Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 21
No
1

의료기기 소프트웨어에서 발생한 취약점은 환자의 안전과 직결되며, 최근 소프트웨어 공급망의 복잡성이 증가함에 따라 Software Bill of Materials(SBOM) 기반 취약점 관리의 중요성이 더욱 강조되고 있다. 특히, U.S. Food and Drug Administration(FDA)은 의료기기 인허가 과정에서의 SBOM 제출 및 체계적인 취약점 관리 체계 구축을 요구하고 있으나, 기존의 취약점 관리 방법은 주로 Common Vulnerability Scoring System(CVSS) 기반 정적 위험 평가 혹은 Software Composition Analysis(SCA) 중심의 취약점 식별에 의존하고 있어, 소프트웨어 구성 요소 간 의존성 관계 및 실제 악용 가능성이 높은 취약점 정보를 충분히 반영하지 못하는 한계가 존재한다. 따라서 본 연구에서는 SBOM 데이터를 기반으로 취약점 간 의존성을 반영하여 이종 그래프(Heterogeneous Graph)를 구축하고, 그래프 신경망(Graph Neural Network, GNN)을 활용하여 컴포넌트 단위의 취약점 위험도를 정량적으로 평가하는 방법을 제안한다. 제안 기법은 CVSS 점수, Known Exploited Vulnerabilities(KEV) Catalog, 그리고 컴포넌트 간 의존성 구조를 통합적으로 반영하여 위험도를 산출하고, 이를 기반으로 패치 우선순위를 자동으로 결정한다. 실험 결과, 제안 모델은 기존의 정적 평가 기반 접근 방식 대비 주요 ranking 성능 지표에서 전반적으로 우수한 성능을 보였으며, 의료기기 소프트웨어의 실질적인 취약점 대응 우선순위 결정에 효과적으로 활용될 수 있음을 확인했다.

Vulnerabilities in medical device software are directly linked to patient safety, and the increasing complexity of software supply chains has amplified the importance of Software Bill of Materials (SBOM)-based vulnerability management. In particular, the U.S. Food and Drug Administration requires SBOM submission and systematic vulnerability management as part of the medical device approval process. However, existing approaches primarily rely on static risk assessment based on the Common Vulnerability Scoring System or vulnerability identification using Software Composition Analysis(SCA), which fail to sufficiently capture dependency relationships among software components and real-world exploitability. To address this limitation, this paper proposes a method for component-level vulnerability risk assessment by constructing a heterogeneous graph from SBOM data and applying Graph Neural Networks(GNNs). The proposed approach integrates CVSS scores, the Known Exploited Vulnerabilities Catalog, and dependency structures to compute risk scores and automatically prioritize patches. Experimental results show that the proposed model outperforms conventional static approaches across key ranking metrics, demonstrating its effectiveness for practical vulnerability prioritization in medical device software.

2

4,900원

현재 오픈소스 라이브러리를 사용한 SW 증가에 따른 소프트웨어 공급망에 대한 보안이 요구 되는 실정이다. 소프트웨어 공급망 보안의 해결책으로 SBOM을 요구하는 정책 및 지침이 제시되 고 있다. 소프트웨어에 대한 모든 정보들이 담겨있는 소프트웨어 자재명세서인 SBOM은 소프트 웨어 구성요소에 대한 가시성을 제공하고 소프트웨어의 취약성 및 위험을 이해하기 위한 기반으 로 사용되고 있다. 하지만, SW 개발사에서 제공하는 SBOM이 SW 사용자에게 제공되는 SBOM 과 동일한 문서인지 알 수 없기 때문에 SBOM에 대한 무결성을 검증하기에 부족함이 있다. 본 논문에서는 블록체인의 특성인 무결성을 SBOM에 적용하기 위해 암호화폐의 거래내역만 저장할 수 있는 일반 블록체인이 아닌 데이터 저장이 가능한 스마트컨트랙트 블록체인을 활용한다. SBOM 제공으로 SW 및 소프트웨어 공급망의 가시성이 확보되며, SBOM에 대한 무결성 확보를 통해 SW에 대한 사용자의 신뢰가 향상될 수 있다.

