Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 160
No
1

조직의 능동적 보안문화 형성을 위한 활성화 요인에 관한 연구 KCI 등재

안병구, 유하랑, 장항배

한국융합보안학회 융합보안논문지 제20권 제2호 2020.06 pp.3-13

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

급속하게 변화하는 ICT 기반의 산업 환경이 조성되면서 조직은 새롭게 발생하는 보안위협에 당면하고 있다. 조직은 보안 위협에 대한 대응방안의 일환으로 조직구성원 대상의 보안문화 내재화를 수립하고자 하고 있다. 그러나 보안활동 이행으로 인 해 업무 프로세스에서 발생하는 불편사항이 존재하고 기존의 보안문화 정립 방안은 제어, 통제 등의 규범적 성격이 강조됨에 따라 조직구성원들의 보안 수용성이 낮은 실정이다. 본 논문에서는 능동적인 조직 보안문화의 활성화를 하나의 대응방안으로 구축하기 위해 기존의 수동적인 보안문화 정립 방안에서 벗어나 전사적 보안업무 효율을 높고 조직구성원의 자발적 참여를 유도할 수 있는 보안문화를 형성하고자 하였다. 이에 따라 관련 선행연구 간의 비교·분석을 진행하고 도출된 실행요소에 대해 통계적 검증을 수행하였다. 본 연구에서 도출된 보안문화 활성화 요인을 통해 향후 보안문화 수준측정을 위한 연구에 기여할 수 있을 것으로 기대된다.

Organizations are facing a new, diverse security threat as ICT based industrial environment arises. As a way of effective countermeasure for security threat, organizations are making an effort to establish internalization of security culture, targeting a organizational members. However, members’ awareness toward security receptiveness is low as inconvenience exists in business process and existing security culture focuses on controlling and regulating. Accordingly, this research desires to develop a participatory security culture which can higher the efficiency of security work process and induce members’ voluntary participation. A comparative analysis on security culture related prior researches is conducted and based on a drawn components, statistical verification is accomplished. It is expected to contribute on future research on measuring a security culture level.

2

산업기술 보호 관리실태 및 발전방안에 관한 연구 KCI 등재

정태황, 장항배

한국보안관리학회(구 한국경호경비학회) 시큐리티 연구 제24호 2010.09 pp.147-170

※ 기관로그인 시 무료 이용이 가능합니다.

6,100원

본 연구는 산업기술 보호를 위한 관리적 발전방안을 마련하기 위하여 공공기관, 대기업, 중소기업 등을 대상으로 관리적 보안실태에 대해 조사․분석을 실시하였으며, 그 결과는 다음 과 같다. 첫째, 보안정책을 효과적으로 실행할 수 있는 기반 구축이 필요하다. 조사대상 대부분이 보안규정을 잘 관리하고 있으나 보안규정을 지키거나 지속적으로 개선하려는 노력이 부족한 것으로 나타났다. 이를 개선하기 위하여 보안전담조직과 보안담당자 운영방법을 개선할 필요 가 있으며, 보안규정을 모든 구성원에게 알리고 보안업무 수행을 위한 팀 간 업무 공조체계를 이룰 수 있는 조직문화를 활성화 할 필요가 있다. 이와 함께 지속적인 보안점검과 보안감사를 통해 보안의식을 향상시키고, 보안규정 준수 여부를 직원업무평가에 반영함으로써 보안정책 을 가시화 할 필요가 있다. 둘째, 보안활성화를 위한 보안투자가 필요하다. 기술 유출경로와 수단이 다양화․첨단화 되어가고 있을 뿐 아니라 복잡하고 빠른 속도로 변화하기 때문에 관련 전문기관인 국가정보원, 한국인터넷진흥원, 정보보호 컨설팅 전문기업, 관련 대학 및 연구소 등과의 협조채널 유지하 고, 필요에 따라서는 보안 전문기관으로부터 outsourcing 도입을 검토할 필요가 있다. 특히 공공기관이나 대기업에 비해 보안정책 운영실태가 미흡한 중소기업은 조직 규모나 재정적 여 건을 감안하여 보안관리 능력을 보강할 수 있도록 국가적인 차원의 지원시스템을 증가할 필요 가 있다. 셋째, 산업기술 유출의 주체는 사람으로 인력관리가 중요하다. 신규 입사자와 임직원을 대상으로 하는 정기적인 교육률은 높은 것으로 평가되나 핵심기술에 접근하는 임직원과 제3자로부 터의 보안서약서 작성과 중요자산에 대한 접근권한이 변경될 때 접근권한 변경 적용과 같은 업무의 활성화가 필요하다. 중요기술을 다루는 사람에 한하여 신원조사를 실시할 수 있는 여건 조성이 필요하며, 퇴사자에 대한 보안서약서 징구와 정보시스템에 대한 접근권한 제거, 계정 삭제와 같은 퇴직자 관리를 강화할 수 있어야 한다. 넷째, 중요한 자산에 대한 관리와 통제를 강화해야 한다. 자산에 대한 목록과 관리기준은 비교적 잘 정리되어 있으나 자산의 중요성에 따른 등급화작업의 활성화와 자산의 유출 및 손상 의 경우를 대비한 영향 정도를 평가할 수 있는 작업이 필요하다. 자산에 대한 중요도는 시간흐 름 및 업무특성에 따라 변화되기 때문에 주기적인 자산평가 작업과 분류작업을 통해 사용자별 로 권한을 설정할 수 있어야 한다.

