년 - 년
4,000원
보안경보 이벤트를 이용한 네트워크 보안상황 시각화 기술은 보안 장비들에서 발생하는 대량의 보안경보 이벤트들을 효율적으로 시각화하여 관리자에게 네트워크 내의 보안상황과 정보를 직관적으로 전달하는 기술이다. 하지만, 기존 대부분의 시각화 방법들은 시간 흐름에 중첩하여 이벤트를 표시하거나 또는 빈도수를 활용한 상위 개체 분석이 대부분이기 때문에 공격의 추이, 발생한 시점, 공격의 연속성, 그리고 보고된 공격 정보들 간의 연관 관계를 살펴보기 어려웠다. 본 논문에서는 시간 흐름에 따라 이벤트들을 나선형으로 배치하고 발생 시간들과 공격 유형을 함께 표시함으로써, 전체 공격의 추이와 개별 공격들의 연속성 및 지속성을 직관적으로 살펴 볼 수 있다. 또한 전체 공격자와 피해자간의 연관관계를 하나의 화면을 통해 제공함으로써 전체 공격상황 뿐만 아니라 공격 유형과 공격 지점 등을 종합적으로 인지할 수 있다.
Network security visualization technique using security alerts provide the administrator with intuitive network security situation by efficiently visualizing a large number of security alerts occurring from the security devices. However, most of these visualization techniques represent events using overlap the timelines of the alerts or Top-N analysis by their frequencies resulting in failing to provide information such as the attack trend, the relationship between attacks, the point of occurrence of attack, and the continuity of the attack. In this paper, we propose an effective visualization technique which intuitively explains the transition of the whole attack and the continuity of individual attacks by arranging the events spirally according to timeline and marking occurrence point and attack type. Furthermore, the relationship between attackers and victims is provided through a single screen view, so that it is possible to comprehensively monitor not only the entire attack situation but also attack type and attack point.
4,000원
본 논문은 플로우 시각화 기반의 네트워크 보안 상황 감시 방법인 VisFlow를 제안하며, 기존 트래픽 플로우 시각화기술의 단점인 대량 트래픽 발생 시의 직관성 상실 문제, 대칭적 주소 공간에 의한 반사현상 문제, 종단간 연결 의미의상실 문제를 해결하고자 한다. VisFlow는 단순하고 효율적인 보안 시각화 인터페이스로써 플로우 시각화 기술을 활용하여 개별적인 트래픽 데이터들에서는 볼 수 없었던 다양한 네트워크 현상들을 패턴으로 형상화하고 관리 네트워크 내의 보안 상황을 실시간으로 분석 및 감시하는 방법이다. 트래픽 플로우의 포트 역할 분석 방법을 이용하여 노드 유형과중요 정보를 식별 분류하고, 분류된 정보는 중요도에 따라 2D/3D 공간 상에 단순화 및 강조하여 표시함으로써 직관성과 실용성을 높인다. 또한, IP주소값에 기반한 비대칭적 노드 배치를 통해 반사현상 문제를 해결하고 노드간의 연결선을 활용하여 종단간의 세션 의미를 유지함으로써 정보성은 높인다. 관리자는 VisFlow를 통해 방대한 트래픽 데이터를쉽게 탐색하고 전체 네트워크 상황을 직관적으로 파악함으로써 네트워크 보안 상황을 효과적으로 감시할 수 있다.
In this paper we propose a new method of security visualization, VisFlow, using traffic flows to solve theproblems of existing traffic flows based visualization techniques that were a loss of end-to-end semantics ofcommunication, reflection problem by symmetrical address coordinates space, and intuitive loss problem in mass oftraffic. VisFlow, a simple and effective security visualization interface, can do a real-time analysis and monitoringthe situation in the managed network with visualizing a variety of network behavior not seen in the individualtraffic data that can be shaped into patterns. This is a way to increase the intuitiveness and usability by identifyingthe role of nodes and by visualizing the highlighted or simplified information based on their importance in 2D/3Dspace. In addition, it monitor the network security situation as a way to increase the informational effectively usingthe asymmetrical connecting line based on IP addresses between pairs of nodes. Administrator can do a real-timeanalysis and monitoring the situation in the managed network using VisFlow, it makes to effectively investigate themassive traffic data and is easy to intuitively understand the entire network situation.