Currently, security for the software supply chain is required due to the increase in software using open source libraries. Policies and guidelines that require SBOM as a solution to software supply chain security are being presented. SBOM, which is a software bill of materials containing all information about software, provides visibility into software components and is used as a basis for understanding software vulnerabilities and risks. However, since it is not known whether the SBOM provided by the SW developer is the same document as the SBOM provided to the SW user, there is a shortage in verifying the integrity of the SBOM. In this paper, in order to apply integrity, a characteristic of blockchain, to SBOM, we use a smart contract blockchain that can store data, rather than a general blockchain that can only store cryptocurrency transaction history. Visibility of SW and software supply chain is secured by providing SBOM, and user's trust in SW can be improved by securing the integrity of SBOM.

3

4,300원

공급망 공격은 주요기반시설을 타겟하여 피해 규모가 크고 공공 안전 및 국가안보를 위협하는 요소로 진화하고 있다. 이에 사이버안보 전략 및 정책 수립 시 공급망 위험관리를 명시하여 보안성을 제고하고 있으며, 2021년 美 바이 든 행정부가 발표한 국가 사이버안보 강화를 위한 행정명령에서는 소프트웨어 공급망 보안 강화를 위한 지침 중 일부로 SBOM을 언급하였다. 정부 차원에서 SBOM을 의무화하여 공급망 보안 검증 도구로 활용한다면, 향후 국내 조달체계에 도 영향을 받을 수 있으며 정책 시행 경과에 따라 국내 공급망 보안 체계 수립 시에도 참고 가능할 것으로 보인다. 이에 따라 본 논문에서는 소프트웨어 공급망 보안 강화 방안으로써 SBOM 정책을 추진 중인 국가를 선정하여 관련 사례를 중점으로 분석하였다. 또한, 국외 SBOM 정책 동향의 비교·분석을 통하여 국내 SBOM 도입 시 기술, 정책, 법률 측면에서의 활용 방안을 고찰하였다. 향후 공급망 무결성·투명성 검증 도구로 SBOM의 활용 가치가 기대되는바 SBOM 에 대한 국제적 표준화 정립 및 정책 개발에 관한 지속적인 동향 파악과 표준 형식 개발 연구가 요구된다.

Supply chain attacks target critical infrastructure, causing large amounts of damage and evolving into a threat to public safety and national security. Accordingly, when establishing cybersecurity strategies and policies, supply chain risk management is specified to enhance security, and the US Biden administration recently issued the Executive Order on Improving the Nation’s Cybersecurity, SBOM was mentioned as part of the guidelines for strengthening software supply chain security. If the government mandates SBOM and uses it as a security verification tool for supply chains, it can be affected by the domestic procurement system in the future and can be referenced when establishing a security system for domestic supply chains according to the progress of policy implementation. Accordingly, in this paper, countries that are promoting the SBOM policy as a way to strengthen the security of the software supply chain were selected and analyzed with a focus on related cases. In addition, through comparison and analysis of foreign SBOM policy trends, methods for using domestic SBOM in terms of technology, policy, and law were considered. As the value of using SBOM as a supply chain integrity/transparency verification tool is expected in the future, it is necessary to continuously identify trends in the establishment of international standardization and policy development for SBOM and study the standard format.

4

4,300원

전 세계적으로 증가하는 소프트웨어 공급망 공격은 새로운 사이버 안보 위협으로 부상하고 있으며, 이에 미국 행정명령, 유 럽 CRA 등 주요국의 정책이 빠르게 구체화되고 있다. 본 연구는 이러한 상황에 대응하여 2018년부터 2024년까지의 소프트웨 어 공급망 보안 관련 학술 논문 432편에 LDA 토픽 모델링을 적용하여 핵심 학술 연구 동향을 추출했다. 분석 결과, (1) SBOM 구조화 및 취약점 분석, (2) 오픈소스 기반 개발 프로세스, (3) 펌웨어 및 빌드 취약점, (4) 공격 표면 및 종속성 분석, (5) 정책 및 거버넌스, (6) 악성 패키지 탐지, (7) DevSecOps 워크플로우 보안 등 7개의 핵심 연구 주제가 도출되었다. 나아가, 본 연구는 도출된 학술 연구 동향과 주요 정책의 요구사항을 비교하여, 현재 학술 연구의 초점과 정책의 궁극적 목표 간에 존 재하는 간극을 조명하고, 이를 해소하기 위한 네 가지 기회 영역(증명 가능한 보안, 설계 기반 보안, 지능형 보안 자동화, 상호 운용성)을 제시한다. 본 연구는 분석된 격차를 바탕으로 향후 학계가 나아가야 할 구체적인 연구 방향을 제안함으로써, 실효성 있는 공급망 보안 정책 수립의 기초 자료로 활용될 수 있다.

