard ofeducation and security consciousness of the nation is also necessary to strengthen the globalcompetitiveness.
정보보호영재교육원 운영현황 분석 및 개선방안 KCI 등재
한국디지털정책학회 디지털융복합연구 제14권 제12호 2016.12 pp.441-449
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
오늘날 행정, 금융 등의 일상 업무가 정보시스템 기반으로 운영되고, 국가‧공공‧민간기관 등을 대상으로 다양 한 사이버 침해가 발생됨에 따라 기술적인 보안 대책뿐만 아니라 정보보호 전문 인력에 대한 사회적 수요가 증가하 고 있다. 이에 교육부에서는 정보보호 우수 인재를 조기에 발굴하여 정보보호 전문성과 윤리의식을 겸비한 전문 인 력을 양성하고자 2014년에 전국 4개 대학에 정보보호영재교육원을 설치하였다. 그러나 이미 오랫동안 운영되어 많은 연구가 이루어진 수학영재나 과학영재교육원에 비해 초기 운영단계인 정보보호영재교육원은 아직까지 체계적인 분석 이나 연구가 미비한 실정이다. 본 논문에서는 전국 4권역 정보보호영재교육원의 현황을 운영, 선발, 교육 3분야로 나 눠 분석하여 현재 운영체계의 부족한 부분을 도출하고 이를 토대로 향후 정보보호영재교육원이 효과적인 운영 및 인 력양성을 위한 실질적인 프로그램을 구축할 수 있도록 개선방안을 제안한다.
Today, as a daily routine such as administration/finance is operated under information system and various cyber crime against national, public, and private institutions happen, demand for information security manpower is increasing. Hence, Ministry of Education has formed an Institute of Information Security Education for the Gifted to early discover talent in the field of information security and train professional personnel with specialty and ethics in 4 universities of country in 2014. But the nascent Institute of Information Security Education for the Gifted lack systematic analyses compared to Institute of Mathematics and Science Education for the Gifted that has existed from a long time ago. In this paper, we analyze the state of the Institute of Information Security Education for the Gifted in three parts: operation, selection, education and suggest an improvement to build a practical program for effective operations and education.
국내 정보보호의 체계적인 교육을 위한 대학교육과정에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제16권 제4호 2016.06 pp.35-41
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 국내 정보보호에 대한 인식은 사이버전과 해킹 사고들로 인해 매우 높아졌으나, 아직까지 정보보호 전문가가 매우 부족한 상황이다. 이러한 상황에서 국내 대학들의 관련학과 개설이 늘어나고, 교육기관들은 다양한 커리큘럼들을 개발하고 있다. 그러나 국내 정보보호 교육과정은 대학 또는 학과에 따라 서로 다르고, 실무적인 교육보다는 이론 교육에비중이 높은 경향이 나타나고 있다. 따라서 본 논문은 국내 정보보호 관련 대학들의 정보보호 관련 교육과정을 조사 및개선방향을 알아봄으로써, 향후 국내 정보보호 교육에 대한 체계적인 교육과정 개발에 활용될 것으로 기대한다.
Recently, the awareness of the domestic information security is very higher due to cyber war and hacking incidents. Yet, the information security professional is very scarce situation. In these circumstances are increasing of a opening the information security related departments of the domestic universities. And the Educational institutions are developed various curriculums. However, the domestic information security curriculum is different depending on the university or department. And there tends to be concentrated on the practical education rather than theoretical education. Therefore, in this paper will be analyzed to the Information security curriculum situation of the domestic Information Security related universities. This is expected to be utilized in a systematic curriculum development of the domestic information security education in a future.
우리나라 주요정보통신기반시설의 정보보호 개선방안 - 보안취약점 분석ㆍ평가제도를 중심으로 - KCI 등재
한국사회안전범죄정보학회 한국범죄정보연구 제11권 제2호 통권 제22호 2025.12 pp.181-213
※ 기관로그인 시 무료 이용이 가능합니다.
