년 - 년
SIP 이동성 및 세션 설정 형태를 고려한 효과적인 SIP 플러딩 공격 탐지 및 대응 방법 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.11 No.6 2015.12 pp.69-78
SIP(Session Initiation Protocol)는 인터넷 전화 등 많은 응용 서비스의 세션을 관리하는 응용 계층 프로토콜로사용되고 있다. SIP는 다른 프로토콜들처럼 공격에 노출되어 있는데, 플러딩 공격은 가장 위협이 큰 공격이라고 할수 있다. 기존의 방법들은 고정 세션 정보를 사용하여 SIP 플러딩 공격을 탐지하고 대응하고 있다. 그러나 이들 방법들은 다양한 세션 설정 특성을 반영하지 못하여 정상 사용자들로부터의 메시지를 공격으로 간주하여 처리하는 문제가 발생할 수 있다. 본 논문에서는 SIP 이동성과 세션 설정 패턴을 고려한 효과적인 SIP 플러딩 공격 탐지 및 대응 방법을 제안한다. 이를 위하여, 다중 블룸필터를 사용하여 SIP 이동성과 세션 설정 패턴을 판별하는 방법을 제안한다. 이로부터 버퍼 스케줄링을 적용하여 우선순위에 따라 메시지 제어를 통해 플러딩 공격을 차단한다. 실험 결과는 제안 방법이 공격 중에도 정상적인 메시지들에 대하여 서비스가 가능하고, 공격 메시지들도 효과적으로 차단하고제어함을 보여준다.
SIP(Session Initiation Protocol)is an application layer protocol to manage sessions for various application services such as Internet telephony. Similar with other conventional Internet protocols, SIP has been faced with various attacks. Among those attacks, flooding attacks are one of the most dangerous attacks on SIP-based applications. Existing schemes utilized fixed information of sessions, so they have severe problem that they treat normal messages as attack ones. In this paper, we propose a method to detect and countermeasure against SIP flooding attacks by considering SIP mobilities and session establishment patterns. The proposed method adapts multiple Bloom filters to classify the SIP mobilities and session setup patterns. Then, flooding attacks are dropped according to the priority message control by applying the scheduling buffer. The experimental results show that the proposed method can provide effective services for normal messages during attacks, and block and control the attack messages effectively.
사물인터넷 서비스와 연계된 수많은 IoT 단말들과 시스템에 대한 DoS 공격의 위협이 증가하고 있다. 이러한 보안 위협에 대응하여 IoT 센서, 게이트웨이 등 디바이스들, 응용 서비스를 안정적으로 제공하는 IoT 플랫폼들이 개발되 었다. IoT 플랫폼상에서 디바이스들과 시스템 간 세션 관리를 위하여 SIP가 활용될 수 있으나, SIP가 내포한 보안 문제는 또 다른 문제를 일으킬 위험성을 내포하고 있다. 본 논문에서는 개방형 IoT 플랫폼에 SIP를 사용하여 세션 을 관리하는 환경에서, 보안 문제를 해결하기 위한 방법을 제안한다. 제안 방법은 SIP 세션이 유지되는 일정 시간 동안에만 정상 단말의 접속을 허용함으로써 비정상 접속 요청이나 악의적인 트래픽을 차단할 수 있다. 제안 방법을 뫼비우스 IoT 플랫폼상에 구현하여 성능을 검증하였다. 실험 결과는 제안 방법이 SYN Flood 공격 상황에서 효과 적으로 대응하고, 정상 서비스를 제공할 수 있음을 보여준다.
The threats of DoS attacks on numerous IoT devices and systems for IoT services are increasing. To counteract against these security threats, various IoT platforms have been developed to provide the secure operations for IoT components such as sensors, gateways, servers and application services. SIP can be utilized to manage sessions between devices, systems, and services on IoT platforms. However, the security issues that SIP has arise another security problem. This paper proposes a method to overcome the security problem when SIP is utilized for IoT session managements on IoT platforms. The proposed method can block abnormal access requests or malicious traffic by allowing only traffic from terminals managed by the SIP only during its session period. The proposed method is implemented, and its performances are tested on the Mobius IoT platform. Experimental results show that the proposed method can effectively countermeasure against SYN Flood attacks and protect normal services.