The growing frequency of software supply chain attacks has become a major cybersecurity concern, prompting key policy responses such as the U.S. Executive Orders and the EU’s Cyber Resilience Act. In response, this study collected 432 academic papers published between 2018 and 2024 and applied LDA topic modeling to identify key academic research trends. The analysis extracted seven core research topics: (1) SBOM structuring and vulnerability analysis, (2) open-source based development processes, (3) firmware and build vulnerabilities, (4) attack surface and dependency analysis, (5) policy and governance, (6) malicious package detection, and (7) DevSecOps workflow security. Furthermore, by comparing these academic research trends with major policy requirements, this study highlights the gap between the focus of current academic research and ultimate policy goals, proposing four key opportunity areas to address it: establishing verifiable security frameworks, applying the Secure-by-Design principle, ensuring intelligent security automation, and achieving policy interoperability. Based on this analysis, this study suggests concrete future research directions for the academic community, providing foundational data for the development of effective supply chain security strategies.

5

블록체인 활용 연구사례 분석을 통한 소프트웨어 공급망 보안 강화 방안 연구 KCI 등재

김정우, 국경완, 류연승

한국융합보안학회 융합보안논문지 제24권 제5호 2024.12 pp.55-61

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

4차 산업혁명과 더불어 블록체인(BlockChain) 기술이 눈부시게 발전했으며, 대규모 컨소시엄이 지원하는 블록체인 개발 프 레임워크를 통해 빠르게 대중화되었다. 최근에는 국내에서도 다양한 분야의 블록체인 응용사례가 등장하고 있다. 한편 Log4j 사건, 솔라윈즈 사태 등 사전탐지가 어렵고 한 번의 공격으로 광범위한 피해를 일으키는 소프트웨어 공급망 공격이 감행되면 서 소프트웨어 공급망 보안에 대한 중요성이 대두되고 있다. 국내·외에서 SBOM(Software Bill of Materials) 기반의 공급망 보안체계를 수립하고 있으나, SBOM 유통 측면에서 보완이 필요한 점을 발견했다. 본 논문에서 블록체인 활용 연구사례를 바 탕으로 블록체인 기반의 안전한 SBOM 유통체계 아키텍처를 설계하고자 한다.

With the Fourth Industrial Revolution, blockchain technology developed remarkably, and was quickly popularized throug h a blockchain development framework supported by large-scale consortiums. Recently, blockchain application cases in var ious fields are also appearing in Korea. Meanwhile, the importance of software supply chain security is emerging as softw are supply chain attacks that are difficult to detect in advance such as the Log4j incident and the SolarWinds incident and cause widespread damage in one attack are carried out. Although SBOM(Software Bill of Materials)-based supply chain s ecurity systems are being established at home and abroad, we have found that they need to be supplemented in terms of SBOM distribution. In this paper, we intend to design a secure SBOM distribution system architecture based on blockchai n utilization research cases.

7

ICT의 발달과 함께 기업에서는 정보교환 또는 운영관리를 위해 소프트웨어를 필수적으로 사용하게 되었다. 그 러나 ICT의 발달과 함께 증가한 보안 및 소프트웨어 관리이슈는 지속해서 해결해나가야 할 문제이다. 2021년 미국에 서는 이러한 소프트웨어 보안 대응책 중 하나로 SBOM을 정부주도하에 표준화 및 제도를 수립하였다. 본 연구는 이 러한 SBOM이 국내에 도입되기 위한 초석을 마련하는 연구로서 시작되었다. SBOM의 대표적인 특징들이 도입 의도 에 미치는 영향을 바탕으로 경영층 지원과 제도적 지원을 조절 변수로 검증하였다. 그 결과, 경영층 지원으로는 보안 관리가 유의미한 조절 변수로 나타났으며, 정부의 제도적 지원에서는 투명성이 유의미한 조절 변수로 나타났다. SBOM을 도입하기 위해서는 기업과 정부의 노력이 함께 이루어져야 하는데, 각 관점에서 중요하게 여기는 변수가 다르다는 것을 검증한 것이다. 본 연구가 SBOM의 발전과 도입에 기여하길 바라는 바이다.

With the development of ICT, the use of software has become essential for organizations to exchange information or manage operations. However, security and software management issues that have increased with the development of ICT are issues that need to be continuously addressed. In 2021, the U.S. government has standardized and established SBOM as one of the countermeasures for software security. This research was initiated as a study to lay the groundwork for the introduction of SBOM in Korea. Based on the effects of SBOM characteristics on adoption intention, we tested management support and institutional support as moderating variables. As a result, security management was found to be a significant moderating variable for management support, and transparency was found to be a significant moderating variable for government institutional support. This study verified that SBOM adoption requires both corporate and government efforts, and the variables that are important from each perspective are different. We hope that this study will contribute to the development and adoption of SBOM.

