년 - 년
디지털 홈 네트워크에서의 콘텐츠 공유를 위한 DRM License 관리
한국융합보안학회 융합보안논문지 제9권 제3호 2009.09 pp.77-86
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
DRM 시스템의 목적은 인가된 사용자만이 컨텐츠를 사용할 수 있게 함으로써 컨텐츠 제공자의 저작권을 보호하는 것이다. 기존의 서비스는 갈수록 복잡해지고 재분배의 범위를 제한하고있다. 그러나 소비자는 여러 디바이스에서 자신이 구매한 컨텐츠를 사용하고 싶어 하고 있다. 본 논문에서는 소비자가 소유하고 있는 여러 디바이스간의 컨텐츠 재배포를 지원하는 라이센스 관리 기법을 제안한다. 제안된 기법에서 우리는 도매인키를 생성하여 디바이스들을 인증하고 컨텐츠 암호키를 다시한번 암호화 함으로서 보다 안전하게 키를 공유한다. 또한 일정시간마다 디바이스들의 상태를 체크하여 변동이 있다면 도메인키를 재발행함으로써 인가되지 않은 침입자의 공격을 막을 수 있다. 제안하는 방법을 다른 대표적인 방법과 비교 평가하여 그 우수성을 입증하였다.
The purpose of DRM is to protect the copyrights of content providers by the thing that enables only designated users to access digital contents. The existing service become complicated and restrict the range of superdistribution. however, the consumers want to use the contents in their multiple devices. in this paper we propose a license management method supporting superdistribution among multiple deivices owned by the consumer. our proposed method creates domain key to authenticate devices and encrypte the contents encryption key It makes secure in key sharing. We check the state of devices at regular time. If there is a change, we can protect the attack of unauthenticated intruder by reissuing the domain key. We prove the superiority of our proposed method with the analysis of other methods.
임시파일 데이터 조작을 통한 아두이노 보드 공격 기법에 관한 연구 KCI 등재
한국융합학회 한국융합학회논문지 제8권 제11호 2017.11 pp.21-27
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
초연결사회를 지향하기 위해 발전하고 있는 사물인터넷(Internet of Things)은 아두이노 등의 OSHW (Open Source Hardware)를 기반으로 두고 있으며 다양한 소형 제품 등이 등장하고 있다. 이러한 사물인터넷은 저성능, 저메모리라는 한계로 인하여 강력한 보안 기술을 적용하기 어렵다는 심각한 정보보안 문제를 야기하고 있다. 본 논문에서는 사물인터넷 기기로 주로 사용되는 아두이노의 응용프로그램이 호스트컴퓨터에서 컴파일과 로딩이 수행됨에 따라 발생할 수 있는 취약성을 분석하여 아두이노 보드의 센서로부터 입력되는 값을 공격자가 임의로 변경할 수 있는 새로운 공격 방법을 제안한다. 이러한 방법을 통해 아두이노 보드가 환경정보를 오인식하여 정상적인 동작이 불가능하게 할 수 있다. 이러한 공격 기법의 이해를 통해 안전한 개발환경 구축방안을 고려할 수 있으며 이러한 공격으로부터 대응할 수 있다.
Internet of Things(IoT), which is developing for the hyper connection society, is based on OSHW (Open Source Hardware) such as Arduino and various small products are emerging. Because of the limitation of low performance and low memory, the IoT is causing serious information security problem that it is difficult to apply strong security technology. In this paper, we analyze the vulnerability that can occur as a result of compiling and loading the application program of Arduino on the host computer. And we propose a new attack method that allows an attacker to arbitrarily change the value input from the sensor of the arduino board. Such as a proposed attack method may cause the arduino board to misinterpret environmental information and render it inoperable. By understanding these attack techniques, it is possible to consider how to build a secure development environment and cope with these attacks.