This study is to present a improvement directions for the protection of industrial key technology. For the purpose of the study, the survey was carried out on the administrative security activity of 68 enterprises including Large companies, small-midium companies and public corporations. survey result on the 10 items of security policy, 10 items of personal management and 7 items of the assets management are as follows; First, stable foundation for the efficient implement of security policy is needed. Carrying a security policy into practice and continuous upgrade should be fulfilled with drawing-up of the policy. Also for the vitalization of security activity, arrangement of security organization and security manager are needed with mutual assistance in the company. Periodic security inspection should be practiced for the improvement of security level and security understanding. Second, the increase of investment for security job is needed for security invigoration. Securing cooperation channel with professional security facility such as National Intelligence Service, Korea internet & security agency, Information security consulting company, security research institute is needed, also security outsourcing could be considered as the method of above investment. Especially small-midium company is very vulnerable compared with Large company and public corporation in security management, so increase of government's budget for security support system is necessary. Third, human resource management is important, because the main cause of leak of confidential information is person. Regular education rate for new employee and staff members is relatively high, but the vitalization of security oath for staff members and the third party who access to key technology is necessary. Also access right to key information should be changed whenever access right changes. Reinforcement of management of resigned person such as security oath, the elimination of access right to key information and the deletion of account. is needed. Forth, the control and management of important asset including patent and design should be tightened. Classification of importance of asset and periodic inspection are necessary with the effects evaluation of leak of asset.

3

개발 환경 보안수준 점검도구 연구 KCI 등재후보

고일석

한국융합보안학회 융합보안논문지 제6권 제4호 2006.12 pp.133-140

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

IT 제품 개발환경에 대한 보안수준을 점검하기 위해서는 IT 제품 개발환경에 존재하는 취약성과 각종 위협 요인을 분석하고 정보보호 수준을 정확히 평가하고 이를 개선시킬 방향을 제시하는 기준과 평가 도구가 필요하다. 또한 이를 위해 관련분야에 대한 정보보호 수준을 평가하고 개선할 수 있는 평가 지표나 기준과 이를 실제 IT 제품 개발환경에 적용할 수 있는 평가방법론이 연구되어야 한다. 본 연구는 IT 제품 개발 환경의 보안수준을 점검하기 위한 확인 도구를 개발하는 것을 목표로 하고 있다.

For the verification of the security level against a IT product development environment, we should analyze the vulnerability and the various threatening factors which exists in the IT product development environment. Also we need the evaluation criteria and tools for evaluation and improvement of the level of information security. For that, we need evaluation indices and the standard it will be able to improve the evaluation methodology in the actual IT product development environment which will reach it will be able to apply must be researched. In this study, our aims are the development of verification tools for the security level of IT product development environment.

4

A Security Level Decision Method for Multimedia System

김태훈, 이덕규, 여상수, 조성언

[Kisti 연계] 한국항행학회 한국항행학회논문지 Vol.12 No.1 2008 pp.61-67

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

특정 목적을 달성하기 위해서 멀티미디어 시스템을 구축하고 운영하는 조직은, 보안수준을 결정하고, 보안대책을 구현하며, 보안대책의 효과를 유지하기 위해 관리를 하여야 한다. 멀티미디어 시스템이 보안수준을 결정하고 관리하기 위해서, 첫째, 조직은 보안 수준을 결정할 수 있어야 하고, 둘째, 보안 수준에 따라 보안대책을 수립하는 절차를 확립하여야 하며, 셋째, 보안대책이 적용되어야 하는 영역을 결정할 수 있어야 하고, 마지막으로 조직은 보안대책의 효과를 평가하고 개선할 수 있어야 한다. 본 논문에서는 멀티미디어 시스템에 대한 위협의 분석, 멀티미디어 자산의 중요도 분석에 기반하여 멀티미디어 시스템의 보안수준을 결정하는 방법을 제안하였다.

Each organization installing and operating multimedia system, to achieve the goal of organization, should decide security level, implement security countermeasure, and manage these countermeasures to keep the effects. To decide and manage security level of multimedia system, the first, organizations must be able to decide security level, and then, organizations must establish procedures for building security countermeasures according to security level. For the next step, organizations must be able to select areas where security countermeasures should be applied, and the last, organizations must be able to evaluate and improve the effect of security countermeasures. In this paper, based on the analysis of threat to multimedia system and the consideration for multimedia assets, we propose a method for deciding security level of multimedia system.

5

FIDO 인증 체계의 구현상 보안 취약점의 분류와 실제 사례 분석을 통한 설계 가이드라인 제시

함주혁, 조해현

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.2 2026 pp.515-531

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

FIDO 프로토콜은 공개 키 암호화 방식 기반의 비밀번호 없는 강력한 인증 표준으로서 높은 수학적 안전성을 보장하지만, 실제 서비스 환경에서의 구현 과정에서는 다수의 보안 사각지대가 발생할 수 있다. 본 연구에서는 FIDO 인증 구현 단계에서 발생 가능한 보안 위협을 체계적으로 분류하고, 이를 기반으로 정부24 서비스에서 발생한 중간자 공격을 통한 전자서명 탈취 취약점 및 인증 우회로 인한 대규모 계정 탈취 취약점 사례를 분석한다. 아울러 이러한 분석을 토대로 설계 시 필수적으로 검증하여야 할 보안 요구사항을 제언함으로써 안전한 FIDO 인증 체계의 구축을 위한 구체적인 가이드라인을 제시한다. 본 연구는 FIDO 인증 도입 과정에서 반복적으로 발생할 수 있는 취약점의 예방을 위한 실무적 기준을 제시한다는 점에서 의의를 갖는다.

Although the FIDO protocol provides a strong passwordless authentication standard based on public-key cryptography and ensures a high level of mathematical security, numerous security blind spots may arise during its implementation in real-world service environments. This study systematically classifies security threats that can occur at the implementation stage of FIDO authentication and, based on this classification, analyzes practical vulnerability cases identified in the Government24 service, including a man-in-the-middle attack leading to the theft of electronic signatures and an authentication bypass vulnerability resulting in large-scale account takeover. Furthermore, drawing on these analyses, this study derives essential security requirements that must be verified during the design phase and presents concrete guidelines for building secure FIDO-based authentication systems. This work contributes practical criteria for preventing recurrent implementation vulnerabilities in the deployment of FIDO authentication systems.

