년 - 년
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제11권 제10호 2021.10 pp.144-150
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 논문의 연구목적은 5G 통신네트워크 보안에서 표준화가 진행되고 있는 상황에서 주요 고려 사항인 슬라이싱 보안 정책에 대한 방향을 검토하고, 5G 통신 네트워크 가상화의 보안 취약점 진단 항목들을 도출하며, 위험관리에 대한 주요 논의 사항들을 분석하고 제시하는데 있다. 연구방법은 유럽 핵심보안 연구기관인 ENISA(European Union Agency for Cybersecurity)의 5G 통신네트워크의 가상화 보안 정책 방향과, 국외 주요 관련 저널로부터 5G 통신네트워크의 가상화 보 안정책과 취약점 분석 등의 연구 내용을 분석에 활용하였다. 본 논문의 연구 결과에서는 5G 통신 네트워크의 가상화 보안에 서 보안구조를 정리하였고, 보안 위협들과 위험관리 요소를 도출하였다. 또한 위험관리 영역에서 보안 서비스별로 취약점 진단 항목들을 도출하였다. 본 연구의 기여도는 여전히 논의 되고 있는 5G 통신 네트워크 가상화 보안에서 보안 위협 항목들 을 요약하였다는 것과, 유럽의 5G 통신네트워크 사이버보안 방향을 파악 할 수 있었다는 것, 그리고 5G 통신 네트워크의 가상화 보안에 고려되어야 하는 취약점 진단 항목들을 도출하였다는 데 있다. 아울러 본 연구의 결과는 국내 5G 통신네트워 크 가상화 보안을 위한 취약점 진단 항목들을 개발하는데 기초 자료로 활용 될 수 있다. 향후 5G 통신네트워크 가상화 보안의 취약점 진단 항목에 대한 상세한 진단 프로세스를 연구하는 것이 필요하다.
The purpose of this paper is to review the direction of the slicing security policy, which is a major consideration in the context of standardization in 5G communication network security, to derive security vulnerability diagnosis items, and to present about analyzing and presenting the issues of discussion for 5G communication network virtualization. As for the research method, the direction of virtualization security policy of 5G communication network of ENISA (European Union Agency for Cybersecurity), a European core security research institute, and research contents such as virtualization security policy and vulnerability analysis of 5G communication network from related journals were used for analysis. In the research result of this paper, the security structure in virtualization security of 5G communication network is arranged, and security threats and risk management factors are derived. In addition, vulnerability diagnosis items were derived for each security service in the risk management area. The contribution of this study is to summarize the security threat items in 5G communication network virtualization security that is still being discussed, to be able to gain insights of the direction of European 5G communication network cybersecurity, and to derive vulnerabilities diagnosis items to be considered for virtualization security of 5G communication network. In addition, the results of this study can be used as basic data to develop vulnerability diagnosis items for virtualization security of domestic 5G communication networks. In the future, it is necessary to study the detailed diagnosis process for the vulnerability diagnosis items of 5G communication network virtualization security.
스마트카드 가상화 클라우드 플랫폼 기반 모바일 결제 비즈니스 모델 설계
한국경영정보학회 한국경영정보학회 정기 학술대회 빅데이터 시대의 창조 비타민 2014.06 pp.872-877
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
스마트폰 및 인터넷 보급률의 증가는 카드를 소지 하지 않고도 거래가 가능한 모바일 결제 솔루션 구 축을 용이하게 했으며, NFC, 블루투스 등의 센서기 반 네트워크 기술은 모바일 결제 서비스의 이용 편 의성을 높일 거라는 기대를 받으며 적용되었다. 하 지만 기존 인프라에 대한 서비스의 불연속성, 모바 일 기기 구조상의 보안 취약성, 기존 결제 시스템과 의 유사성 등으로 사용자와 오프라인 가맹점주에게 외면 당했다. 본 연구에서 적용하는 단말 가상화 기술 및 클라우 드 컴퓨팅 기술은 스마트카드 및 기존 상거래 인프 라 하드웨어를 가상화하고, 클라우드를 통해 가상화 된 다수의 스마트카드와 상거래 인프라를 통합∙관리 한다. 이는 근본적인 보안 강화와 비용 절감, 관리 효율 증대, 사용자 주도의 서비스 제공 등을 달성할 수 있는 기술로, 본 연구에서는 ViSCa (Virtualization of Smart Cards) 클라우드 플랫폼 기반 모바일 결제 비즈니스 모델을 제안한다. 선행연구를 통해 기존 모바일 결제 서비스의 실패 원인을 찾고 고도 정보 연계 사회 속에서 제안하는 비즈니스 모델의 특징을 설명한다. 이는 시나리오 제시 및 참여자 분석과 함께 비즈니스 모델의 가치 의 흐름, 수익의 흐름, 물류의 흐름을 토대로 설명한다.