Snort를 이용한 비정형 네트워크 공격패턴 탐지를 수행하는 Spark 기반 네트워크 로그 분석 시스템
[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.18 No.4 2018 pp.48-59
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 네트워크 기술의 발달로 인해 다양한 분야에서 네트워크 기술이 사용되고 있다. 그러나 발전하는 네트워크 기술을 악용하여 공공기관, 기업 등을 대상으로 하는 공격 사례가 증가하였다. 한편 기존 네트워크 침입 탐지 시스템은 네트워크 로그의 양이 증가함에 따라 로그를 처리하는데 많은 시간이 소요된다. 따라서 본 논문에서는 Snort를 이용한 비정형 네트워크 공격패턴 탐지를 수행하는 Spark 기반의 네트워크 로그 분석 시스템을 제안한다. 제안하는 시스템은 대용량의 네트워크 로그 데이터에서 네트워크 공격 패턴탐지를 위해 필요한 요소를 추출하여 분석한다. 분석을 위해 Port Scanning, Host Scanning, DDoS, Worm 활동에 대해 네트워크 공격 패턴을 탐지하는 규칙을 제시하였으며, 이를 실제 로그 데이터에 적용하여 실제 공격 패턴 탐지를 잘 수행함을 보인다. 마지막으로 성능평가를 통해 제안하는 Spark 기반 로그분석 시스템이 Hadoop 기반 시스템에 비해 로그 데이터 처리 성능이 2배 이상 우수함을 보인다.
Recently, network technology has been used in various fields due to development of network technology. However, there has been an increase in the number of attacks targeting public institutions and companies by exploiting the evolving network technology. Meanwhile, the existing network intrusion detection system takes much time to process logs as the amount of network log increases. Therefore, in this paper, we propose a Spark-based network log analysis system that detects unstructured network attack pattern. by using Snort. The proposed system extracts and analyzes the elements required for network attack pattern detection from large amount of network log data. For the analysis, we propose a rule to detect network attack patterns for Port Scanning, Host Scanning, DDoS, and worm activity, and can detect real attack pattern well by applying it to real log data. Finally, we show from our performance evaluation that the proposed Spark-based log analysis system is more than two times better on log data processing performance than the Hadoop-based system.
XAI 기반 Network 침입공격 탐지 및 공격유형별 대표적 특징분석에 관한 연구
[NRF 연계] 전북대학교 문화융복합아카이빙연구소 디지털문화아카이브지 Vol.5 No.1 2022.04 pp.193-204
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
오늘날 다양한 네트워크 시스템이 연계되어 상용화가 이루어짐에 따라 사이버 보안의 중요성이 더욱 강조된다. 그중 IDS(Intrusion Detection System)는 사이버 보안 영역 내에 존재하는 네트워크 보안 분야에서 중요한 역할을 한다. 빅데이터 시대를 맞이하여 방대한 데이터 내에 존재하는 침입 행위를 빠르고 정확하게 탐지하는 것이 가장 중요하다. 분석가들은 이러한 침입 행위 탐지를 위하여 AI를 도입하여 탐지율을 높이고 알려지지 않은 공격 행위를 탐지하는 연구에 집중해왔다. 하지만 AI의 판단만을 근거로 탐지 결과를 신뢰할 수 없다. 이를 해결하기 위해 도입된 개념이 XAI(eXplainable Artificial Intelligence)로 불리우는 설명 가능한 AI이다. 본 논문은 XAI 중 하나인 SHAP을 활용하여 분류된 레이블 별 중요하게 작용하는 feature를 선정하여 레이블을 설명하고자 한다.
Today, the importance of cybersecurity is further emphasized as various network systems are linked and commercialized. Among them, IDS plays an important role in the field of network security that exists within the cybersecurity area. In the era of big data, it is most important to quickly and accurately detect intrusion behavior that exists within massive data. Analysts have been focusing on research to increase the detection rate and detect unknown attack behaviors by introducing AI to detect such intrusive behaviors. However, the detection results cannot be trusted based solely on AI’s judgment. The concept introduced to solve this problem is an explainable AI called XAI. This paper intends to explain the Label by selecting important features for each classified Label using SHAP, one of the XAI.