6

다변수 이차식 기반 서명 기법 Rainbow의 공격 기법 및 보안강도 분석

조성민, 김제인, 서승현

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.31 No.3 2021 pp.533-544

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

양자적 특성을 활용한 Shor 알고리즘은 인수분해 및 이산대수 문제를 효율적으로 풀 수 있다. 이로 인해 RSA, 타원곡선(ECC: Elliptic Curve Cryptography) 등 인수분해와 이산대수 문제의 어려움에 기반하고 있는 기존 공개키 암호 시스템이 위협받고 있다. 이에 미국 국립표준기술연구소(NIST)에서는 양자 컴퓨터의 강력한 연산 능력에도 안전한 새로운 공개키 암호 체계의 표준인 양자 내성 암호(PQC: Post Quantum Cryptography)를 선정하는 공모를 진행하고 있다. 양자 내성 암호 후보군 중 다변수 이차식 기반 서명 기법은 짧은 서명 길이와 빠른 서명 및 검증으로 인해 사물인터넷(IoT) 등 제한된 자원을 갖는 기기에 적합하다. 이에 본 논문에서는 다변수 이차식 기반 서명 중 유일하게 3 라운드까지 최종 선정된 Rainbow에 대한 클래식 공격 기법과 양자적 특성을 이용한 공격 기법들을 분석하고, 현재 3라운드에 제시된 레인보우 파라미터에 대한 공격 복잡도를 계산하여 양자 내성 암호표준화 후보 알고리즘인 레인보우 서명기법이 제공하는 보안 강도를 분석한다.

Using Shor algorithm, factoring and discrete logarithm problem can be solved effectively. The public key cryptography, such as RSA and ECC, based on factoring and discrete logarithm problem can be broken in polynomial time using Shor algorithm. NIST has been conducting a PQC(Post Quantum Cryptography) standardization process to select quantum-resistant public key cryptography. The multivariate quadratic based signature scheme, which is one of the PQC candidates, is suitable for IoT devices with limited resources due to its short signature and fast sign and verify process. We analyzes classic attacks and quantum attacks for Rainbow which is the only multivatiate quadratic based signature scheme to be finalized up to the round 3. Also we compute the attack complexity for the round 3 Rainbow parameters, and analyzes the security level of Rainbow, one of the PQC standardization candidates.

7

자연어 처리 기반 멀티 소스 이벤트 로그의 보안 심각도 다중 클래스 분류

서양진

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.32 No.5 2022 pp.1009-1017

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

로그 데이터는 정보 시스템의 주요 동작과 상태를 이해하고 판단하는 근거로 사용되어 왔으며, 여러 보안 분야 응용에서도 중요한 입력 데이터로 사용된다. 로그 데이터로부터 필요한 정보를 얻어 이를 근거로 의사 결정을 하고, 적절한 대응 방안을 취하는 것은 시스템을 보호하고 안정적으로 운영하는 데 있어 필수적인 요소이지만, 로그의 종류와 양이 폭발적으로 증가함에 따라 기존 도구들로는 효과적이고 효율적인 대응이 쉽지 않은 상황이다. 이에 본 연구에서는 자연어 처리 기반의 머신 러닝을 이용해 멀티 소스 이벤트 로그의 보안 심각도를 여러 단계로 분류하는 방법을 제안하였으며, 472,972건의 훈련 및 테스트 샘플을 이용하여 실험을 수행한 결과 99.59%의 정확도를 달성하였다.

Log data has been used as a basis in understanding and deciding the main functions and state of information systems. It has also been used as an important input for the various applications in cybersecurity. It is an essential part to get necessary information from log data, to make a decision with the information, and to take a suitable countermeasure according to the information for protecting and operating systems in stability and reliability, but due to the explosive increase of various types and amounts of log, it is quite challenging to effectively and efficiently deal with the problem using existing tools. Therefore, this study has suggested a multiclass classification of the security severity level of multi-source event log using machine learning based on natural language processing. The experimental results with the training and test samples of 472,972 show that our approach has archived the accuracy of 99.59%.

8

4,000원

본 연구의 목적은 국가핵심기술을 보유하고 있는 기업들의 물리보안수준이 보안성과와 업무효율성에 미치 는 영향을 분석하는데 있다. 이를 위해 보안요원 200여명을 대상으로 한 달 동안 설문조사를 실행하였다. 설 문조사에서 독립변수는 물리보안수준, 매개변수는 보안성과, 종속변수는 업무효율성으로 선정하였다. 신뢰도 분석과 타당성분석, 판별타당성분석 등을 SPSS를 통해 인과관계를 분석한 결과 “물리보안수준 ⇒ 보안성과, 보안성과 ⇒ 업무효율성”는 채택되었으나 “물리보안수준 ⇒ 업무효율성”은 기각되었다. 따라서 물리보안수준 이 매개변수인 보안성과를 거쳐 업무효율성에 영향을 주는 것으로 조사되었으나 물리보안수준이 직접 업무 효율성에 영향을 미치지 않는 것으로 나타났다. 향후 업무효율성을 향상시키기 위해서는 보안성과를 높이는 것이 우선되어야 할 것이다.

The purpose of this paper is to take a look the effect of the physical security level of companies possessing national core technology on security performance and work efficiency. To this end, a survey was set out for about 200 security officers for a month. In the survey, the independent variable was physical security level, the parameter was security performance, and the dependent variable was work efficiency. Reliability analysis, validity analysis, discriminant validity analysis, etc. were analyzed for causality through SPSS. As a result, “Physical Security LevelSecurity Performance, Security Performance ⇒ Work Efficiency” was adopted, but “Physical Security Level ⇒ Work Efficiency” was rejected. Therefore, it was found that the physical security level affects work efficiency through security performance, which is a parameter. However, it was found that the physical security level did not directly affect work efficiency. In order to improve work efficiency in the future, improving security performance should be a priority.