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제4권 제4호 2014.12 pp.1-6
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
무선 센서 네트워크는 여러 지역에 퍼져 있는 다수의 센서 노드들이 무선 방식으로 연결 되어있는 그물망 으로 전 세계에서 연구되고 있는 기술 중 하나이다. 그러나 자원의 제약성, 무선 통신 사용 등, 네트워크 자체적인 특성으로 인해 일반 네트워크에 비해서 보안이 매우 취약하다. 무선 센서 네트워크의 공격법은 크게 도청기반 공격, 위조기반 공격, 서비스 거부 기반 공격으로 나누어지며, 보안법으로 대개의 Sensor Network Application은 전송되 는 정보의 도청 또는 수정, 잘못된 정보의 삽입 등 여러가지 공격으로부터 방어를 해야 할 필요가 있다. 이를 위한 기본적인 방법은 암호화 방법, 스위칭 기법 등을 서술 한다.
A wireless sensor network is being actively researched around the world that are connected to the mesh are a plurality of sensor nodes in a wireless manner that span different regions of the techniques. However, wireless communications use the limitation of resources, so it is very weak due to the properties of the network itself secure in comparison to the normal network. Wireless sensor network is divided into tapped-based attacks, forgery based attacks, denial of service attacks based largely by securities laws must defend against various attacks such as insertion of the wrong information being sent eavesdropping or modification of information, which is usually sensor network applications need to do. The countermeasure of sensor network attack is described in this research, and it will contribute to establish a secure sensor network communication.
센서 네트워크의 복합적 공격에 대하여 신뢰성 있는 데이터 전달을 위한 경로 선택 방법
한국정보통신설비학회 한국정보통신설비학회 학술대회 2010년도 정보통신설비 학술대회 2010.08 pp.345-349
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
공격시스템을 위한 보안-역-공격공학 생명주기 모델과 공격명세모델 KCI 등재
한국융합학회 한국융합학회논문지 제8권 제6호 2017.06 pp.17-27
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
최근 사이버공격이 활성화됨에 따라 이러한 많은 공격사례들이 다양한 매체를 통해 접해지고 있다. 사이버공격에 대한 보안공학이나 역공학에 대한 연구는 활발하지만, 이들을 통합하고 비용효과적인 공격공학을 통해 공격시스템을 연계하여 적용시킨 연구는 부족하다. 본 논문에서는, 보안강화형 정보시스템을 보안공학적으로 개발하고, 역공학을 통해 취약점을 식별한다. 이 취약점을 이용하여 공격공학을 통해 공격시스템을 구축하거나 리모델링하는 생명주기모델을 비교·분석하여 각 시스템의 구조 및 행동을 명세화하고, 더욱 실효성 있는 모델링을 제안한다. 또한, 기존의 모델·도구를 확장하여 공격방법 및 시나리오를 기능적, 정적, 동적과 같은 모델의 관점에서 명세하는 도형적 공격명세모델을 제시한다.
Recently, as cyber attacks have been activated, many such attacks have come into contact with various media. Research on security engineering and reverse engineering is active, but there is a lack of research that integrates them and applies attack systems through cost effective attack engineering. In this paper, security - enhanced information systems are developed by security engineering and reverse engineering is used to identify vulnerabilities. Using this vulnerability, we compare and analyze lifecycle models that construct or remodel attack system through attack engineering, and specify structure and behavior of each system, and propose more effective modeling. In addition, we extend the existing models and tools to propose graphical attack specification models that specify attack methods and scenarios in terms of models such as functional, static, and dynamic.
공격 시나리오 기반의 정보보호 투자 최적화 : 병원 정보 시스템을 대상으로 KCI 등재
한국경영정보학회 경영정보학연구 제27권 제1호 2025.02 pp.109-126
※ 기관로그인 시 무료 이용이 가능합니다.
