Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 51
No
1

네트워크 접근제어 시스템의 보안성 메트릭 개발 KCI 등재

이하용, 양효식

한국디지털정책학회 디지털융복합연구 제15권 제6호 2017.06 pp.217-227

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

네트워크 접근제어(Network Access Control)를 통해 IT 인프라에 대한 보안위협 즉, 비인가 사용자, 단말의 네트 워크 무단 접속, 직원의 내부 서버 불법접근 등을 효과적으로 차단할 수있어야 한다. 이러한 관점에서는 보안성을 충족시키 고 있음을 확실히 하기 위해 관련 표준에 기반을 둔 메트릭 구축이 요구된다. 그러므로 관련 표준에 따른 NAC의 보안성 평가를 위한 방법의 체계화가 필요하다. 따라서 이 연구에서는 네트워크 접근제어시스템의 보안성 메트릭 개발을 위해 ISO/IEC 15408(CC:Common Criteria)과 ISO 25000 시리즈의 보안성 평가 부분을 융합한 모델을 구축하였다. 이를 위해 네트워크 접근제어시스템의 품질 요구사항을 분석하고 두 국제표준의 보안성에 관한 융합 평가메트릭을 개발하였다. 이를 통해 네트워크 접근제어시스템의 보안성 품질수준 평가 모델을 구축하고, 향후 네트워크 접근제어시스템에 대한 평가방법 의 표준화에 적용할 수 있을 것으로 사료된다.

Network access control should be able to effectively block security threats to the IT infrastructure, such as unauthorized access of unauthorized users and terminals, and illegal access of employees to internal servers. From this perspective, it is necessary to build metrics based on relevant standards to ensure that security is being met. Therefore, it is necessary to organize the method for security evaluation of NAC according to the related standards. Therefore, this study builds a model that combines the security evaluation part of ISO / IEC 15408 (CC: Common Criteria) and ISO 25000 series to develop security metric of network access control system. For this purpose, we analyzed the quality requirements of the network access control system and developed the convergence evaluation metric for security of the two international standards. It can be applied to standardization of evaluation method for network access control system in the future by constructing evaluation model of security quality level of network access control system.

2

안전한 클라우드 환경을 위한 소프트웨어 정의 경계 기반의 네트워크 보안 솔루션 제안 KCI 등재

차욱재, 신재인, 이동범, 김협, 이대효

한국융합학회 한국융합학회논문지 제9권 제12호 2018.12 pp.61-68

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

스마트폰과 모바일 환경이 발전하면서 개인의 업무 수행을 위한 시간과 공간의 제약이 사라지고 있다. 기업은 클라 우드 컴퓨팅을 통하여 비용을 절감하고 사업의 범위를 빠르게 확대할 수 있게 되었다. 다양한 클라우드의 사용이 확대되면 서 사용자, 데이터, 어플리케이션의 경계가 사라지고 있다. 경계(Perimeter)을 기준으로 하는 전통적인 보안 접근은 클라우 드 환경에서 효용을 잃어가고 있다. 이에, 본 논문에서는 클라우드 환경에서 기존 Network Access Control(NAC)의 한계를 기술하고 이를 보완한 네트워크 보안 기술을 제안한다. 관련연구로 SDP에 대해서 설명하고, NAC의 한계를 극복하기 위해 SDP(Software Defined Perimeter)를 융합하고 동시에 클라우드 환경의 지원을 위한 새로운 프레임워크로의 역할을 설명한 다. 본 논문에서 제안한 새로운 프레임워크는 물리적인 부분과 소프트웨어적인 부분에 SDP 기술을 적용하여 IP 기반이 아 닌 신원 중심 접근제어 제공, 암호화된 세그먼트 관리, 동적정책관리 등을 지원하는 소프트웨어 기반의 네트워크 보안 솔루 션을 제안한다.