8

기술의 발전은 기업 간 손쉬운 정보공유 및 협업을 가능하게 하였다. 그러나 여러 주체가 정보를 공유하며 접 속하는 협업을 위한 시스템은 보안에 취약할 수밖에 없다. SBOM은 소프트웨어 프로그램의 구성요소를 파악하고 투 명하게 관리하여 정보보안을 강화하는 방안으로 소프트웨어 자재명세서(Software Bill Of Materials, SBOM)라는 개 념으로 등장하였다. 본 연구는 이러한 SBOM의 국내 도입을 촉진하고자 협업시스템 담당자들을 대상으로 도입 의도 를 연구하였다. 본 연구는 계획된 행동이론과 통합기술수용이론을 기반으로 하였다. 본 연구 결과, SBOM 도입으로 인한 성과기대가 도입 의도에 미치는 중요한 변수였으며, 보안에 대한 긍정적인 태도 또한 성과기대를 매개하여 간접 효과를 나타내는 것으로 확인하였다. SBOM의 도입이 기업을 대상으로 한다는 특성상 성과와 중요한 인과관계가 있 으며, 보안에 대한 긍정적인 태도나 사회적 분위기로 도입 의도에 강한 영향을 줄 수 있다는 것을 확인하였다.

Advances in technology have made it easier for organizations to share information and collaborate. However, collaboration systems where multiple entities share and access information are vulnerable to security. The concept of Software Bill Of Materials (SBOM) has emerged as a way to strengthen information security by identifying and transparently managing the components of software programs. To promote the adoption of SBOM in Korea, this study investigated the intention to use of collaboration system managers. This study was based on the theory of planned behavior and the integrated technology acceptance theory. The results of this study confirmed that performance expectations from SBOM adoption were an important variable for intention to use, and positive attitudes toward security also had an indirect effect through performance expectations. We found that SBOM adoption has an important causal relationship with performance due to the fact that it is targeted at enterprises, and that positive attitudes toward security and social climate can have a strong effect on intention to use.

9

SBOM 및 보안 데이터 연계를 활용한 의료기기 보안 사전검증 시뮬레이터 설계 및 구현

우정현, 고광만

[Kisti 연계] 한국정보처리학회 정보처리학회논문지 Vol.14 No.11 2025 pp.871-879

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문은 SBOM(Software Bill of Materials)과 실존 취약점 정보를 연계하여 의료기기 소프트웨어의 보안성을 사전에 점검할 수 있는 시뮬레이터 시스템의 설계 및 구현 방안을 제안한다. 제안된 시스템은 사용자가 등록한 소프트웨어 자산을 기반으로 SBOM을 생성하고, 이를 CVE, CWE, NVD, GitHub Advisory 등과 같은 공개 취약점 데이터와 연계하여 보안 취약점을 자동으로 식별한다. 이후 CWE 유형을 기반으로 위협 시나리오를 도출하고, CVSS 점수를 활용한 정량적 위험도 평가를 수행한다. 평가 결과는 보안 요구사항 체크리스트와 연결되어 시각화되며 최종 리포트로 출력된다. 이를 통해 의료기기 개발자는 제품 설계 단계에서 구조화된 보안 검토를 사전에 수행할 수 있으며, 인허가 문서 작성에도 활용 가능하다. 본 연구는 실존 취약점 기반의 자동 분석 흐름을 구조화함으로써, 의료기기 보안성 내재화를 실질적으로 지원하는 평가 도구의 가능성을 설계하였다.

This paper proposes the design and implementation of a simulator system that enables pre-verification of medical device software security by integrating SBOM (Software Bill of Materials) with real-world vulnerability data. The proposed system generates an SBOM from user-registered software assets and automatically identifies vulnerabilities by linking with public sources such as CVE, CWE, NVD, and GitHub Advisory databases. It then derives threat scenarios based on CWE types and performs quantitative risk assessment using CVSS scores. The results are connected to a security checklist, visualized, and exported as a final report. This approach allows medical device developers to conduct structured security reviews in the early design phase and supports regulatory documentation preparation. The study demonstrates the potential of an automated analysis framework based on actual vulnerabilities to support embedded cybersecurity in medical devices.