9

SaaS 협업 환경 보안 취약점 분석 및 다층 보안 아키텍처 제안 KCI 등재

오다은, 이호준, 이동휘

한국융합보안학회 융합보안논문지 제25권 제4호 2025.10 pp.161-168

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 기업과 기관에서 도입이 급격히 확산되고 있는 클라우드 기반 협업 도구(Software as a Service, SaaS)는 높은 접근 성과 편의성을 제공하지만, 네트워크 분리 정책과 다중 사용자 환경에서 다양한 보안 위협에 노출되고 있다. 특히 Adversary-in-the-Middle(AiTM) 공격, 권한 오남용, 접근제어 설정 오류, 세션 하이재킹, 그리고 제3자 애플리케이션 연계로 인한 공급망 위협 등은 SaaS 환경에서 빈번히 발생하는 주요 취약점으로 지적된다. 본 연구에서는 SaaS 협업 환경의 보안취 약점을 체계적으로 분석하고, 이를 대응하기 위한 다층 보안 아키텍처를 제안한다. 제안 아키텍처는 (1) 데이터 민감도에 따른 C/S/O 분류 기반 망 분리, (2) WebAuthn 기반 다중 인증과 RBAC·ABAC 기반 정교한 접근제어, (3) UTM(Unified Threat Management)을 통한 네트워크 및 웹 필터링, (4) TLS 기반 로그 암호화 및 ELK 스택 기반 실시간 보안관제의 네 가지 계층 으로 구성된다. 이를 통해 기존 망 분리 모델의 한계였던 업무 효율성과 비용 부담 문제를 완화하면서도, 최신 위협(AiTM, 세 션 하이재킹 등)에 대한 방어력을 확보하였다.

Cloud-based collaboration tools, or Software as a Service (SaaS), have seen rapid adoption in companies and institutions due to their high accessibility and convenience. However, they are exposed to multiple security threats in multi-user environments and under network segmentation policies. Key vulnerabilities include Adversary-in-the-Middle (AiTM) attacks, privilege abuse, misconfigured access controls, session hijacking, and supply chain risks from third-party integrations. This study systematically analyzes these vulnerabilities and proposes a multi-level security architecture to address them. The architecture comprises four layers: (1) network segmentation based on data sensitivity using C/S/O classification, (2) multi-factor authentication with WebAuthn combined with RBAC and ABAC-based access control, (3) network and web filtering through Unified Threat Management (UTM), and (4) TLS-based log encryption with real-time monitoring via the ELK stack. The proposed approach mitigates the limitations of existing segmentation models, such as operational inefficiency and high costs, while providing effective defense against modern threats like AiTM attacks and session hijacking.

10

4,300원

본 연구는 자율주행차 보안 강화를 목적으로 자율주행차 특징, 보안 위협, 국내외 컴플라이 언스 등 자율주행차 보안 관련 현황 분석을 통해 보안 수준 점검 항목을 도출하였고 이를 토 대로 AHP 모형에 적용하여 상대적 중요도를 확인하였다. 실증 분석 결과 사이버보안 관리체 계 수립·이행, 암호화, 위험평가 등의 순으로 중요도 우선 순위가 나타났다. 본 연구의 의의는 자율주행차관련 보안 수준 점검 항목을 도출하고 연구 모형을 실증함으로써 인명 피해까지 초 래할 수 있는 사이버 보안 사고 감소 및 관련 기업들의 자율주행차 보안 관리 수준을 향상시킬 수 있다. 그리고 자율주행차 점검 항목의 상대적 중요도를 고려하여 점검을 수행한다면 보안 수준을 조기에 식별할 수 있을 것이다.

To strengthen the security of autonomous vehicles, this study derived checklists through the analysis of the status of autonomous vehicle security. The analyzed statuses include autonomous vehicle characteristics, security threats, and domestic and foreign security standards. The derived checklists are then applied to the AHP(Analytic Hierarchy Process) model to find their relative importance. Relative importance was ranked as one of cyber security management system establishment and implementation, encryption, risk assessment, etc. The significance of this study is to reduce cyber security incidents that cause human casualties as well improve the level of security management of autonomous vehicles in related companies by deriving the autonomous vehicle security level checklists and demonstrating the model. If the inspection is performed considering the relative importance of the checklists, the security level can be identified early.

11

6,900원

국가중요시설이 외부의 불순 세력으로부터 공격을 받았을 때 국가안보와 국민생활에 미치는 부정적 영향은 매우 심각할 수 있다. 따라서, 이러한 시설의 보안을 책임지는 보안 조직의 역량 강화는 해당 시설과 사회의 안전을 위해 매우 중요한 과제이다. 그럼에도 불구하고, 최근 국가중 요시설 물리적 보안 조직의 부실한 역할 수행으로 인해 밀입국, 총기 관리 부실, 출입증 부정 사 용 등 관련된 사건들이 꾸준히 발생하고 있는 실정이다. 이에 따라, 본 연구는 국가중요시설의 물리적 보안을 담당하는 보안 조직의 역량을 높이는 데 도움을 주기 위한 목적으로, 물리적 보안 조직의 보안업무 수준을 평가할 수 있는 평가지표를 제시하였다. 이를 위해, 본 연구에서는 우선 문헌분석을 통해 물리적 보안 조직의 업무 수준을 평가할 수 있는 지표들을 도출하였고, 전문가 들의 설문조사를 통한 검증 과정을 거쳐 지표를 확정하였다. 확정된 지표를 보다 정교하게 활용 할 수 있도록, AHP 분석을 수행하여 각 지표에 대한 우선순위와 가중치를 도출하였다. 본 연구 에서 제시한 물리적 보안 조직의 보안업무 수준 평가지표는 국가중요시설뿐만 아니라 물리적 보 안을 필요로 하는 모든 기관에서 물리적 보안 조직 역량관리 및 보안요원들의 성과관리 체계를 구축하거나 개선하는 데 유용하게 활용될 수 있을 것으로 기대된다.