7,500원
우리나라는 주요정보통신기반시설의 안전성을 확보하기 위해 매년 관리적·기술적·물리적 측면에서 478개 항목을 적용한 취약점 분석·평가를 실시하고 있다. 그러나, 매년 발생하는 취약점을 해소하고 주요기반시설을 확대하여 안전성을 높이기 위한 제도로서 활용할 수 있도록 제도개선이 필요하다. 이에 본 연구에서는 안전한 사회환경을 구현하기 위하여 취약점 분석·평가제도에 관해 SWOT분석을 실시하 여 개선방안을 제시하고자 하였다. 그 결과, 먼저, 약점요인을 개선하기 위한 방안으로는 취약점 분석· 평가기준의 최신화, 노후화된 인프라, 설비 및 레거시 시스템의 장비교체 등 보안강화, 보안예산 및 유지보수 비용 확충 등을 들 수 있다. 둘째, 위협요인에 관한 개선방안으로는 사이버공격 대응을 위한 사전방지대책 마련, 천재지변 등 물리적 피해방지를 위한 실제 설비 운영점검, 새로운 정책 및 환경변화 에 맞는 기준보완 등이 필요하다. 뿐만 아니라 주요기반시설의 안전성을 높이기 위해 세부 절차 및 세부 점검항목의 개선 및 기관 특성별 유연한 기준 제고, 취약점 분석·평가 종합점수 산출방식 적용, 새로운 공격대응 모델 개발 및 취약점 분석·평가부터 개선조치까지 관리할 수 있는 종합적 관리시스템 도입 등을 들 수 있다. 이처럼 주요정보통신기반시설의 보안취약점 분석·평가제도를 개선하여 효율적 으로 운영한다면, 안전한 대한민국을 구현해 나가는 핵심적인 제도기반을 마련할 수 있으리라 본다.
To ensure the security of critical information and communications infrastructure, South Korea has conducted vulnerability analysis and assessments annually, covering 478 items from management, technical, and physical perspectives. However, it is needed to institutionsal improvements for decreasing vulnerabilities that arise each year and to expand the scope of critical infrastructure to enhance its security. Therefore, this study conducted a SWOT analysis of the vulnerability analysis and assessment system to propose improvement measures to create a safe social environment. The results suggest that, first, measures to address weaknesses include updating vulnerability analysis and assessment criteria, strengthening security by replacing aging infrastructure, equipment, and legacy systems, and increasing security budgets and maintenance costs. Second, the improvement measures is needed to resolve the threats as like establishing preventative measures to respond to cyberattacks, conducting actual facility operation inspections to prevent physical damage from natural disasters, and revamping standards to adapt to new policies and environmental changes. Furthermore, it needed to enhance the security of critical infrastructure, including improving detailed procedures and inspection items, increasing flexibility in supplemented standards to the specific characteristics of each institution, applying a comprehensive score calculation method for vulnerability analysis and assessment, developing a new attack response model, and introducing a comprehensive management system that can manage everything from vulnerability analysis and assessment to remedial action. As like this, by improving and efficiently operating the security vulnerability analysis and assessment system for critical information and communications infrastructure, it will be established a core institutional foundation for a safer South Korea.
Discord 플랫폼 기반 실시간 스테가노그래피 탐지 시스템 구현 및 성능 분석 KCI 등재
국제차세대융합기술학회 차세대융합기술학회논문지 제10권 1호 2026.01 pp.20-27
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 Discord 메신저 플랫폼에서 이미지를 통해 은밀하게 정보를 전달하는 스테가노그래피 기법을 실시 간으로 탐지하는 시스템을 제안한다. 제안된 시스템은 Discord 봇을 기반으로 하여 채널에 업로드되는 모든 이미지를 자동으로 분석하고, LSB(Least Significant Bit) 분포 통계 분석, 고급 LSB 패턴 분석, 히스토그램·엔트로피 기반 통 계 분석, 파일 크기 및 메타데이터 이상 탐지 등 다중 탐지 기법을 적용한다. Python으로 구현된 이 시스템은 Discord.py, PIL, NumPy, Stegano, SciPy 라이브러리를 활용하여 실시간 이미지 처리와 통계 분석을 수행한다. 반복 테스트 결과, 정상 이미지와 LSB 기반 스테고 이미지를 모두 정확하게 판별하였으며, 평균 탐지 정확도는 약 99.9% 수준으로 유지되었다. 또한, 이미지당 평균 처리 시간은 약 0.61초(정상 이미지 약 0.65초, 스테고 이미지 약 0.58초)로 측정되어 Discord 실시간 메시지 환경에서 요구되는 1초 이내 처리 지연 조건을 만족함을 확인하였다. 본 연구는 소셜 미디어 플랫폼에서의 자동화된 스테가노그래피 탐지 시스템의 실현 가능성을 제시하였다는 점에서 의의가 있다.