SNS를 이용한 분산서비스거부(DDoS) 공격 분석 및 탐지 방안 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제9권 제1호 2009.03 pp.151-159
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 네트워크나 서버의 가용성을 위협하는 형태의 공격이 급증하고 있으며 이로 인한 국가적, 경제적인 손실이 점차 증가하고 있다. 이러한 서비스거부(Denial of Service)공격의 형태는 SNS의 발전과 함께 변화 되었으며, 특히, SNS를 이용한 공격은 2007년 에스토니아의 주요 웹사이트 공격 처럼 국가나 인터넷 전체 기반체계를 대상으로 하는 형태의 조직적인 공격이나 최근 일본에서의 국내 반크 홈페이지 공격에 이르기까지 매우 광범위하게 전개되고 있는 실정이다. 따라서 본 논문 에서는 기존 서비스 거부 공격 방법과 SNS를 이용한 국가간 사이버공격에 대해 분석하고 이러한 공격을 탐지할 수 있는 방안에 대해 연구한다.
In recent, attacks which threaten the availability of networks or servers are rapidly increasing, costing the nation and economics are gradually extended.This type of Distributed Denial of Service(DDoS) has changed with the development of Social Network Service(which is called SNS). Especially, attacks using SNS is widely developed from the organized attacks to the nation or whole internet infrastructure such as attacks against the main website of Estonia in 2007, and to the recent Japan’s attack against Korean VANK website. Therefore, in this paper I explain the well-known DDoS attack technical and international cyber attacks, study the detection to those attacks.
시계열 분석을 적용한 사설 모바일 네트워크의 DDoS 공격 탐지 KCI 등재
한국융합보안학회 융합보안논문지 제16권 제4호 2016.06 pp.17-24
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
많은 기업과 조직에서는 LTE 망을 활용한 모바일 오피스 환경을 구축하고 있으며 공공 안전과 국가 방위에서도 모바일 환경의 국가재난망과 공군 LTE망을 구축하고 있다. 하지만 최근의 모바일 정보보안 위협은 정보유출 공격에서서비스를 무력화 시키는 DDoS 공격으로 위협이 진화되고 있다. 특히, 스마트폰, 스마트패드, 태블릿PC 등 단말기의 종류와 수가 기하급수적으로 증가하고, 모바일 단말기의 사양 및 회선 속도가 빠르게 발전함에 따라 모바일 환경에서DDoS 공격은 더욱 위협적으로 진화하고 있다. 현재 DDoS 공격 대응은 네트워크 또는 서버 앞 단계에서 차단하는 방법이 보편적이지만 모바일 네트워크 상에 DDoS 공격 트래픽이 유통되어 네트워크 자원을 소비하는 문제점은 계속 상존하고 있다. 그러므로 본 논문에서는 단말기 단계에서부터 DDoS 공격을 선제적으로 차단하기 위해 국가재난망 및 공군 LTE망과 같은 사설 모바일 네트워크에서 유통되는 트래픽 유형을 분석하여 DDoS 공격을 차단하는 방안을 제시한다. 하지만 국가재난망과 공군 LTE망에서 유통되는 트래픽을 직접적으로 분석하는 것은 제한되므로 유통되는 정보유형이 유사한 마인크래프트 게임의 전송 트래픽과 동영상 파일 업로드 전송 트래픽을 대상으로 시계열 분석하여 사설모바일 네트워크에서의 DDoS 공격 탐지 기준을 정립하고 DDoS 공격을 탐지·차단하는 APP을 시범 구현하여 그 실효성을 검증하였다.
