년 - 년
6,700원
기계경비업무는 1981년 3월 국내 최초로 기계경비 영업을 개시한 (주)에스원을 필두로 (주)ATD캡스, 텔레캅서비스(주) 등의 업체들이 현재 전국 네트워크를 구성하며 기계경비업을 주도하고 있다. 그러나 2009년 1월 ADT캡스의 직원이 경비를 맡은 고객 사무실에서 컴퓨터를 훔쳐간 사건, 2008년 9월 에스원의 직원이 편의점 주변에서 술에 만취한 여성을 출동차량에 태워 인근 학교에서 성폭행한 사건, 2008년 2월 발생한 숭례문 화재사건으로 KT텔레캅의 기업 이미지가 실추되었던 사건 등 크고 작은 사건들로 인해 기계경비업은 물론 경비업 자체에 대한 불신과 문제점들이 부각되어 사회적으로 큰 관심의 대상이 되고 있는 실정이다.따라서 본 연구에서는 최근 사회적으로 이슈화되고 있는 기계경비업무 사건들에 대해 여러 측면에서 문제점을 분석하고 그에 대한 정책적 시사점과 개선방안을 논의하고자 하였다.최근에 발생하고 있는 기계경비업무 사건들의 가장 큰 핵심은 고객의 재산과 생명을 지켜야하는 경비원의 경비업무에 대한 목적의식, 책임의식 결여와 윤리성의 부재라고 볼 수 있다.이러한 문제점은 원천적으로 한국에서는 경비원에 대한 검증제도 자체가 미흡하기 때문이다. 부적격 경비원이 채용되지 않아야함은 물론「경비업법」을 개정하여 경비원 채용기준과 결격사유를 강화해야 할 것이다. 그리고 근본적으로는 경비원의 전문성을 확보하기 위해서 높은 이직률에 따른 개선대책과, 주요 선진국에서 일반화된 경비원 자격제도 및 검증제도 도입에 관한 논의가 이루어져야 할 것이다.또한 한국 민간경비 교육제도상 일반경비원과 특수경비원 신임교육으로 양분되어 시행되고 있는 교육훈련 프로그램을 5개 업무별로 교육훈련 프로그램을 마련하여 실효성 있는 교육과목으로 재구성해야 한다. 그리고 윤리교육 등 현장에서 필요로 하는 실질적 교육이 시행될 수 있도록 노력해야 할 것이다.특히 기계경비업무에 있어서 인력경비 교육훈련 프로그램과는 다른 기계경비업무에 적합한 교육훈련 프로그램으로 재구성하여야하고, 기본적 문제로 대두되는 오경보문제와 대응체제문제에 대한 대책마련도 지속적으로 요구된다.
Since S1 started the security business in March 1981 for the first time in Korea, the companies like ADT Caps, Telecop etc. have leaded the machine security business with the nationwide networks at the moment. However, the machine security business and security business itself have become a big issue in our society due to the small and big accidents such as the staff of ADT Caps stole a computer from their customer's office in January 2009, etc.In this study, therefore, the researcher tried to analyze the problems in various aspects on the machine security accidents that recently issued in the society and discuss the political implications and the method of improvement.The most important core fact of the machine security business related accidents can be said the lack of a sense of purpose and responsibility, and the absence of morals on the security business of the guards that they have to keep their customers' property and life. Therefore, there should be training programs on each 5 area through the amendment of 「Security business law」 and the subjects need to be reconstructed effectively. And the training should be done for actual training like ethical education, etc. Also, we have to strengthen the reasons of disqualification as the counter plan of hiring disqualified people and we need to set the plans for false alarm and response system problems that are merging as the basic problems. Basically, there should be discussions on improving the high separation rate and introducing a qualification system to secure the speciality of the guard.
Uniting cyber security and machine learning: Advantages, challenges and future research
[NRF 연계] 한국통신학회 ICT Express Vol.8 No.3 2022.09 pp.313-321
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Machine learning (ML) is a subset of Artificial Intelligence (AI), which focuses on the implementation of some systems that can learn from the historical data, identify patterns and make logical decisions with little to no human interventions. Cyber security is the practice of protecting digital systems, such as computers, servers, mobile devices, networks and associated data from malicious attacks. Uniting cyber security and ML has two major aspects, namely accounting for cyber security where the machine learning is applied, and the use of machine learning for enabling cyber security. This uniting can help us in various ways, like it provides enhanced security to the machine learning models, improves the performance of the cyber security methods, and supports effective detection of zero day attacks with less human intervention. In this survey paper, we discuss about two different concepts by uniting cyber security and ML. We also discuss the advantages, issues and challenges of uniting cyber security and ML. Furthermore, we discuss the various attacks and provide a comprehensive comparative study of various techniques in two different considered categories. Finally, we provide some future research directions.