This paper presents a real-time detection system for steganographic techniques that covertly convey information via images on the Discord messaging platform. Implemented as a Discord bot, the system automatically analyzes every image uploaded to a channel and applies multiple detection methods, including least significant bit (LSB) distribution statistics, advanced LSB pattern analysis, histogram- and entropy-based statistical analysis, and file-size and metadata anomaly detection. Developed in Python using Discord.py, PIL, NumPy, Stegano, SciPy, it performs real-time image processing and statistical analysis. Experimental evaluation based on repeated tests shows that the system correctly discriminates between normal images and LSB-based stego images, achieving an average d etection accuracy of about 99.9%. In addition, the average processing time is about 0.61 seconds per image (approximately 0.65 s for normal images and 0.58 s for stego images), thereby satisfying the sub-second latency requirement (within 1 s) for Discord’s real-time messaging environment. The proposed approach thus validates the feasibility of an automated steganography detection framework for social-media platforms.
의료기기 사이버 보안 강화를 위한 규제과학적 고찰 : 환자 안전 중심의 전 생애주기 관리 KCI 등재
한국융합보안학회 융합보안논문지 제25권 제3호 2025.09 pp.133-146
※ 기관로그인 시 무료 이용이 가능합니다.
4,600원
의료기기 환자 정보 보호의 중요성에 대한 이해를 다루고, 미국·영국·한국의 의료기기 사이버 보안 침해 사례를 통해 사이 버 보안의 영향을 살펴보았다. 의료기기의 환자 정보 보호는 기술적 접근만으로는 해결되지 않으며, 과학적·정책적 균형을 기 반으로 한 규제 접근이 필수적이다. 규제과학(Regulatory Science)은 과학적 근거 기반 의약품, 의료기기, 디지털 헬스케어 제 품 등의 안전성·유효성을 평가하고 그 결과를 정책 수립·개선에 반영하는 융합 학문이다. 특히 디지털 헬스 케어 및 의료기기 네트워크의 연결성 확대는 보안 위협을 증가시키고 있어, 개발 단계에서부터 보안 요구상항을 통합할 수 있는 규제과학 전문 가의 양성이 중요하다. 규제과학 전문가는 위험 기반 평가 수행, 제품 설계 초기 단계에서 보안 요구사항 반영, 사후 보안 사 고 대응 및 재발 방지 대책 수립, 다학제 간 협업과 효과적인 커뮤니케이션, 그리고 가이드라인 및 표준 개발에 대한 자문 등 다양한 역할을 수행해야 한다. 앞으로의 의료기기 산업은 단순한 기술 혁신을 넘어서, 신뢰 기반의 보안 체계 구축이 경쟁력 이 될 것이며, 이 과정에서 규제과학 전문가의 역할은 더욱 확장될 것이다.
The importance of protecting patient information in medical devices has been addressed, and the impact of cybersecurity has been examined through case studies from the United States, the United Kingdom, and South Korea. Protecting patient information in medical devices cannot be achieved solely through technical approaches; a regulatory approach based on a balance of scientific and policy considerations is essential. Regulatory Science is an interdisciplinary field that evaluates the safety and effectiveness of pharmaceuticals, medical devices, and digital healthcare products based on scientific evidence and applies the findings to policy development and improvement. In particular, the growing connectivity of digital healthcare and medical device networks increases security risks, highlighting the importance of fostering regulatory science professionals who can integrate security requirements from the development stage. Regulatory science professionals should perform risk-based assessments, incorporate security requirements at the early stages of product design, develop and implement post-incident responses and recurrence prevention measures, engage in multidisciplinary collaboration and effective communication, and provide expert advice on the development of guidelines and standards. The future of the medical device industry will go beyond mere technological innovation toward building a trust-based security system as a competitive advantage, and in this process, the role of regulatory science professionals will become increasingly significant.
정보보안 커뮤니케이션과 업무 모호성이 제언 행동에 미치는 영향 : 경쟁적 심리 분위기의 조절 효과 KCI 등재
대한경영정보학회 경영과 정보연구 제41권 제3호 2022.09 pp.133-154
※ 기관로그인 시 무료 이용이 가능합니다.
