년 - 년
Malware 동향 분석과 향후 예측 - 국방기관 및 방산분야를 중심으로 - KCI 등재후보
한국융합보안학회 융합보안논문지 제12권 제4호 2012.09 pp.97-108
※ 기관로그인 시 무료 이용이 가능합니다.
4,300원
본 연구는 이메일을 활용한 멀웨어 공격 중 국내 국방 분야 및 방산 분야에 대한 공격 동향을 분석하고, 새로운 공 격 유형을 예측하였다. 국방 분야와 방산업계 대상으로 발생하는 멀웨어 배포는 주로 사회공학적으로 수집된 개인정보 를 바탕으로, 특정 기능이 포함된 악성코드가 포함된 문서 파일로 배포한다. 배포된 멀웨어는 피해자 사용 단말기의 정 보를 습득하려는 의도로 사용된다. 본 연구는 실제 사례들에 대한 분석을 통해 이메일을 활용한 멀웨어 배포 동향을 분석하여, 향후 시도될 것으로 예상되는 멀웨어 배포 유형을 예측했다.
In this study, we analysis the distributing malware using email on the korean defense service and defense industr y as the social engineering attack. E-mail attack distributes the document files with the malware. Using the malwar e, attacker get the Information of the targeted people and devices. we proposed expected new types of attacks by an alysis and transformation. And, expect the new email attack agendas which will be tried.
웹에 숨겨진 악성코드 배포 네트워크에서 악성코드 전파 핵심노드를 찾는 방안 KCI 등재
한국융합보안학회 융합보안논문지 제23권 제2호 2023.06 pp.3-10
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
웹에 존재하는 악성코드 배포 네트워크에는 악성코드 배포를 위해 핵심 역할을 수행하는 중심 노드가 있다. 이 노드를 찾아 차단하면 악성코드 전파를 효과적으로 차단할 수 있다. 본 연구에서는 복잡계 네트워크에서 위험 분 석이 적용된 centrality 검색 방법을 제안하였고, 이 방식을 통해 악성코드 배포 네트워크 내에서 핵심노드를 찾는 방법을 소개한다. 그 외에, 정상 네트워크와 악성 네트워트는 in-degree와 out-degree 측면에서 큰 차이가 있고, 네트워크 레이아웃 측면에서도 서로 다르다. 이 특징을 통해 우리는 악성과 정상 네트워크를 분별할 수 있다.
In the malware distribution network existing on the web, there is a central node that plays a key role in distributing malware. If you find and block this node, you can effectively block the propagation of malware. In this study, a centrality search method applied with risk analysis in a complex network is proposed, and a method for finding a core node in a malware distribution network is introduced through this approach. In addition, there is a big difference between a benign network and a malicious network in terms of in-degree and out-degree, and also in terms of network layout. Through these characteristics, we can discriminate between malicious and benign networks.
HTTP Header 정보의 변조를 통한 악성코드 분석과 대응방안 KCI 등재후보
한국융합보안학회 융합보안논문지 제10권 제2호 2010.06 pp.43-49
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 새로운 유형의 악성코드 발생이 꾸준히 증가하고 있으며 점점 지능화, 고도화되면서 그 형 태 또한 다양한 형태로 변화하고 있다. 정보화산업의 발달로 정보의 경제적, 금전적 가치가 높아지 면서 정보유출 악성코드로 인한 그 피해 또한 점점 더 증가하고 있다. 본 논문은 HTTP Header 정 보 중 User-Agent의 일반적인 사용기법에 대해 알아본다. 또한, User-Agent 정보의 변조를 통한 다양한 악성코드 제작기법을 연구하고 이에 대한 기술적․정책적 대응방안을 제안한다.
Nowadays, the occurrence of Malware is steadily increasing. The Malware is also becoming more intelligent, advanced and changing into various types. With the development of the information industry, the economic and monetary value of the information is going up and the damage due to the leaked information by the Malware is also increasing. This paper investigates the general usage of the User- Agent in the HTTP Header, studies the Malware production techniques by transformation of the User-Agent information and suggests the technical and political counterplan against them.