As the smartphone and mobile environment develop, the time and space constraints for individual work performance are disappearing. Companies can reduce costs and expand their business quickly through cloud computing. As the use of various cloud expands, the boundaries of users, data, and applications are disappearing. Traditional security approaches based on boundaries (Perimeter) are losing their utility in the cloud environment. This paper describes the limitations of existing network access control (NAC) in a cloud environment and suggests network security technology that complements it. The study explains the SDP and combines SDP(Software Defined Perimeter) to overcome the limitations of NAC, while at the same time explaining its role as a new framework for supporting the cloud environment. The new framework proposed in this paper suggests a software-based network security solution that supports physical and software parts, providing identity-based access control, encrypted segment management, and dynamic policy management, not IP-based.

3

VLAN 환경에서 네트워크 주소 인증을 통한 정책 기반 실시간 시스템 제어 기술 연구 KCI 등재후보

최원우, 안성진, 정진욱

한국융합보안학회 융합보안논문지 제5권 제1호 2005.03 pp.35-43

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

네트워크(IP/MAC) 주소를 관리함에 있어 네트워크의 임의의사용자가 사용자가 사용 중인 네트워크 장비 혹은 PC의 IP 주소나 네트워크 인터페이스 카드를 임의적으로 또는 악의적으로 변경하는 것을 차단할 필요성이 있다. 또한 새로운 네트워크 자원 장비의 도입 시 수많은 네트워크 자원을 임의적으로 할당하지 않고, 관리자가 관리하게 됨으로써 효율적인 자원관리 및 네트워크 문제 발생시 신속한 대처를 할 수 있어야 한다. 이것은 하위레벨에서의 네트워크 관리 및 보안을 유지할 수 있게 한다. 그러나 이러한 작업을 현재는 대부분 관리자에 의한 수작업으로 진행하고 있으며 이로 인한 관리 인력의 낭비와 업무능률의 저하는 관리효율 자체의 저하로 이어진다. 본 논문에서는 기업이나 관공서에서 사용되는 VLAN 환경에서 네트워크 주소 인증을 통해 보안성을 더욱 향상시키기 위한 방안을 제시하고자 한다.

It is need to control network access that a user personally change own IP or network devices in managing network address. Also, When we use new network devices or assign network address, we do them by design, not arbitrarily. And then, we can immediately control network's problems. It could be used network management and security in low level. But most of managers do this works by hand not automatically. This paper propose the solutions that improve the security by network address authentication in VLAN environment, such as corporations and public offices.

4

4,000원

기존의 네트워크 구조는 게이트웨이 보안을 경계로 사용하므로 내부자 간의 무단 액세스를 방지하고 내부자 공격을 완화하기가 어렵다. 또한 조직의 규모가 커지면서 네트워크 트래픽이 복잡해지면서 모니터링 및 위협 식 별이 어려운 작업이 되었다. 이러한 문제를 극복하기 위해 그래프 데이터베이스를 사용하여 네트워크 노드를 모 델링하고 네트워크 동작을 분석할 것을 제안한다. 네트워크 트래픽 데이터를 수집하고 전처리를 통한 데이터 확 보와 그래프 모델링을 통한 내부 네트워크의 구조, 운영 및 잠재적인 보안 위협에 대한 통찰력을 얻을 수 있다. 이를 통해 접근통제 테이블과 접근통제 정책을 수립함으로써 보안 위협을 가하는 잠재적인 노드를 식별하고 비정 상적인 활동을 감지할 수 있다. 또한 접속 패턴을 분류하고 정상 편차를 식별하며 악의적인 사용을 방지하기 위 한 노드 간 접근통제 조치를 구현함으로써 발생할 수 있는 잠재적 위협을 방지할 수 있다.

Existing network structures use gateway security as a boundary, making it difficult to prevent unauthorized access between insiders and mitigate insider attacks. Additionally, as organizations grow in size, network traffic becomes more complex, making monitoring and threat identification a difficult task. To overcome these problems, we propose to model network nodes and analyze network behavior using a graph database. You can collect network traffic data, obtain data through preprocessing, and gain insight into the structure, operation, and potential security threats of internal networks through graph modeling. Through this, it is possible to identify potential nodes that pose security threats and detect abnormal activities by establishing access control tables and access control policies. In addition, potential threats that may occur can be prevented by classifying access patterns, identifying normal deviations, and implementing access control measures between nodes to prevent malicious use.