Machine Learning-Based Security Framework for Detecting Compromised IoT Hardware Devices
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 학술대회 ICNGC 2025 The 11th International Conference on Next Generation Computing 2025 2025.12 pp.161-163
In this paper, a machine learning-based technique is presented for detecting compromised IoT devices in edge computing networks. The model profiles device behavior using parameters such as CPU usage, network traffic, and power data, detecting anomalies that suggest an attack may be in progress. The lightweight framework can achieve high detection accuracy at low computational cost and is capable of processing in realtime.
본 논문에서는 시대의 흐름에 따라 새롭게 발생하는 재해와 나날이 발생하는 재난과 범죄에 대하여 기 계경비가 직·간접적 으로 재난과 재해, 범죄 대응에 영향을 끼치는가에 대하여 분석하고자 한다. 대표적인 재난이라고 불리는 자연재난과 사회재 난, 그리고 범죄 사건을 기계경비를 이용하여 대응효과를 보았던 실제 사례를 보며 기계경비가 재난대응에 기여를 한다는 것과 기계경비의 중요성을 알아보고자 한다. 최근 발생한 재난과 재해, 범죄 사건 자료와 사례를 통하여 심각성을 알림과 함께 확인 하고 분석하여 기계경비가 직·간접적으로 재난과 재해, 더 나아가 범죄예방을 하는 것을 확인할 수 있다. 또한 기계경비를 통한 재난과 재해, 범죄 대응 대책을 제시하여 재난과 재해, 범죄 발생률을 감소시키고 예방률을 증가하는 효과를 거두고자 한다.
기계경비시스템의 서비스품질이 고객만족에 미치는 영향에 관한 연구 KCI 등재후보
한국보안관리학회(구 한국경호경비학회) 시큐리티 연구 제17호 2008.11 pp.361-381
※ 기관로그인 시 무료 이용이 가능합니다.
5,700원
기계경비시스템이 제공하는 서비스에는 유․무형의 서비스가 모두 포함되어 그에 대한 품질평가가 쉽지 않은 것이 사실이다. 그럼에도 불구하고 본 연구는 서브퀼 모형을 도입하여 기계경비시스템의 서비스품질 구성차원을 확인하고, 서비스품질과 고객만족과의 관계를 실증적으로 검증하고자 하였다. 이를 위하여 대구지역에서 기계경비서비스를 이용하고 있는 소규모 상점을 대상으로 경험적 연구를 진행하였으며 연구결과와 시사점은 다음과 같다.첫째, 서비스품질을 구성하는 요인들이 고객만족에 영향을 주는지 검증한 결과, 서비스품질의 4가지 구성요소는 모두 고객만족에 유의미한 영향을 미치는 것으로 나타났다. 또한 그 영향력의 크기는 공감성, 확신․신뢰성, 응답성, 유형성의 순서로 확인되었다. 따라서 회사가 제공하는 최신식 설비․장비도 중요하지만 그보다는 고객에 대한 배려와 개별적 관심 및 신뢰성과 확신성을 심어줄 수 있는 직원들의 능력이 더욱 중요함을 알 수 있었다.둘째, 서브퀼 모형을 도입하여 기계경비시스템의 서비스품질을 측정하고자 하였으나 요인분석결과 서비스품질을 구성하는 차원은 확신․신뢰성, 공감성, 유형성, 응답성 4가지로 확인되었다. 따라서 향후의 연구에서는 확신성과 신뢰성의 개념을 보다 명확히 구분하는 한편, 국내 기계경비업체의 서비스품질 평가에 보다 적합한 모형으로의 개발을 고려해보아야 할 것이다.