5,200원
최근의 의료 서비스는 정보통신기술과 융합하여 발전하고 있으며, 의료 서비스 영역의 보안 사고를 예방하기 위해서는 다양한 보안 대책을 포함하는 포괄적인 정보보호 투자가 필요하다. Sönmez et al.(2022)은 Attack Graph 기반 정보보호 투자 최적화 툴인 CysecTool을 활용하여 병원 정보 시스템의 취약점에 대한 위험 평가와 제어 방안에 대한 최적화를 진행했다. 본 논문에서는 Sönmez et al.(2022)의 취약점과 대책 관련 데이터와 국내 주요 병원의 실제 네트워크 구조도를 활용하여 어택 그래프를 제작하고, CysecTool 투자 최적화 모델의 한계점을 개선하여 정보보호 투자 최적화를 수행했다. 동일한 공격 시나리오에서 CysecTool 모델보다 더 많은 위협들을 제거하는 모델을 개발하고 이를 통해 공격 시나리오에 기반하여 정보보호 투자를 더욱 효율적으로 수행할 수 있도록 한다. 본 연구에서 제안한 모델을 기반으로 병원 정보 시스템에 대한 공격 시나리오를 활용하여 사이버공격의 위험을 더욱 효율적으로 관리할 수 있다. 또한 다양한 해결 방안을 제시함으로써 경영진들의 정보보호 투자 의사결정을 지원할 수 있다.
Recent medical services have been evolving through integration with information and communication technologies. To prevent security incidents in the healthcare service sector, a comprehensive investment in information security, incorporating various security measures, is essential. Sönmez et al. (2022) conducted risk assessments on hospital information system vulnerabilities and optimized security control measures using CysecTool, an attack graph-based information security investment optimization tool. In this study, we created an attack graph by utilizing vulnerability and countermeasure-related data from Sönmez et al. (2022) along with the actual network topology of major hospitals in Korea. Additionally, we improved the limitations of the CysecTool investment optimization model to enhance information security investment optimization. By developing a model that eliminates more threats than the CysecTool model under the same attack scenario, this study enables more efficient cybersecurity investment based on attack scenarios. The proposed model allows for a more effective risk management approach for cyberattacks targeting hospital information systems. Furthermore, by presenting various countermeasures, this research supports decision-making processes for executives in information security investments.
공격 트리를 이용한 산업 제어 시스템 보안 위험 분석 KCI 등재후보
한국융합보안학회 융합보안논문지 제11권 제6호 2011.12 pp.53-58
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
산업 현장에서 일반 컴퓨터와 윈도우 운영체계를 사용하여 생산 시스템을 제어 하게 되면서, 산업 시설에 대한 사이버 보안 위협이 심각한 문제로 대두 되고 있다. 네트워크와 연결된 산업 제어 시스템은 우리가 일상적으로 사용하는 PC나 기업의 정보 시스템에서 문제시 되던 악성코드의 공격에 노출되었다. 특히 컴퓨터 웜인 스턱스넷은 가스 수송관이나 발전소 같은 특정 산업 제어 시스템을 표적으로 하며, 이론상 물리적 타격도 가능하다. 본 논문에서는 산업 제어 시스템 구성 요소와 SCADA의 사이버 보안 위협을 살펴본 후, SCADA 보안 취약점을 조기에 파악하고 평가하여 가능한 사이버 공격을 사전에 대처할 수 있는 위험 분석 방법으로 공격 트리 분석을 고찰한다.
There is increasing use of common commercial operation system and standard PCs to control industrial production systems, and cyber security threat for industrial facilities have emerged as a serious problem. Now these network connected ICS(Industrial Control Systems) stand vulnerable to the same threats that the enterprise information systems have faced and they are exposed to malicious attacks. In particular Stuxnet is a computer worm targeting a specific industrial control system, such as a gas pipeline or power plant and in theory, being able to cause physical damage. In this paper we present an overview of the general configuration and cyber security threats of a SCADA and investigate the attack tree analysis to identify and assess security vulnerabilities in SCADA for the purpose of response to cyber attacks in advance.