10

런타임 타입 SBOM을 이용한 리눅스 시스템 동적 구성요소 명세 방안 연구

손현승, 김지민, 이만희

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.35 No.3 2025 pp.573-584

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

미국은 행정명령(Executive Order 14028)을 통해 소프트웨어 공급망 보안 강화를 위한 방안으로 소프트웨어가 어떤 컴포넌트를 이용하여 개발되었는지를 나타내는 소프트웨어 구성 명세서인 SBOM(Software Bill of Materials)의 활용을 제시하였다. 미국 CISA(Cybersecurity and Infrastructure Security Agency)와 독일 BSI(Bundesamt für Sicherheit in der Informationstechnik) 등 주요 기관들은 소프트웨어 개발 생명 주기에 따라 SBOM을 여섯 단계로 분류하였다. 이 중 런타임 타입(Runtime-Type) SBOM은 실제 실행 환경에서 작동 중인 소프트웨어의 구성요소를 실시간으로 파악하는 SBOM으로써, 소프트웨어의 실제 사용 단계에서 불법적으로 삽입되는 악성 라이브러리 식별 또는 동적으로 로드된 시스템 라이브러리의 취약점 파악에 매우 유익할 것으로 판단된다. 본 논문은 추상적인 개념 수준으로 제안된 런타임 타입 SBOM을 리눅스 시스템에서 구현하였으며, 이 런타임 타입 SBOM이 소프트웨어 실행 상의 공격을 효과적으로 탐지할 수 있음을 보였다.

The United States, through Executive Order 14028, has proposed the use of the Software Bill of Materials (SBOM) as a means to enhance software supply chain security by specifying the components used in software development. Major organizations such as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Germany's Federal Office for Information Security (BSI) have classified SBOMs into six types based on the software development lifecycle. Among them, the Runtime-Type SBOM identifies the components of software actively in the execution environment in real-time. This SBOM is particularly useful in detecting malicious libraries that are illegally injected into software during execution and in identifying vulnerabilities in dynamically loaded system libraries. This paper presents the first implementation of a Runtime-Type SBOM, which was proposed at an abstract conceptual level, on a Linux system, demonstrating its effectiveness in detecting attacks on running software.

11

가동 중 원자력시설의 SBOM(Software Bill Of Materials)구현방안 연구

김도연, 윤성수, 엄익채

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.34 No.2 2024 pp.229-244

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 APR1400 노형과 같이 원자력발전소의 디지털 기술 적용에 따라 "이블 PLC"같은 원자력시설 대상의 공급망 공격이 증가하는 추세이다. 원자력 공급망 보안에 있어 산업 특성상 수많은 공급업체가 존재하기에 이를 체계적으로 관리할 수 있는 자원 관리 시스템이 필요하다. 하지만, 제어시스템 특성상 소프트웨어 자산의 긴 생명 주기로 인해 속성 정보가 일관되지 않게 관리된다는 문제점이 존재한다. 또한, 운영 환경의 가용성 문제로 인해 형상 관리 자동화 도입이 미흡한 상태에서 입력 오류와 같은 한계점이 존재한다. 본 연구에서는 SBOM(Software Bill Of Materials)을 적용한 체계적인 자산 관리 방안 및 자연어처리 기법을 적용한 입력 오류에 관한 개선 방안을 제안한다.

Recently, supply chain attacks against nuclear facilities such as "Evil PLC" are increasing due to the application of digital technology in nuclear power plants such as the APR1400 reactor. Nuclear supply chain security requires a asset management system that can systematically manage a large number of providers due to the nature of the industry. However, due to the nature of the control system, there is a problem of inconsistent management of attribute information due to the long lifecycle of software assets. In addition, due to the availability of the operational technology, the introduction of automated configuration management is insufficient, and limitations such as input errors exist. This study proposes a systematic asset management system using SBOM(Software Bill Of Materials) and an improvement for input errors using natural language processing techniques.

12

SW공급망 관리 및 SBOM 동향

류원옥, 박수명, 이승윤

[Kisti 연계] 한국전자통신연구원 전자통신동향분석 Vol.38 No.4 2023 pp.81-94

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The increased adoption of open source security management in supply chains is gaining worldwide attention. In particular, as security and threatening situations, such as solar winds, Kaseya ransomware, and Log4j vulnerability, are becoming more common in supply chains using software (SW)-defined networks, SW bills of materials (SBOMs) for SW products should be prepared to protect major countries like the United States. An SBOM provides SW component information and is expected to become required for SW supply chain management. We focus on SW supply chain management policies and SBOM trends in major countries and private organizations worldwide for safe SW use and determine the current status of Korea and ETRI's open source SW supply chain management trends.