Quality rating of machine security systems is difficult because both tangible and intangible services are included. However, still, the research template applied the SERVQUAL model with the intention of confirming machine security systems’service quality formation and experimentally inspecting the relationship between service quality and customer satisfaction. Therefore, the following highlights the experimental research outcomes and their implications for small-scale businesses utilizing machine security systems in the Daegu region.First, after observing whether the determining factors constitute service quality, four components were found to have significant influence on customer satisfaction. Additionally, in observing any differences in their influences, the following in order were observed as having influence on customer satisfaction: empathy, assurance․reliability, responsiveness, and tangibility. Moreover, though companies’newest facilities and equipment are important, it can be concluded that a company employees’ prudent consideration, individual interest, reliability, and assurance for the customer carry greater importance. Secondly, though we intended to survey machine security systems by employing the SERVQUAL model, determinant factor analysis results found applying SERVQUAL model in its original state a challenge. According to results from determinant factor analysis, the basis for forming service quality is determined by assurance․reliability, empathy, tangibility, and responsiveness. Furthermore, in future research, while more accurately distinguishing between assurance and reliability, a more appropriate model must also be considered for modification in domestic machine security system industry’s service quality evaluation.
빅데이터 환경에서 기계학습 알고리즘 응용을 통한 보안 성향 분석 기법 KCI 등재
한국디지털정책학회 디지털융복합연구 제13권 제9호 2015.09 pp.269-276
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 빅데이터 관련 산업 활성화에 따라 글로벌 보안 업체들은 지능적인 보안 위협 모니터링과 예방을 위 해 분석 데이터의 범위를 정형/비정형 데이터로 확대하고, 보안 예방을 목적으로 사용자의 성향 분석 기법을 활용하 려는 추세이다. 이는 기존 정형 데이터(기존 수치화 가능한 자료)의 분석 결과에서 추론할 수 있는 정보의 범위가 한 정적이기 때문이다. 본 논문은 빅데이터 환경에서 기계학습 알고리즘(Naïve Bayes, Decision Tree, K-nearest neighbor, Apriori)을 효율적으로 응용하여 보안 성향(목적 별 항목 분류, 긍정·부정 판단, 핵심 키워드 연관성 분석)을 분석하 는데 활용한다. 성능 분석 결과 보안 성향 판단을 위한 보안항목 및 특정 지표를 정형/비정형 데이터에서 추출할 수 있음을 확인하였다.
Recently, with the activation of the industry related to the big data, the global security companies have expanded their scopes from structured to unstructured data for the intelligent security threat monitoring and prevention, and they show the trend to utilize the technique of user's tendency analysis for security prevention. This is because the information scope that can be deducted from the existing structured data(Quantify existing available data) analysis is limited. This study is to utilize the analysis of security tendency(Items classified purpose distinction, positive, negative judgment, key analysis of keyword relevance) applying the machine learning algorithm(Naïve Bayes, Decision Tree, K-nearest neighbor, Apriori) in the big data environment. Upon the capability analysis, it was confirmed that the security items and specific indexes for the decision of security tendency could be extracted from structured and unstructured data.
Security Parallel Migration of the Federal Cloud Markov Chain Multi Virtual Machine SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.8 2016.08 pp.29-38
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In order to improve the customer service quality during the virtual machine (VM) migration process in networks, a multi-VM parallel migration strategy based on Markov chain is proposed in this paper. Specifically, the simulation experiment is carried out to provide the data regarding the influence of the algorithm parameters on blocking probability, network migration time and downtime. According to the simulation result, under the condition of the same algorithm parameters, the multi-VM parallel migration process has low parallel downtime, and this index can significantly influence user experience improvement, thus indicating the advantage of the parallel strategy for improving user experience. Meanwhile, under the condition of the same parameters, the network blocking probability of the multi-VM parallel migration process is obviously lower than that of the sequence migration process, thus indicating that the parallel process has higher network utilization. Moreover, the network parameters can be properly selected according to actual needs.
클라우드 컴퓨팅 환경에서의 가상머신 보안 취약점 탐지 도구 설계 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.9 No.6 2012.12 pp.519-530
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
최근 많은 기업들은 IT 비용에 대한 원가절감을 통한 생존전략으로 클라우드 컴퓨팅 기술이 IT 핵심전략기술로 급부상되고 있다. 국내에서는 공공기관을 중심으로 다양한 산업에서 클라우드 컴퓨팅 기술을 점차적으로 도입하고 있는 추세이다. 그러나 클라우드 컴퓨팅 기술의 실제 도입을 지연되고 있는 가장 큰 장애요소는 보안에 대한 우려 이며, 클라우드 컴퓨팅 활성화를 위해서는 보안 문제에 대한 대응이 시급한 실정이다. 이에 따라, 본 논문에서는 가상머신의 취약성 및 보안위협들을 조사하여, 안전한 클라우드 컴퓨팅 을 보호하기 위한 가상머신 보안 취약점 탐지 도구를 제시하고자 한다.