그래프 데이터베이스 기반 악성코드 행위 탐지 기법 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제11권 제4호 2021.04 pp.55-63
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 악성코드 발생률은 약 수만 건이 넘는 추세로, 전부 탐지/대응하는 것은 불가능에 가깝다고 알려졌다. 본 연구는 새로운 악성코드 대응방법으로 그래프 데이터베이스 기반 다중행위 패턴 탐지 기법을 제안한다. 기존 동적 분석 기법과는 다른 새로운 그래프 모델을 설계하고, 대표적인 악성코드 패턴(프로세스, PE, 레지스트리 등)의 그래프 연관 관계를 분석하는 방법을 적용했다. 패턴 검증 결과 기본 악성 패턴에 대한 행위 탐지와 기존 분석이 어려웠던 변종 공격 행위(5단계 이상)의 탐지를 확인했다. 또한, 성능 분석결과 5단계 이상의 복잡한 패턴에 대하여 관계형 데이터베이스 대비 약 9.84배 이상 성능이 향상되었음을 확인하였다.
Recently, the incidence rate of malicious codes is over tens of thousands of cases, and it is known that it is almost impossible to detect/respond all of them. This study proposes a method for detecting multiple behavior patterns based on a graph database as a new method for dealing with malicious codes. Traditional dynamic analysis techniques and has applied a method to design and analyze graphs of representative associations malware pattern(process, PE, registry, etc.), another new graph model. As a result of the pattern verification, it was confirmed that the behavior of the basic malicious pattern was detected and the variant attack behavior(at least 5 steps), which was difficult to analyze in the past. In addition, as a result of the performance analysis, it was confirmed that the performance was improved by about 9.84 times or more compared to the relational database for complex patterns of 5 or more steps.
CFG, 라이브러리 정보를 이용한 권한 기반 안드로이드 악성코드 탐지 기술의 성능 향상 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.15 No.6 2019.12 pp.15-24
본 논문에서는 안드로이드 악성코드의 증가 추세에 대응하여 향상된 성능의 정적 악성코드 탐지 기법을 고안하였다. 기존의 어플리케이션의 권한을 특징(feature)으로 사용하는 악성코드 탐지 기법에 라이브러리 사용 정보와 control flow graph (CFG)의 속성을 특징으로 추가하여 성능을 향상시켰다. 또한, 라이브러리와 CFG는 구조 분 석을 통해 특징을 추출하므로 리네이밍(renaming) 난독화에 대하여 독립적이라는 특징이 있어 난독화에 취약한 권한 사용 탐지 기법을 보완하는 추가적인 이점을 가진다. 어플리케이션으로부터 추출한 세 가지 특징을 기반으로 양방향 장단기 기억 네트워크(bidirectional long short-term memory)를 이용한 악성코드 탐지 모델을 제안하 였다. 세 가지 특징을 모두 사용한 악성코드 분류 모델을 안드로이드 악성코드와 일반 어플리케이션을 합친 데이터 에 적용하였을 때 정확도 99.62%, 정밀도 100%, 재현율 99.26%, F1 99.62%로 높은 성능과 신뢰도를 보였다.
In this paper, we propose a static Android malware detection technique to improve the detection performance and reliability. Based on the permission feature which is heavily used in the previous works, we additionally use the library dependency and control flow graph (CFG) as features for improving our detection performance. Library dependency and CFG-based features are efficient to detect Android malware, which is obfuscated using renaming technique because these are extracted by structural analysis. By combining these three features, we propose a novel malware detection model using bidirectional long short-term memory. As results, we achieved 99.62% overall detection rate. Our model is highly reliable: where the precision, recall and F1 scores are 100%, 99.26% and 99.62%, respectively.