13

소프트웨어 공급망 보안 체계 구축을 위한 SBOM의 역할과 과제

오진혁, 손성원, 김민서, 황진석

[NRF 연계] 한국IT정책경영학회 한국IT정책경영학회 논문지 Vol.17 No.4 2025.12 pp.4101-4107

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 오픈소스와 외부 라이브러리에 대한 의존도가 확대되면서, 이를 활용한 소프트웨어 공급망 공격이 증가하고 있다. 이러한 위협에 대응하고자 국제적으로 소프트웨어 자재명세서(SBOM)의 도입이 강조되고 있다. SBOM은 소프트웨어를 구성하는 컴포넌트를 체계적으로 관리하여 취약점 도출 시 신속한 추적과 대응이 가능하게 하며, 글로벌 규제 준수와 표준화에 부합하여 국가와 기업 차원에서 신뢰성을 확보하는 핵심 도구이다.

The increasing dependence on open-source and third-party libraries has heightened the risk of software supply chain attacks that exploit these components. To mitigate such threats, the global adoption of the Software Bill of Materials (SBOM) has been underscored as a crucial measure. An SBOM provides a structured framework for documenting and managing software components, thereby facilitating prompt traceability and effective remediation when vulnerabilities are detected. Moreover, it ensures consistency with international regulatory compliance and standardization initiatives, positioning SBOM as an essential mechanism for reinforcing security, transparency, and trustworthiness at both national and organizational levels.

14

공개 펌웨어 수집 및 펌웨어 바이너리 SBOM 생성 기법 연구

이인혁, 정수은, 박정흠

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.34 No.6 2024 pp.1307-1319

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사물인터넷(Internet of Things, IoT) 기기의 보급이 확산함에 따라 보안 위협 또한 증가하고 있다. IP 카메라 해킹과 같은 사례는 IoT 기기 보안의 중요성을 강조한다. 이러한 보안 문제를 해결하기 위해서는 분석가에게 펌웨어 버전 기반으로 구성 요소의 특성을 정리하고, 버전 간의 차이를 식별하여 잠재적인 취약성을 분석할 수 있는 정보를 제공하는 것이 필수적이다. 본 논문에서는 IoT 기기에 사용되는 13,880개의 공개 펌웨어를 수집하고, 이를 대상으로 펌웨어 내 바이너리의 관계를 고려한 'BOM(Bill of Materials)'을 생성하는 방법론을 제안한다. 제안된 방법론을 기반으로 자동화된 펌웨어 정보 추출 도구인 'FIRE(Firmware InfoRmation Extractor)'를 개발하였으며, 이는 기존의 'SBOM(Software Bill of Materials)' 개념을 확장하여 펌웨어에 특화된 BOM 정보를 생성한다. 구축된 펌웨어 데이터세트와 제안된 방법론을 통해 공개된 펌웨어의 구성 요소를 검증하고 추가 분석에 필요한 정보를 제공하여 기존보다 안전한 IoT 기기 생산에 기여될 것으로 기대한다.

The rapid proliferation of Internet of Things (IoT) devices has been accompanied by a corresponding rise in security threats. High-profile incidents, such as IP camera hacking, underscore the critical importance of ensuring IoT device security. Addressing these challenges necessitates providing analysts with comprehensive insights to characterize firmware components by version, identify inter-version differences, and assess potential vulnerabilities. This study introduces a novel methodology for generating a Bill of Materials (BOM) that considers the relationships between binaries within firmware. To support this approach, a dataset comprising 13,880 publicly available firmware samples for IoT devices was collected and analyzed. Furthermore, an automated firmware information extraction tool, FIRE (Firmware InfoRmation Extractor), was developed based on the proposed methodology. FIRE extends the concept of the Software Bill of Materials (SBOM) to generate BOMs tailored specifically for firmware. The constructed firmware dataset and the proposed methodology enable the verification of firmware components and provide actionable insights for subsequent analysis, ultimately contributing to the development of more secure IoT devices.