Cloud computing technology as a strategy of survival through cost savings on IT costs, many companies use IT technology as the core strategy. Domestic cloud computing technology in a variety of industries, public institutions gradually introduced in the trend. However, the actual delay the introduction of cloud computing technology, which is the biggest obstacle on the security concerns and respond to security issues in order to enable cloud computing, is urgently needed. In this paper, we investigate the virtual machine's vulnerabilities and security threats, accordingly, propose virtual machine protection for secure cloud computing security vulnerability detection tools.
기계경비시스템의 발전을 위한 AI 응용 KCI 등재
한국치안행정학회 한국치안행정논집 제19권 제2호 2022.05 pp.89-110
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
제4차 산업혁명은 세계의 경제와 산업을 혁신적으로 변모시키고 있다. 그동안 현실적이지 않았던, 실현될 가망이 없었던, 단지 미래의 공상으로 느껴왔던 것들을 현실로 만들어나가고 있다. 기계경비시스템은 아날로그 기술에서 디지털 기술로 급격히 전환되고 있으며, 최근 제4차 산업혁 명의 도래에 따라 인공지능(AI), 사물인터넷(IoT), 빅데이터(Big Data) 등의 핵심기술을 응용해 시스 템들을 혁신적으로 개발하고 변화시키고 있으며, 동시에 기업의 정책과 경영 전반에 변모를 꾀하고 있다. 4차 산업혁명은 기계경비시스템은 물론 시큐리티산업 전반에 혁신적인 변화를 가져오고 있다. 4차 산업혁명에 대해 ‘4차산업혁명위원회’에서는 “인공지능, 빅데이터 등 디지털 기술로 촉발되는 초연결 기반의 지능화 혁명”으로 정의하고, “D(데이터), N(네트워크), A(Ai) 지능정보기술을 기반으 로, 정보·통신·기술 산업뿐 아니라 제조, 의료, 농업 등 다양한 산업 분야가 혁신되어가는 과정”이라 고 설명하고 있다. 아울러 정책·정보를 통해 인공지능 대중화(AI for all)를 표방하고 있다. 실제 기계경비시스템은 2016년 다보스 포럼에서 의장이었던 Klaus Schwab이 4차 산업혁명이라 는 용어를 사용하여 이슈화되기 전부터 이미 지능형 영상감시스템, 지능형 통합관제 등을 개발하고, 인공지능과 사물인터넷 등의 기술을 접목하여 사용하고 있었으며, 시큐리티산업을 혁신화하고 있었 다. 현재는 세계보안엑스포와 같은 박람회에서 쉽게 볼 수 있듯이 인공지능, IoT 등 디지털 기술을 연결한 지능형 첨단보안시스템들이 대거 출품되고 경비시설물 현장에 적용되고 있다. 이 연구는 제4차 산업혁명의 도래에 따라 핵심 키워드인 AI, IoT 등의 핵심기술을 어떻게 기계경 비시스템에 응용하고 있는지, 어떻게 발전시켜 나갈 수 있는지를 규명하고자 하는 데 연구의 목적을 두었다. 연구방법은 문헌연구를 기반으로 하였으며, 제4차 산업혁명 및 AI 대응 관련 기계경비업체 의 주요 언론 기사를 검색하고 그 사례와 내용을 분석했다. 더불어 국내 최대의 주요 기계경비업체 전문가 면담도 포함하였다. 연구결과 제4차 산업혁명의 도래에 따라 기계경비업자들은 기계경비시스템을 AI 등을 응용하여 디지털 가속화(디지털 전환) 시키고 있었으며, 모든 것들을 4차 산업혁명의 디지털 기술로 초연결 시키고 혁신하고 있는 것을 확인할 수 있었다.