If important national facilities are being attacked by external threats, the negative impact on the national security and people’s life will be very serious. Therefore, strengthening the capabilities of security organizations responsible for the security of national critical facilities is a very important task for the safety of the facility and community. Nevertheless, recent incidents such as smuggling, poor gun management, and illegal use of passes have been steadily occurring due to inappropriate performance of physical security organizations of important national facilities. Accordingly, in order to help the security organization in charge of physical security of important national facilities, and to improve their work capabilities, this study presents an evaluation index that can properly assess the security work level of the physical security organizations. At First, based on the literature review, We derived the evaluation index factors that can evaluate the work level of a physical security organizations. Then, we confirmed the evaluation indices after a verification process through a survey by physical security experts. In order to utilize the determined evaluation index finely, an AHP analysis was performed to derive the priorities and weights for each evaluation index. We found that The security level evaluation index of the physical security organizations developed in this study is useful in establishing and improving the physical security organization’s competent management and performance system of security guards in all organizations that require physical security.

12

공공기관의 정보보안 솔루션 도입이 정보보안 수준 향상에 미치는 영향 KCI 등재

김협, 엄수정, 권혁준

한국융합보안학회 융합보안논문지 제17권 제5호 2017.12 pp.19-25

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

공공기관에서는 보안위협에 대응하기 위해 매년 정보보안 솔루션에 투자하고 있다. 하지만 도입된 솔루션이 실제 공공기관의 정보보안 수준 향상에 영향을 미치는지에 대한 연구가 미비한 상태이며, 이로 인해 공공기관에 도입된 솔루션의 투자효과에 대한 측정의 어려움 등이 발생하고 있다. 이에 따라 본 논문은 정보보안 솔루션의 도입 시 실제 정보보안 수준 향상에 미치는 영향에 대한 실증을 위해 전체 공공기관에 도입되어 있는 ‘내PC지키미’ 솔루션을 중심으로 연구를 수행하였다. 분석 결과 내PC지키미 솔루션은 공공기관 사용자의 정보보안 인식향상에 긍정적인 영향을 미쳤고, 이로 인해 조직의 정보보안 수준이 높아진 것을 실증하였다. 또한, 솔루션 운영 시 보안 정책의 강제화 유무에 따른 보안성 향상에 대하여 확인하였다. 본 연구의 결과를 바탕으로 향후 공공기관의 사용자 및 관리자들이 정보보안 솔루션 도입 시 내부 보안정책 수립과 같은 운영 프로세스 개선 방안에 활용할 수 있다.

Public institutions invest about half of the information protection budget annually to introduce information security products and information protection services in order to prevent cyber terrorism and establish organizational security. However, research on whether introduced information security products has a positive influence on improving the information security level of the actual institution is in an incomplete state, and accordingly, There are problems such as the measurement of the investment effect of the information security product introduced in the organization and the difficulty in selecting the optimum information security product that the agency actually needs. In this paper, prior research will conduct research on the influence of the introduction of information security products on the improvement of information security level of organization through analysis of operational data of inadequate information security products, and based on the research results, It would be useful to use it for information security practices such as optimal product selection and internal security policy formulation through validation of the introduction of information security products of public institutions.

13

IT 시스템의 다중 수준 보안을 위한 관리 환경 연구 KCI 등재후보

김점구

한국융합보안학회 융합보안논문지 제10권 제4호 2010.12 pp.39-48

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

복잡한 환경에서 안전한 IT환경은 하나이상으로 분리된 데이터의 그룹으로 나뉘어 같은 시스 템에 상주하지 않게 함으로서 그 목적을 얻을 수 있다. 이러한 시스템의 사용자는 특정 데이터 에 접근하는 방법과 등급을 다르게 하여야 한다. 정보구조, 물리적 구조, 사용자 권한 및 응용 프로그램 보안 정책을 위한 유지 보수 등은 이러한 환경 관리를 더욱 복잡하게 하고 보안 관리 자의 수의 증가를 가져온다. 본 논문은 이러한 환경관리를 위한 CM 툴을 시스템 공학의 CASE 툴을 모델로 하여 제안하 고자 한다. 시스템 공학의 모델링 기법은 다중 정보 보안을 처리하는 데 사용할 수 있다. SE의 CASE 툴 모델은 동일 시스템에 대한 논리와 물리적인 관리를 쉽게 할 수 있는 중요한 구성 요 소를 가지게 된다. CASE 툴의 확장된 영역은 물리적인 CM 툴을 사용자 친화적이고 안전한 IT 시스템의 관리 환경의 문제점을 해결하는 기본을 제공하게 될 것이다.

In a complex, secure IT system environment there will be groups of data that be segregated from one another, yet reside on the same system. Users of the system will have varying degrees of access to specific data. The Configuration Management(CM) of the information architecture, the physical architecture, user privileges and application security policies increases the complexity for operations, maintenance and security staff. This pager describes(current work to merge the capabilities of a network CM toll with those of a Computer Aided System Engineering(CASE) tool. The rigour of Systems Engineering(SE) modelling techniques can be used to deal with the complexities of multi-level information security. The SE logical and physical models of the same system are readily tailorable to document the critical components of both the information architecture and physical architecture that needs to be managed. Linking a user-friendly, physical CM tool with the extended capabilities of a CASE tool provide the basis for improved configuration management of secure IT systems.