6

NAC 시스템의 시험방법과 평가사례에 관한 연구 KCI 등재

양효식, 전인오

한국디지털정책학회 디지털융복합연구 제12권 제9호 2014.09 pp.159-168

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷과 이동통신 기기의 발전으로 인해 개인의 경제활동에 관련된 인터넷뱅킹, 인터넷대출, 스마트폰등과 같은 이동통신기기를 이용한 모바일 뱅킹이 활성화되고 있다. 이에 따라 신종 범죄를 막기 위해 보안 시스템들이 새 롭게 선보이고 있으며, 앞으로 보안 시스템의 시장은 날로 늘어날 것으로 보고 이에 따른 보안 시스템들에 대한 질 적인 발전이 지속적으로 요구되고 있다. 따라서 보안시스템 제품의 시장이 지속적으로 성장할 것으로 예상되는 시점 에서 보안 시스템의 품질평가 요구에 대응하기 위해 본 논문에서는 보안 시스템중의 네트워크 접근제어시스템 분야 의 기반기술과 표준을 조사하고, 동향을 분석하여 관련 시스템의 시험과 평가방법을 제안하여 네트워크 접근제어시 스템의 품질평가 방법과 체계를 제안하였다.

With the advancement of internet and mobile communication devices, mobile banking such as internet banking, internet loan and smart phones related to the people's economic activities using mobile communication devices is becoming increasingly more popular. Various security systems to prevent such new crimes are being introduced and the security system market is anticipated to continuously increase substantially in the future. Accordingly, qualitative advancement of the security systems are also in continuous demand. Therefore, this thesis proposes the method and system for quality evaluation of the network access control system by proposing testing and evaluating method for the relevant system through surveying and analyzing the tend in the foundation technologies and standards in the area of network access control system, which is one of the security systems, in order to cope with the demands for the evaluation of the quality of the security system as the security system product market is anticipated to grow continuously.

7

적외선 기반 피기백킹 방지 기법을 적용한 네트워크 그룹 접근통제 시스템 KCI 등재후보

김종민, 최경호, 이동휘

한국융합보안학회 융합보안논문지 제12권 제4호 2012.09 pp.109-114

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

오늘날과 같은 정보화사회에서는 비인가자의 조직 내 출입 시, 중요 정보자산에 접근이 용이해지기 때문에 통제 상의 어려움이 있다. 비인가자는 고도의 기술을 활용하지 않더라도, 뒤따름(Piggy-backing)과 어깨 너머로 훔쳐보기(Shoulder surfing) 등의 방법을 통해 중요 정보를 획득 할 수 있다. 그러므로 본 연구에서는 비인가자가 조직 내 주요 공간에 위 치 시 연관된 정보통신기기의 네트워크 접속을 차단하여 내부 정보를 열람할 수 있는 권한을 적절히 통제하는 방법을 제시하고자 한다. 제시된 방법은 RFID와 적외선 센서를 결합하여 네트워크 접근통제 시스템에 적용시킨 것으로, 이를 통해 비인가자 출입으로 인한 내부 정보 유출 위협을 차단하여, 인원 보안 측면을 강화한 보다 안전한 내부 네트워크 환경을 제공할 수 있다. 또한 내부 사용자의 보안인식 제고를 위한 수단으로 활용할 수 있는 장점도 있다.

Information society in recent times, lots of important information have been stored in information systems. In this situation, unauthorized person can obtains important information by piggy-backing and shoulder surfing in specific area of organization. Therefore, in this study, we proposed network group access control system by combining RFID and infrared-ray for blocking information leakage due to unauthorized access by internal threats and enhancing personnel security. So it can provides a more secure internal network environment.