15

거대언어모델 기반 구조 분석 및 위조 탐지 에이전트를 활용한 소프트웨어 자재 명세서(SBOM) 변경 이력 자동 분석 기법

이재승, 유제혁

[Kisti 연계] 한국산업정보학회 한국산업정보학회논문지 Vol.30 No.4 2025 pp.39-60

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

소프트웨어 공급망 보안의 중요성이 증가함에 따라, 소프트웨어 자재 명세서(Software Bill of Materials, SBOM)의 신뢰성과 일관성을 확보하는 것이 핵심 과제로 대두되고 있다. 본 연구는 동일 프로젝트의 다양한 버전에서 생성된 SBOM 문서 간 유사도 분석을 통해 위조 가능성을 탐지하고, 변경 이력을 자동으로 분석하는 기법을 제안한다. 이를 위해 공개 SBOM 데이터셋에 대해, 사전 학습된 언어 모델을 이용하여 각 문서를 임베딩한 후 코사인 유사도 기반으로 비교하였다. 이후 OpenAI GPT-4o를 활용한 거대언어모델 기반 에이전트를 통해 실제 변경된 구성 요소를 식별하고, 사용자가 이해할 수 있는 설명 보고서를 생성하였다. 실험 결과, 본 기법은 기존의 단순 비교 방식에 비해 위조 탐지 정확도와 변경 이력 해석 측면에서 우수한 성능을 보였다. 본 연구는 SBOM 기반 보안 검사를 자동화하고, 신뢰 가능한 변경 이력 관리 도구 개발의 초석을 마련하는 데 기여할 수 있을 것으로 기대된다.

As the importance of software supply chain security continues to grow, ensuring the reliability and consistency of Software Bills of Materials (SBOM) has emerged as a critical challenge. In this study, we propose an automated method to detect potential forgeries and analyze component-level modifications by analyzing the semantic similarity between SBOM documents generated from different versions of the same software project. Using a publicly available SBOM dataset, each document is embedded with a pre-trained language model and compared using cosine similarity. Subsequently, structural differences are identified through dedicated large language model (LLM)-based agents, implemented via OpenAI GPT-4o, which generate human-readable explanation reports that highlight suspicious changes. Experimental results demonstrate that the proposed method outperforms traditional comparison techniques in both forgery detection accuracy and interpretability of change history. This research contributes to the automation of SBOM-based security auditing and provides a foundational approach for the development of trustworthy change tracking tools in the software supply chain domain.

16

CycloneDX-SPDX 상호 변환 손실률 정량 분석과 중소기업 환경을 위한 경량 SBOM 필드 도출

이현정

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.2 2026 pp.533-537

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

소프트웨어 공급망 공격이 고도화·상시화됨에 따라, 소프트웨어 구성요소의 투명성 확보를 위한 SBOM (Software Bill of Materials)의 필요성이 증가하고 있다. 그러나 산업 현장에서의 도입은 제한적이며, 특히 중소기업 환경에서는 SBOM의 생성·유지·활용이 추가적인 업무 부담으로 작용해 도입 장벽이 높다. 또한 대표적인 SBOM 표준인 CycloneDX와 SPDX는 데이터 모델과 필드 구조가 상이하여 상호 운용성이 낮고, 형식 변환 시 정보 손실이 발생할 가능성이 크다. 본 연구는 CycloneDX 및 SPDX 형식의 실제 SBOM 문서 200건을 분석하고, Python 기반 양방향 변환기를 구현한 뒤, 변환 과정에서의 손실을 필드 손실률(FLR)과 정보 손실률(ILR)로 정량 평가한다. 실험 결과 방향 A(CycloneDX→SPDX)에서 FLR 11.3%, ILR 37.2%, 방향 B(SPDX→CycloneDX)에서 FLR 18.2%, ILR 64.6%의 비대칭 손실이 확인되었다. 또한 CISA의 '2025 SBOM Minimum Elements'를 반영하여 중소기업이 초기 단계에서 부담 없이 도입할 수 있는 경량 SBOM 핵심 필드 11개와 선정 기준을 제안한다.

With the escalation of software supply chain attacks, SBOM has gained recognition as a practical mechanism for improving component transparency. However, adoption remains limited, particularly among SMEs. This paper implements a bidirectional Python-based conversion between CycloneDX and SPDX, and quantitatively evaluates conversion loss using field loss rate(FLR) and information loss rate(ILR) across 200 real-world SBOM documents. Results show asymmetric losses: direction A(CycloneDX→SPDX) yields FLR 11.3%, ILR 37.2%; direction B(SPDX→CycloneDX) yields FLR 18.2%, ILR 64.6%. Based on these findings and CISA's 2025 Minimum Elements, we derive an 11-field lightweight SBOM suitable for SME adoption.

