Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 53
No
1

Communal Antecedents in the Adoption of Secure Coding Methodologies KCI 등재

Sung Kun Kim, Ji Young Kim

한국경영정보학회 Asia Pacific Journal of Information Systems 제26권 제2호 2016.06 pp.231-246

※ 기관로그인 시 무료 이용이 가능합니다.

4,900원

Technology acceptance model has demonstrated that technology adoption behavior can be explained by two user belief constructs: perceived usefulness and perceived ease of use. A number of studies have explored how these beliefs develop by utilizing primarily individual-level antecedents. However, because innovation and new techniques bear a direct relation to social concerns, non-individual antecedents may be necessary. Therefore, in this study, social and organizational supports are used to understand how software developers foster beliefs regarding secure coding practices. We compiled data from 83 software developers to evaluate the technology acceptance model. Our findings show that these collective antecedents can effectively explain user belief constructs and the intention to adopt secure coding methodologies. These findings imply that society and organizations offering more concrete support programs will experience smoother deployment of security-enhancing measures.

2

사이버전 대응을 위한 국방 SW 개발보안 적용 방안 - 무기체계 내장형 SW 적용 수준을 중심으로 KCI 등재후보

최준성, 김우제, 박원형, 국광호

한국방위산업학회 한국방위산업학회지 제19권 제2호 2012.12 pp.90-103

※ 기관로그인 시 무료 이용이 가능합니다.

4,600원

The need for security in the SDLC (SW Development Life Cycle) has been increasing. Also, it is well-known that the error correction cost in the SW operational phase is soaring highly compared with that in the design phase. On the other hand, it is known that the security vulnerabilities have decreased with the application of Secure Coding in the design phase. Security for the warfare systems embedded SW of defense SW is very important, though, but has not yet been discussed. In this paper, defense SW factors and methods, especially the warfare systems embedded SW, are discussed. <Keywords> Secure Coding, Defense Software, Warfare System Embedded Software

3

4,000원

이 연구는 사이버범죄예방을 위해 민간기업시스템의 시큐어 코딩 적용상의 문제점과 이에 대한 개선안을 시사 하는 것이 목적이다. 본 연구를 위해 3가지 실험이 진행되었는데, 실험 1은 보안담당자가 개발과정에 참여하여 시큐어 코딩준수를 조언 하도록 하였고, 실험 2는 보안담당자의 조언 없이 개발자가 스스로 시큐어 코딩을 준수하도록 하였고, 실험 3은 개발자는 담 당 소스만 개발하고 보안담당자는 소스의 취약점 진단분석만 집중적으로 하도록 설계하였다. 이 연구의 결과는 첫째, 실험1,2 를 통해 사이버범죄관련 보안문제 해결을 위해 보안담당자의 개발과정 참여가 프로젝트가 반복될수록 기간 내 과업달성 및 시큐어 코딩준수율 역시 높아지는 것으로 나타났다. 둘째, 실험 3을 통해 개발자에게 시큐어 코딩 가이드 준수를 맡기는 것 보다 기업보안 담당자의 업무전담이 프로젝트 목표달성 및 시큐어 코딩 준수율을 높이는 것으로 나타났다.

The purpose of this study is to prevent cyber crime in private company systems by applying secure coding and identify its problems. Three experiments were conducted. In Experiment 1, a security manager was participated and gave advise to the developer to follow secure coding guidelines. In Experiment 2, a security manager did not participate, but let the developer himself committed on secure coding. In Experiment 3, a security manager provided reports on weaknesses of each package source to the developer and the developer was only focused on source development. The research results showed that the participation of a security manager on development raised secure coding compliance rate and finished the project within a given periods. Furthermore, it was better to entrust a security manager with the task of following the secure coding guide than the developer, which raised secure coding compliance rate and achieved project objectives faster. Further implications were discussed.