8

RFID 출입통제시스템과 연동한 네트워크 이중 접근통제 시스템 KCI 등재후보

최경호, 김종민, 이대성

한국융합보안학회 융합보안논문지 제12권 제3호 2012.06 pp.53-58

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

내부에 있는 정보를 보호하기 위한 노력들 중 하나인 네트워크 접근통제 시스템의 적용은 내부 사용자들의 효과적 제어 및 자동적인 네트워크 관리와 보안을 가능하게 한다. 그러나 이미 허가된 PC 또는 모바일 기기로 위장하거나 자 리를 비운 사용자의 인가된 시스템을 이용하여 내부 네트워크에 접속할 수 있는 문제점이 있다. 또한 허가된 PC 또는 모바일 기기의 악성코드 감염으로 인해 사용자가 직접 사용하는 시간 이외에도 동작하여 비의도적인 정보유출 및 내부 네트워크 공격 등이 발생할 수 있다. 따라서 내부 네트워크에 접속을 허가 받은 이가 인가된 장비를 이용하여 접근정책 에 따른 통신을 수행하고 있는지를 확인해야 한다. 이를 위해 본 연구에서는 RFID 출입통제시스템과 연동한 네트워크 이중 접근통제 시스템을 제안한다. 제안된 시스템은 내부 네트워크 접속 시 이중인증을 수행함으로써 허가된 사용자가 인가된 장비를 이용하여 통신을 수행하는 환경을 제공한다.

Network Access Control System that is one of the efforts to protect the information of internal applies to effectively control of insider and automatic network management and security. However, it has some problems : spoofing the authorized PC or mobile devices, connect to the internal network using a system that authorized users are away. In addition, information leakage due to malicious code in the same system. So in this paper, Network 2-Factor Access Control System based on RFID security control system is proposed for safety communication environment that performing a two-factor authentication using authorized user and devices to connect to the internal network.

9

의료 정보유출 방지를 위한 네트워크 이중 접근통제 모델 연구 KCI 등재

최경호, 강성관, 정경용, 이정현

한국디지털정책학회 디지털융복합연구 제10권 제6호 2012.07 pp.341-347

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

시스템 및 네트워크에 설치/운용되는 의료자산보호 솔루션 중 네트워크 접근통제 시스템은 내부 네트워크에 접근하는 정보통신 디바이스의 안전성을 검증한 후 자원을 사용하게 하는 프로세스를 제공한다. 그러나 인가된 정보통신 디바이스의 위장 및 허가된 사용자의 이석 시간을 이용한 비인가 사용 등으로 내부 네트워크에 대한 의료 정보절취 위협은 여전히 존재하고 있고, 장시간 운영되는 정보통신 디바이스의 경우는 사용자가 인지하지 못하는 시간대에 악성코드 감염에 의한 외부 네트워크 임의 접속 및 의료 정보유출도 발생할 수 있기 때문에 이러한 위협을 차단하기 위한 보안 대책이 필요하다. 따라서 본 논문에서는 의료 정보유출 방지를 위해 현행 네트워크 접근통제 시스템을 개선하여 적용한 네트워크 이중 접근통제 모델을 제시한다. 제안한 네트워크 이중 접근통제 모델은 사용자가 실제 조직 내부에 위치하고 있어 인가된 정보통신 디바이스를 활용하는 때에만 내부 네트워크 접속을 허용한다. 그러므로 비인가자의 내부 네트워크 접근을 차단하고, 허가된 사용자 부재 시의 불필요한 외부 인터넷 접속을 차단함으로써 의료 정보를 보호할 수 있는 안전한 의료자산 환경을 제공한다.