Many companies and organizations are building a mobile office environment using the LTE network, the national disaster network and Air Force LTE network are built for public safety and national defense. However the recent threats on information security have been evolving from information leakage to DDoS attacks to neutralize the service. Especially, the type of device such as Smart phones, smart pad, tablet PC, and the numbers are growing exponentially and As performance of mobile device and speed of line develop rapidly, DDoS attacks in the mobile environment is becoming a threat. So far, universal countermeasure to DDoS attacks has been interception the network and server step, Yet problem regarding DDoS attack traffic on mobile network and expenditure of network resources still remains. Therefore, this paper analyzes the traffic type distributed in the private mobile network such as the National Disaster Network, and Air Force LTE network in order to preemptively detect DDoS attacks on terminal step. However, as direct analysis on traffic distributed in the National Disaster Network, and Air Force LTE network is restricted, transmission traffics in Minecraft and uploading video file upload which exhibit similar traffic information are analyzed in time series, thereby verifing its effectiveness through establishment of DDoS attacks standard in mobile network and application that detects and protects DDoS attacks
Improving Analysis Phase in Network Forensics By Using Attack Intention Analysis SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.5 2016.05 pp.297-308
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The increasing amount of cyber crimes has motivated network forensics researchers to develop new techniques to analyze and investigate these crimes. Reconstructing useful evidence of a cybercrime is difficult due to the vagueness of the analysis phase processes. The analysis phase is challenging because it provides detailed information on the intention and strategy of the attack. This paper aims to show the importance of reconstructing attack intentions in order to improve the analysis phase in network forensics. Intentions are identified through an algorithm called Attack Intention Analysis, which predicts cyber crime intentions by combining mathematical evidence theory and a probabilistic technique. In this paper, the attack intention model will be improved to present the motivation behind cyber crimes. The results of the comparison of the attack intention analysis methods prove that the AIA algorithm is more accurate.
Ransomware Detection Using Deep Q-Network and L2PGD Attack Analysis on a Custom Dataset
[Kisti 연계] 한국스마트미디어학회 스마트미디어저널 Vol.14 No.2 2025 pp.19-25
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In the current fast changing cyberspace, ransomware has continued to be a formidable threat. Through this research, using deep reinforcement learning and adversarial attack models, we undertook performance analysis evaluation of a locally constructed ransomware dataset. The dataset contained key dynamic features that were extracted from raw ransomware samples processed in Cuckoo sandbox environment. Our approach combined supervised learning for initial detection and Deep Q-Network (DQN) algorithm for adaptive behavioral analysis. An L2 Projected Gradient Descent (L2PGD) adversarial attack was then carried out to evaluate the robustness of both security and stability of the ransomware detection model. The results that were obtained demonstrated that Deep Reinforcement Learning (DRL) can effectively classify samples as benign and ransomware. Moreover, the successful adversarial attack underscores the need for improved robustness measures in artificial intelligence models.
MapReduce 환경에서 Snort 로그를 이용한 실시간 네트워크 공격패턴 분석 시스템
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2017 pp.75-77
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 급격히 증가하고 있는 네트워크 로그 상에서 보안위협에 신속히 대응하기 위해 기업들은 방화벽, IDS 등의 네트워크 보안 로그를 분석하여 보안 위협을 파악한다. Snort는 이러한 보안 위협에 대응하기 위해 네트워크 로그를 수집하는 도구 중 하나이다. 그러나 보안 관제 담당자는 방대한 양의 보안 관련 로그를 분석하기 위해 많은 시간이 필요하기 때문에, 관제 결과를 보고하고 대응하기까지 시간이 지체되는 문제가 존재한다. 이러한 문제를 해결하기 위해, 본 논문에서는 Snort 로그를 이용한 실시간 네트워크 공격패턴 분석 시스템을 제안한다. 제안하는 시스템은 대용량 데이터 처리에 효과적인 MapReduce 분산 처리를 활용하여 방대한 네트워크 로그를 추출 및 분석하기 때문에 보안 위협 상황 발생 여부를 실시간으로 빠르게 인지할 수 있다.
MapReduce 환경에서 Snort 로그를 이용한 실시간 네트워크 공격패턴 분석 시스템
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2017 pp.75-77
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 급격히 증가하고 있는 네트워크 로그 상에서 보안위협에 신속히 대응하기 위해 기업들은 방화벽, IDS 등의 네트워크 보안 로그를 분석하여 보안 위협을 파악한다. Snort는 이러한 보안 위협에 대응하기 위해 네트워크 로그를 수집하는 도구 중 하나이다. 그러나 보안 관제 담당자는 방대한 양의 보안 관련 로그를 분석하기 위해 많은 시간이 필요하기 때문에, 관제 결과를 보고하고 대응하기까지 시간이 지체되는 문제가 존재한다. 이러한 문제를 해결하기 위해, 본 논문에서는 Snort 로그를 이용한 실시간 네트워크 공격패턴 분석 시스템을 제안한다. 제안하는 시스템은 대용량 데이터 처리에 효과적인 MapReduce 분산 처리를 활용하여 방대한 네트워크 로그를 추출 및 분석하기 때문에 보안 위협 상황 발생 여부를 실시간으로 빠르게 인지할 수 있다.