통합선박항해지원시스템을 위한 가상화 스케줄링 알고리즘에 관한 연구
한국정보통신설비학회 한국정보통신설비학회 학술대회 2017년도 정보통신설비 학술대회 2017.08 pp.227-229
※ 기관로그인 시 무료 이용이 가능합니다.
3,000원
최근 클라우드 컴퓨팅이 확산되면서 주목 받고 있는 기술 중 하나는 가상화(virtualizaion) 기술이다. 가상화 기술 을 이용하여 시스템을 구축할 경우 하나의 호스트 운영체제에서 복수개의 운영체제를 구동시킬 수 있으며 효율적인 컴퓨팅 자원의 관리를 용이하게 한다는 장점이 있지만 하이퍼바이저(Hypervisor) 위에서 구동하는 운영체제들이 많아질수록 가상화 시스템의 전반적인 성능을 측정하는 것이 필요하며 이는 중요한 기술로 떠오르고 있다. 본 논문 에서는 가상화 시스템의 효율적인 성능측정을 위해 기존 프로파일링 도구의 주요 기능을 분석하여 가상화 시스템에 서 발생할 수 있는 이벤트에 대하여 모니터링 도구들이 수행할 수 있는 프로파일링 커버리지를 측정하고 분류하였으 며, 더 나아가 모니터링을 수행하는 원격 시스템에서 수신 된 정보에 따라 가상화 시스템에 성능측정이 필요할 경우 적합한 프로파일링 도구를 게스트 시스템에 적재시켜 성능측정을 할 수 있도록 하는 프레임워크를 연구하였다.
Virtualization technology is one of the technologies that have been attracting attention as cloud computing spreads recently. When a system is constructed using virtualization technology, mutiple operation systems can be operated in a single host operating system, thereby facilitating efficient management of computing resources. As more and more operating systems are running on the hypervisor, it is important to measure the overall performance of the virtualization system and this is becoming an important technology. In this paper, we analyze the main functions of the existing profiling tools to measure the performance of the virtualization system, and measure and classify the profiling coverage that the monitoring tools can perform for events that may occur in the virtualization system. In addition, we have studied a framework that enables performance measure-ment by loading appropriate profiling tools into the guest system when performance measurement is required for the virtualization system according to the information received from the remote system performing the monitoring.
융합서비스를 위한 클라우드 컴퓨팅 환경에서 가상화 보안에 관한 연구 KCI 등재후보
한국융합학회 한국융합학회논문지 제5권 제4호 2014.12 pp.93-99
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
클라우드 컴퓨팅은 인터넷 기술을 활용하여 IT자원을 필요한 만큼 빌려서 사용하고 서비스 부하에 따라 서 실시간 확장성을 지원받으며 사용한 만큼 비용을 지불하는 컴퓨팅 기술을 말한다. 클라우드 컴퓨팅의 핵심기술 인 가상화는 서버, 스토리지 및 하드웨어 등을 분리된 시스템이 아닌 하나의 영역으로 간주하여 자원을 필요에 따라 할당하는 기술이다. 그러나 가상화 환경에서 필요로 하는 보안 메커니즘은 하나의 서버 내부가 아닌 서버 간의 트래 픽을 모니터링 하도록 설계되어 있고 기본 수준의 가시성, 통제성 및 감사 기능을 갖는 기존 보안 메카니즘으로는 대응하기 어려운 상황이다. 본 논문에서는 클라우드 컴퓨팅 환경에서 가상화 기술의 보안 취약점을 분석하고 이를 토대로 가상화 기술과 관련된 하이퍼바이저 보안 및 게스트 OS 보안 권고 사항을 제시하고자 한다.