윈도우 기반 악성코드 증거 수집 모듈 개선에 관한 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제10권 제3호 2010.09 pp.61-68
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 경제적 이득을 얻기 위한 목적으로 개인정보․신용정보․금융정보 등을 외부로 유출하는 악성코드가 증가하고 있으며 명의도용, 금융사기 등 2차 피해 또한 급증하고 있다. 그런데 정보 유출형 악성코드에 감염되었을 경우 이를 탐지하고 대응할 수 있는 악성코드 증거 수집 도구가 증거를 수집하지 못하기 때문에 보안담당자가 침해사고를 처리하는데 많은 어려움을 겪고 있다. 본 논문은 기존 윈도우 기반 악성코드 증거 수집 도구의 현황과 문제점을 분석하고 이를 개선 할 수 있는 새로운 모듈을 제시한다.
Recently a malware is increasing for leaking personal data, credit information, financial information, etc. The secondary damage is also rapidly increasing such as the illegal use of stolen name, financial fraud, etc. But when a system is infected by a malware of leaking information, the existing malware evidence collection tools do not provide evidences conveniently or sometimes cannot provide necessary evidences. So security officials have much difficulty in responding to malwares. This paper analyzes the current status and problems of the existing malware evidence collection tools and suggests new ways to improve those problems.
스마트폰 악성코드 제거를 위한 단말 관리 시스템 설계 KCI 등재후보
한국융합보안학회 융합보안논문지 제11권 제4호 2011.08 pp.67-75
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 많은 외산제품들이 국내시장에 유입되고 국내 제품의 출시로 스마트폰 사용자는 급속히 증가하고 있다. 스마트폰 사용자가 증가함에 따라 모바일 악성코드 또한 빠르게 증가하고 있다. 이에 모바일 악성코드에 대한 적절한 대응의 필요성이 증대되고 있다. 단말 관리 방법으로는 SNMP, TR-069 프로토콜이 널리 사용되었지만 이들 프로토콜은 제한적인 관리기능, 이동성 미지원 등으로 인해 모바일 단말 관리에는 적합하지 않다. 모바일 단말 관리 표준인 OMA DM 프로토콜이 대부분의 2G, 3G 무선 단말들의 관리 프로토콜로 채택되고 있으며, 따라서 스마트폰 단말 관리를 위해서도 적합한 프로토콜이라 할 수 있다. 본 논문에서는 악성코드에 대한 현황을 설명하고 스마트폰의 악성코드를 원격제어로 제거할 수 있는 OMA DM기반의 단말 관리 시스템을 설계하였다.
Recently, the number of smartphone users is rising rapidly due to an influx of foreign smartphones and sales of domestic products. According to the increase of smartphone users, smartphone malwares are also increasing sharply. Hence it is necessary to protect smartphone against mobile malwares. There are device management protocols as SNMP, TR-069. But these protocols are not suitable for mobile device management because of restrictive management function and unsupported mobility. OMA DM which is a standard for mobile device management has been adopted as mobile device management protocol for most of 2G,3G. Thus it amounts that OMA DM is suitable for smartphone management system. In this paper, the mobile device management system based on OMA DM is designed. This system can remove smartphone malware by remote control.
윈도우 악성코드 분석을 통한 탐지 및 대응 기술에 관한 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제10권 제1호 2010.03 pp.19-27
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
오늘날 네트워크의 속도와 인터넷 기술의 발전과 동시에 윈도우 취약점을 통한 악성코드가 많 이 발생하고 있다. 악성코드는 여러 감염 형태 및 특성이 있어 바이러스 백신을 이용하여 탐지 하기도 어려울 뿐만 아니라 제거하는 것도 쉽지 않다. 본 논문은 윈도우 악성코드의 분류와 특 징을 분석하여 프로그램을 이용한 악성코드의 위치를 파악하고 신종 악성코드에 대한 신속한 대응을 위해 스크립트 기술을 제안 한다.
Nowadays, the network’s speed and internet technology are progressing rapidly but malwares are occurring frequently through the Window’s weak point. Since the malwares have various infection types and characteristics, it is hard to detect them by the virus vaccine and to cure them. This paper analyzes the type and characteristics of the malware and proposes a script technology that can find the location of the malware by the program and respond rapidly to the new kind of malwares.