The Fourth Industrial Revolution is innovatively transforming the world economy and industry. What used to be unrealistic, not expected to come true, and just a fantasy of the future is becoming a reality. A machine security system is rapidly changed from analog technology to digital technology. Recently, with the advent of the Fourth Industrial Revolution, it is innovatively developing and changing systems by applying core technologies such as Artificial Intelligence(AI), Internet of Things(IoT), and Big data, while it is trying to change corporate policies and overall management simultaneously. The Fourth Industrial Revolution is bringing innovative changes not only to the machine security system but also to the overall security industry. The ‘Presidential Committee on The Fourth Industrial Revolution(PCFIR)’ defined the Fourth Industrial Revolution as “a hyper-connected intelligent revolution that is triggered by digital technologies such as artificial intelligence and big data”, and explained it as “a process of innovation not only in the ICT industry, but also in various industrial fields such as manufacturing, medicine, and agriculture based on intelligent information technologies such as DNA(Data-Network-AI)”. It is also adopting a slogan of 'AI for all' through policies and information. In fact, the machine security system industry was already revolutionizing the security industry by combining and using technologies such as artificial intelligence(AI) and the Internet of Things(IoT) and developing an intelligent video surveillance system and an intelligent integrated control and management system even before Klaus Schwab, Executive Chairman of the World Economic Forum(WEF), first used the term the Fourth Industrial Revolution(4IR) in Davos forum 2016 to be on the issue. As it can be easily seen now, intelligent high-tech security systems that connect digital technologies such as AI and IoT are being exhibited at the International Security Exhibition & Conference(SECON) and being applied to security facilities. The purpose of this study is to identify how core technologies such as AI and IoT are applied to the machine security system and how it can be developed with the advent of the Fourth Industrial Revolution. The research method is based on literature review, in which major news articles of machine security companies related to the Fourth Industrial Revolution and AI response are searched, and the cases and contents are analyzed. In addition, it includes interviews with experts from the largest major machine security companies in Korea. As a result of the study, it was confirmed that machine security companies were digitally accelerating(Digital Transformation) the machine security system by applying AI, etc., and everything was hyper-connected and innovated with digital technology of the era with the advent of the Fourth Industrial Revolution.
사물인터넷의 계층적 보안 기술을 적용한 연마기 원격 모니터링 시스템 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.14 No.3 2017.06 pp.215-222
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
수동 금속 연마과정의 효율성을 향상시키기 위한 IoT 센서 기술을 이용한 자동 시편 연마 시스템 들이 개발되고 있다. IoT 기술을 이용한 자동 시편 연마 시스템들의 경우 고속으로 데이터를 처리하 기 위하여 비-트리 인덱스를 이용하여 센서에서 수집된 데이터를 분석하여 처리하는 기술을 사용하고 있다. 그러나 IoT 기반의 연마기의 원격 제어를 수행하기 위해서는 공유 리소스에 대한 액세스를 제 어해야하나 기존 시스템들은 이에 대한 보안 위협을 대처하기 위한 방법이 적용되지 않은 데이터 처 리 기술을 적용하고 있다. 따라서 본 논문에서는 IoT 계층 보안 기술을 적용하여 자동 시편 연마기에 서 수집된 정보를 비트맵 인덱스로 연산 처리하는 모니터링 시스템을 제안한다.
Automatic specimen polishing systems using IoT sensor technology are being developed to improve the efficiency of the passive metal polishing process. In the case of automatic specimen polishing systems using IoT technology, a technique of analyzing and processing the data collected by sensors using a bitmap index is used to process data at high speed. However, in order to perform remote control of IoT-based grinder, it is necessary to control access to shared resources, but existing systems are applying data processing technology that does not apply a method to cope with the security threat. Therefore, in this paper, we propose a monitoring system that computes information collected from automatic specimen grinder by using bitmap index by applying IoT layer security technology.
머신러닝 알고리즘이 적용된 가상화 내부 환경의 보안 인증벡터 생성에 대한 연구 KCI 등재
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제16권 제6호 2016.12 pp.33-43
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
최근 인공지능 분야는 구글, 아마존, 마이크로 소프트 등 선진 기업을 중심으로 머신러닝에 대한 투자와 연구 경쟁이 가속화 되고 있다. 가상화 기술은 가상화 보안 구조에 대한 보안 취약점 문제가 지속적으로 이슈화 되었다. 또 한 내부 데이터 보안이 플랫폼 제공자의 가상화 보안 기술에 의존적인 경우가 대부분이다. 이는 기존 소프트웨어, 하드 웨어 보안 기술은 가상화 영역 접근이 어렵고 보안 기능 수행에 데이터 분석 및 처리 효율성이 낮기 때문이다. 본 논 문은 사용자 중요 정보를 기계학습 알고리즘을 적용하고, 학습 가능한 보안 인증벡터 생성하여 이를 가상화 내부 영역 에서 보안 검증을 수행할 수 있는 방법을 제안한다. 성능분석 결과 인증벡터의 가상화 환경의 내부 전송 효율성, 연산 방법의 높은 효율성과 주요 생성 파라미터에 대한 안전성을 입증하였다.