공격키워드 사전 및 TF-IDF를 적용한 침입탐지 정탐률 향상 연구 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제2호 2022.06 pp.9-19
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
최근, 디지털전환의 확대로 사이버공격의 위협에 더욱 더 노출되고 있으며, 각 기관 및 기업은 공격이 유입되는 것 을 막기 위해 시그니처 기반의 침입차단시스템을 네트워크 가장 앞단에 운영중에 있다. 그러나, 관련된 ICT시스템에 적절한 서비스를 제공하기 위해 엄격한 차단규칙을 적용할 수 없어 많은 오이벤트가 발생되고, 운영효율이 저하되고 있다. 따라서, 공격탐지 정확도 향상을 위하여 인공지능을 이용한 많은 연구과제가 수행되고 있다. 대부분의 논문은 정 해진 연구용 데이터셋을 이용하여 수행하였지만, 실제 네트워크에서는 연구용 학습데이터셋과는 다른 로그를 이용해야 만 하기 때문에 실제 시스템에서는 사용사례는 많지 않다. 본 논문에서는 실제 시스템에서 수집한 보안이벤트 로그에 대하여 주요 공격키워드를 분류하고, 주요 키워드별로 가중치를 부과, TF-IDF를 이용하여 유사도 검사를 수행후 실제 공격여부를 판단하는 기법에 대하여 제안하고자 한다.
As the expansion of digital transformation, we are more exposed to the threat of cyber attacks, and many institution or company is operating a signature-based intrusion prevention system at the forefront of the network to prevent the inflow of attacks. However, in order to provide appropriate services to the related ICT system, strict blocking rules cannot be applied, causing many false events and lowering operational efficiency. Therefore, many research projects using artificial intelligence are being performed to improve attack detection accuracy. Most researches were performed using a specific research data set which cannot be seen in real network, so it was impossible to use in the actual system. In this paper, we propose a technique for classifying major attack keywords in the security event log collected from the actual system, assigning a weight to each key keyword, and then performing a similarity check using TF-IDF to determine whether an actual attack has occurred.
U-Healthcare 기기에서 DRDoS공격 보안위협과 Big Data를 융합한 대응방안 연구 KCI 등재후보
한국융합학회 한국융합학회논문지 제6권 제4호 2015.08 pp.243-248
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
U-Healthcare는 언제, 어디서나 환자의 건강을 검사하고 관리하며 유지할 수 있도록 하는 의료와 IT가 융합된 서비스이다. U-Healthcare 서비스에서 이루어지는 통신은 검진한 분석 결과나 긴급 데이터를 무선 통신방식을 이용하여 병원 서버에 전송하는 방식이 활용되고 있다. 이 때 악의적인 접근을 수행하는 자(공격자)가 U-Healthcare기기나 BS(Base Station)에 DRDoS(Distributed Reflection DoS)공격을 하면 위급한 환자의 상황정보가 병원 서버까지 전송되지 않는 다양한 피해가 예상된다. 이를 대응하기 위해 DRDoS 공격 시나리오와 DRDoS에 대한 대응방안을 제안하고 대량의 패킷을 처리할 수 있는 빅데이터와 융합한다. 공격자가 U-Healthcare기기나 BS(Base Station)를 공격 시 DB와 연동하여 일치하면 공격을 막는다. 본 논문은 원격의료 서비스인 U-Healthcare기기나 BS에서 나타날 수 있는 공격방법을 분석하고, 빅데이터를 활용하여 보안 위협에서의 대응방안을 제안한다.
U-Healthcare is a convergence service with medical care and IT which enables to examine, manage and maintain the patient’s health any time and any place. For communication conducted in U-Healthcare service, the transmission methods are used that patient’s medical checkup analysis results or emergency data are transmitted to hospital server using wireless communication method. At this moment when the attacker who executes the malicious access makes DRDoS(Distributed Reflection DoS) attack to U-Healthcare devices or BS(Base Station), various damages occur that contextual information of urgent patients are not transmitted to hospital server. In order to deal with this problem, this study suggests DRDoS attack scenario and countermeasures against DRDoS and converges with Big Data which could process large amount of packets. When the attacker attacks U-Healthcare devices or BS(Base Station), DB is interconnected and the attack is prevented if it is coincident. This study analyzes the attack method that could occur in U-Healthcare devices or BS which are remote medical service and suggests countermeasures against the security threat using Big Data.