SIP기반 임베디드 IoT 안전관리 시스템 설계 KCI 등재
한국융합학회 한국융합학회논문지 제9권 제10호 2018.10 pp.69-74
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
국내, 외에서 개발된 IP, SIP 전관방송 시스템들은 윈도우나 리눅스 서버 환경에서 개발되어 서버-랙에 장착되어 운용되는 구조이며, 소비전력이 많고, 시스템 장애 시 원격 대응에 어려움이 있다. 따라서 본 논문에서는 전광방송을 위해 사물인터넷 서비스 구조를 이용하여 IoT 디바이스와 IoT 게이트웨이를 IoT 서비스 서버에 연결하는 IoT 플랫폼을 구성 하고, 이 구조를 이용하여 호 처리 및 방송 기능을 내장하며 공공장소의 비상통화 및 비상방송을 처리할 수 있는 임베디드 OS 기반의 안전관리 시스템 서버를 설계 했다. 본 서버는 표준 SIP를 지원하는 다양한 SIP기반 통화 및 방송장치와 상호 호환되어 구내전화 및 구내방송시스템과 통합구축이 가능하다.
IP and SIP public broadcasting systems developed in Korea and abroad are developed in a Windows or Linux server environments and are installed in a server-rack structure, have high power consumption, and are difficult to remotely respond to system failures. In this paper, IoT platform is designed to connect IoT device and gateway to IoT service server by using internet service structure. We also designed a server based on embedded OS that can provide a variety of public safety management services according to the order of the server with built-in call processing and broadcasting function that can handle emergency calls and emergency broadcasts in public places using this structure. This server is interoperable with a variety of SIP-based call and broadcast devices that support the standard SIP and can be integrated with an in-house phone and on-premises system
모비우스 IoT 플랫폼에서 게이트웨이와 서버간 SIP 기반 세션 관리 구조 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.13 No.4 2017.08 pp.90-99
oneM2M 표준을 기반으로 개발된 모비우스 IoT 서버 플랫폼의 서비스 구조는 서버와 IoT 게이트웨이가 서로 직접적으로 연결되어 HTTP 혹은 MQTT 프로토콜을 사용하여 데이터를 교환한다. 이러한 구조는 IoT 서비스의 안정적 운용에 지장을 초래할 수 있다. 본 논문에서는 SIP를 사용하여 서버와 게이트웨이 (또는 장치)들 간에 세션을안전하고 안정적으로 관리하여 주기위한 방안을 제시한다. 또한, 모비우스 IoT 플랫폼상에서 제안한 방법을 구현하기 위한 방안을 제시한다. 제안방법의 동작확인을 위하여 제안 방법을 모비우스 IoT 플랫폼상에 구현하여, 전형적인 IoT 응용서비스 환경에 SIP 서버를 연계한 테스트베드를 구현한다. 실험결과는 제안방법이 정상적으로 수행됨을 확인할 수 있고, 제안방법이 IoT 서비스의 안정적 운용에 기여할 수 있음을 보여준다.
The service structure of the Mobius IoT platform, which has been developed on the basis of the oneM2M standard, connects servers and gateways directly to exchange data using HTTP or MQTT. Such structure may cause problems not to operate IoT services safely. In this paper, we propose an effective structure to manage sessions between gateways (or devices) and server using SIP safely and stably. In addition, we provide the way to implement the proposed method on Mobius IoT platform. To verify the operation of the proposed method, we actually implement the proposed method on Mobius IoT platform, and construct a testbed for a typical IoT application service environment with SIP servers. The results of the experiment show that the proposed method works normally, and it can contribute to the stable operation of IoT services.
한국ITS학회 한국ITS학회 학술대회 2007년 한국ITS학회 추계학술대회 및 정기총회 2007.10 pp.219-224
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷 망의 고속화와 무선 인터넷의 발달로 다양한 인터넷 서비스가 지원되고 있다. 한 예로 DMB, VOD 서비스 등은 대표적인 서비스로 자리 매김을 하고 있다. 하지만 이 서비스들을 무선 인터넷에 접목시킴으로서 이동성 지원에 따른 문제가 대두되고 있다. 이로 인하여 IETF (Internet Engineering Task Force)에서 이동성을 지원하는 Mobile IP를 제시하였지만 삼각라우팅 문제로 인하여 데이터 전송 지연이 발생하게 되었고, 실시간 서비스와 데이터 손실이 많은 응용프로그램에서는 빠른 핸드오버를 제공하지 못하는 문제가 발생하게 되었다. 따라서 본 논문에서는 SIP를 접목하여 효율적인 이동성을 지원하면서, SIP의 Redirect 기능을 이용하여 삼각 라우팅 문제를 해결하였으며, 본 논문의 결과를 이동성 DMB 서비스, 이동성 VOD 서비스에 접목시키면 효율적인 이동성 서비스에 큰 기여를 할 것으로 보인다.