Cloud computing refers to borrow IT resources as needed by leveraging Internet technology and pay as much as you used by supporting real-time scalability depending on the service load. Virtualization which is the main technology of cloud computing is a technology that server, storage and hardware are regarded as not separate system but one system area and are allocated as needed. However, the security mechanisms provided by virtualized environments are difficult to cope with the traditional security mechanisms, having basic levels of visibility, control and audit function, on which the server is designed to monitor the traffic between the servers. In this paper, the security vulnerabilities of virtualization are analysed in the cloud computing environment and cloud virtualization security recommendations are proposed.
웹 어플리케이션 보안을 위한 가상화 기반 보안 모델 KCI 등재
한국융합보안학회 융합보안논문지 제14권 제4호 2014.06 pp.27-32
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
네트워크 기술의 빠른 발전과 컴퓨팅 환경의 변화로 인하여 웹 어플리케이션 활용 분야가 최근 몇 년 사이에 광범위 하게 넓어졌으며 복잡해졌다. 이러한 웹 어플리케이션이 중요한 서비스에 많이 사용되면서, 이를 대상으로 한 공격도 증가하고 있으며, 그 방법도 다양해지고 지능화되고 있다. 본 논문에서는 웹 어플리케이션의 취약점을 이용한 공격을 막기 위해 가상화 기술을 이용한 보안 모델을 제안하였다. 제안한 모델에서는 클라이언트 요청에 의해 생성되는 세션에 ID를 부여한 후 해당 요청에서 쿼리 유형을 분석하여 해당 가상 웹 서버에 전달함으로써 데이터베이스 서버에서도 쿼 리에 대한 요청 정보를 인지할 수 있도록 하였다. 그리고 가상 웹 서버들 사이의 트래픽을 감시하고, Host OS의 자원 낭비를 줄이기 위해 VM-Master 모듈을 구성하였다. 제안한 기법의 공격탐지 및 자원 활용의 우수한 성능은 실험을 통 하여 확인할 수 있었다.
Utilization of web application has been widely spread and complication in recent years by the rapid development of network technologies and changes in the computing environment. The attack being target of this is increasing and the means is diverse and intelligent while these web applications are using to a lot of important services. In this paper, we proposed security model using virtualization technology to prevent attacks using vulnerabilities of web application. The request information for query in a database server also can be recognized by conveying to the virtual web server after ID is given to created session by the client request and the type of the query is analyzed in this request. VM-Master module is constructed in order to monitor traffic between the virtual web servers and prevent the waste of resources of Host OS. The performance of attack detection and resource utilization of the proposed method is experimentally confirmed.
기상화 기법을 이용한 리눅스 기반 모바일 단말기용 시뮬레이터 설계 및 구현 KCI 등재후보
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.5 No.1 2009.03 pp.41-52
모바일 단말용 운영체제로서 리눅스가 채택되는 사례가 증가하고 있다. 기존의 모바일 단말용 시뮬레이터들은 개발자에 제공되어 개별 모바일 응용을 개발하고 응용 계층과 미들웨어 계층 중심의 기능적 테스트에 초점을 두고 있다. 제안된 시뮬레이터는 가상화 기법을 이용하여 실제 단말에 탑재되는 운영체제를 포함한 전체 SW 스택을 테스트 할 수 있는 환경을 제공한다. 또한 단말의 시장 출시 전에 수작업에 의한 SW 동작 시험 대신 하드웨어 에뮬레이션 계층, 운영체제 계층, 미들웨어 계층 및 응용 계층에서 발생되는 각각의 이벤트 정보를 저장 및 재생할 수 있는 기능을 통해 전체 SW 스택을 자동 테스트할 수 있는 방법을 제공한다.