4

정보시스템의 정보보호를 위한 사전점검에 관한 연구 KCI 등재

이근호

한국디지털정책학회 디지털융복합연구 제12권 제2호 2014.02 pp.513-518

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

IT기술의 발전에 따라 다양한 신규 IT서비스가 생겨나고 있다. 신규 IT 서비스는 이용자의 서비스 접근의 편의성을 제공하나 네트워크와 복합 단말기 사용 등 정보시스템의 복잡도가 증가하고 있어 다양한 보안에 대한 위협과 취약성이 증가하고 있다. 정보시스템에 대한 안전성을 확보하기 위하여 정보통신 서비스 구축단계에서부터 정보보호 취약점 분석 등을 통해 사전에 취약점을 제거하고 정보보호 대책을 수립하여 적용하였는지에 대한 점검 활동에 대한 제도를 마련하고 있다. 본 논문에서는 정보시스템에 사전점검 방법에 대한 각 나라별 소개와 추진현황에 대해서 살펴본다. 한국인터넷 진흥원에서 추진하고 있는 사전점검 방법에 대한 추진 방향과 안전성을 확보하기 위한 활성화 방향에 대해서 제안한다.

According to the development of IT technology, various new technologies are being produced. As the complexity of the information system like using the network and convergence devices is increasing, threat and vulnerability against various security problems are increasing even though new IT services provide the convenience of users’ accessibility to services. In order to secure the safety of information system, the weakness is being removed through the information protection vulnerability analysis starting from information and communication service construction stage and the system is being prepared for pre-inspection activities about whether the information protection measures were established and applied. In this paper, introduction and current status of each country about advanced check-up systems in the information system are to be identified. Progress direction about the advanced pre-inspection system which is driven by Korea Internet Security Agency and its activation plan to secure the safety are to be suggested.

5

융복합 전자정부 서비스를 위한 전자정부 표준프레임워크 기반 시큐어코딩 점검 시스템 설계 및 개발 KCI 등재

김형주, 강정호, 김경훈, 이재승, 전문석

한국디지털정책학회 디지털융복합연구 제13권 제3호 2015.03 pp.201-208

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 IT 제품의 활용 분야가 다양화 되면서 소프트웨어의 활용 분야가 컴퓨터, 스마트폰, 의료기기 등 다양한 환경에서 이용되고 있다. 이처럼 소프트웨어의 활용분야가 다양해짐에 따라 소프트웨어 보안 취약점을 악용하는 공격사례가 증가하고 있으며 이에 따라 다양한 시큐어코딩 프로그램이 출시되었지만 이력관리, 업데이트, API 모듈 등의 취약점이 존재하고 있다. 본 논문에서는 안전한 소프트웨어 개발을 위해 송신모듈에 형상관리를 연동하는 시스템과, 콘텐츠 단위로 소스코드의 취약점을 점검할 수 있는 CMS 연동 시스템을 구현하고, 프로그램의 기능을 세분화 하여 국내외 시큐어코딩 관련 표준을 분석 및 적용함으로서 효율적인 시큐어코딩 시스템 방법을 구현하였다.

Recently computer, smart phone, medical devices, etc has become used in a variety of environments as the application fields of IT products have become diversification. Attack case of abuse of software security vulnerabilities is on the increase as the application fields of software have become diversification. Accordingly, secure coding program is of a varied but history management, updating, API module to be vulnerable to attack. Thus, this paper proposed a materialization of CMS linked system to enable check the vulnerability of the source code to content unit for secure software development, configuration management system that interwork on the transmission module. Implemented an efficient coding system secure way that departmentalized by the function of the program and by analyzing and applying secure coding standards.