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2005 pp.909-912
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
다양한 정보보호체계가 운영되고 있지만, 방화벽과 침입탐지시스템이 가장 많이 운영되고 있는 실정에서, 본 논문에서는 방화벽 관리자의 차단로그 분석을 효율적으로 지원하면서, 방화벽에 의해 차단되어 침입탐지시스템이 탐지하지 못해 관리자가 지나칠 우려가 있는 공격행위를 방화벽을 통해 인지할 수 있는 방안을 구성했다. 이를 통해 관리자는 침입탐지시스템과 함께 네트워크를 통한 스캔 및 DOS 등의 공격을 방화벽을 통해 인지할 수 있어 안정적인 네트워크 운영이 가능하다.
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2018 pp.189-192
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
사토시 나카모토는 비트코인 논문을 통해서 P2P 네트워크에 기반을 둔 전자화폐인 비트코인을 제안하였다. 비트코인은 블록체인과 합의 알고리즘을 이용해 금융기관이 필요 없는 전자화폐 기술이며 이에 대한 관심이 높아지면서 비트코인에 관련된 다양한 보안 문제들이 발견되었다. 본 논문에서는 비트코인에서 발생할 수 있는 네트워크 관련 취약점을 기술하고 이에 대한 대응 방안을 분석한다.
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2018 pp.189-192
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
사토시 나카모토는 비트코인 논문을 통해서 P2P 네트워크에 기반을 둔 전자화폐인 비트코인을 제안하였다. 비트코인은 블록체인과 합의 알고리즘을 이용해 금융기관이 필요 없는 전자화폐 기술이며 이에 대한 관심이 높아지면서 비트코인에 관련된 다양한 보안 문제들이 발견되었다. 본 논문에서는 비트코인에서 발생할 수 있는 네트워크 관련 취약점을 기술하고 이에 대한 대응 방안을 분석한다.
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2024 pp.192-195
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 빠른 속도로 개발되고 있는 인공지능 기술은 여러 산업 분야에서 활용 되고 있다. 그러나 최근 딥러닝 네트워크에 대한 부채널 공격 기법들이 등장하고 있으며, 이는 해당 모델을 재구현하여 자율 주행 자동차에 대한 해킹 등과 같이 치명적인 보안 위협이 될 수 있으므로 이에 대한 이해와 대응책이 필요하다. 본 논문에서는 딥러닝 네트워크에 대한 부채널 공격 기법 동향에 대해 살펴보고, 이에 대한 대응 기술 또한 함께 알아본다.
[NRF 연계] 한국자료분석학회 Journal of The Korean Data Analysis Society Vol.20 No.4 2018.08 pp.1973-1988
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구는 네트워크 이론을 활용하여 국내 풋살 경기에서 이루어지는 주요 공격패턴을 알아보고자 하였다. 구체적으로 경기내용 중 득점을 시도하기 위해 수행한 마지막 공격패턴 3회를 기준으로 공격유형 및 득점유무에 따른 주요 공격패턴을 분석하였다. 연구목적을 위해 한국풋살연맹 주관 2017-18시즌 현대해상 FK 슈퍼리그에 참가한 16개 팀의 공격패턴 1,731개의 자료가 분석에 활용됐다. 공격패턴의 분석을 위해 네트워크 이론의 사회연결망 분석을 적용하였다. 자료처리는 MS-Excel과 NetMiner(ver. 4.0) 프로그램을 활용하였다. 연구의 결론은 다음과 같다. 첫째, 국내 풋살 경기는 경기장 중앙지역에서 공격수행의 높은 중요도를 나타낸다. 높은 공격빈도와 공격수행의 이동지역으로는 경기장 우측지역을 활용하고 있다. 둘째, 주요 공격패턴으로는 킥인 상황에서 패스 후 직접 슈팅을 시도하고 있다. 셋째, 개인돌파 상황에서는 경기장 좌측지역에서 높은 공격패턴이 이뤄지며, 조합 플레이 상황에서는 경기장 좌측과 중앙을 활용한 공격패턴이 이뤄진다. 넷째, 득점 상황에서의 주요 공격패턴은 킥인을 통한 득점과 중앙지역에서 돌파를 통한 득점이 주요한 것으로 알 수 있었다. 본 연구의 결과는 풋살 경기의 경기력 관련 정보의 다양화와 함께 주요 공격패턴을 확인할 수 있는 기초 정보로 적용될 수 있을 것이라 기대한다.