스마트폰 악성코드 분석을 통한 확산 방지 모델에 관한 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제10권 제1호 2010.03 pp.1-8
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 전 세계적으로 스마트폰을 이용한 인터넷 이용인구의 증가에 따라 스마트폰 악성코드에 대한 관심이 높아지고 있다. 특히, 해외에서는 심비안, 윈도우 모바일이 탑재된 스마트폰을 대상 으로 모바일 악성코드가 발생하고 있어 이에 대한 대응이 필요하다. 따라서 본 논문은 2004년 이후 발생한 모바일 악성코드에 대한 현황 및 구체적 사례 분석을 통해 보안 위협을 설명한다. 또한, 국내 스마트폰 악성코드의 발생에 대응하기 위해 향후 발생할 수 있는 악성코드 확산 방 지 시스템에 대한 모델을 제시한다.
Recently, the number of internet users using smartphone is increasing worldwide, and the interest in the smartphone malware is increasing. Especially, since mobile malware are occurring to the smartphones using Symbian or Windows Mobiles in the abroad, it is necessary to have an action plan against these malwares. This paper describes the possible security threat through the analysis of the malwares occurred after 2004. Also we present a model for the future propagation prevention system which can cope with domestic smartphone malwares.
악성코드의 특성 이미지화를 통한 딥러닝 기반의 탐지 모델 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제11권 제11호 2021.11 pp.137-142
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷의 발달로 많은 편리와 이익을 얻었지만 반대로 지능화되는 악성코드로 인하여 사용자의 경제적, 사회적 피해를 주고 있다. 이를 탐지하고 방어하기 위해 대부분 시그니처 기반의 탐지나 방어 프로그램을 사용하 지만 지능화된 악성코드의 변종을 막기에는 매우 어렵다. 따라서 본 논문에서는 쏟아져 나오는 지능화된 악성코드 를 탐지하고 방어할 수 있는 모델을 제안한다. 제안 모델은 악성코드의 특성을 이미지화하여 딥러닝을 이용한 학 습을 통해 만들어지며 새롭게 탐지된 악성코드와 악성코드 변종들은 이미지화를 수행한 다음 만들어진 모델에 적용하여 탐지한다. 제안된 모델을 사용하면 기존에 탐지되었던 악성코드와 더불어 유사한 변종도 대 부분 탐지됨 을 알 수 있다.
Although the internet has gained many conveniences and benefits, it is causing economic and social damage to users due to intelligent malware. Most of the signature-based anti-virus programs are used to detect and defend this, but it is insufficient to prevent malware variants becoming more intelligent. Therefore, we proposes a model that detects and defends the intelligent malware that is pouring out in the paper. The proposed model learns by imaging the characteristics of malware based on deeplearning, and detects newly detected malware variants using the learned model. It was shown that the proposed model detects not only the existing malware but also most of the variants that transform the existing malware.
CNN 기반 악성코드 탐지에서 이미지 형식이 탐지성능과 자원 사용에 미치는 영향 분석 KCI 등재
한국융합보안학회 융합보안논문지 제21권 제4호 2021.10 pp.69-75
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
CNN 기반의 악성코드 탐지모델을 활용하기 위해 다양한 이미지 형식을 사용할 수 있다. 하지만 대부분의 기존 연구들은 최종적인 악성코드 탐지 및 분류 성능을 주로 강조하고 있으며, CNN에 입력되는 이미지의 형식이 모델의 성능과 자원 사용 량에 미칠 수 있는 영향은 거의 고려하지 않는다. 이에 본 논문에서는 CNN을 기반으로 안드로이드 악성코드를 탐지하는 모 델을 구축함에 있어 입력되는 이미지 형식이 탐지성능과 학습에 소요되는 자원의 사용량에 어떠한 영향을 미치는지를 분석하 였다. CICAndMal2017 데이터세트를 사용하여 BMP, JPG, PNG 및 TIFF 4가지 형식의 이미지로 변환하고, 자체적으로 구축 한 CNN 모델에 학습시킨 후 악성코드 탐지성능과 자원 사용량을 측정하였다. 그 결과 이미지 형식에 따른 이진분류 및 다중 분류 성능과 GPU 및 RAM 사용량은 큰 차이를 보이지 않았다. 그러나 생성된 이미지의 파일 크기는 이미지 형식에 따라 최 대 6배까지 차이가 났으며, 학습에 소요되는 시간에서도 유의미한 차이가 발생함을 확인하였다.