재전송 메커니즘에 의한 SIP 등록 취소 및 통화 방해 공격 대응 방안 KCI 등재후보
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.4 No.3 2008.09 pp.15-23
SIP는 상호 간의 멀티미디어 통신 세션을 관리하는 응용 계층 시그널링 프로토콜이다. 현재 SIP는 프로토콜의 간편성, 유연성, 다양성 등의 장점을 가지고 인터넷 메신저, 게임, VoIP(Voice over IP)등에 널리 이용되고 있다. 그러나 SIP는 여러 보안상의 문제점들을 가지고 있고, 특히 통화 방해 공격은 사용자들에게 큰 불편을 줄 수 있는 공격으로 이에 대한 대응 방법이 요구된다. 따라서 본 논문에서는 SIP 등록 취소 공격 및 통화 방해 공격에 대해서 분석해보고 이를 탐지 하는 기법을 제안한다. 공격 탐지는 재전송 메커니즘을 기반으로 공격으로 의심되는 메시지와 사용자가 마지막으로 전송한 메시지의 비교를 통해서 이루어진다. 만약 메시지가 공격으로 판단될 경우 사용자에게 이를 알리고 재인증 과정을 거친다.
SIP is an application-level signaling protocol that manages a mutual multimedia communication session. Presently, SIP is widely used with internet messaging, games and with VoIP (Voice over IP) due to advantages such as its simplicity, flexibility and variety of protocols. However, SIP is associated with many types of security issues and requires a countermeasure device against call-disturbance attacks that can cause a great amount of inconvenience to users. Therefore, this study analyses SIP De-registration and call-disruption attacks and proposes a means of detecting these attacks. Attack detection is accomplished through a comparison of the messages last sent by the user and those that are considered to be an attack based on a Retransmission mechanism. When a message is detected as an attack, the user is informed and a Reauthentication process is performed.
이동통신망에서 SIP를 이용한 효율적인 이동성 지원방안
한국ITS학회 한국ITS학회 학술대회 2006년 한국ITS학회 추계학술대회 및 정기총회 2006.10 pp.195-198
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
이중주파수 GPS 및 DR을 지원하는 고성능 측위 SIP 설계
한국ITS학회 한국ITS학회 학술대회 2005년 한국ITS학회 추계학술대회 및 정기총회 2005.11 pp.79-82
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
카운팅 블룸 필터를 사용한 화이트리스트 사용자에의한 SIP DDoS 공격 탐지 및 대응 기법 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.11 No.5 2015.10 pp.25-35
SIP(Session Initiation Protocol)는 멀티미디어 세션을 관리하는 응용계층 프로토콜로서, 인터넷 전화 등 많은응용서비스에서 활용되고 있다. SIP 대상 공격들 중 플러딩 공격은 가장 위협이 큰 공격이라고 할 수 있다. 이를해결하기 위하여 제안된 화이트리스트 기반의 탐지 및 대응 방법들은 화이트리스트에 없는 비정상 사용자로 부터의공격을 탐지하고 차단하는 것이 가능하지만, 정상 사용자로 위장하여 화이트리스트에 등록한 후에 플러딩 공격할 시에는 대응할 수 없다. 본 논문에서는 화이트리스트에 속한 사용자들로부터 발생되는 메시지를 대상으로 카운팅 블룸필터를 적용하여 정상 사용자에 의한 악의적인 플러딩 공격을 탐지하고, 이에 대응하는 방법을 제안한다. 실험 결과는 기존 방법에서는 화이트리스트에 속한 사용자로 부터의 공격을 탐지하지 못하나, 제안방법은 이를 효과적으로 탐지하고 대응함을 보여준다.
SIP(Session Initiation Protocol) is an application layer protocol to manage multimedia sessions, and has been utilized for various application services such as Internet telephony. Flooding attacks are one of the most dangerous attacks on SIP-based applications. To solve the problem, the whitelist-based schemes can detect and countermeasure against attacks from abnormal users. However, they can’t react against attacks by legitimate users who have been registered in the whitelist. In this paper, we propose a method to detect and countermeasure flooding attacks from legitimate users listed in the whitelist by applying counting Bloom filters to messages from them. Experimental results show that existing whitelist-based schemes can’t detect flooding attacks from users listed in the whitelist, while the proposed method can detect and countermeasure against those attacks very effectively.