Many companies have adopted Linux as mobile OS for their products. Most simulators provided todevelopers, however, have focused on testing only individual application functionality and interface withmiddleware. The proposed simulator based on virtualization technology provides execution environment forrunning full software stack including mobile OS. The simulator can record and replay all events generated fromthe hardware emulation layer, OS layer, middleware layer and application layer. This enables phone makers totest a full S/W stack running on their product in some autonomous way.
4,000원
정보 통신의 발전으로 공공기관과 기업에서는 인터넷 및 인트라넷을 이용하여 업무 연속성을 활용하고 있다. 이러한 환경에서 공공기관과 기업에서는 내부 정보의 유출에 대한 보호를 위해 많은 솔루션과 어플라이언스 장비들을 도입하 고 있다. 그러나 이 역시 외부 네트워크와 연결이 되어 있어 완벽한 정보유출을 방지하기에는 역부족이다. 이를 극복하 기 위해 내부 망과 외부 망으로 분리가 필요하다. 본 논문에서는 가상화를 이용하여 물리적인 망분리와 논리적인 망 분 리를 적용하여 망 구성을 하고 그에 따른 기술적인 검토 및 망 분리에 대해 다양한 방안을 제시하였다.
With the development of information and communication, public institutions and enterprises utilize the business continuity using the Internet and Intranet. In this environment, public institutions and enterprises is to be introduced the number of solutions and appliances equipment to protect the risk of leakage of inside information. However, this is also the perfect external network connection is not enough to prevent leakage of information. To overcome these separate internal and external networks are needed. In this paper, we constructed the physical and logical network separation is applied to the network using the virtualization and thus the network configuration and network technical review of the various schemes were proposed for the separation.
가상화를 이용한 웹 서버 보안시스템 설계 및 구현 KCI 등재후보
한국융합보안학회 융합보안논문지 제8권 제4호 2008.12 pp.199-207
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
웹 서비스는 기능의 특성상 다른 서비스와는 달리 외부에 노출되어 있고 다양한 어플리케이션들이 웹 서비스와 연동되어 있어서 많은 보안 취약점들이 존재한다. 특히 새로운 웹 기술들이 개발되면서 전에 없던 새로운 형태의 보안 취약점들이 꾸준히 생겨나고 있다. 본 논문에서는 이러한 취약점들을 바탕으로, 가상화 환경을 이용하여 웹서버와 허니웹을 구축함으로써 어떤 공격에 대해서도 시스템의 하드웨어까지 영향을 미치지 않도록 구성되며 허니웹을 통하여 새로운 공격에 대해서도 정보를 수집할 수 있도록 웹 서버 보안시스템을 설계 및 구현 하였다. 이를 통하여 상호 통신의 웹 환경에서 적절한 보안을 제공 할 수 있다.
Web service has many security weekness because it is exposure to outside and connected with various application. Especially, as new technology developed new type of security weakness has occured consistently. In this paper, we construct webserver and honeyweb by using virtual reality on a basis these weakness. So it cannot be influenced by any attack to the hardware of the system. By using honey web, it disigned and embodied web server secutiry system to collect the data about new attack. Through this, it can provide proper secutiry in a web environment of mutual communication.