Various image formats are being used when attempting to construct a malware detection model based on CNN. However, most previous studies emphasize only the detection or classification performance, and do not take into account the possible impact of image format on detection performance and resource usage. Therefore, in this paper, we analyze how the input image formats affect detection performance and resources usage when detecting android malware based on CNN. The dataset used in the experiment is the CICAndMal2017 Dataset. Subdataset extracted from the CICAndMal2017 Dataset were converted into images in four formats: BMP, JPG, PNG, and TIFF. We then trained our CNN model and measured malware detection performance and resource usage. As a result, there was no sifnificant difference between detection performance and the GPU/RAM usage, even if the image format changed. However, we found that the file size of the generated images varied by up to six times depending on the image format, and that significant differences occurred in the training time.
Mem-Shot : 악성코드 난독화 분석을 위한 API-Trigger 기반의 메모리 덤프 시스템 설계 및 구현 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.12 No.4 2016.08 pp.23-32
최근 유포되는 악성코드에는 악성코드 분석을 방해하기 한 코드삽입, 난독화, 문자열 암호화 등 다양한 악성코드 분석회피 기술이 용되고 있다. 본 논문에서는 이러한 분석회피 기술이 용된 악성코드의 분석을 해, 가상머신 에 악성코드를 구동시킨 후 악성코드가 특정 API를 호출하면 정확한 시에 가상머신의 메모리 이미지를 빠르게 추 출 할 수 있는 악성코드 분석 시스템을 구하다. 악성코드에서 특정 API가 호출된 정확한 시에 메모리 덤 일을 얻을 수 있다면, 메모리분석을 통해 악성코드가 사용한 함수의 매개변수나 암호화 된 데이터 난독화가 해 제된 코드 정보를 얻을 수 있게 된다. 실험결과 악성코드가 API호출한 정확한 시에 메모리 덤를 할 수 있었고, 메모리 분석을 통해 분석회피 기술이 용된 악성코드로부터 숨겨진 문자열과 API 매개변수를 추출 할 수 있었다.
As malware generation techniques have been advanced, malware authors utilize various malware analysis evasion techniques such as obfuscation, garbage code insertions and string encryption. To alleviate such problems, we designed and implemented a malware analysis system which is specialized in dumping memory of a virtual machine. Malware analysis based on memory dump is a promising way to deep dive into the obfuscated malwares. Our system makes it possible to take a memory snapshot at a time of a certain API called. Furthermore, it accelerated the memory dump. Consequently, users can extract hidden information such as encrypted data and functional parameters from the malware in a user friendly manner. According to our experiments, our system can detect such hidden strings and API arguments even with analysis evasion techniques.
4,000원
최근 몇 년 동안 사이버 위협의 수와 복잡성이 증가하고 있다. 이러한 위협은 개인 소유 장치를 업무에 사용하는 것 의 위험성을 증가시킨다. 이 연구는 인공지능을 활용한 침해분석 도구의 활용 방안에 대해 다루고 있다. 이를 위해 자 동화된 분석 프로세스를 통해 분석자의 업무 부담을 줄이고 분석 효율을 향상시키는 인공지능 기반 침해분석 도구를 개발하고 활용 가능성을 제안하였다. 이를 통해, 분석자는 더욱 중요한 업무에 집중할 수 있다. 본 논문에서는 인공지능 기반 침해분석 도구의 개발과 활용 가능성을 제시하는 것이다. 이를 통해 침해분석 분야의 새로운 연구 방향을 제시하 고, 자동화 도구의 성능, 적용 범위, 사용 편의성을 향상시켜 조직이 효과적으로 사이버 공격에 대응할 수 있도록 하는 것이 필요하다는 것을 제시하였다. 연구 방법으로는 인공지능 기술을 활용하여 침해분석 도구를 개발하고, 이를 통해 다양한 활용 사례를 연구하였다. 또한, 자동화 도구의 성능, 적용 범위, 사용 편의성을 평가하고, 침해 사고의 예측 및 예방, 자동 대응을 위한 연구도 진행하였다. 본 연구는 인공지능 기반 침해분석 도구의 개발과 활용을 위한 기초가 될 것으로 이를 통해 효과적으로 사이버 공격에 대응 방안을 실험을 통해 확인할 수 있었다.