시멘틱 정보처리를 위한 Zero-shot Learning 기반 데이터셋 수집 프레임워크
한국ITS학회 한국ITS학회 학술대회 대한민국 ITS 30년 2023.11 pp.249-251
※ 기관로그인 시 무료 이용이 가능합니다.
3,000원
IP PBX기반 안전관리 IoT 방송 시스템 구현 KCI 등재
한국융합학회 한국융합학회논문지 제10권 제8호 2019.08 pp.9-14
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
현재, 5G 상용화 성공에 따라 IoT 기술이 고도화 되고 있어 다양한 사물인터넷 공공 안전 서비스를 통합한 서버 시스템이 개발되어야 한다. 본 논문에서는 IP PBX를 기반으로 IoT 디바이스와 게이트웨이를 연결하는 IoT 플랫 폼인 공공 안전 통합서버를 구현하였다. 본 서버는 임베디드 OS 기반으로 다양한 IoT 서비스가 하나의 시스템에서 수 행되고 공공장소의 비상통화 및 방송을 처리하는 호 처리/방송서버 기능을 내장하고 있고, IoT센서 데이터와 비상벨 정보를 수집하여 응급 상황 시 사고현장에서 비상알람과 대피방송 등을 자동송출 하며, 일상적인 정보는 상위의 IoT 서비스 서버에 전달하여 IoT서비스 서버의 명령에 따라 공공안전관리 서비스를 제공하여 국가 사회의 안전망 서비스를 편리하고 저렴하게 제공할 수 있다.
Currently, with the success of 5G commercialization, a server system that integrates various Internet public safety services should be developed. In this paper, we developed a public safety integrated server, which is an IoT platform connecting IoT device and IoT gateway based on IP PBX. This server is based on embedded OS and various IoT services are executed in one system and call processing / broadcasting server function that processes emergency call and emergency broadcasting in public places is built in. This system collects IoT sensor data and emergency bell information and automatically sends out emergency alarms, emergency evacuation broadcasts, etc. at an accident site in an emergency situation, and transmits the daily information to the upper IoT service server, Provide public safety management services.
민방위 대피시설 계획 및 설계 방안에 관한 연구 2 - 미국의 대피시설 계획 및 설계를 중심으로 -
한국재난정보학회 한국재난정보학회논문집 제10권 3호 통권25호 2014.09 pp.442-451
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
현재 국내에 2만 여개의 대피시설이 지정되어 운영되고 있다. 그러나 북한의 화생방공격혹은 화생방테러로부 터 방호가 가능한 시설은 극소수에 불과하다. 또한 공공용 대피시설은단순 방공호 수준의 성능만을 보유하고 있으며, 화생방공격에 대한 기준 확립이 시급하다. 이에 본 연구는 미국의 화생방 대피시설 중 SIP(건물 내 대피시설)를 중심으로 개념과 기준등의 현황분석을 통하여, 한국형 대피시설의 계획 및 구축 방안을 도출하고자 하였다.
Over 20,001 defense shelters are currently designated and operated in Korea. However,only few sheltershave the capacity to defend against CBR attack or terror from NorthKorea. Furthermore, as public defense shelters are only equipped with air-raid shelters,it is urgent to establish standard for CBR attack.This study focuses onshelter-in-place(SIP),a kind of CBR shelter in the U.S., and aims to draw up constructionplan and planning of Korean defenses helter.
확장성을 고려한 Asterisk 기반 인터넷 전화 관리 방법 KCI 등재
한국디지털정책학회 디지털융복합연구 제12권 제8호 2014.08 pp.235-242
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷 전화망은 VoIP기술을 이용해서 음성 전화를 지원하는 인터넷 서비스다. 인터넷 전화는 영상통화, 메 시징과 같은 인터넷 멀티미디어 서비스를 융합한 서비스를 지원할 수 있는 장점을 갖고 있다. 본 논문은 Asterisk를 기반으로 구축한 인터넷 전화망의 확장성을 고려한 효율적인 관리 방법을 제안한다. 기존 시스템은 SIP 사용자, 다 이얼플랜, CDR, IVR 및 서버 연동 등의 기능을 관리하기 위해 텍스트 파일 형식의 설정 파일을 사용하였다. 본 논 문은 관리의 효율성과 확장성을 위해서 DB 기반으로 여러 기능을 수행할 수 있는 관리시스템을 설계 구현하였고, 전반적인 관리를 웹을 통해서 할 수 있도록 Apache, MySQL, jQuery와 PHP 등의 오픈 소스 소프트웨어를 사용하여 구현하였다.