5,800원
비대면 기반의 조직업무 환경으로의 급격한 변화는 시간적, 물리적 제약을 받지 않도록 돕는 정보시스템 활용성을 높이고 있다. 하지만, 조직 구성원들의 정보시스템에 대한 외부 접속 권한이 증가할수록 내부자의 정보 노출과 같은 조직의 정보보안 위협 요인이 증가할 수 있다. 또한, 조직원의 관점에서 정보보안 활동은 정보 교류 활동을 어렵게 하여 업무 성과 달성에 어려움을 줄 수 있다. 본 연구는 조직의 정보보안 미준수 조건을 다각적으로 제시함으로써, 내부의 정보보안 목표 달성에 기여 하는 것을 목적으로 한다. 세부적으로, 경쟁적 심리 분위기와 정보보안 커뮤니케이션 및 업무 모호성이 제언 행동에 미치는 부정적 영향 관계를 확 인하고자 하였다. 연구는 정보보안 정책을 조직원 업무에 반영하고 있는 조직의 구성원에게 설문을 수행하 였으며, 확보한 표본을 활용하여 가설 검정을 하였다. 결과적으로, 정보보안 커뮤니케이션 모호성이 업무 모 호성을 증가시켜 제언 행동에 부정적 영향을 주었으며, 경쟁적 심리 분위기는 직접 제언 행동에 부정적 영 향을 주고, 업무 모호성이 제언 행동에 주는 영향을 조절하였다. 본 연구는 조직 내부자의 정보보안 제언 행 동을 약화하는 업무 및 정보보안 환경을 제시하여, 역설적으로 정보보안 행동 강화를 위한 조직 전략 수립 의 시사점을 제시한다.
The rapid change to a non-face-to-face-based organizational work environment is increasing the usability of information systems that help avoid time and physical constraints. However, as the external access authority to the information system increases, the information security (IS) threat of insiders may increase. In addition, information security activities required of employees may make it difficult to exchange knowledge such as information and know-how required for work, making it difficult for them to achieve efficient work performance. The purpose of this study is to contribute to the achievement of internal IS goals by suggesting the conditions for non-compliance with IS within the organization. In detail, this study tried to identify the negative mechanisms of competitive psychological climate and IS communication ambiguity and role ambiguity on voice behavior. We conducted a questionnaire survey on the members of the organization reflecting the IS policy in their work and tested the hypothesis using the sample obtained. As a result, IS communication ambiguity increased role ambiguity and had a negative effect on voice behavior. In addition, the competitive psychological climate directly negatively affected voice behavior and moderated the effect of role ambiguity on voice behavior. Our results paradoxically suggest conditions for reinforcing IS behavior by identifying the work and IS environment that weakens the IS behavior of insiders.
조직의 산업보안 활동이 구성원의 보안 정책 준수 의도에 미치는 영향 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제3호 2022.09 pp.57-68
※ 기관로그인 시 무료 이용이 가능합니다.
4,300원
최근 보안에 대한 중요성과 인식이 확대됨에 따라, 기업과 정부는 보안 관리를 위하여 지속적인 노력과 투자를 하고 있다. 그러나 조직에는 여전히 많은 보안 위협이 존재하며, 특히 내부직원에 의한 보안사고가 빈번하게 발생하고 있다. 그러므로 조직의 보안 관리를 위해서는 무엇보다 구성원이 보안 정책을 준수하는 것이 매우 중요하다. 따라서 본 연구 는 조직적 측면의 산업보안 활동을 기술적 보안, 물리적 보안, 관리적 보안으로 분류하였고, 개인적 측면의 계획된 행동 이론을 적용하여 보안 정책 준수 의도에 미치는 영향 관계를 규명하였다. 통계 분석을 위하여 SPSS 25와 AMOS 25를 활용하였으며, 연구결과, 기술적 보안은 주관적 규범에 정(+)의 영향, 물리적 보안은 지각된 행동통제에 정(+)의 영향, 관리적 보안은 태도에 정(+)의 영향, 태도와 지각된 행동통제는 보안 정책 준수 의도에 정(+)의 영향을 미치는 것으로 나타났다.
As the importance and awareness of security have recently expanded, companies and governments are making cont inuous efforts and investments for security management. However, there are still many security threats in the organiz ation, especially security incidents caused by internal staff. Therefore, it is very important for members to comply with security policies for organizational security management. Therefore, this study classified industrial security manageme nt into technical security, physical security, and managerial security, and applied the theory of planned behavior to inv estigate the impact relationship on the intention to comply with security policies. SPSS 25 and AMOS 25 were used for statistical analysis, and the study found that technical security had a positive(+) effect on subjective norms, physic al security had a positive(+) effect on perceived behavior control, and attitude and perceived behavior control had a po sitive(+) effect on security policy compliance intention.