Network Access Control system of medical asset protection solutions that installation and operation on system and network to provide a process that to access internal network after verifying the safety of information communication devices. However, there are still the internal medical-data leakage threats due to spoof of authorized devices and unauthorized using of users are away hours. In this paper, Network 2-Factor Access Control Model proposed for prevention the medical-data leakage by improving the current Network Access Control system. The proposed Network 2-Factor Access Control Model allowed to access the internal network only actual users located in specific place within the organization and used authorized devices. Therefore, the proposed model to provide a safety medical asset environment that protecting medical-data by blocking unauthorized access to the internal network and unnecessary internet access of authorized users and devices.

10

ARC 접근제어 정책 기반의 공공 교육망 제로트러스트 보안 모델 연구 KCI 등재

김동우, 한수진, 이기찬, 오수현

한국융합보안학회 융합보안논문지 제24권 제5호 2024.12 pp.145-154

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 업무 환경이 확장되면서 네트워크의 경계가 모호해지고 기존 경계 기반 보안 모델의 한계가 부각됨에 따라, 새로운 대안으로 제로트러스트 보안 모델이 주목받고 있다. 이에 다양한 분야에서 제로트러스트 도입을 위한 노력이 활발한 가운데, 민감한 데이터를 다루는 공공 교육망 환경에서의 적용은 고려되지 않고 있다. 특히 2006년부터 교육기관을 대상으로 전용회선 을 구축해 온 스쿨넷 사업은 경계 기반 보안 모델을 채택하고 있어 기존의 취약점에 여전히 노출되어 있다. 따라서 본 논문에 서는 공공 교육망에 제로트러스트 보안 모델을 적용한 아키텍처를 제안한다. 또한 접근 주체의 신뢰도를 평가하기 위한 접근 위험 계수(Access Risk Coefficient)를 정의하고 이를 시스템에 적용하여 보안성을 강화한다. 나아가 제안하는 시스템에서 고 려해야 할 보안 요구사항을 도출하고, 안전성을 분석함으로써 공공 교육망에 적합한 제로트러스트 보안 모델을 제시한다.

As the work environment has expanded recently, the boundaries of the network have become ambiguous and the limitations of the existing perimeter-based security model have been highlighted, so the zero-trust security model is attracting attention as a new alternative. Accordingly, while efforts to introduce zero-trust are active in various fields, its application in the public education network environment that handles sensitive data has not been considered. In particular, the SchoolNet project, which has been building dedicated lines for educational institutions since 2006, has adopted a perimeter-based security model and is still exposed to existing vulnerabilities. Therefore, this paper proposes an architecture that applies the zero-trust security model to the public education network. In addition, the access risk coefficient for evaluating the reliability of the access subject is defined and applied to the system to enhance security. Furthermore, the security requirements to be considered in the proposed system are derived and the safety is analyzed, thereby proposing a zero-trust security model suitable for the public education network.

11

ScienceDMZ 기반의 네트워크 구성에서 접근제어정책 적용 KCI 등재

권우창, 이재광, 김기현

한국융합보안학회 융합보안논문지 제21권 제2호 2021.06 pp.3-10

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

데이터 기반의 과학연구가 추세인 요즘 대용량의 데이터 전송은 연구 생산성에 많은 영향을 미친다. 이러한 문제를 해결하 기 위해서 대용량 과학 빅데이터를 전송하기 위한 별도의 네트워크 구조가 필요하다. ScienceDMZ는 이러한 과학 빅데이터를 전송하기 위해서 고안된 네트워크 구조이다. 이러한 네트워크 구성에서는 사용자 및 자원에 대한 접근제어정책(ACL, access control list) 수립이 필수적이다. 본 논문에서는 실제 ScienceDMZ 네트워크 구조로 구현된 R&E Together 프로젝트와 네트워 크 구조를 설명하고, 안전한 데이터 전송 및 서비스 제공을 위해 접근제어정책을 적용할 사용자 및 서비스를 정의한다. 또한 네트워크 관리자가 전체 네트워크 자원 및 사용자에 대해 일괄적으로 접근제어정책을 적용할 수 있는 방법을 제시하며, 이를 통해 접근제어정책 적용에 대한 자동화를 이룰 수 있었다.