17

NIS SBOM 속성의 CycloneDX 및 SPDX 구현

김지민, 조은정, 이만희

[Kisti 연계] 한국정보보호학회 정보보호학회지 Vol.35 No.1 2025 pp.25-32

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

미국, 유럽 등 주요국은 소프트웨어에 포함된 보안취약점을 추적·관리하기 위해 정부·공공기관에 도입되는 소프트웨어를 대상으로 SBOM(Software Bill of Materials) 제출을 의무화하는 등 공급망 보안을 강화하고 있다. 이에 국가정보원은 SW 공급망보안 가이드라인을 통해 SBOM 기본항목(NIS-SBOM)을 제안하였으며, 이는 기본항목 간소화, 보안 취약점 정보 연동, 사이버 위험 관리 효율성 향상을 주요 목표로 하였다. 본 연구에서는 CycloneDX 및 SPDX의 필드를 통해 NIS-SBOM이 제시한 요건을 표현하고 두 표준의 적합성을 비교 분석하였다. 분석 결과, CycloneDX는 계층적 구조와 명시적 필드 정의를 통해 직관적인 구현이 가능한 반면, SPDX는 평면적 구조를 통해 높은 확장성과 상세한 보안 정보 표현이 가능한 것으로 확인되었다. 이러한 분석 결과는 국내 소프트웨어 공급망보안 강화를 위한 SBOM 표준 선택 및 구현에 있어 실질적인 지침이 될 것으로 기대된다.

18

OSS 추적성을 위한 SBOM 동향

김선우, 손경호

[Kisti 연계] 한국정보보호학회 정보보호학회지 Vol.32 No.5 2022 pp.53-66

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 몇 년 동안 엄청난 양의 데이터 혁신이 진행되어왔고, 그에 따라 소프트웨어 개발의 편리성을 위해 오픈소스를 사용하는 경우가 많아졌다. 이로 인해 소프트웨어 생산성 측면에서는 많은 도움이 되었지만, 보안 관점에서는 많은 문제를 야기했다. 이러한 OSS 사용에 따른 위험을 줄이고자 OSS 추적성을 위한 도구를 사용하는 방법이 지속적으로 개발되었지만, 아직까지도 OSS 사용에 따른 위험은 증가하고 있다. 이에 본 논문은 OSS 추적성의 보완을 위한 SBOM(Software Bill of Materials)의 정의와 현재 국외 SBOM 추진 동향에 대해 소개하고자 한다.

19

공급망 보안을 위한 소프트웨어 명세서(SBOM) 개선 연구

최영재, 양희동, 우승훈

[Kisti 연계] 한국정보보호학회 정보보호학회지 Vol.35 No.1 2025 pp.9-16

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

안전한 소프트웨어 공급망을 형성하기 위해, 소프트웨어 제품에 포함된 구성요소, 라이브러리, 모듈 및 그 버전 정보를 체계적으로 명시하는 소프트웨어 명세서(Software Bill of Materials; SBOM)의 활용이 주목받고 있다. SBOM의 투명성 및 공급망 보안에서의 효율성에도 불구하고, 여전히 여러 한계점과 개선의 여지가 존재한다. 본 고에서는 현재 SBOM의 한계점을 분석하고, 실질적 해결 방안과 연구 동향을 제시한다.

20

미국의 소프트웨어 공급망 보안 정책 동향: SBOM 사례를 중심으로

최윤성

[Kisti 연계] 한국정보보호학회 정보보호학회지 Vol.32 No.5 2022 pp.7-14

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

2021년에 발생한 일련의 소프트웨어 공급망 공격으로 미국 연방 정부의 사이버보안 개선 정책이 가속됐다. 이중 소프트웨어 구성 정보를 유통하는 SBOM 정책은 SW 구성요소의 투명성을 강화하여, 이를 활용하는 공급자와 수요자의 보안 인식 개선에도 도움을 줄 것이 기대된다. 다만 SBOM으로 공급망 보안 위협을 완화하려면 해결해야 할 기술적 이슈가 있고, SBOM 수집자를 위한 구체적인 가이드도 마련되지 않아 제도 정착에는 시간이 걸린다. SW 공급망 문제는 SW 개발 관행에 대한 지속적인 개선이 요구되며, 글로벌 연쇄 위험으로 결코 혼자서는 해결할 수 없다. 따라서 우리는 실태조사, 실증사업 등을 시작으로 현실에 맞는 정책을 먼저 적용하고, 제도적 조화를 위한 국제협력에도 힘써야 한다.

 
1 2
페이지 저장