6

SDLC 설계절차에 기반한 웹 애플리케이션 시큐어코딩 접근방법 연구 KCI 등재후보

노시춘

한국융합보안학회 융합보안논문지 제12권 제6호 2012.12 pp.93-99

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

웹 애플리케이션 개발이 보편화됨에 따라 대부분의 소프트웨어는 개발기간 단축, 에러없는 품질, 수시 유지보수에 대 한 적응성, 거대하고 복잡한 소프트웨어의 필요성 등과 같은 과제가 제기되었다. 웹 애플리케이션 개발시 이러한 품질 문제에 대응하기 위해 소프트웨어의 재사용성, 신뢰성, 확장성, 단순성 등과 같은 측면을 고려하지 않을 수 없는 환경으 로 변화 되었다. 이같은 상황에서 전통적 개발방법론으로는 보안품질을 해결하는데 한계를 가지고 있기 때문에 품질에 기반한 시큐어코딩 방법론이 필요하다. 웹 애플리케이션 보안품질은 애플리케이션 로직, 데이터, 아키텍처 전체 영역에 서 별도의 방법론으로 대처하지 않으면 목표를 달성할 수 없다. 본 연구는 시큐어코딩의 최대 현안인 웹 애어플리케이 션 개발을 위하여 웹 애플리케이션 아키텍쳐 설계절차를 제안한다.

As the most common application development of software development time, error-free quality, adaptability to frequent maintenance, such as the need for large and complex software challenges have been raised. When developing web applications to respond to software reusability, reliability, scalability, simplicity, these quality issues do not take into account such aspects traditionally. In this situation, the traditional development methodology to solve the same quality because it has limited development of new methodologies is needed. Quality of applications the application logic, data, and architecture in the entire area as a separate methodology can achieve your goals if you do not respond. In this study secure coding, the big issue, web application factors to deal with security vulnerabilities, web application architecture, design procedure is proposed. This proposal is based on a series of ISO/IEC9000, a web application architecture design process..

7

AHP기법을 이용한 시큐어 코딩의 항목 간 중요도 분석 KCI 등재

김치수

한국디지털정책학회 디지털융복합연구 제13권 제1호 2015.01 pp.257-262

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

해킹과 같은 사이버 공격의 약 75%가 애플리케이션의 보안 취약점을 악용하기 때문에 안전행정부에서는 코딩 단계에서부터 사이버 공격을 막을 수 있고 보안취약점을 제거할 수 있는 시큐어 코딩 가이드를 제공하고 있다. 본 논문에서는 안행부가 제시한 시큐어 코딩 가이드 7개의 항목들에 대해 AHP기법을 사용하여 우선순위를 찾고 중요도 분석을 하였다. 그 결과 ‘에러 처리’가 가장 중요한 항목으로 결정되었다. 현재 소프트웨어 감리에 시큐어 코딩에 관한 항목이 없는데, 이 분석 결과는 소프트웨어 개발 과정 중 감리 기준으로 유용하게 사용될 것이다.

The ministry of security and public administration provide the secure coding guide that can remove the vulnerability of applications and defend cyber attack from the coding step because cyber attack like the hacking about 75% abusing the vulnerability of applications. In this paper we find the oder of priority and did the criticality analysis used by AHP about 7 items in the secure coding which the ministry of security and public administration provide. The result is decided that ‘exception handling’ is the most important item. There is no secure coding items in software supervision currently, therefore the result of the research will make good use audit standards in the process of the software development.

8

Design and Implementation of the Compiler with Secure Coding Rules for Developing Secure Mobile Applications in Memory Usages

YunSik Son, YangSun Lee, SeMan Oh

보안공학연구지원센터(IJSH) International Journal of Smart Home Vol.6 No.4 2012.10 pp.153-168

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

With the recent dynamic growth of the mobile market, the problem of personal information leakage through mobile applications’ weaknesses has become a newly rising problem. Guaranteeing the reliability of input and output data is particularly difficult nowadays because software exchange data across the internet. There is also a risk of being the target of an arbitrary intruder’s malicious attack. Such weaknesses have been the root to software security violations that can cause some serious financial damages. Such weaknesses are the direct causes of software security incidents, which generate critical economic losses. Therefore it is important eliminate weaknesses in the software development stage and these areas such as the secure software development process model are being studied, recently. In this study, a compiler which can examine applications’ weaknesses at the software development stage has been designed and implemented based on existing weakness research. The proposed compiler analyzes the weaknesses within a program at the point of compilation, different to the existing development environments which separate compilers and weakness analysis tools. As a result, the new compiler enables mobile applications that are developed in rapid development cycles to be created safely from the very first stages of development.