Internet telephony is an Internet service which supports voice telephone using VoIP technology on the IP-based Internet. It has some advantages in that voice telephone services can be accompanied with multimedia services such as video communication and messaging services. In this paper we suggested an Asterisk-based Internet telephony system which can be easily scalable. Most current systems use text files to manage their configuration: SIP users, dialplans, IVR service and etc. But we designed the management system which introduces database tables for efficiency and scalability. It also supports web-based functions developed by using Asterisk, Apache, MySQL, jQuery, PHP and open source softwares.
오픈 소스 소프트웨어를 활용한 인터넷 전화망 시스템 설계 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제6호 2012.07 pp.259-267
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷 전화망은 IP기반 인터넷에서 VoIP기술을 이용해서 음성 전화를 지원하는 인터넷 서비스다. 인터넷 전화는 영상통화, 메시징과 같은 인터넷 멀티미디어 서비스를 융합한 음성전화 서비스를 지원할 수 있는 장점을 갖고 있다. 특히 스마트폰을 통한 인터넷 소셜 네트워크 서비스가 보급되면서 기존의 전화망을 대체하는 서비스로써 인터넷 전화에 대한 연구와 개발이 활발히 진행되고 있다. 본 논문에서는 오픈 소스 소프트웨어인 Asterisk를 활용해서 인터넷 전화망 시스템을 설계하고 구현하였다. 리눅스 상에 구현된 Asterisk 서버는 음성 사서함 및 통화 녹취 기능 등을 제공하고, 웹을 통한 사용자 및 시스템 관리 구현은 Apache 서버와 PHP 등의 오픈 소스 소프트웨어를 사용하였다. 본 논문에서 구현된 시스템은 소규모 업체나 조직에 적용 가능한 인터넷 전화망으로써 오픈 소스 소프트웨어의 활성화 측면에서 역할을 하리라 기대된다.
Internet telephony is an Internet service which supports voice telephone using VoIP technology on the IP-based Internet. It has some advantages in that voice telephone services can be accompanied with multimedia services such as video communication and messaging services. Recently, the introduction of smart phones has led to a growth in social networking services and thus, the research and development of Internet telephony has been actively progressed and has the potential to become a replacement for the telephone service that is currently being used. In this paper we designed and implemented an Internet telephony network system which is developed by using Asterisk and open source softwares. It is developed on the linux system and has some features such as VoIP telephony service between SIP phones, voice mail, and call recording. It also supports web-based functions such as SIP users and server system management that is implemented by Apache web server and PHP programs. Afterwards, this system will be applied as VoIP network base technology for small sized companies and organizations. It will paly a role for encouraging companies to use open source softwares.
오픈 소스 소프트웨어를 활용한 인터넷 전화 녹취 시스템 KCI 등재
한국디지털정책학회 디지털융복합연구 제9권 제5호 2011.10 pp.225-233
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷 전화는 IP 기반 인터넷에서 VoIP(Voice over IP) 기술을 이용해서 음성 전화를 지원하는 인터넷 서비스다. 인터넷 전화는 영상통화, 메시징과 같은 인터넷 멀티미디어 서비스를 융합한 음성전화 서비스를 지원할 수 있는 장점을 갖고 있다. 특히 스마트폰을 통한 인터넷 소셜 네트워크 서비스가 보급되면서 기존의 전화망을 대체하는 서비스로써 인터넷 전화에 대한 연구와 개발이 활발히 진행되고 있다. 본 논문에서는 SIP(Session Initiation Protocol) 기반 인터넷 전화의 음성 통화 내용을 녹취하는 시스템의 설계 및 구현에 대해 설명한다. 인터넷 전화 녹취 시스템은 리눅스 기반으로 양방향 음성 스트림을 믹싱하는 기능, 라이브 패킷 스니핑 기능, 녹취 음성 파일 송신 기능은 공개 소프트웨어를 사용해서 구현하였다. 향후 개발된 시스템은 VoIP 기반 콜센터 시스템 등과 같은 복합 시스템을 구축하는데 있어 기반 기술로 활용될 계획이다.