14

4,600원

AI 패러다임은 언어 생성을 넘어 파일 시스템 접근, 외부 도구 호출, 결제 권한 등을 수행하는 실행형 에이전트 환경으로 확장되고 있으며, 이기종 멀티 에이전트 시스템에서는 개인 에이전트(PA: Personal Agent)와 서비스 에이전트(SA: Service Agent)가 서로 다른 정책, 감사 기준, 데이터 보존 규칙하에서 협업한다. 이로 인해 정책 불일치, 프롬프트 주입, 공급망 공격, 설정 오류가 연쇄적 피해로 이어질 수 있으므로, 본 논문은 소유권 기반 보안 수준 협약 프레임워크인 Agent-SecSLA를 제안한다. 제안 프레임워크는 데이터 민감도와 실행 위험도의 이원 분류, 3단계 보안 레벨, DSPN(Discover-Settle-Pin-Notify) 프로토콜, 사건 단위 PEP/PDP 정책 집행, 위임 토큰의 depth/fanout 제어, 해시 포인터 기반 연계보관성(CoC: Chain of Custody), 단계적 패널티 메커니즘으로 구성된다. 또한 기존 정책 협상·집행 기법과의 비교, 형식적 안전성 명제와 증명 스케치, 합성 시뮬레이터 기반 예비 정량 평가를 통해 제안 프레임워크의 적용 가능성을 분석한다.

The AI paradigm is expanding beyond language generation toward action-capable agent environments that perform file-system access, external tool invocation, and payment authorization, while heterogeneous multi-agent systems require Personal Agents (PAs) and Service Agents (SAs) to collaborate under different policies, audit criteria, and data-retention rules. As a result, policy mismatches, prompt injection, supply-chain attacks, and misconfigurations may lead to cascading damage; therefore, this paper proposes Agent-SecSLA, an ownership-based security level agreement framework. The proposed framework consists of a bivariate classification of data sensitivity and action risk, three security levels, the DSPN (Discover-Settle-Pin-Notify) protocol, event-level PEP/PDP policy enforcement, depth/fanout control for delegation tokens, hash-pointer-based Chain of Custody (CoC), and a graduated penalty mechanism. In addition, this paper analyzes the framework’s applicability through comparison with existing policy negotiation and enforcement techniques, formal safety propositions, proof sketches, and preliminary quantitative evaluation using a synthetic simulator.

15

국회 시설물의 경호·경비 적합성에 관한 연구 KCI 등재

전용태, 이주락, 김태연

한국경찰연구학회 한국경찰연구 제12권 제2호 2013.06 pp.237-260

※ 기관로그인 시 무료 이용이 가능합니다.

6,100원

국회의사당은 '가'급 국가중요시설로서 위협상황으로 인해 그 기능에 장애가 생겼을 경우 국가적으로 막대한 손실이 초래되는 장소이므로 어떠한 위협으로부터도 항상 안전하게 보호되어야 한다. 그러나 국회가 과거 권위주의적 국회상을 탈피하고 국민에게 보다 나은 서비스를 제공하기 위하여 개방성을 추구하는 과정 중에 국회는 여러 가지 위협에 취약성을 드러내게 되었다. 그러나 아직 우리 국회에서는 경호·경비의 중요성을 심각하게 받아들이지 않고 있으며, 경호·경비의 효율성을 향상시킬 수 있는 국회 시설물에도 이용자의 편의성에 치우쳐 국가중요시설에 맞는 보안설계 및 운용의 개념이 매우 부족한 실정이다. 이에 본 연구에서는 국회에서 경호·경비 업무를 담당하고 있는 공무원들을 대상으로 포커스 그룹 인터뷰와 설문조사를 통해 현 국회 시설물의 경호·경비 적합성에 대한 인식을 파악하고 이를 바탕으로 출입통제방법의 개선과 CCTV시스템 설치 확대 및 범죄예방설계(CPTED)기법 도입을 개선방안으로서 제시하였다.

The National Assembly is a crucial institution that needs to be secured at all times from any types of threat and attack, as its disorder can cause the country immeasurable harm. Despite its importance, the security of the National Assembly has not been considered seriously and the concept of security planning and management has not been established sufficiently since much emphasis is placed on the providing convenience to the visitors. In addition, the "openness" policy employed in an effort to change the past authoritarian image of the National Assembly and provide better services to the citizens has revealed different weaknesses in the aspect of security. Therefore, in this study, a Focus Group Interview (FGI) and a survey are performed with the public officials who carry out the security-related duties at the National Assembly to examine the perception of the facilities' suitability for security measures. With the results from the analyses, employment of Crime Prevention Through Environmental Design (CPTED), establishment of an access control system, and expansion of Closed-circuit Television (CCTV) Installation are suggested improvement measures.

16

7,200원

우리나라 방위산업은 1970년대 자주국방을 위해 국방과학연구소가 창설 이후 급속하게 성장 하여 2021년에는 국방과학기술력이 9위 수준이며, 전 세계 무기 수출 점유율도 2.7%를 차지하고 있다. 이러한 기술을 탈취하기 위하여 국내 ․ 외 경쟁 방산업체의 정보탐지는 물론 해킹에 의한 기술 유출이 증가되고 있다. 방산업체의 경우 관련법령에 의거 정부기관으로부터 보안지원은 물론 통합실태조사 등으로 기술보호 수준이 높은 반면, 방산관련업체의 경우 중소기업으로 기술보 호 수준이 상대적으로 저조하여 보안에 취약하다. 이러한 방산관련업체에 대한 보안 수준 향상 을 위해 원청업체에 의한 실태조사, 산업기술보호협회에 의한 일부 방산관련업체 실태조사를 실시하고 있으나 각 원청업체마다 실태조사 평가항목이 모두 상이하고, 산업기술보호협회의 평가 항목도 상이하는 등 일관성 있는 보안 수준 관리에 어려움이 있다. 이에 원청업체의 실태조사 평 가항목, 산업기술보호협회의 실태조사 평가항목은 물론 방산보안업무훈령에 의해 방산관련업체 보안측정 평가항목, 중소기업 기술보호 수준 진단지표의 평가항목을 분석하여 방산관련업체 보안 수준 평가 지표 개선방안을 제안하였으며, 본 연구 결과를 토대로 방산관련업체에 대한 보안 수준을 표준화된 지표를 통해 일관성 있게 평가함으로써 방산관련업체의 보안 수준을 향상시키는데 기여할 것으로 기대된다