Cryptosystem-Adaptive Learning for Encrypted Images Classification
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 학술대회 The 7th International Conference on Next Generation Computing 2021 2021.11 pp.274-275
To manage the big data in constraint resources has difficulties and challenges. The power and the cost can be saved when the cloud services are used to process and store the data. However, the data includes the personal information that can be sensitive and should be hidden from the others. So we propose the privacy-preserving classification scheme for image data. The pixel-based learning is the scheme that is adapted to the cryptosystem, and is used to classify the encrypted images. Our proposed deep learning model has the convolutional layers that has the same size of the kernel with the block size in the cryptographic algorithm. The experiment results show that it can improve the accuracy on classification of encrypted images, and make it possible to use the private data securely.
보안성을 고려한 스마트 의료기기 관리(Secure-MEMP) 방법에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제21권 제1호 2021.03 pp.63-72
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
병원의 Biomedical engineering team은 의료기기가 안전하고 신뢰할 수 있도록 의료기기 관리 프로그램(MEMP, Medical Equipment Management Program)을 수립하고 규제할 책임이 있다. 기술의 발전으로 인공지능, 정밀의료 등 의료기기는 언제 어디서나 사물들 간 연결이 가능한 형태로 발전하고 있으며 다양한 기술의 융합에 따라 내외∙부 보안위협이 지속적으로 증 가하고 있다. 본 논문에서는 기술의 발전으로 지속적으로 증가하는 의료기기의 보안위협을 고려하여 안전한 의료기기 관리 프 로그램(Secure-MEMP) 방법을 연구 제시한다.
The hospital biomedical engineering team is responsible for establishing and regulating the Medical Device Management Program (MEMP) to ensure that medical devices are safe and reliable. As technology advances, medical devices such as a rtificial intelligence and precision medicine are developing into a form that allows connection between objects anytime, any where, and as various technologies converge, internal and external security threats continue to increase. In this paper, we present a study of the Medical Device Management Program (Secure-MEMP) method, considering that the security threat of medical devices continues to increase due to advances in technology.
딥 러닝을 이용한 인터네트워크 토폴로지 내 네트워크 경계의 악성 패킷 필터링 스킴 KCI 등재후보
국제차세대융합기술학회 차세대융합기술학회논문지 제4권 3호 2020.06 pp.250-257
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
5G가 본격적으로 도입되기 시작하면서 스마트시티, 자율주행자동차, 스마트 팜 등의 IoT 시장이 빠르게 성장하고 있다. 그러나 이러한 IoT 기기들은 탑재되는 애플리케이션, 기기 유형 등이 다양하기 때문에 표준화된 아키텍처 설계가 어려워, 5G 네트워크에 연결될 경우 수백억 개의 IoT 기기들이 사이버위협에 노출되게 된다. 특 히, 저사양 IoT 기기는 높은 수준의 보안 기능 탑재가 어렵기 때문에 분산 서비스 거부 공격 (Distributed Denial of Service, DDoS), 개인 정보 유출 등의 다양한 공격으로부터 위협받게 된다. 따라서 5G 네트워크에 연결된 다 양한 기기들을 사이버위협으로부터 보호하기 위해 본 논문에서는 5G 네트워크상의 전송되는 패킷을 분석하여 악 성 여부를 판단하는 Malicious Packet Filtering Scheme (MaPS)을 제안한다.
As 5G began to be introduced in earnest, IoT markets such as smart cities, autonomous vehicles, and smart farms are rapidly growing. However, since these IoT devices have various applications and device types, it is difficult to design a standardized architecture, and when connected to a 5G network, tens of billions of IoT devices are exposed to cyber threats. In particular, low-end IoT devices are threatened by various attacks such as distributed denial of service (DDoS) and personal information leakage because it is difficult to mount high-level security functions. Therefore, in order to protect various devices connected to the 5G network from cyber threats, this paper proposes a Malicious Packet Filtering Scheme (MaPS) that analyzes transmitted packets on the 5G network to determine whether they are malicious.