Recently, in order to build a cyber threats have increased in number and complexity. These threats increase the risk of using personally owned devices for work. This research addresses how to utilize an AI-enabled breach analysis tool. To this end, we developed and proposed the feasibility of using an AI-based breach analysis tool that reduces the workload of analysts and improves analysis efficiency through automated analysis processes. This allows analysts to focus on more important tasks. The purpose of this research is to propose the development and utilization of an AI-based breach analysis tool. We propose a new research direction in the field of breach analysis and suggest that automated tools should be improved in performance, coverage, and ease of use to enable organizations to respond to cyberattacks more effectively. As a research method, we developed a breach analysis tool using A.I. technology and studied various use cases. We also evaluated the performance, coverage, and ease of use of automated tools, and conducted research on predicting and preventing breaches and automatically responding to them. As a result, this research will serve as a foundation for the development and utilization of AI-based breach analysis tools, which can be used to respond to cyberattacks more effectively through experiments.
정적분석을 위한 통합 언패킹 및 역난독화 자동화 시스템 개발 KCI 등재후보
한국법과학회 한국법과학회지 제24권 제2호 2023.11 pp.34-51
※ 기관로그인 시 무료 이용이 가능합니다.
5,200원
Recently, technologies that make static analysis difficult are applied to most malicious codes, and the most representative technologies are packing and obfuscation technologies. Therefore, research on unpacking and deobfuscation techniques is essential for effective static analysis. Therefore, in this paper, an integrated unpacking and deobfuscation automation system was developed to solve this problem, and a 94.9% recovery rate was confirmed through a verification process.
능동적 탐지 대응을 위한 지능적 침입 상황 인식 추론 시스템 설계 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제12권 제4호 2022.04 pp.126-132
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
현재 스마트폰의 급격한 보급과 IoT을 대상으로 활성화로 인해 소셜네트워크 서비스를 이용하여 악성코드 를 유포하거나 지능화된 APT와 랜섬웨어 등과 같은 지능적인 침입이 진행되고 있고 이로 인한 피해도 이전의 침입 보다는 많이 심각해지고 커지고 있는 실정이다. 따라서 본 논문에서는 이런 지능적인 악성 코드로 이루어지는 침입 행위를 탐지하기 위하여 지능적인 침입 상황 인식 추론 시스템을 제안하고, 제안한 시스템을 이용하여 지능적으로 진행되는 다양한 침입 행위를 조기에 탐지하고 대응하게 하였다. 제안 시스템은 이벤트 모니터와 이벤트 관리기, 상황 관리기, 대응 관리기, 데이터베이스로 구성되어 있으며 각 구성 요소들 사이에 긴밀한 상호 작용을 통해 기존 에 인식하고 있는 침입 행위를 탐지하게 하고 새로운 침입 행위에 대해서는 학습을 통해 추론 엔진의 성능을 개선 하는 기능을 통하여 탐지하게 하였다. 또한, 지능적인 침입 유형인 랜섬웨어를 탐지하는 시나리오 통하여 제안 시 스템이 지능적인 침입을 탐지하고 대응함을 알 수 있었다.