MIL-STD-1553 보안 위협 검증을 위한 저비용 테스트베드 구현 및 공격 시나리오 분석 KCI 등재
한국융합보안학회 융합보안논문지 제26권 제2호 2026.03 pp.95-103
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
국방 및 항공우주 표준인 MIL-STD-1553은 보안 설계의 부재로 다양한 위협에 노출되어 있으나, 고가의 장비와 폐쇄성으 로 인해 실증적 연구가 어렵다. 이에 본 연구는 아두이노를 활용한 저비용 모의 테스트베드를 구현하여 접근성 문제를 해결하 였다. STRIDE 기법을 통해 도출된 스니핑 및 스푸핑 시나리오를 테스트베드에서 검증한 결과, 평문 데이터 노출에 따른 기밀 성 침해와 위조 메시지 주입에 의한 무결성 훼손을 실험적으로 확인하였다. 본 연구는 저비용으로 구형 항공전자 시스템의 보 안 취약점을 효과적으로 검증할 수 있는 환경을 제시하였다.
MIL-STD-1553 lacks security considerations, yet empirical verification is difficult due to high equipment costs and limited accessibility. This paper proposes a low-cost Arduino-based testbed to address this issue. We applied STRIDE threat modeling to identify sniffing and spoofing attacks and experimentally verified them. The results demonstrated confidentiality breaches through plaintext exposure and integrity violations caused by unauthorized message injection. This study contributes by presenting an accessible environment for analyzing legacy avionics vulnerabilities.
천안함 침몰사건과 연명도 포격사건을 통해 본 ‘국가안보’와 ‘인간안보’
아주대학교 법학연구소 아주법학 제4권 제2호 2010.12 pp.243-285
※ 기관로그인 시 무료 이용이 가능합니다.
9,000원
자동차 내부망 통신네트워크 해킹범죄예방을 위한 융합보안적 대응방안 : Bluetooth 활용사례를 중심으로 KCI 등재
한국융합보안학회 융합보안논문지 제16권 제6호 제2호 2016.10 pp.99-107
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
이 연구의 목적은 Bluetooth를 활용한 자동차의 내부망 통신네트워크를 해킹공격으로부터 예방하기 위한 대응방안을 제시하기 위함이다. 이를 위해 2장에서는 자동차 통신네트워크의 정의와 내부망 통신네트워크의 종류에 대해서 살펴보 았다. 3장에서는 자동차 내부망 통신네트워크 해킹위험성을 분석하기 위해 Bluetooth에 의한 해킹범죄사례를 살펴보았 다. 4장에서는 본 연구의 결과로서 첫째, 『자동차안전기준에 관한 규칙』개정이 이루어져야 한다. 동법에서는 전자제 어시스템의 정의 및 기준사항과 안전운행을 위한 제작 및 정비를 규정해 놓았음에도 불구하고 전자제어시스템을 대상 으로 한 해킹범죄 예방 및 방어와 관련된 보안프로그램 혹은 펌웨어 등의 제작과 관련된 규정이 없는 실정이다. 둘째, 자동차의 전자제어시스템 기술의 복잡성에 기인된 자동차 통신네트워크를 보호하고자 자동차 통신네트워크 보호 법률 이 신설되어야 한다.
The purpose of this study is to analyse motor vehicle communication network hacking attacks and to provide its prevention. First, the definition of motor vehicle communication network was provided and types of in-vehicle communication network were discussed. Also, bluetooth hacking attack cases were analysed in order to illustrate dangers of hacking attacks. Based on the analysis, two preventive measures were provided. First, Motor Vehicle Safety Standard Law should be revised. Although the law provides the definition of electronic control system and its standards as well as manufacturing and maintenance for safe driving standards, the law does not have standards for electronic control system hacking prevention and defensive security programs or firmware. Second, to protect motor vehicle communication network, it is necessary to create new laws for motor vehicle communication network protection.
소프트웨어 보안성 증진을 위한 취약점 특성 분석 및 AI기반 공격기법 분류 시스템 제안 KCI 등재
한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제14권 특별호 2024.01 pp.179-201
※ 기관로그인 시 무료 이용이 가능합니다.