복원탄력성기반 정보시스템 성과평가모델 연구 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제10권 제3호 2020.03 pp.1-6
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
정보시스템은 새로운 기술의 변혁에 영향을 받는다. 따라서 정보시스템은 외부환경 변화에 신속하게 대응하 여야 하며, 특히 정보시스템 장애발생시 그 복원능력이 중요시되어야 한다. 본 연구에서는 Delone과 McLean의 성공요인에 복원탄력성을 추가한 정보시스템 평가모형을 제안하였다. 또한 국내 중견제조업체의 115 사용자 들을 대상으로 한 설문조사를 바탕으로 한 자료포락분석으로 복원탄력성의 영향을 평가하였다. 연구방법으로 채택한 자 료포락분석 모형은 금융권에서 주로 적용하는 Charnes 등의 모형을 적용하여 노드생성 중단값 5%에서 민감도분 석에 의해 순위화된 인자들을 찾아 다른 인자들에 미치는 영향도를 탐색하였다. 분석결과, 복원탄력성에 대한 영향 력은 이전의 연구에서 적용했던 다른 요인들보다 강한 영향을 미치는 것으로 나타났다. 복원탄력성을 ISO27001 정보보호규격의 평가요인으로 포함하여 정보시스템의 흡수역량을 강화하여야 할 것이다.
Information System is influenced by the innovation of new IT. Therefore, IS should response to external environment’s changes quickly. Particularly, resilience should be considered in barriers of IS. This study suggests a new information system evaluation model in which resilience is added to the existing factors of Delone and Mclean. Then the effect of resilience is evaluated through the DEA(Data Envelopment Analysis) based on a survey targeting 115 users of a mid-sized manufacturing company. The results show that the effect of resilience is stronger than any other factors in the previous researches. We, thus, suggest that the resilience should be included as an evaluation factor of the ISO27001 information security standard in order to enhance the absorptive capacity of the information system.
모바일 오피스를 위한 보안성검토 분석 및 추가 요구사항 도출 KCI 등재
한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제9권 제2호 통권 제16호 2019.12 pp.257-276
※ 기관로그인 시 무료 이용이 가능합니다.
5,500원
스마트폰 사용자의 급격한 증가로 인해, 많은 기업이 PC 기반으로 임직원에게제공하던 업무 서비스를 모바일에서도 이용할 수 있도록 모바일 오피스를 도입 중에 있다. 단말기 분실 및 도난, 악성코드 감염 사례가 증가함에 따라, 개인정보 및기업 기밀정보 유출 등 모바일 오피스 관련 보안사고도 함께 증가하고 있어 기업에서 모바일 오피스 도입 시 보안점검의 중요성이 대두되고 있다. 하지만 모바일오피스 가동 시 실시하고 있는 보안점검 항목으로는 모바일 오피스의 보안 위협들을 도출하고 대응하는 데 한계가 있어 모바일 오피스에 특화된 보안점검 항목을도출할 필요가 있다. 따라서 본 논문에서는 먼저 모바일 점검 가이드, 국내외 기업에서 사용하는 보안진단 기준, 관련 연구논문을 비교 분석하였고 모바일 오피스의보안 위협과 보안 요구사항 연구를 통하여 모바일 오피스에 특화된 보안점검 15개항목을 추가로 도출하여, 9개 영역의 총 53개 항목을 제시하였다. 본 연구에서 제안하는 모바일 오피스 보안점검 항목을 통해 보안 관리자에게는 보안점검기준으로, 개발자에게는 안전한 모바일 오피스를 개발하는 가이드로 활용될 것이다.
Due to the rapid increase in smartphone users, many companies are distributing mobile office services that make their business functions available not only on a PC basis but also mobile to employees. As case of lost or stolen devices and malware infections increases, security incidents related to mobile offices such as the leakage of personal information and corporate confidential information are also increasing. As a result, security check is becoming more important when company operate mobile office. However, there is a limit in the security checklist that companies are operating, so it is necessary to develop security checklist specific to mobile offices. Therefore, this paper first compared and analyzed mobile inspection guide, security checklist used by domestic and overseas companies, and related research papers. In addition, through analysis on the security threats and requirements of mobile offices, 15 additional checklist specific to mobile offices were derived, and a total of 53 items in 9 areas were presented. The security checklist for mobile office proposed in this study will be used as a standard for security administrators and a guideline for developers.