Internet telephony is an Internet service which supports voice telephone using VoIP technology on the IP-based Internet. It has some advantages in that voice telephone services can be accompanied with multimedia services such as video communication and messaging services. Recently, the introduction of smart phones has led to a growth in social networking services and thus, the research and development of Internet telephony has been actively progressed and has the potential to become a replacement for the telephone service that is currently being used. In this paper we designed and implemented a recording system which records voice data of SIP-based Internet telephone's voice calls. It is developed on the linux system and has some features such as audio mixing of two in/out voice channels, live packet sniffing, and the ability to transfer mixed audio files to the log file server. These functions are implemented using various open source softwares. Afterwards, this VoIP recording system will be applied as a base technology to advanced services like a VoIP-based call center system.
Design and Implementation of Mobile P2P Collaboration Framework for Spatial Data
서울대학교 국토문제연구소 지리학논총 제54호 2009.09 pp.45-74
※ 기관로그인 시 무료 이용이 가능합니다.
7,000원
A Study on Cooperation between Kerberos system and Credit-Control Server
한국정보기술응용학회 한국정보기술응용학회 학술대회 2005년도 6th 2005 International Conference on Computers, Communications and System 2005.11 pp.281-284
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Kerberos is system that offer authorization in internet and authentication service. Can speak that put each server between client and user in distributed environment and is security system of symmetry height encryption base that offer authentication base mutually. Kerberos authentication is based entirely on the knowledge of passwords that are stored on the Kerberos Server. A user proves her identity to the Kerberos Server by demonstrating Knowledge of the key. The fact that the Kerberos Server has access to the user's decrypted password is a rwsult of the fact that Kerberos does not use public key cryptogrphy. It is a serious disadvantage of the Kerbercs System. The Server must be physically secure to prevent an attacker from stealing the Kerberos Server and learning all of the user passwords. Kerberos was designend so that the server can be stateless. The Kerberos Server simply answers requests from users and issues tickets. This study focused on designing a SIP procy for interworking with AAA server with respect to user authentication and Kerberos System. Kerberos is security system of encryption base that offer certification function mutually between client application element and server application element in distributed network environment. Kerberos provides service necessary to control whether is going to approve also so that certain client may access to certain server. This paper does Credit-Control Server's function in AAA system of Diameter base so that can include Accounting information that is connected to Rating inside certification information message in Rating process with Kerberos system.
SIP를 위한 Qiu등의 개선된 패스워드 인증 기법에 대한 보안 분석 및 강화 기법 KCI 등재
한국디지털정책학회 디지털융복합연구 제18권 제5호 2020.05 pp.249-256
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
세션 시작 프로토콜(Session Initiation Protocol, SIP)은 인터넷 프로토콜 기반 네트워크에서 세션 생성과 관리 및 종료하는데 사용되는 신호 프로토콜이다. 이를 통해 음성 기반 전자 상거래나 인스턴트 메시징과 같은 서비스를 구현할 수 있다. 최근에 Qiu등은 SIP를 위한 개선된 패스워드 인증 기법을 제안하고 모든 알려진 공격에 안전하다고 주장하였다. 하지만, 본 논문에서는 Qiu등의 인증 기법이 오프라인 패스워드 추측 공격에 취약하고 서비스 거부의 문제 가 있음을 도출한다. 또한, 이러한 문제를 해결하기 위한 강화된 패스워드 인증 기법을 제안한다. 제안한 기법은 서버의 검증자를 사용하지 않고 타원곡선암호의 기본 연산을 활용한다. 정형화된 보안 검증 툴인 ProVerif에 기반한 보안 검증 을 제시한다. 보안 분석을 통해 본 논문에서 제안한 강화된 인증 기법이 SIP 상의 다양한 보안 공격에 안전함을 보인다.
The session initiation protocol (SIP) is a signaling protocol, which is used to controlling communication session creation, manage and finish over Internet protocol. Based on it, we can implement various services like voice based electronic commerce or instant messaging. Recently, Qiu et al. proposed an enhanced password authentication scheme for SIP. However, this paper withdraws that Qiu et al.’s scheme is weak against the off-line password guessing attack and has denial of service problem. Addition to this, we propose an improved password authentication scheme as a remedy scheme of Qiu et al.’s scheme. For this, the proposed scheme does not use server’s verifier and is based on elliptic curve cryptography. Security validation is provided based on a formal validation tool ProVerif. Security analysis shows that the improved authentication scheme is strong against various attacks over SIP.
SIP기반의 IP Multimedia Network 구축
한국정보통신설비학회 한국정보통신설비학회 학술대회 2003 한국정보통신설비학회 하계학술대회 2003.08 pp.223-225
※ 기관로그인 시 무료 이용이 가능합니다.
3,000원
4,000원
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.