Nowadays, data-based scientific research is a trend, and the transmission of large amounts of data has a great influence on research productivity. To solve this problem, a separate network structure for transmitting large-scale scientific big data is required. ScienceDMZ is a network structure designed to transmit such scientific big data. In such a network configuration, it is essential to establish an access control list(ACL) for users and resources. In this paper, we describe the R&E Together project and the network structure implemented in the actual ScienceDMZ network structure, and define users and services to which access control policies are applied for safe data transmission and service provision. In addition, it presents a method for the network administrator to apply the access control policy to all network resources and users collectively, and through this, it was possible to achieve automation of the application of the access control policy.

12

An Access Control Mechanism based on Permission Delegation in P2P Network SCOPUS

ZHANG Changyou, LIU Renfen, CAO Yuanda, LI Yanhua, CUI Liang

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.2 No.2 2008.04 pp.59-70

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

P2P(Peer-to-Peer) is a popular model in distributed computing. We present an access control mechanism based on permission delegation in this paper. This mechanism consists of three protocols, i.e. agency discovering protocol, permission delegating protocol and resource access protocol. Firstly, the task initiator decomposes the task into subtasks and chooses other peers in high trust degree with satisfied abilities to accomplish these subtasks. We call these neighbors as task agents. Then task initiator temporarily transfers some necessary permission to subtask agents by means of credit certificate and delegation certificate. Finally, the subtask agents consume resources of resource peers followed access protocol. These protocols are analyzed in Colored Petri-Net, and simulated with CPN Tools.

13

A Formal Policy Oriented Access Control Model for Secure Enterprise Network Environment SCOPUS

Manpreet Singh, Manjeet Singh Patterh, Tai-Hoon Kim

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.3 No.2 2009.04 pp.1-14

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper we use Security Evaluation Criteria as basis to develop the Network access control model for enterprise wide network computing environment. The Network access control model addresses both the access control and information flow control requirements of the enterprise network system. The security architecture of the model attempts to ensure authorized access to network resources and secure flow of information between network entities. The underlying concept of the Network access control model relies on the separation of the access control mechanism from the access control policy. This enables support for multiple access control policies within a single model specification. A further advantage of Network Access control model is that it is highly extensible, since it can be augmented with any new policy that a specific application or a user may require. The precision property is satisfied as network access control model is written in a formal mathematical notation. The property of simplicity is satisfied as only the security properties related to network computing system are modeled.

14

Wireless Mesh network, a typical wireless ad hoc network, can effectively solve the “last one thousand meters” problem of broadband access. It, with features of self-forming, self-healing and high bandwidth, provides its users with better service by integrating the advantages of WLAN and ad hoc network and fully utilizing and combining with WiMAX, WiFi and other wireless technologies. In network planning, the effective configuration of access point is of great importance for network set-up cost control. A good topological structure, in addition, plays a decisive role in network throughput capacity. The research stated in the thesis studied the configuration of wireless Mesh network access point and internet topology control, simulating a pure Mesh network connecting to external networks. By studying the relationships between such parameters as gateway connection and broadcast interval with transfer rate of packets, end to end delay and system overhead, their relationships were able to be confirmed and the correctness of the analysis results was tested by the comparative studies of the simulation results.

15

Access Control to Objects and their Description in the Future Network of Information

Renault, Eric, Ahmad, Ahmad, Abid, Mohamed

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.6 No.3 2010 pp.359-374

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The Future Internet that includes Real World Objects and the Internet of Things together with the more classic web pages will move communications from a nodecentric organization to an information-centric network allowing new a paradigm to take place. The 4WARD project initiated some works on the Future Internet. One of them is the creation of a Network of Information designed to enable more powerful semantic searches. In this paper, we propose a security solution for a model of information based on a semantic description and search of objects. The proposed solution takes into account both the access and the management of both objects and their descriptions.