Recently, the investment and study competition regarding machine running is accelerating mainly with Google, Amazon, Microsoft and other leading companies in the field of artificial intelligence. The security weakness of virtualization technology security structure have been a serious issue continuously. Also, in most cases, the internal data security depend on the virtualization security technology of platform provider. This is because the existing software, hardware security technology is hard to access to the field of virtualization and the efficiency of data analysis and processing in security function is relatively low. This thesis have applied user significant information to machine learning algorithm, created security authentication vector able to learn to provide with a method which the security authentication can be conducted in the field of virtualization. As the result of performance analysis, the interior transmission efficiency of authentication vector in virtualization environment, high efficiency of operation method, and safety regarding the major formation parameter were demonstrated.
Analyses of Security Architecture for a Virtual Heterogeneous Machine
[Kisti 연계] 한국정보통신학회 한국정보통신학회 학술대회논문집 2005 pp.791-794
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In this paper, we describe security for a virtual heterogeneous machine. Our security architecure is based on separation of services into for distinct system support for domains, where available. We have chosen to use emergong public key technology as an interim solution to provide domain seperation. Th proposed architecture has been analysed in numerically.
[NRF 연계] 한국IT정책경영학회 한국IT정책경영학회 논문지 Vol.9 No.2 2017.04 pp.373-382
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구는 영상감시 기반 기계경비시스템의 수용의도에 영향을 미치는 요인에 관한 연구이다. 영상감시 기반 기계경비시스템의 수용에 어떠한 요인들이 지각된 가치에 영향을 주는지 살펴보고자 한다, 그리고 지각된 가치가 사용자 만족과 수용의도에 어떠한 영향을 미치는지 인과관계를 규명하는데 있다. 이를 위해 정보시스템 성공모형과 가치기반 수용모델을 통합하여 지각된 가치(Perceived Value), 사용자 만족(User Satisfaction), 수용의도(Intent of Acceptance)의 구조 방정식을 분석하였다. 본 연구에서는 기계경비시스템이나 영상감시시스템을 이용해 본 경험이 있거나 관련 업종 종사자를 대상으로 설문조사를 실시하고 실증분석을 실시하였다.
The purpose of this study is to investigate the factors affecting the acceptance intention of the machine security system based on video surveillance. we will examine what factors affect the perceived value of users. And the purpose of this study is to investigate the causal relationship between perceived value and user satisfaction on acceptance intention. To do this, we analyzed the structural equation of perceived value, user satisfaction, and acceptance intention by integrating information system success model and value-based acceptance model. In this study, we conducted questionnaires and conducted empirical analysis on workers who have experienced or related industry workers using machine security system or video surveillance.
보안 점검 목록을 효율적으로 관리하기 위한 머신러닝 기반의 보안 점검 항목 분류
[Kisti 연계] 한국스마트미디어학회 스마트미디어저널 Vol.11 No.11 2022 pp.75-83
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
미국의 NIST에서는 CVE나 CPE와 같은 기존의 취약점 관련 표준을 이용하여 보안 취약성 점검 및 관리를 자동화할 수 있도록 하는 프로토콜인 SCAP을 개발했다. SCAP은 XCCDF 및 OVAL 언어를 이용하여 점검파일을 작성하고 작성한 점검 파일을 OpenSCAP에서 만든 SCAP Workbench와 같은 SCAP 도구로 실행하면 점검 결과를 반환하는 식으로 동작한다. 다양한 운영체제에 대한 SCAP 점검 파일이 NCP 커뮤니티를 통해 공유되고 있으며 점검 파일에는 점검 항목별로 아이디, 제목, 설명, 점검 방법 등이 작성되어 있다. 하지만 점검항목은 단순히 작성한 순서대로 나열되어 있어 보안 관리자가 SCAP 점검 파일을 이용하여 체계적으로 관리할 수 있도록 점검 항목을 유형별로 분류하여 관리할 필요가 있다. 본 연구에서는 OVAL 언어로 작성된 SCAP 점검 파일에서 각 점검 항목에 대한 설명이 작성된 부분을 추출하여 머신러닝 모델을 통해 카테고리를 분류하고, SCAP 점검 결과를 분류한 점검 항목별로 출력하는 방법을 제안한다.