The purpose of this study is to analyze the futsal attack pattern using network theory. Specifically, major attack patterns were confirmed according to attack type and score. For this study, 1,731 attack pattern of 16 teams from 2017 to 2018 Korea futsal super league were collected. Social network analysis based on network theory was applied. For the data analysis, MS-Excel and NetMiner 4.0 programs were used. The conclusion of this study is as follows. First, futsal games represent the high importance of attack performance in the central area. The area of the right side of the field is used as a moving area for high attack frequency and attack performance. Secondly, the main patterns of attacks are an attempt after a pass from the direct kick-in situation. Third, in the solo play situation, high attack pattern is performed in the left side of the field, and in the combination play situation, the attack pattern using the left side and the center of the field is achieved. Fourth, major attack patterns in the goal situation were found to be important in kick-in and dribble in the central area.
누리온 슈퍼컴퓨팅서비스 네트워크에서 트래픽 및 공격 빈도 분석
[NRF 연계] 한국정보처리학회 KIPS Transactions on Computer and Communication Systems Vol.9 No.5 2020.05 pp.113-120
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
한국과학기술정보연구원은 대용량 데이터를 초고속으로 생산ㆍ처리ㆍ활용할 수 있는 국가슈퍼컴퓨팅시스템을 구축․운영하여 사용자(대학, 연구소, 정부 및 산하기관, 기업체 등)에게 HPC(High Performance Computing) 서비스를 제공하고 있다. 2019년 1월 1일 공식 서비스를 개시한 국가슈퍼컴퓨터 누리온은 한국과학기술정보연구원에서 5번째로 구축한 시스템으로 이론성능 25.7 페타플롭스를 갖는다. 시스템 운영자나 사용자의 관점에서 슈퍼컴퓨터의 사용 방법과 운영 방식을 이해하는 것은 매우 중요하다. 이를 이해하는 작업은 네트워크 트래픽을 모니터링하고 분석하는 것에서 시작된다. 본 논문에서는 누리온 시스템과 슈퍼컴퓨팅서비스 네트워크 및 보안 구성에 대하여 간략히 소개한다. 그리고 슈퍼컴퓨팅서비스 현황을 실시간으로 확인하기 위한 모니터링 체계를 기술하고 서비스를 시작하고 11개월(2019년 1월~11월) 동안 수집된 슈퍼컴퓨팅서비스 네트워크의 인바운드 및 아웃바운드 트래픽과 비정상행위(공격) 탐지 IP 개수에 대한 시계열 및 상관관계 분석을 수행한다.
KISTI(Korea Institute of Science and Technology Information) provides HPC(High Performance Computing) service to users of university, institute, government, affiliated organization, company and so on. The NURION, supercomputer that launched its official service on Jan. 1, 2019, is the fifth supercomputer established by the KISTI. The NURION has 25.7 petaflops computation performance. Understanding how supercomputing services are used and how researchers are using is critical to system operators and managers. It is central to monitor and analysis network traffic. In this paper, we briefly introduce the NURION system and supercomputing service network with security configuration. And we describe the monitoring system that checks the status of supercomputing services in real time. We analyze inbound/outbound traffics and abnormal (attack) IP addresses data that are collected in the NURION supercomputing service network for 11 months (from January to November 1919) using time series and correlation analysis method.