16

Unidirectional Ring Ethernet and Media Access Controller with Automatic Relaying for Low-complexity In-vehicle Control Network

Yoo, Injae, Jo, Jihyuck, Ju, Youngjin, Park, In-Cheol

[Kisti 연계] 대한전자공학회 Journal of semiconductor technology and science Vol.17 No.5 2017 pp.697-708

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

This paper proposes an Ethernet-based in-vehicle control network and its hardware realization. Since modern premium-class vehicles contain nearly a hundred electronic control units (ECUs), multiple control networks needed for the ECUs become considerably complex. In order to reduce the network complexity, the proposed network connects the ECUs by employing an Ethernet-based unidirectional ring topology. In addition, a new Ethernet media access controller (MAC) is proposed to automatically relay mismatched frames. As a result, the proposed ring network can be constructed without any switching device. A hardware platform employing the proposed MAC as a network controller is implemented on a field programmable gate array to evaluate the realistic performance of the proposed network. Experimental results show that the proposed MAC increases the communication speed by 123%. Moreover, the performance of the proposed network with a large number of ECU nodes is evaluated using the OMNET++ simulation tool, which shows that the proposed network provides the ECUs with much higher communication speed than the conventional CAN and FlexRay do.

17

효율적인 BYOD 접근통제를 위한 802.1X 네트워크 접근통제 구현과 성능 해석

이민철, 김정호

[Kisti 연계] 한국정보처리학회 정보처리학회논문지/컴퓨터 및 통신 시스템 Vol.4 No.9 2015 pp.271-282

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

비즈니스 환경에서 BYOD(Bring Your Own Device) 활용은 지속적으로 확대되고 있다. 시스코(Cisco)는 2012년 600개 기업을 대상으로 BYOD 활용에 관한 설문조사를 실시했다. 조사 결과 95%의 기업에서 이미 BYOD 사용을 허용하고 있으며, 업무 생산성이 향상된 것으로 나타났다. 가트너(Gartner)는 BYOD 도입으로 보안위협이 증가할 것으로 예측했으며, 보안위협 완화 방안으로 네트워크 접근통제(Network Access Control, NAC) 도입을 제안했다. 또한 접근통제 중요도에 따라 네트워크 영역을 나누고, 사용자 역할과 단말기 유형을 고려하여 접근통제 정책을 상세히 정의하고, 네트워크에 연결된 모든 단말기에 강제로 적용할 것을 주장했다. 본 논문에서는 IEEE 802.1X와 DHCP 핑거프린팅(fingerprinting)을 응용하여 네트워크 접근통제를 설계 구현하고, BYOD 환경에 적용하여 접근통제 성능을 해석하고자 한다.

In the business environment BYOD(Bring Your Own Device) is used and being expanded continuously. According to a survey conducted by Cisco in 2012 on 600 companies, 95% of them are already permitting the use of BYOD in their work environments so that productivity of their employees has improved as a result. Gartner predicted that the use of BYOD will be caused new security threat. They also suggested to introduce NAC(Network Access Control) to resolve this threat, to separate network zone based on importance of their business, to establish the policy to consider user authority and device type, and to enforce the policy. The purpose of this paper is to design and implement the NAC for granular access control based on IEEE(Institute of Electrical and Electronics Engineers) 802.1X and DHCP(Dynamic Host Configuration Protocol) fingerprinting, and to analyze the performance on BYOD environment.

18

효율적인 BYOD 접근통제를 위한 802.1X 네트워크 접근통제 구현과 성능 해석

이민철, 김정호

[NRF 연계] 한국정보처리학회 KIPS Transactions on Computer and Communication Systems Vol.4 No.9 2015.09 pp.271-282

