Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 7
No
1

무인항공기의 안전한 도입을 위한 보안기능요구사항 개발 KCI 등재

강동우, 원동호, 이영숙

한국융합보안학회 융합보안논문지 제19권 제4호 2019.10 pp.97-106

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

니콜라 테슬라에 의해 항공기의 무선제어 가능성이 제시되면서 출현한 무인항공기는 제 1, 2차 세계대전을 통해 항공력의 급속한 발전과 함께 군사, 방산용으로 사용하게 되었다. 2000년대, 무인항공기의 분야가 촬영, 배송, 통신 등 민간분야까지 확대 됨에 따라 여러 서비스와 융합되어 활용되고 있다. 하지만, 최근 무인항공기 시스템에서의 통신이나 무인항공기 자체의 보안 취 약점을 이용하여 GPS 스푸핑, 전파 교란 공격 등을 시도하는 보안사고가 발생하고 있다. 이에, 안전한 무인항공기의 도입을 위 하여 국내에서는 자체 무인항공기 검증 제도인 감항 인증 제도가 마련되었다. 그러나 감항 인증 제도는 무인항공기의 보안성보 다는 시험 비행, 설계 및 물리적 구조의 안전성과 인증하는 쪽에 초점이 맞추어져 있다. 보안성 높은 안전한 무인항공기의 도입 을 위해 본 논문에서는 무인항공기 시스템 모델을 제안하고 데이터 흐름도를 작성하였다. 작성한 데이터 흐름도를 바탕으로 무 인항공기 시스템에서의 위협을 도출하였고, 도출한 위협을 방지할 수 있는 보안기능요구사항을 개발하였다. 제안한 보안기능요 구사항을 통해 향후 무인항공기의 안전한 도입을 위한 앞으로의 평가, 검증 기술의 발전 방향을 제시한다

With the possibility of wireless control of the aircraft by Nicola Tesla, Unmanned Aerial Vehicle(UAV) was mainly used for military an d defense purposes with the rapid development through World War I and II. As civilian applications of unmanned aerial vehicles have exp anded, they have been used with various services, and attempts have been made to control various environmental changes and risk factor s of unmanned aerial vehicles. However, GPS spoofing, Jamming attack and security accidents are occurring due to the communication in the unmaned aerial vehicle system or the security vulnerability of the unmanned aerial vehicle itself. In order to secure introduction of Un manned aerial vehicle, South Korea has established Unmanned Aerial Vehicle verification system called Airworthiness Certification. Howe ver, the existing cerfication system is more focused on test flight, design and structure's safety and reliability. In this paper, we propose a unmanned aerial vehicle system model and propose security functional requirements on unmanned aerial vehicle system in the correspon ding system model for secure-introduction of Unmanned Aerial Vehicle. We suggest the development direction of verification technology. From this proposal, future development directions of evaluation and verification technology of Unmanned Aerial Vehicle will be presented.

2

보안기능요구사항명세서 개발도구 KCI 등재후보

문길종, 이성권, 류동주

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.8 No.5 2011.10 pp.509-524

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

정보기술의 발달과 정보화가 확대됨에 따라 정보시스템의 안전한 관리에 대한 중요도가 커져가고 있다. 이러한 정보시스템의 안전한 관리를 위한 정보보호제품의 보안기능 검증을 통해 사용자에게 신뢰성에 대한 보증이 요구된다. 정보보호제품의 평가는 국제공통기준인 CC(Common Criteria)가 있으며, 특히 국내의 경우 이에 대비하기 위한 다양한 보호프로파일들의 개발이 시급하며, 그 수요 또한 폭발적으로 증가할 것으로 기대된다. 따라서, 본 연구에는 향후 지속적인 보안기능요구사항명세서 작성 업무의 효율성과 편리성을 제공하기 위하여, “보안기능요구사항명세서 개발도구”인 SFRS을 개발하였다.

Development of information technology and the proliferation of information, depending on the importance of safe management of information systems is growing. These information systems for the safe management of information security products to the user through the verification of the security guarantee of reliability is required. The evaluation of information security products CC (Common Criteria) has, especially in preparation for the case of the domestic variety stimulated the development of protection profiles, and the demand is also expected to increase exponentially. Therefore, the study continued, the future business of writing security requirements specification in order to provide efficiency and convenience, "Security Requirements Specification Development Tool" was developed with SFRS.

3

CC 3.1 기반 무선위협관리시스템(AIRTMS V1.0) 보안기능요구사항 개발 KCI 등재후보

고갑승, 문길종, 류동주

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.8 No.6 2011.12 pp.645-655

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

선진 각국에서는 안전한 IT 환경을 보증하기 위하여, 다양한 정보보증제도를 시행하고 있다. 이 중 국내에서는 정보보호제품평가인 CC평가제도(Common Criteria)를 시행하고 있으며, 보호프로파일 (Protection Profile, PP) 및 보안목표명세서(Security Target, ST)를 활용하여 보안성 평가를 시행하고 있다. 현재, 스마트 기기에 대한 사용이 증가하면서 무선랜에 대한 무선정보보호에 관심이 증가되고 있으며, 무선랜에 대한 무선정보보호제품에 대한 수요가 높아질 것으로 예상된다. 이에 따라, 무선정 보보호제품에 대한 보안성평가가 필수적으로 요구되고 있으며, 무선정보보호제품군의 CC 평가에 대 비한 보호프로파일의 개발이 시급한 실정이다. 따라서, 본 논문에서는 안전한 무선랜의 사용을 관리하는 무선위협관리시스템인 AIRTMS V1.0을 소개하며, 무선정보보호제품군의 보호프로파일 개발에 참고자료로써 활용될 AIRTMS V1.0의 보안목 표명세서를 소개하고자한다.