SIP망에서 트래픽 측정 및 IP 추출을 통한 DDoS공격 탐지 기법 설계
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2010 pp.729-732
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
통신망의 발달로 다양한 인터넷 기반 기술들이 등장함에 따라 현재는 데이터뿐만 아닌 음성에 대한 부분도 IP 네트워크를 통해 전송하려는 움직임이 발판이 되어 VoIP(Voice Over Internet Protocol)라는 기술이 등장하였다. SIP(Session Initiation Protocol) 프로토콜 기반 VoIP 서비스는 통신 절감 효과가 큰 장점과 동시에 다양한 부가서비스를 제공하여 사용자 수가 급증하고 있다. VoIP 서비스는 호(Call)를 제어하기 위해 SIP 기반으로 구성이 되며, SIP 프로토콜은 IP 망을 이용하여 다양한 음성과 멀티미디어 서비스를 제공하게 되는데 IP 프로토콜에서 발생하는 인터넷 보안 취약점을 그대로 동반하기 때문에 DoS(Denial of Service) 및 DDoS(Distribute Denial of Service)에 취약한 성향을 가지고 있다. DDoS 공격은 단시간 내에 대량의 패킷을 타깃 호스트 또는 네트워크에 전송하여 네트워크 접속 및 서비스 기능을 정상적으로 작동하지 못하게 하거나 시스템의 고장을 유도하게 된다. 인터넷 기반 생활이 일상화 되어 있는 현 시점에서 안전한 네트워크 환경을 만들기 위해 DDoS 공격에 대한 대응 방안이 시급한 시점이다. DDoS 공격에 대한 탐지는 매우 어렵기 때문에 근본적인 대책 마련에 대한 연구가 필요하며, 정상적인 트래픽 및 악의적인 트래픽에 대한 탐지 시스템 개발이 절실히 요구되는 사항이다. 본 논문에서는 SIP 프로토콜 및 공격기법에 대해 조사하고, DoS와 DDoS 공격에 대한 특성 및 종류에 대해 조사하였으며, SIP를 이용한 VoIP 서비스에서 IP 분류와 메시지 중복 검열을 통한 DDoS 공격 탐지기법을 제안한다.
SIP망에서 트래픽 측정 및 IP 추출을 통한 DDoS공격 탐지 기법 설계
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2010 pp.729-732
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
통신망의 발달로 다양한 인터넷 기반 기술들이 등장함에 따라 현재는 데이터뿐만 아닌 음성에 대한 부분도 IP 네트워크를 통해 전송하려는 움직임이 발판이 되어 VoIP(Voice Over Internet Protocol)라는 기술이 등장하였다. SIP(Session Initiation Protocol) 프로토콜 기반 VoIP 서비스는 통신 절감 효과가 큰 장점과 동시에 다양한 부가서비스를 제공하여 사용자 수가 급증하고 있다. VoIP 서비스는 호(Call)를 제어하기 위해 SIP 기반으로 구성이 되며, SIP 프로토콜은 IP 망을 이용하여 다양한 음성과 멀티미디어 서비스를 제공하게 되는데 IP 프로토콜에서 발생하는 인터넷 보안 취약점을 그대로 동반하기 때문에 DoS(Denial of Service) 및 DDoS(Distribute Denial of Service)에 취약한 성향을 가지고 있다. DDoS 공격은 단시간 내에 대량의 패킷을 타깃 호스트 또는 네트워크에 전송하여 네트워크 접속 및 서비스 기능을 정상적으로 작동하지 못하게 하거나 시스템의 고장을 유도하게 된다. 인터넷 기반 생활이 일상화 되어 있는 현 시점에서 안전한 네트워크 환경을 만들기 위해 DDoS 공격에 대한 대응 방안이 시급한 시점이다. DDoS 공격에 대한 탐지는 매우 어렵기 때문에 근본적인 대책 마련에 대한 연구가 필요하며, 정상적인 트래픽 및 악의적인 트래픽에 대한 탐지 시스템 개발이 절실히 요구되는 사항이다. 본 논문에서는 SIP 프로토콜 및 공격기법에 대해 조사하고, DoS와 DDoS 공격에 대한 특성 및 종류에 대해 조사하였으며, SIP를 이용한 VoIP 서비스에서 IP 분류와 메시지 중복 검열을 통한 DDoS 공격 탐지기법을 제안한다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.