6,000원
최근 은행, 공공기관 등에서 사용되는 고전적인 소프트웨어에서 PC 해킹 및 악성코드 유포가 이루어지는 등 보안위협이 제기되고 있다. C 스타일로 제작되어 프로그램에 자체적으로 내장된 취약점의 특성상 이로 인한 해킹의 연쇄효과는 막대하며 특정 서비스 이용을 위해 반드시 설치 해야하는 프로그램인 경우 그 파급효과가 매우 크다는 점에서 개인정보 유출과 금융 보안에 매 우 중요한 영향을 미친다. 이에 본 논문에서는 이러한 프로그램 자체에 내장되어있는 보안 취약 점으로 인한 시스템 해킹 공격기법들의 특성과 feature를 도출하여 AI의 학습에 활용될 수 있는 기반기술을 제안하고자한다. 이에 더 나아가 취약점에 따른 공격(Exploitation) 템플릿들을 자동 생성 할 수 있는 시스템을 제안하고자 한다.
Recently, security threats such as PC hacking and malicious code distribution are being raised in classic software used in banks and public institutions. Due to the characteristics of vulnerabilities built in the C style and built into the program itself, the chain effect of hacking caused by this is enormous, and in the case of programs that must be installed to use a specific service, the ripple effect is very large, which is very important for personal information leakage and cyber security. have a significant impact In this paper, we propose a basic technology that can be used for AI learning by deriving the characteristics and features of system hacking attack techniques due to security vulnerabilities built into the program itself. Furthermore, we propose a system that can automatically generate exploit templates according to vulnerabilities.
무아레를 이용한 융합 보안토큰생성과 전파공격 보호 기법 KCI 등재
한국융합학회 한국융합학회논문지 제10권 제2호 2019.02 pp.7-11
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
급격한 전파를 이용하는 기기의 다양화와 대중화로 인해 많은 전파 관련 보안 문제들이 일어나고 있다. 일상적인 생활에서의 전파의 안전은 매우 밀접한데 전파의 방해와 교란은 단순 생활의 불편뿐 아니라 신체의 직접적인 피해를 입힐 수도 있기 때문에 전파보호는 매우 중요한 과제이다. 본 논문에서는 전파 교란과 교섭을 막기 위한 방안으로 백색광 광원, 투영격자와 광원으로 영사식 무아레를 측정 하여 기준격자 및 변형격자의 영사 이미지를 획득한 후 위상도를 알고리즘에 적용하여 화상처리 알고리즘으로 무아레 무늬를 생성하고 무늬 위상도를 3차원 형상도로 생성한다. 이렇게 측정된 얼굴 형 상을 이용한 암호화된 토큰을 만들어 토큰링을 통한 정보의 수신여부를 결정 하여 인증 강도, 호출자의 정보 등이 포함된 동적 보안 속성을 가진 수평 전파를 전송하고 java직렬화와 직렬화 해제 기능을 이용하여 토큰의 고유성을 확인 수평전파를 송·수신 하여 문제점을 해결하는 기법을 제안하였다.
Due to diversification and popularization of devices that use rapid transmission, there are many security issues related to radio waves. As the disturbance and interference of the radio wave can cause a direct inconvenience to a life, it is a very important issue. In this paper, as a means to prevent radio disturbance and interference, the projected image of the reference grid and the deformed grid is obtained by measuring the projected moiré using the white light source, projecting grid and the light source, and a moiré pattern is generated with an image processing algorithm by applying a phase diagram algorithm, and generated moiré pattern phase diagram creates a three-dimensional shape. By making an encrypted token using this measured face shape, the transmission of the information through token ring is determined in order to transmit the horizontal transmission having the dynamic security characteristics which includes authentication strength and caller information, etc. And by confirming the uniqueness of the token and by sending and receiving the horizontal transmission using java serialization and deserialization function, a problem solving method is suggested.