4,000원
정보보호(Information Security)는 최근 사이버공간의 출현과 확장으로 인해 그 중요성이 점차 증가하고 있다. 1998년 미국 국방부 정보작전 교리에서 유래된 ‘정보보증(Information Assurance)’은 기존의 정보보호 개념에 대응과 복구를 포함한 광의 의 적극적 보호, 정보체계 전 수명주기에서 보안관리, 위험분석 과정에서의 신뢰성 등을 추가한 개념으로서 현재 널리 사용 중이다. 그러나 국내에서는 정보보증 개념을 잘못 이해하거나 정보보호와 혼용하여 사용하는 경우가 종종 발생하고 있다. 본 논문에서는 정보보증 개념의 명확한 이해를 위해 정보보증 관련 기존 문헌들을 고찰하여 정보보증 개념을 정의하고자 하였다. 본 논문에서 제안한 정보보증 용어 정의의 주요 표현들에 대한 구문 분석을 수행함으로써, 용어 정의의 타당성을 제시하였다.
Today, information security (INFOSEC) as a discipline is gaining more and more importance according to the emergenc e and extension of the cyberspace. Originated from Joint Doctrine for Information Operation (Joint Pub 3-13) by the U.S. Department of Defense, ‘information assurance (IA)’ is the concept widely used in the relevant field. Grown from the pract ice of information security, it encompasses broader and more proactive protection that includes countermeasures and repair, security management throughout an information system (IS)’s life-cycle, and trustworthiness of an IS in the process of ris k analysis. In Korea, many industry professionals tend to misunderstand IA, remaining unaware of the conceptual differenc es between IA and INFOSEC. On this account, the current study attempted to provide a combined definition of IA by revi ewing relevant literature. This study showed the validity of the wordings used in the proposed definition phrase by phrase.
웨어러블 장치를 이용한 헬스케어시스템을 위한 안전한 통신 기법에 대한 분석 및 해결책 KCI 등재
한국디지털정책학회 디지털융복합연구 제17권 제2호 2019.02 pp.187-194
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
기존에 다양한 헬스케어 시스템에 대한 보안 개념이 제시되었다. 하지만 제시된 다양한 프로토콜에서 좀 더 나은 연산의 효율성과 안정성을 갖추기 위한 개선점이 보인다. 본 논문은 Vijayakumar등이 제안한 웨어러블 장치를 이용한 헬스 케어시스템을 위한 효율적인 안전한 통신 기법에 대한 보안 분석 및 이에 대한 해결책을 제시한다. 특히, Vijayakumar등의 기법은 서비스거부공격에 취약하고 무결성을 제공하지 못하는 문제점이 있다. 이러한 문제들을 해결하기 위해서 본 논문에 서는 새로운 안전한 통신 기법을 제안한다. 새롭게 제안한 기법은 인증 및 무결성을 제공함으로서 Vijayakumar등의 기법에 대한 효율적인 보안 해결책이 될 수 있다. 특히, 제안한 기법은 연산의 오버헤드 관점에서도 장점을 제시한다.
A security company has been proposed for various healthcare systems. However, there are improvements in order to achieve better efficiency and stability in the various protocols presented. The purpose of this paper is to provide cryptanalysis and solution on Vijayakumar et al.’s secure communication scheme for healthcare system using wearable devices. Especially, it is weak against denial of service attack and it does not provide integrity of the transmitted messages. Thereby, this paper proposes a new secure communication scheme to cope from the problems in Vijayakumar et al.’s scheme. It provides authentication and integrity, which could be the security solution against Vijayakumar et al.’s scheme. Furthermore, it also provides a good computational overhead compared to Vijayakumar et al.’s scheme.
6,000원
인터넷이 우리의 생활에 편리함을 가져오면서 인터넷 금융의 회색산업도 더욱 성장하고 있다.《2017년 중국 인터넷 안전태세 보고서(2017年我国互联网网络安全态势报告)》에 따르면, 인터넷 영역의 안전성은 이전과 다름없이 심각하다. 현재 이론계와 실무계는 인터넷 금융 회색산업이 일관되게 형성되지 않아 이와 관련한 문제를 연구하는데 있어 제약이 따르는 것이 사실이다. 인터넷 금융 회색산업 사슬이라 함은 인터넷 금융거래과정에 있어 금융기업 관리상의 부재나 법률규제 상의 공백을 이용해 인터넷 금융거래와 관련한 인터넷 거래 주체나 기타 행위자가 불법으로 개인 공민에게 정보를 제공하거나, 허위증명서와 인터넷 바이러스 및 악의의 프로그램 등을 제공함으로써 온라인 금융의 상품과 서비스의 안전에 위해를 가하는 것을 말한다. 인터넷 회색산업 사슬은 조직화, 분업화, 규모화되어 있어 이에 존재하는 이익이 서로 얽혀 있다는 특징이 있다. 이로 인해 인터넷 회색산업 사슬은 재산침해범죄, 금융범죄, 컴퓨터 온라인 범죄 등과 연관되어 있어 법적 해결이 쉽지 않다. 그러므로 국가 금융안전과 정보안전의 차원에서 인터넷 회색산업 사슬의 형성체계, 특징, 문제파악을 통하여 전체적인 입법과 사법 등의 수단을 이용하여 오늘날 중국의 인터넷 금융 회색산업 사슬 시스템에 대한 법적 해결방안을 제시하고자 한다.