NIST in the United States has developed SCAP, a protocol that enables automated inspection and management of security vulnerability using existing standards such as CVE and CPE. SCAP operates by creating a checklist using the XCCDF and OVAL languages and running the prepared checklist with the SCAP tool such as the SCAP Workbench made by OpenSCAP to return the check result. SCAP checklist files for various operating systems are shared through the NCP community, and the checklist files include ID, title, description, and inspection method for each item. However, since the inspection items are simply listed in the order in which they are written, so it is necessary to classify and manage the items by type so that the security manager can systematically manage them using the SCAP checklist file. In this study, we propose a method of extracting the description of each inspection item from the SCAP checklist file written in OVAL language, classifying the categories through a machine learning model, and outputting the SCAP check results for each classified item.
LTE-Advanced에서의 Machine Type Communications을 위한 그룹 기반 보안 프로토콜
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.23 No.5 2013 pp.885-896
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
사람이 개입할 필요 없이 기기 및 사물들을 셀룰러 망(cellular network)으로 연결하여 언제 어디서나 다양한 서비스를 제공하는 MTC(Machine Type Communications)는 차세대 통신의 주요 이슈로 고려되고 있다. 현재, 다수의 MTC 단말들이 동시적으로 망에 접속하려고 하면 각 MTC 단말들은 독립적인 접근 인증 절차를 수행해야 된다. 이로 인해 LTE-Advanced 네트워크에서 인증 시그널링(authentication signaling) 혼잡(congestion)과 부하(overload)의 문제가 야기된다. 본 논문은 그룹 기반의 인증 프로토콜과 키 관리 프로토콜을 제안한다. 그룹 단위로 MTC 단말들을 관리하기 위해 제안하는 프로토콜은 그룹 리더(leader)를 선출하고, 리더만이 코어 망(core network)과의 인증에 참여한다. 인증이 완료된 후, 그룹 리더는 이진트리(binary tree)를 구성하여 나머지 구성원(member)들과 MME(Mobility Management Entity)를 관리한다. 마지막으로 제안 프로토콜 분석은 제안하는 프로토콜이 MTC 단말들과 코어 망 사이에서 발생되는 인증 시그널링을 줄여줄 수 있을 뿐만 아니라 효율적으로 MTC 단말들을 관리할 수 있음도 보여준다.
MTC(Machine Type Communications), providing a variety of services anytime and anywhere by connecting the cellular network to the machine and things without human intervention, is being considered as a major challenge of the next-generation communications. Currently, When a massive MTC devices simultaneously connect to the network, each MTC device needs an independent access authentication process. Because of this process, authentication signaling congestion and overload problems will cause in LTE-Advanced. In this paper, we propose a group-based authentication protocol and a key management protocol. For managing the MTC devices as group units, the proposed protocol elects a group leader and authentications only once with the core network. After the authentication is completed, a group leader manages the rest members and MME(Mobility Management Entity) by constructing a binary tree. Finally, the propose protocol analysis show that the proposed protocol not only can reduces the authentication signaling which generated in between the MTC devices and the core network but also can manages the MTC devices, efficiently.
의료기기 네트워크 트래픽 보안 관련 머신러닝 알고리즘 성능 비교
[Kisti 연계] 한국IT서비스학회 한국IT서비스학회지 Vol.22 No.5 2023 pp.99-108
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
As the computerization of hospitals becomes more advanced, security issues regarding data generated from various medical devices within hospitals are gradually increasing. For example, because hospital data contains a variety of personal information, attempts to attack it have been continuously made. In order to safely protect data from external attacks, each hospital has formed an internal team to continuously monitor whether the computer network is safely protected. However, there are limits to how humans can monitor attacks that occur on networks within hospitals in real time. Recently, artificial intelligence models have shown excellent performance in detecting outliers. In this paper, an experiment was conducted to verify how well an artificial intelligence model classifies normal and abnormal data in network traffic data generated from medical devices. There are several models used for outlier detection, but among them, Random Forest and Tabnet were used. Tabnet is a deep learning algorithm related to receive and classify structured data. Two algorithms were trained using open traffic network data, and the classification accuracy of the model was measured using test data. As a result, the random forest algorithm showed a classification accuracy of 93%, and Tapnet showed a classification accuracy of 99%. Therefore, it is expected that most outliers that may occur in a hospital network can be detected using an excellent algorithm such as Tabnet.