Korea's defense industry has grown rapidly since the establishment of Agency for Defense Development for self-defense in the 1970s, ranking ninth in defense science and technology in 2021, and accounting for 2.7 percent of global arms exports. In order to steal these technologies, information detection by domestic and foreign competitors as well as technology leakage by hacking are increasing. In the case of defense companies, the level of technology protection is high due to security support from government agencies as well as integrated survey under related laws, while in the case of defense-related companies, the level of technology protection is relatively low. In order to improve the security level of defense-related companies, some defense-related companies are surveyed by the Korea Industrial Technology Protection Association, but each company has different evaluation items and the Korea Industrial Technology Protection Association's evaluation items are difficult to improve the security level. Accordingly, it analyzed the evaluation items of the original company's survey and the evaluation items of the Korea Industrial Technology Protection Association, as well as the evaluation items of the defense-related company's security measurement and SME technology protection level, Based on the results of this study, it is expected to improve the security level of defense-related companies by analyzing the security measurement items of the original contractor, the Industrial Security Association, and the technical protection level diagnostic index of small and medium-sized companies.

17

6,700원

최근 국가 경쟁력 강화를 위한 연구개발 투자가 확대되고 있으며, 개방형 혁신환경의 도래로 산·학·연간 공동연구 및 협업이 활성화되었다. 특히 전문인력을 양성하는 대학 및 대학부설연 구소는 국가 연구개발(R&D) 사업과 관련된 공동연구 및 위탁연구 비중이 매년 증가하고 있어 중 요성이 커지고 있다. 그럼에도 불구하고 대학부설연구소는 보안의 사각지대에 위치해 있고, 최 근 대학부설연구소를 대상으로 한 중국의 스파이 행위 또한 증가하고 있어 보호의 필요성이 증 대되고 있다. 본 연구에서는 끊임없이 발생하는 대학부설연구소 대상의 연구 성과물 유출 범죄 에 대비하기 위해 대학 차원에서 안전한 연구보안 환경을 구축할 수 있는 연구보안 수준평가 모 형을 설계하였다. 먼저 국내 대학부설연구소 관련 문헌, 선행연구들을 분석하고 이를 토대로 정 부출연연구소, 기업부설연구소와는 다른 17개의 대학 및 대학부설연구소의 고유한 특성과 보안 현황을 도출하였다. 다음으로 연구보안 컴플라이언스, 선행연구들을 비교분석하여 종합한 후 클 러스터링을 통해 보안항목 풀을 설계하였다. 마지막으로 연구보안 전문가 설문을 통해 대학 연 구실에 적합하면서도 타당성이 높은 연구보안 보안수준 평가 항목을 도출하였다. 최종 도출한 대학 연구실 대상 연구보안 보안수준 평가항목은 실제 대학 및 대학교 연구실이 자체적으로 보 안 수준에 대해 객관적으로 평가할 수 있는 자가진단도구로서 활용이 가능할 것이라 판단된다. 또한 안전한 보안환경 구축을 통해 신뢰를 기반으로 한 연구정보 및 결과물의 공유가 가능해짐 으로써 산·학·연간 활발한 협업이 진행될 것이라 기대한다.

Recently, the expansion of R&D investment to strengthen national competitiveness and the advent of open innovation environment have stimulated industry-academy-academia’s joint research and collaboration. Universities and university-affiliated research institutes that foster professionals are growing in importance, with the growing proportion of joint research and commissioned research related to national R&D projects every year. Nevertheless, the necessity of protection is increasing, as university-affiliated research institutes are in the blind spot of security and China's espionage against them is becoming more common. This study designed a research security level evaluation model that can establish a safe research security environment at universities, to prepare against the constant crime of research performance leakage from university-affiliated research institutes. First, to this end, this study analyzed the literature and previous studies related to domestic university-affiliated research institutes. Based on this, the study derived the unique characteristics and security status of 17 universities and university-affiliated research institutes, which are different from government-funded research institutes and corporate research institutes. Next, this study designed a pool of security items by synthesizing, comparing, and clustering research security compliance and previous studies. Finally, through the research security expert survey, this study derived the research security level evaluation items that are suitable for university labs and have high validity. According to the results, it is judged that the final research security level evaluation items for university labs can be used as a self-diagnosis tool for universities and university labs to objectively evaluate their security level themselves. In addition, it is expected that establishing a safe and secure environment will enable the sharing of research information and results based on trust and thus active collaboration will be conducted among industry, academia, and research centers.

18

6,000원

군 조직의 보안수준 변화요인을 확인하기 위해 시작된 본 연구는 현역 간부들이 군의 보안수준 향상을 바라며 국방일보에 투고한 기고문으로부터 수집된 데이터를 근거이론(Grounded Theory)이라는 질적연구 방법에 의해 분석 후 조직구성원들이 내부자 보안위협에 대해 어떻게 대응하는지에 관한 인과적 관계를 도출하였다. 분석 결과, 인과적 조건은 ‘내부자의 보안위협’, 맥락적 조건은 ‘군 조직의 특수성’, 중심현상은 ‘군인으로서 가치관의 충돌’, 중재적 조건은 ‘보안의식’, 전략은 ‘보안위협에 대응’, 결과는 ‘보안수준 변화’로 나타났다. 핵심범주는 ‘내부자 보안위협에 대한 가치관의 충돌 정도’로 제시할 수 있으며, 두 가지의 가설이 도출되었다. 첫째, 군 조직의 구성원은 안보를 중시하는 성향이 강할수록 보안위협에 대한 가치관의 충돌을 강하게 느끼며 이에 강경하게 대응하여 조직의 보안수준을 발전시키는데 일조하고 있었다. 둘째, 동료를 중시하는 성향이 강할수록 보안위협에 대한 가치관의 충돌 정도가 약하며 이에 미온적으로 대응하여 조직의 보안수준을 퇴보시키고 있었다. 최종적으로 조직의 보안수준 향상을 위해서는 조직구성원들의 확고한 안보의식 확립을 위한 방안과 더불어 이를 뒷받침할 수 있는 제도적 발전이 필요함을 나타낸다.