9

A Study on the Optimization Method for the Rule Checker in the Secure Coding SCOPUS

JaeHyun Kim, YangSun Lee

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.1 2014.01 pp.333-342

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Today’s software allows data transfer with the use of internet. Therefore, there is always a threat of attack by hackers. These security weaknesses cause a critical economic loss which is a direct cause of software security invasion accidents. Recently in order to solve these security weaknesses, rather than strengthening the security system from the external environment, many have started to realize it is essential and most efficient for programmers to develop stronger software. Internationally, resolving software weakness from the coding stage to prevent security incidents by providing a coding guide is rising as a security issue. Especially, user demands of software are becoming enormous and complicated. In order to reduce weaknesses that could lie in the software have to be removed and the costs for these increases as the development process progresses. This leads to issues nowadays with removing the security weaknesses from the coding stage. This technique is called secure coding and not only is the academic and the industrial world showing interest in this technique, but also national agencies are showing great interest. Especially in Korea, the electronic government business has decided to introduce secure coding and all developed programs will apply the security coding methodology. Rule checker, the object of study of this research, is a core tool for secure coding which is used to analyze security weaknesses existing in programs using a rule base. Especially, it can be used in the developmental stage and examination stage which makes an efficient composition of rule checker very important. In this research, a maximized technique to compose a rule checker with most efficiency has been proposed.

10

시큐어 코딩룰 선정평가 모형을 활용한 국내 시큐어 코딩룰 분석 KCI 등재

최준성, 국광호

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.11 No.4 2014.08 pp.325-338

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 논문은 시스템 특성에 최적화된 시큐어 코딩룰 선정평가 모형을 일반화하여 전자정부 웹서비스 시큐어 코딩룰을 평가하는 영역까지 적용범위를 확대하고 그 효과를 검증하였다. 또한 현행 정부 지 침에 의한 국내 시큐어 코딩룰에 대한 재평가를 통하여 정부 지침으로 제공되고 있는 시큐어 코딩룰 의 가중치 중요도를 확인하여 활용할 수 있게 하였다.

In this paper, we generalized the Evaluation Model for Secure Coding Rule Selection Optimized on the System Characteristics to the existing domestic e-government secure coding rule evaluation area and validated the effect. And verify and use that weighted value of existing e-gov secure coding rule by re-evaluating existing e-gov secure coding rule.

11

무기체계 내장형 소프트웨어 시큐어 코딩 교육 과정 설계 KCI 등재

최준성, 박상현, 이정민, 국광호

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.12 No.4 2015.08 pp.351-362

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 논문에서는 무기체계 내장형 소프트웨어 시큐어 코딩 교육을 위한 교육 과정을 설계하여 제안 한다. 무기체계 내장형 소프트웨어에 대한 개발보안 적용과 시큐어 코딩은 무기체계 내장형 소프트웨 어에 대해 증가하는 사이버 위협에 대한 대응방안으로 중요하다. 그러나 현재 시큐어 코딩 제도와 교 육은 전자정부 웹서비스에만 한정되어 있어, 무기체계 소프트웨어에 대한 위협에 대응이 어렵다. 그 러므로 무기체계 내장형 소프트웨어의 특성을 고려한 교육 과정에 대한 요구사항의 분석과 이를 활 용한 교육과정의 설계가 필요하다. 본 논문에서는 무기체계 내장형 소프트웨어 특성을 고려한 시큐어 코딩 교육의 요구조건을 도출하여 계층분석기법으로 분석하여 요구조건 우선순위를 중심으로 하는 시큐어 코딩 교육 교과 과정을 설계하여 제안한다.