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

비즈니스 환경에서 BYOD(Bring Your Own Device) 활용은 지속적으로 확대되고 있다. 시스코(Cisco)는 2012년 600개 기업을 대상으로BYOD 활용에 관한 설문조사를 실시했다. 조사 결과 95%의 기업에서 이미 BYOD 사용을 허용하고 있으며, 업무 생산성이 향상된 것으로나타났다. 가트너(Gartner)는 BYOD 도입으로 보안위협이 증가할 것으로 예측했으며, 보안위협 완화 방안으로 네트워크 접근통제(Network Access Control, NAC) 도입을 제안했다. 또한 접근통제 중요도에 따라 네트워크 영역을 나누고, 사용자 역할과 단말기 유형을 고려하여 접근통제 정책을 상세히 정의하고, 네트워크에 연결된 모든 단말기에 강제로 적용할 것을 주장했다. 본 논문에서는 IEEE 802.1X와 DHCP 핑거프린팅(fingerprinting)을 응용하여 네트워크 접근통제를 설계⋅구현하고, BYOD 환경에 적용하여 접근통제 성능을 해석하고자 한다.

In the business environment BYOD(Bring Your Own Device) is used and being expanded continuously. According to a survey conducted by Cisco in 2012 on 600 companies, 95% of them are already permitting the use of BYOD in their work environments so that productivity of their employees has improved as a result. Gartner predicted that the use of BYOD will be caused new security threat. They also suggested to introduce NAC(Network Access Control) to resolve this threat, to separate network zone based on importance of their business, to establish the policy to consider user authority and device type, and to enforce the policy. The purpose of this paper is to design and implement the NAC for granular access control based on IEEE(Institute of Electrical and Electronics Engineers) 802.1X and DHCP(Dynamic Host Configuration Protocol) fingerprinting, and to analyze the performance on BYOD environment.

19

적응형 네트워크 보안시스템의 네트워크 접근제어 설계

김대식, 박종률, 노봉남

[Kisti 연계] 한국정보보호학회 한국정보보호학회 학술대회논문집 2006 pp.745-748

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

현재의 네트워크 시스템은 보안시스템 및 신규시스템이 추가됨에 따라 복잡함이 증가하고, 그에 따라 관리하기가 어려워져 관리자나 사용자가 이용하기에 불편함이 따른다. 또한 사용자의 잦은 변동과 단말의 이동성으로 인해 네트워크 관리하는데 있어 관리자가 해야할 일들이 많아 졌다. 따라서 앞으로의 네트워크 관리도구는 복잡성을 해결하고, 사용자의 편의성에 중점을 두어야 한다. 이러한 요구사항을 정리하여 본 논문에서는 사용자에게는 보다 쉽게 사용하고, 관리자에게는 최소비용과 관리의 용이성을 위한 보안시스템을 설계하였다. 이 시스템은 신규 사용자의 네트워크 접속후 인증을 받기위한 부분에 있어서 리눅스 시스템과 네트워크 장비를 연동해서 관리자가 정책적용시 자동으로 ACL을 구성해 보안관리를 강화하는데 목적을 두고 설계하였다.

20

네트워크 펌웨어를 이용한 Agent-less 방식의 네트워크접근제어 구현에 관한 연구

김진석, 민성기, 오상석

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2011 pp.703-705

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

내부 네트워크의 IP관리를 위해 많은 네트워크 관리 방안 및 솔루션들이 기 구축되어 운영 중이고, 이를 위해 내부 네트워크에 연결된 모든 단말에 특정 Agent를 설치하여 IP를 관리하고 있어 단말(PC, IPT전화기 등)의 OS에 따른 기종별 Agent의 호환문제 및 단말에 기 설치 운영중인 응용프로그램과의 충돌문제가 발생한다. 본 연구에서는 이러한 네트워크 IP관리를 위해 Agent가 필요 없는 네트워크 관리 방식을 제안한다. 네트워크 Switch장비 Firmware의 포트차단 설정을 이용한 기법으로 Agent의 설치없이 Switch장비의 Firmware를 이용하여 네트워크의 접근제어가 가능함을 제안한다. 이를 위하여 인가되지 않은 IP를 Switch장비의 Firmware로 차단하여 네트워크의 접근제어가 가능함을 증명하였다.

 
1 2 3
페이지 저장