This study which was started to identify the factors that change the security level of military organizations, analyzed the data collected from articles written by the active officers in the Defense Daily Journal hoping to improve the military security level by the qualitative research method called Grounded Theory, and establish causal relationship how organizational members respond to insider security threats. As a result of the analysis, the causal condition is ‘the security threat of the insider’, the contextual condition is ‘the specificity of the military organization’, the central phenomenon is ‘the conflict of values as a soldier’, the arbitrary condition is ‘the security consciousness’, Strategy is ‘the responds to security threats’, and the result was ‘security level change’. The core categories can be presented as ‘the degree of conflict of values on insider security threats’ and two hypotheses have been derived. First, the members of the military organization strongly felt the conflict of values about security threat as the tendency to emphasize security was strong, and they helped to develop the security level of organization by responding strongly. Second, the stronger the tendency to focus on colleagues, respond weakly to security threats. And it undermines the security level of the organization. Finally, in order to improve the security level of the organization, it is necessary to establish a solid security consciousness and to make institutional development to support it.

19

Multi-level 보안 아키텍처(MLSA) 구축 방안 KCI 등재후보

최경호, 이동휘, 김귀남

한국융합보안학회 융합보안논문지 제7권 제4호 2007.12 pp.107-114

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

보안 평가 체계에서 요구하는 보안 수준은 제시되는 세부지침, 가이드라인 및 우수 구현 사례를 이용하여 달성될 수 있다. 그러나 조직이 2가지 이상의 서로 다른 보안 인증 체계를 요구 받는 경우, 중점 평가 기준, 보안 요구 수준, 평가 항목들이 상이하기 때문에, 보안 아키텍처의 재구축 또는 변경 절차가 요구된다. 따라서 본 연구에서는 ML Analysis를 이용하여 제시되는 다양한 보안 관리 수준을 달성하기 위한 Multi-level 보안 아키텍처(MLSA) 구축 방법론을 제시한다. MLSA는 다양한 보안인증체계의 동시적 달성을 위한 방법론을 제공한다.

We need development methodology of security architecture which offered various levels of security management in case of the required more than two security certifications. In this study, therefore, development methodology of Multi-level Security Architecture(MLSA) proposed. Specifi-cally, we should consider factors of commonness and difference between information security mana-gement level evaluation of multiple security architecture. This kinds of endeavor can suggest the direction of the improvement of the evaluating security management and the dynamic plan for the security architecture, and it will make the continuous and systematic security management.

20

4,000원

최근 4차 산업혁명 환경이 도래하면서 어느 조직이든 데이터의 개방과 공유, 융합이 활발하게 이루어지고 있다. 그런 데 데이터의 개방과 공유는 필연적으로 보안 취약성을 초래할 수밖에 없으며 오히려 4차 산업혁명 환경에서 운영되는 조직의 존폐까지 영향을 미칠 수 있는 위협요인으로 대두되는 양면성이 있다. 특히 군이라는 조직에서 보안 문제는 군 자체가 아닌 국가의 위협이 될 수 있으므로 항상 높은 수준의 보안 기강 유지가 필수적으로 요구된다. 이에 본 논문에 서는 軍보안수준에 영향을 미칠 수 있는 요인을 추출하여 보안수준 발전대책을 모색하기 위해 계획 행동이론, 억제이 론, 보호 동기 이론 등을 적용한 구조방정식 모형을 통해 14개 변수를 선별하였고 각 이론과 변수의 영향력을 검정하였 다. 그 결과 평소 보안규정 교육과 평가를 통해 체화된 보안지식은 행동에 영향을 미친다는 계획 행동이론을 채택할 수 있었고, 억제이론과 보호 동기 이론은 기각 수준의 유의미성을 나타냈다. 또한, 3년간의 보안감사 결과 측정된 값을 통 해 軍보안수준에 가장 큰 영향을 미치는 변수는 지휘 관심과 정신보안이라는 사실도 확인되었다. 결론적으로 軍보안 수준을 높이기 위해서는 보안교육과 신상필벌, 보안시스템 고도화 등과 함께 지휘 관심과 정신보안 태세를 확고히 해야 한다는 내용이 발전대책으로 제시되었다.

Recently, as the environment of the 4th industrial revolution has arrived, the opening, sharing and convergence of data are actively being achieved in any organization. However, the opening and sharing of data inevitably leads to security vulnerability and there is ambivalence that is a threat that can affect the existence of an organization operated in the 4th industrial revolution environment. Especially security issues in the organization of the military can be a threat to the state, not the military itself, so it is always necessary to maintain a high level of security discipline. In this paper, 14 variables were selected through structural equation model applying theory of planned behavior, deterrence and protection motivation to find out the security level development measures by extracting factors that can affect security level. As a result, the theory of planned behavior that the security knowledge embodied through the usual security regulation education and evaluation affects the behavior was adopted, and the theory of deterrence and protection motivation showed the significance of the rejection level. In addition, it was confirmed that the variables that have the greatest impact on the military security level through the measured values of the three-year security audit were commanders and mental security. In conclusion, in order to improve the security level, it is suggested that security education, definite reward and punishment, and security system upgrading should be firmly established and mental security posture should be secured.

 
1 2 3 4 5
페이지 저장