In developed countries in order to guarantee a secure IT environment, have implemented a variety of information assurance systems. In Korea, PP and ST has been implemented by taking advantage of the CC. Currently, the increasing use of smart devices on the Wireless LAN to have increased interest in information security. So Wireless LAN for information security products is expected to increase demand for. Accordingly, the wireless information security product is essential for the security assessment is required, and the CC family of wireless information security is required in preparation for the development of PP. Therefore, in this paper that govern the use of a secure wireless LAN introduce AIRTMS V1.0 and wireless information security protection profile in the development of family AIRTMS V1.0 serve as references will be introduced in the Security Target.

4

정보보호 운영시스템 수준의 보안기능요구사항명세서 지원도구 개발 KCI 등재후보

김영선, 고갑승, 신재인, 방영환

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.7 No.1 2010.02 pp.29-42

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

정보기술의 발달과 정보화가 확대됨에 따라 정보시스템의 안전한 관리에 대한 중요도가 커져가고 있다. 이러한 정보시스템의 안전한 관리를 위한 정보보호제품의 보안기능 검증을 통해 사용자에게 신뢰성에 대한 보증이 요구된다. 본 논문은 기존의 제품 평가내의 보안요구사항명세서 뿐만 아니라, 운영시스템 수준의 보안요구사항명세서 개발을 지원하는 SFRS v2.0 v2.0(Security Functional Requirement Specification)도구를 제시하고자 한다.

According as development and computerization of Information Technology are expanded, importance about safe management of information system. Assurance about authoritativeness is required to user through security function verification of information security product for safe management of information system. In this paper, presents security functional requirement specification(SFRS v2.0) v2.0 in product level(i.e., PP(Protection Profile) or ST(Security Target) in CC(Common Criteria)) and security requirement specification in system level(i.e., SPP(System Protection Profile) or SST(System Security Target) in ISO/IEC 19791).

5

클라우드 시스템 보안기능요구사항 분석 KCI 등재

이현정, 원동호

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.9 No.6 2012.12 pp.495-502

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

최근 IT 기술이 고도화됨에 따라 기업, 금융, 국가기관 등 주요 IT 인프라 환경이 클라우드 시스템 기반으로 이동할 것으로 예측되며, 이에 따른 클라우드 시스템 환경의 안전성과 신뢰성에 대한 요구 가 증대되고 있다. 그러나 현재 클라우드 시스템 기술 도입 시 여러 기술적, 제도적인 문제로 인하여 클라우드 시스템에 대한 보안문제를 우려하고 있는 실정이다. 이에 본 논문에서는 클라우드 시스템의 보안 위협들을 조사 및 검토하고 안전한 클라우드 컴퓨팅 기술 적용을 위한 보안기능요구사항들을 조사 및 분석하였다.

IT technology advancement as accordingly, is expected to move into the cloud-system-based corporate, financial, and national institutions, including major IT infrastructure environments are increasing demands on the safety and reliability of the cloud system environment. However, current cloud system technology introduced several technical concerns and security issues for cloud systems, due to institutional problems. In this paper, investigation and review of the threat the security of the cloud system and security features for secure cloud computing technology requirements and analyzed.

6

A Prototyping on Common Criteria Evaluation Security functional Requirement for Developer of IT products supporting tool.

한경수, 정현미, 이강수

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2012 pp.702-705

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

공통평가 기준(CC, Common Criteria)은 정보 보호 제품, 즉 IT제품에 대한 보안성을 평가하기 위한 국제 평가 기준이다. 그러나 개발자 측면에서는 CC 에서 정의된 보안 기능 사항 중 IT제품 개발에 있어서 어떤 보안기능을 요구하며, 적용 가능한 IT기술에는 무엇이 있는지 알기 어렵다. 이 때문에 평가를 받고자 할 때 제출물을 작성하거나 IT제품 개발에 있어서 많은 시간과 인력이 필요하게 된다. 본 논문은 IT제품 개발자를 위해 공통평가 기준에서 정의하여 서술된 보안기능항목을 이해하고 적용 가능한 IT기술에는 어떤 것 들이 있는지 제시하기 위한 도구를 개발하기 위해 CC(Ver3.1)2부 보안기능 요구사항 중 프라이버시 클래스만을 해결할 수 있는 S/W를 개발 및 프로토타이핑 하였다.

7

공통평가기준에서의 클라우드 환경에 적용 가능한 보안기능요구사항(SFR)에 관한 연구

위유경, 곽진

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2013 pp.731-734

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

클라우드 컴퓨팅이 활성화됨에 따라 다양한 클라우드 서비스가 대중적으로 보급되고, 그에 따른 클라우드 컴퓨팅 관련 제품들을 IT시장에서 쉽게 접할 수 있게 되었다. 일반적으로 IT 제품군에 대해서 보안성평가를 수행하고, 그 결과 값을 통해 소비자에게 객관적인 지침으로 활용될 수 있는 국제 표준인 공통평가기준에서는 보안 제품군에 대한 보안목표명세서인 보호프로파일을 제공하고 있다. 하지만 현재 일반적인 IT제품군에 대한 보호프로파일은 존재하나 클라우드 관련 제품군에 대해서는 보호프로파일이 존재하지 않아 보안성평가를 위한 방법이 없는 실정이다. 따라서 본 논문에서는 공통평가기준을 준수하는 클라우드 환경에 적용 가능한 보안기능요구사항을 도출하고자 한다. 도출한 보안기능요구사항을 통해 클라우드 제품군에 대한 보안성을 적용하기 위한 평가 방법으로 사용될 수 있다.

 
페이지 저장