In this paper, we propose an secure coding education program for warfare system embedded software. warfare system embedded software. It is very important that applying secure coding for warfare system embedded software to prevent cyber threatens on warfare system embedded software. but nowadays every secure coding policy and education programs are only for the e-gov framework web-services. And there is need for secure coding education program design considering warfare system embedded software characteristic and requirement. In this paper, we analysis requirement. considering warfare system embedded software characteristic. And we propose an new secure coding education program especially considering warfare system embedded software characteristic and requirement which are analyzed by AHP..

12

Adaption of Integrated Secure Guide for Secure Software Development Lifecycle SCOPUS

Ki-Hyun Lee, Young B Park

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.6 2016.06 pp.145-154

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

As interests in security increases, several software development lifecycle considering security have been proposed. Actual results of applying software development lifecycle considering security reduced threats have been reported. But to apply software development lifecycle considering security, requires expertise and experiences. In this paper a secure software development lifecycle applying integrated secure guide is proposed. Secure Guides such as Misuse Case, Security Patterns and Secure Coding are integrated in the proposed method. And then, by applying integrated Secure Guide in each software development phase, the security becomes available in every phase of software development. Since, proposed secure guide provides more security information than available secure guides, software developer can use more security information while they are developing software. As a result, it is expected that developers could consider security more easily when developing software even though developers lacks expertise in security or experience.

13

Design and Implementation of a Compiler with Secure Coding Rules for Secure Mobile Applications SCOPUS

Yunsik Son, Seman Oh

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.6 No.4 2012.10 pp.201-206

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

The dissemination and use of mobile applications have been rapidly expanding these days. And in such a situation, the security of mobile applications has emerged as a new issue. Especially, the software including mobile applications will always exist the possibility of malicious attacks by hackers, because it exchanging data in the internet environment. These security weaknesses are the direct cause of software breaches causing serious economic loss. In recent years, the awareness that developing secure software is intrinsically the most effective way to eliminate the software vulnerability than strengthening the security system for the external environment has increased. Therefore, Methodology to eliminate the vulnerability using secure coding rules and checking tools is getting attention to prevent software breaches in the coding stage. However, the existing coding rules do not reflects the characteristics of the mobile environments and the applications. In this paper, we will define the secure coding rules that reflect the characteristics of the mobile environments and applications by the analysis of the existing secure coding rules. And, we will design and implement the compiler to inspect vulnerabilities of the mobile applications using defined secure coding rules in the coding stage.

14

무기체계 소프트웨어 시큐어 코딩룰 평가 모형을 활용한 해군 전투체계 소프트웨어 시큐어 코딩룰 선정 KCI 등재

최준성, 김우제, 박원형, 국광호

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.10 No.4 2013.08 pp.417-428

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

해군 전투체계는 해군 함정의 전투수행을 위해 센서와 무장을 통합하고 운영하는 통합정보체계이다. 최근의 전투함들은 소형 경량화로 인해, 정보체계 의존도가 높아지고 있으며, 이에 따라, 사이버 위협에 대한 위험도 높아지고 있다. 본 연구에서는 해군 전투체계 소프트웨어의 사이버 침해사고를 예방하기 위한 대응방안으로, 무기체계 소프트웨어 시큐어 코딩룰 평가모형을 활용하여, 해군 전투체 계 소프트웨어에 적합한 시큐어 코딩룰을 선정하여 제안한다.

Naval combat management system is an integrated information system to operate by integrating the sensor and armed for naval combat vessels. The warship is recently, for reduction in size and weight, dependence on information systems percentage is increasing. And then there is a growing risk of cyber threats. As for countermeasure to prevent cyber infringement of naval combat management system. In this paper, we suggest secure coding rule for naval combat management system using warfare system Software secure coding rule evaluation Model.