At present, due to the rapid spread of smartphones and activation of IoT, malicious codes are disseminated using SNS, or intelligent intrusions such as intelligent APT and ransomware are in progress. The damage caused by the intelligent intrusion is also becoming more consequential, threatening, and emergent than the previous intrusion. Therefore, in this paper, we propose an intelligent intrusion situation-aware reasoning system to detect transgression behavior made by such intelligent malicious code. The proposed system was used to detect and respond to various intelligent intrusions at an early stage. The anticipated system is composed of an event monitor, event manager, situation manager, response manager, and database, and through close interaction between each component, it identifies the previously recognized intrusive behavior and learns about the new invasive activities. It was detected through the function to improve the performance of the inference device. In addition, it was found that the proposed system detects and responds to intelligent intrusions through the state of detecting ransomware, which is an intelligent intrusion type.
Ransomware Dissemination and Mitigation Techniques - A Review
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 학술대회 The 7th International Conference on Next Generation Computing 2021 2021.11 pp.173-177
Digital assets are one of the most important precious entities for any organization and if someone captures them for the purpose of ransom, then it would be a serious threat. The threat actor behind this activity is the ransomware. The threat posed by the ransomware on personal and business data assets expands very quickly. Data on an infected computer becomes encrypted until a ransom is paid for its release. Each year, ransomware causes hundreds of millions of dollars of losses for the companies throughout the world. Frequently, new versions are released because of the enormous profit margins and notorious practices. Antivirus software and other intrusion detection systems can be bypassed, so they are not a permanent solution so-far. This research work contributes some latest dissemination and mitigation techniques that are using in ransomware attacks. We also discussed the countermeasures to mitigate the ransomware attacks and some decryption tools and ransomware simulation to find the vulnerabilities in the system.
랜섬웨어 탐지를 위한 그래프 데이터베이스 설계 및 구현 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제11권 제6호 2021.06 pp.24-32
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 랜섬웨어(ransomware) 공격은 이메일, 피싱(phishing), 디바이스(Device) 해킹 등 다양한 경로를 통해 감염되어 피해 규모가 급증하는 추세이다. 그러나 기존 알려진 악성코드(정적/동적) 분석 엔진은 APT(Aadvanced Persistent Threat)공격처럼 발전된 신종 랜섬웨어에 대한 탐지/차단이 매우 어렵다. 본 연구 는 그래프 데이터베이스를 기반으로 랜섬웨어 악성 행위를 모델링(Modeling)하고 랜섬웨어에 대한 새로운 다중 복합 악성 행위를 탐지하는 방법을 제안한다. 연구 결과 기존 관계형 데이터베이스와 다른 새로운 그래프 데이터 베이스 환경에서 랜섬웨어의 패턴 탐지가 가능함을 확인하였다. 또한, 그래프 이론의 연관 관계 분석 기법이 랜섬 웨어 분석 성능에 크게 효율적임을 증명하였다.
Recently, ransomware attacks have been infected through various channels such as e-mail, phishing, and device hacking, and the extent of the damage is increasing rapidly. However, existing known malware (static/dynamic) analysis engines are very difficult to detect/block against novel ransomware that has evolved like Advanced Persistent Threat (APT) attacks. This work proposes a method for modeling ransomware malicious behavior based on graph databases and detecting novel multi-complex malicious behavior for ransomware. Studies confirm that pattern detection of ransomware is possible in novel graph database environments that differ from existing relational databases. Furthermore, we prove that the associative analysis technique of graph theory is significantly efficient for ransomware analysis performance.