기계 학습 기반의 자동화된 스머지 공격과 패턴 락 시스템 안전성 분석
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.26 No.4 2016 pp.903-910
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
터치스크린 기반 스마트 기기가 널리 보급 되면서 모바일 환경을 위한 주요 인증 메커니즘으로 그래픽 패스워드 기법 중 하나인 패턴 락 시스템이 등장했다. 사용자가 잠금 해제를 위하여 패턴 락을 사용한 후의 남아있는 패턴 모양의 흔적은 스머지 공격에 취약하다. 이러한 스머지 공격에 대응하기 위하여 TinyLock을 포함한 다양한 패턴 락이 제안되었다. 본 논문에서는 스머지 공격이 발생할 수 있는 환경에서 획득한 스머지 패턴 이미지를 이용하여 기계 학습을 통한 자동화된 스머지 공격의 유효성에 대하여 실험하고 안드로이드 패턴 락과 TinyLock의 안전성에 대하여 비교 분석하였다. 자동화된 스머지 공격에서 높은 공격 성공률을 보였으며 기존에 많이 사용되고 있는 안드로이드 패턴 락이 TinyLock보다 더 안전하지 않음을 검증하였다.
As smart mobile devices having touchscreens are growingly deployed, a pattern lock system, which is one of the graphical password systems, has become a major authentication mechanism. However, a user's unlocking behaviour leaves smudges on a touchscreen and they are vulnerable to the so-called smudge attacks. Smudges can help an adversary guess a secret pattern correctly. Several advanced pattern lock systems, such as TinyLock, have been developed to resist the smudge attacks. In this paper, we study an automated smudge attack that employs machine learning techniques and its effectiveness in comparison to the human-only smudge attacks. We also compare Android pattern lock and TinyLock schemes in terms of security. Our study shows that the automated smudge attacks are significantly advanced to the human-only attacks with regard to a success ratio, and though the TinyLock system is more secure than the Android pattern lock system.
[Kisti 연계] 한국전자거래학회 한국전자거래학회지 Vol.27 No.1 2022 pp.1-13
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
인터넷, 모바일 등 네트워크 기술이 발전함에 따라 내외부 침입 및 위협으로부터 조직의 자원을 보호하기 위한 보안의 중요성이 커지고 있다. 따라서 최근에는 다양한 보안 로그 이벤트에 대하여 보안 위협 여부를 사전에 파악하고, 예방하는 이상징후 식별 알고리즘의 개발이 강조되고 있다. 과거 규칙 기반 또는 통계 학습에 기반하여 개발되어 온 보안 이상징후 식별 알고리즘은 점차 기계 학습과 딥러닝에 기반한 모델링으로 진화하고 있다. 본 연구에서는 다양한 기계 학습 분석 방법론을 활용하여 악의적 내부자 위협을 사전에 식별하는 최적 알고리즘으로 LSTM-autoencoder를 변형한 Deep-autoencoder 모형을 제안한다. 본 연구는 비지도 학습에 기반한 이상탐지 알고리즘 개발을 통해 적응형 보안의 가능성을 향상시키고, 지도 학습에 기반한 정탐 레이블링을 통해 기존 알고리즘 대비 오탐율을 감소시켰다는 점에서 학문적 의의를 갖는다.
With the development of network technologies, the security to protect organizational resources from internal and external intrusions and threats becomes more important. Therefore in recent years, the anomaly detection algorithm that detects and prevents security threats with respect to various security log events has been actively studied. Security anomaly detection algorithms that have been developed based on rule-based or statistical learning in the past are gradually evolving into modeling based on machine learning and deep learning. In this study, we propose a deep-autoencoder model that transforms LSTM-autoencoder as an optimal algorithm to detect insider threats in advance using various machine learning analysis methodologies. This study has academic significance in that it improved the possibility of adaptive security through the development of an anomaly detection algorithm based on unsupervised learning, and reduced the false positive rate compared to the existing algorithm through supervised true positive labeling.
[Kisti 연계] 한국해양정보통신학회 한국해양정보통신학회 학술대회논문집 2005 pp.791-794
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In this paper, we describe security for a virtual heterogeneous machine. Our security architecure is based on separation of services into for distinct system support for domains, where available. We have chosen to use emergong public key technology as an interim solution to provide domain seperation. Th proposed architecture has been analysed in numerically.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.