15

군용항공기 감항인증을 고려한 항공무기체계 보안강화 코딩룰 선정평가 KCI 등재

최준성, 국광호

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.11 No.6 2014.12 pp.439-454

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

항공무기체계 소프트웨어는 군용항공기의 전투임무 수행을 위해 기체, 발사체, 센서와 무장을 제어 통합하고 운영한다. 항공기의 데이터 연동의 증가와 소프트웨어에 대한 기능 의존도가 높아짐에 따라 항공무기체계 소프트웨어에 대한 사이버 공격 위협에 대한 위험도 증가하고 있다. 항공무기체계 소프 트웨어에 대한 보안위협 대응에 있어서도 군용항공기 소프트웨어는 안정성 측면의 감항인증이 먼저 고려되어야 한다. 본 논문은 항공무기체계 소프트웨어의 사이버 위협을 방지하기 위한 수단으로 항공 무기체계에 적합한 보안강화 코딩룰을 개발함에 있어 군용항공기 감항인증 요소를 사전에 고려하여 안정성과 보안성을 동시에 충족시키는 항공무기체계 보안강화 코딩룰 선정 평가한 결과를 제시한다.

Air warfare system softwares operate, control and integrate airframe, projectiles, sensors and arms. In air craft, data connectivity and data link are increasing, and softwares function dependency of air craft are also increasing. Therefore. the risks of cyber threats on the air warfare system softwares are also increasing. Protecting air warfare system softwares against cyber threats, we must consider military air craft air worthiness. In this study we develope and propose secure coding rule selection evaluation result for protecting cyber threats on the air warfare system softwares comply with both safety and security considering defense air craft air worthiness in advance.

16

지상 사격통제컴퓨터 시스템에 최적화된 시큐어 코딩룰 선정 KCI 등재

최준성, 국광호

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.11 No.2 2014.04 pp.187-194

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 논문에서는 지상전의 중요 전력인 화력전의 안정적 수행을 위한 사이버 위협 방지 측면에서 사 격통제 컴퓨터 소프트웨어에 대한 보안을 향상 시켜줄 사격통제컴퓨터에 최적화된 시큐어 코딩룰을 시스템특성에 최적화된 시큐어코딩룰 선정평가 모형과 전문가 평가를 통해 선정하여 제시한다.

In this paper, we suggest that secure coding rule optimized on the army fire control computer by expert evaluation and Secure Coding Rule Selection Model Optimized on the System Characteristics to prevent for cyber threaten on the artillery fire system as a major force of the ground forces operation.

17

Secure Coding for SQL Injection Prevention Using Generative AI

Young-Bok Cho

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.29 No.9 2024 pp.61-68

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

생성형 인공지능은 텍스트, 이미지, 음악 등 다양한 형태의 콘텐츠를 생성하는 기술로, 다양한 분야에 활용되고 있다. 보안 분야에서도 생성형 인공지능을 활용한 디지털포렌식, 악성코드 분석, 취약점분석 등 다양한 분야에 새로운 가능성을 열 준비를 하고 있다. 본 논문에서 생성형 인공지능을 보안영역을 고려한 활용방법으로 보안 취약점 분석 및 예측을 위해 ChatGPT를 활용해 취약점 식별및 시큐어 코딩이 가능한 가이드를 제시한다. 생성형 인공지능은 보안 분야에 혁신적인 가능성을 제시하지만, 기술적 발전과 함께 윤리적, 법적 문제에 대한 심도있는 고민을 통해 생성형 인공지능이 안전하고 효과적으로 활용될 수 있도록 지속적인 연구와 개발이 필요할것이다.

In this paper, Generative AI is a technology that creates various forms of content such as text, images, and music, and is being utilized across different fields. In the security sector, generative AI is poised to open up new possibilities in various areas including security vulnerability analysis, malware detection and analysis, and the creation and improvement of security policies. This paper presents a guide for identifying vulnerabilities and secure coding using ChatGPT for security vulnerability analysis and prediction, considering the application of generative AI in the security domain. While generative AI offers innovative possibilities in the security field, it is essential to continuously pursue research and development to ensure safe and effective utilization of generative AI through in-depth consideration of ethical and legal issues accompanying technological advancements.