오픈소스 활용 드론에 대한 보안 위협과 Telemetry Hijacking을 이용한 군용 드론 공격 시나리오 연구 KCI 등재
한국융합보안학회 융합보안논문지 제20권 제4호 2020.10 pp.103-112
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 민간에서는 취미/레저용 드론에 대한 관심이 많아지고 있으며 군에서도 북한, 미국, 이란 등 다양한 나라에서 드론을 활용하여 정찰, 파괴 등의 군사 목적으로 사용하게 되면서 우리 군 내에서도 드론 부대를 창설하여 드론 운용을 하는 등 다양한 드론 관련 연구가 진행되고 있다. 특히, 최근 드론 개발자들은 드론 비행 제어 소스코드의 크기가 커지 고 기능들이 많아짐에 따라 오픈소스를 가져와 활용하는 것에 익숙해지고 있으며 별도의 보안 취약점에 대한 점검없이 활용하고 있다. 그러나 실제로 이러한 오픈소스는 공격자가 접근가능하기 때문에 다양한 취약점에 노출될 수 밖에 없으 며, 본 논문에서는 Telemetry Hijacking 기법을 활용하여 이러한 취약점과 연계하여 오픈소스를 사용하는 군용 드론에 대한 공격 시나리오를 제시한다.
Recently, the interest in hobby/leisure drones is increasing in the private sector, and the military also uses drones in various countries such as North Korea, the United States, and Iran for military purposes such as reconnaissance and destruction. A variety of drone related research is underway, such as establishing and operating drone units within the Korean military. Inparticular, recently, as the size of drone flight control source code increases and the number of functions increases, drone developers are getting accustomed to using open sources and using them without checking for separate security vulnerabilities. However, since these open sources are actually accessible to attackers, they are inevitably exposed to various vulnerabilities. In this paper, we propose an attack scenario for military drones using open sources in connection with these vulnerabilities using Telemetry Hijacking techniques.
보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.8 No.8 2014.08 pp.171-180
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Regardless that the classic buffer overflow is a known and simple threat against software systems; security agencies still consider this threat as one of the most common software vulnerabilities. Aiming to increasing security resistance against this software threat, emphasize on software design phase is highly reasonable where cost and time required for fixing error in design level is several times lesser than coding or implementation levels. In this purpose, we use the Attack-based security analysis model for tracking and mitigating the classic buffer overflow during the software design phase. Through this model, we use known properties and behaviors of the buffer overflow to determine system vulnerabilities and address required security aspects. In this paper, we describe how to apply the Attack-based security analysis model for increasing security resistance against the classic buffer overflow. The main contribution of this work refers to showing capability of the Attack-based security analysis model in tracking and mitigating the classic buffer overflow into the software design phase in such a way that additional cost and time are not required for system analyzing and defining threat scenario.
Android's External Device Attack : Demonstration and Security Suggestions SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.4 2015.04 pp.317-326
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Two Way Authentication in MITM Attack to Enhance Security of E-commerce Transactions SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.9 2015.09 pp.265-274
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Serviceable and secure authentication is a research field that approaches dissimilar challenges related to authentication, including security, from a human-computer interaction perspective. The process of identifying an individual usually based on an email id and passwords. In this paper, we focus on client and server authentication. We examine the phishing problem, Man-In-The-Middle Attack, The main challenge in the design of a security system for high security is, how to prevent the attacks against data modification and authentication. Web based delivery is one of the most complicated phishing techniques. Also known as “man-in-the-middle,” the hacker is being found on the original website and the phishing system.
Security Management for Distributed Denial of Service Attack KCI 등재후보
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.7 No.2 2010.04 pp.99-110
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
A SECURITY DV-Hop Localization Algorithm Resist Spoofing Attack SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.11 2015.11 pp.303-312
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In order to reduce the node position error of DV-Hop algorithm in wireless sensor network, the artificial bee colony algorithm is introduced to design the DV-Hop algorithm. A new ABCDV-Hop (Artificial Bee Colony DV-Hop) algorithm is proposed in this paper. Based on the traditional DV-Hop algorithm, by using the minimum hops of nodes and position information of anchor nodes, the average distance per hop is solved by artificial bee colony algorithm to make it more close to the actual value. The simulation results show that compared with the traditional DV-Hop algorithm, the improved algorithm can effectively reduce the positioning error without increasing the node hardware overhead.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.