데이터 마이닝 기법을 이용한 소규모 악성코드 탐지에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제19권 제1호 2019.03 pp.11-17
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 인터넷 기술을 악용하는 행위로 인하여 경제적, 정신적 피해가 증가하고 있다. 특히, 신규로 제작되거나 변형된 악성 코드는 기존의 정보보호 체계를 우회하여 사이버 보안 위협의 기본 수단으로 활용되고 있다. 이를 억제하기 위한 다양한 연구 가 진행되었지만, 실제 악성코드의 많은 비중을 차지하는 소규모 실행 파일에 대한 연구는 미진한 편이다. 본 연구에서는 기 존에 알려진 소규모 실행 파일의 특징을 데이터마이닝 기법으로 분석하여 알려지지 않은 악성코드 탐지에 활용할 수 있는 모 델을 제안한다. 데이터 마이닝 분석 기법에는 나이브베이지안, SVM, 의사결정나무, 랜덤포레스트, 인공신경망 등 다양하게 수 행하였으며, 바이러스토탈의 악성코드 검출 수준에 따라서 개별적으로 정확도를 비교하였다. 결과적으로 분석 파일 34,646개 에 대하여 80% 이상의 분류 정확도를 검증하였다.
Recently, the abuse of Internet technology has caused economic and mental harm to society as a whole. Especially, malicious code that is newly created or modified is used as a basic means of various application hacking and cyber security threats by bypassing the existing information protection system. However, research on small-capacity executable files that occupy a large portion of actual malicious code is rather limited. In this paper, we propose a model that can analyze the characteristics of known small capacity executable files by using data mining techniques and to use them for detecting unknown malicious codes. Data mining analysis techniques were performed in various ways such as Naive Bayesian, SVM, decision tree, random forest, artificial neural network, and the accuracy was compared according to the detection level of virustotal. As a result, more than 80% classification accuracy was verified for 34,646 analysis files.
안전한 프로세스 실행 환경을 위한 확장형 화이트리스트 프레임워크
한국정보통신설비학회 한국정보통신설비학회 학술대회 2017년도 정보통신설비 학술대회 2017.08 pp.193-195
※ 기관로그인 시 무료 이용이 가능합니다.
3,000원
스미싱 공격 방지를 위한 클라우드 메시징 서비스 KCI 등재
한국디지털정책학회 디지털융복합연구 제15권 제4호 2017.04 pp.285-293
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
스마트 디바이스에 대한 악의적인 공격들이 빠르게 진화하고 있고, 이들 공격에 대해 스마트 디바이스를 적절하게 보호하는 것은 매우 중요한 이슈로 부각되고 있다. 특히, 스미싱 공격은 스마트 폰에서 가장 중요한 위협들 중의 하나로 주목되고 있다. 이 논문에서는 스미싱 공격의 위험으로부터 사용자를 근본적으로 보호할 수 있는 클라우드 서비스를 제안한다. 제안된 클라우드 메시징 서비스는 사용자 스마트 디바이스에서 URL을 포함한 텍스트 메시지들을 필터링하여 클라우드 서버에 의해 제공되는 가상 머신을 통해 필터링된 메시지들을 확인하고 관리할 수 있는 클라우드 서비스를 제공한다. 기존의 스미싱 방지 기법들이 이미 알려진 패턴의 악성코드에 대해서만 보호하거나, 오탐(FP) 또는 미탐(FN) 등의 오류 가능성을 내포하고 있지만, 제안 기법은 URL을 포함하고 있는 모든 문자 메시지들을 자동적으로 필터링하여 클라우드 서버 상의 저장공간에 저장하고 확인 및 관리하기 때문에 스마트 디바이스에서 스미싱 공격에 의한 멀웨어(악성코드)의 설치를 완벽하게 차단할 수 있다.
They are rapidly evolving malicious attacks on smart devices, and to timely protect the smart devices from these attacks has become a very important issue. In particular, smishing attack has emerged as one of the most important threats on the smartphone. In this paper, we propose the cloud service that can fundamentally protect the user from the risk of smishing attack. The proposed scheme provides cloud messaging service that can filter text messages including URLs in the user’s smart device, view and manage them through a virtual machine provided by a cloud server. The existing techniques for preventing smshing attacks protect only malicious code of a known pattern and there is the possibility of error such as FP(False Positive) or FN(False Negative). However, since the proposed method automatically filters all text messages including URLs, storing, viewing, and managing them in their own storage space on the cloud server, it can completely block the installation of malwares(malicious codes) on the user’s smart device through smishing attacks.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.