While Internet brings convenience to life, internet financial grey industrial chain grows increasingly. China’s Internet Network Security Situation Report, 2017 shows that the trend in this field is still serious. At present, the theoretical and practical communities have not formed a unified and clear view on the definition of internet financial grey industrial chain, which has restricted the research on this issue. The author proposes that, the internet financial grey industrial chain refers to the underground industrial chain that illegally provides goods or services for participants of internet financial transaction through loopholes of regulations or laws, which endanger the security of Internet finance. The internet grey industrial chain has following characteristics: (i) organized, specialization and scale;(ii)forming the distribution of upper, middle and lower reaches;and (iii) long interest chain is attached. The strong dependence of the industry means it attaches internet finance tightly, and the internet financial grey industrial chain has certain connections with crimes of invasion of wealth, financial crimes and computer network crimes. In China, it adopts the mode of “qualitative and quantitative” in criminal investigation, which makes the response and governance of criminal law in this field is not optimistic. Therefore, with the rapid development of internet today, we need to make it become stronger in positive aspects through governance. The current internet financial grey industrial chain in China should be governed from the perspective of national financial security and information security while transplanting the experience of other regions and countries. We should also focus on the process, characteristics and problems of the Internet grey industrial chain. Then, we will strengthen the construction of a legal implementation mechanism for the Cyber Security Act and clarify the responsibilities of manufacturers, intermediaries and e-commerce platforms in the interest chain. We will tighten the judicial system, expand the scope of application of the civil protection order, increase the rate of application of the employment prohibition for employees working in the internet financial grey industrial chain, and raise the standards for the use of fines and penalties. We will further strengthen special governance over interconnection, cooperate with multiple departments to enforce the law comprehensively, and establish an efficient and cooperative case handling mechanism. At the same time, we will also enhance citizens’ awareness of self-protection and the sense of responsibility of service providers through various means. Finally, this paper systematically discusses the governance countermeasures of the internet financial grey industrial chain in China, and takes both prevention and punishment in this field as a systematic project.
互联网给生活带来便利的同时,互联网金融灰色产业链愈发滋长。2017年我国互联网网络安全态势报告表明,该领域的态势依然严峻。目前理论和实务界对于何谓互联网金融灰色产业链并未形成统一、明确的看法,该问题的研究有待厘清。 所谓互联网金融灰色产业链,是指在互联网金融交易过程中借助金融企业管理上的疏漏或法律规制上的空缺,为互联网交易主体非法提供危害互联网金融安全的商品或服务,以达到非法牟利目的的地下产业链条。互联网灰色产业链具有明显的组织化、分工化、规模化,形成上中下游的分配,致使互联网金融灰色产业链存在着利益链条长的特点。行业依附性强表现在依附于互联网金融而存在,互联网灰色产业链与侵财犯罪、金融犯罪、计算机网络犯罪等具有牵连性。我国刑事追缉采取“定性+定量”的模式,使得刑事法律应对和治理该领域不容乐观。 因此,在互联网迅速发展的今天,需要对其进行彻底治理以使其拥有更强大的正面作用。治理当前互联网金融灰色产业链,一是应着重借鉴其他地区、国家有利经验,当然也应当立足于国家金融安全和信息安全的视角,紧盯互联网灰色产业链的流程、特征、问题所在。二是加强《网络安全法》法律实施机制的构建、明确利益链条中生产商、中间商、下游的电商平台责任。严格司法,扩大民事保护令的适用范围,对互联网金融灰色产业链的从业人员提高从业禁止的适用率,提高罚金刑的使用标准。三是进一步加强对互联专项治理,联合多部门综合执法,建立高效的协同办案机制,通过法律宣传教育等手段,增强公民的保护意识,服务者的责任意识。四是系统探讨当前我国互联网灰色产业链的治理对策,将预防和惩治互联网金融灰色产业链视为一个系统工程。
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.