18

Secure Coding guide support tools design for SW individual developers

손승완, 김광석, 최정원, 이강수

[Kisti 연계] 한국정보통신학회 한국정보통신학회 학술대회논문집 2014 pp.595-598

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근의 사이버 공격은 보안패치가 발표되기 이전의 보안취약점을 악용하는 제로 데이(Zero Day) 공격, 웹 사이트를 대상으로 한 공격이 주를 이루고 있다. 이러한 공격은 소프트웨어 자체에 내장된 보안취약점을 이용하는 것이 대부분으로, 특히나 소스코드의 보안취약점을 이용한 사이버 공격은 보안장비로는 대응이 어려운 특성을 가진다. 따라서 이러한 공격을 예방하기 위해 소프트웨어를 구현하는 단계에서부터 보안취약점을 배제 시켜야한다. 본 논문에서는 구현단계에서부터 보안위협을 해소하는 Secure Coding 가이드 지원 도구를 설계하고자 한다.

The cyber attacks of recent attacks that target zero-day exploit security vulnerabilities before the security patch is released (Zero Day) attack, the web site is without the Lord. These attacks, those that use the vulnerability of security that is built into the software itself is in most cases, cyber attacks that use the vulnerability of the security of the source code, in particular, has a characteristic response that are difficult to security equipment. Therefore, it is necessary to eliminate the security vulnerability from step to implement the software to prevent these attacks. In this paper, we try to design a Secure Coding Guide support tool to eliminate the threat of security from the stage of implementation.

19

secure coding 제도의 생태계 차원의 분석

김성근, 이재일

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.22 No.5 2012 pp.1205-1216

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 국내에서도 secure coding 제도화가 처음으로 마련되었다. 개발보안의 체계적 정착을 위한 중요한 첫걸음이라는 점에서 높이 살만하다고 하겠다. 그럼에도 현 제도의 실행 과정에서 예상되는 이슈가 제기되는 등 향후 보완할 점도 제법 있다. 이런 상황에서 본 연구에서는 생태계 차원의 분석을 시도한다. 즉, 개발 보안 제도를 생태계 차원에서 묘사하고, 이를 토대로 현상적 이슈와 문제점을 분석한다. 이런 문제와 이슈의 극복을 위해 향후 강구되어야할 대안을 몇 가지 제시한다.

The Korea government has recently announced that secure coding is going to be required when building e-government systems. As its initial effort to enhance the security level of e-government applications, it should be highly valued. In its implementation, however, there are some problematic areas or issues that are expected and need to be supplemented. In this regards, we attempt to analyze the Secure Coding Initiatives and derive some problems using an ecosystem approach. Furthermore, a set of institutional suggestions are made in an effort to get over the problems.

20

secure coding 제도의 생태계 차원의 분석

김성근, 이재일

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.22 No.5 2012 pp.1205-1216

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 국내에서도 secure coding 제도화가 처음으로 마련되었다. 개발보안의 체계적 정착을 위한 중요한 첫걸음이라는 점에서 높이 살만하다고 하겠다. 그럼에도 현 제도의 실행 과정에서 예상되는 이슈가 제기되는 등 향후 보완할 점도 제법 있다. 이런 상황에서 본 연구에서는 생태계 차원의 분석을 시도한다. 즉, 개발 보안 제도를 생태계 차원에서 묘사하고, 이를 토대로 현상적 이슈와 문제점을 분석한다. 이런 문제와 이슈의 극복을 위해 향후 강구되어야할 대안을 몇 가지 제시한다.

The Korea government has recently announced that secure coding is going to be required when building e-government systems. As its initial effort to enhance the security level of e-government applications, it should be highly valued. In its implementation, however, there are some problematic areas or issues that are expected and need to be supplemented. In this regards, we attempt to analyze the Secure Coding Initiatives and derive some problems using an ecosystem approach. Furthermore, a set of institutional suggestions are made in an effort to get over the problems.

 
1 2 3
페이지 저장