컨테이너 기반 가상화에서 격리성 보장을 위한 취약성 고찰 KCI 등재
한국융합보안학회 융합보안논문지 제23권 제4호 2023.10 pp.23-32
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
클라우드 컴퓨팅 환경에서 컨테이너 기반 가상화는 게스트 운영체제 대신에 호스트 운영체제를 공유함으로써 가벼운 사용 감으로 가상머신 기반 가상화 기술의 대안으로 많은 관심을 받고 있다. 그러나 호스트 운영체제를 공유함으로써 발생하는 문 제점이 컨테이너 기반 가상화의 취약성을 높일 수 있다. 특히 컨테이너들이 자원들을 과도하게 사용함으로 인해 컨테이너들의 격리성을 침해할 수 있는 noisy neighbor problem은 사용자들의 가용성을 위협하게 되므로 보안 문제로 인식할 필요가 있다. 본 논문에서는 컨테이너 기반 가상화 환경에서 noisy neighbor problem이 격리성 보장을 위협할 수 있는 취약성을 고찰한다. 이를 위해 컨테이너 기반의 가상화 구조를 분석하여 기능별 계층에 대한 격리성 보장에 위협이 될 수 있는 취약 점을 도출하고 해결 방향과 한계점을 제시한다
Container-based virtualization has attracted many attentions as an alternative to virtual machine technology because it can be used more lightly by sharing the host operating system instead of individual guest operating systems. However, this advantage may owe some vulnerabilities. In particular, excessive resource use of some containers can affect other containers, which is known as the noisy neighbor problem, so that the important property of isolation may not be guaranteed. The noisy neighbor problem can threat the availability of containers, so we need to consider the noisy neighbor problem as a security problem. In this paper, we investigate vulnerabilities on guarantee of isolation incurred by the noisy neighbor problem in container-based virtualization. For this we first analyze the structure of container-based virtualization environments. Then we present vulnerabilities in 3 functional layers and general directions for solutions with limitations.
ARM 구조의 전가상화를 위한 TLB 관리 명령어를 사용한 섀도 페이지 테이블 구현 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.8 No.6 2012.12 pp.59-68
최근 ARM 구조를 사용하는 임베디드 시스템에서 가상화 기술에 대한 관심이 높아지고 있다. 일반적으로 시스템 가상화 구현을 위해서는 프로세서, 메모리 및 디바이스 등의 하드웨어 자원을 가상화한다. 이 중 메모리 가상화를 구현하기 위한 방법으로 섀도 페이지 테이블 기술이 주로 사용되고 있다. 섀도 페이지 테이블은 가상 머신 상에서 동작하는 게스트의 가상 주소 변환을 관리하기 위하여 가상 머신 모니터가 유지하는 페이지 테이블이다. 섀도 페이지 테이블은 게스트 페이지 테이블과 섀도 페이지 테이블을 동기화하는 방법에 따라 게스트 페이지 테이블에 쓰기 보호를 설정하여 게스트가 페이지 테이블을 수정할 때 발생하는 예외를 이용하는 방법, 혹은 게스트가 수행하는 TLB 관리 명령어를 이용하는 방법으로 구현한다. 본 논문에서는 ARM 구조에서 TLB 관리 명령어를 이용한 섀도 페이지 테이블을 구현하여 본 연구에서 개발 중인 ARM 기반 가상 머신 모니터에 적용하였다. 또한 이 가상 머신 모니터를 이용하여 BeagleBoard-xM을 동작시키는 QEMU 에뮬레이터 상에서 Linux 커널을 수행시켜 성능을 시험하였다. 시험 결과는 기존의 ARM 기반 가상화 연구와 비교하여 반가상화 방식보다는 낮은 성능을 보였지만 전가상화 방식 중에서는 만족스러운 성능을 보였다.
Recently virtualization technology has been applied to ARM architecture based embedded systems. Typically, hardware resources such as processor, memory and device should be virtualized to implement system virtualization. To implement memory virtualization, shadow page table technique is typically used. A shadow page table is a page table which is maintained by a virtual machine monitor to manage the virtual address translation of guests running in a virtual machine. The implementation of shadow page tables is classified depending on the synchronization between guest page tables and shadow page tables. The first method uses traps to capture the page table writes. Since this method modifies guest page tables to be write-protected, the writing guest page tables generates a trap. Another method is using the TLB maintenance operations which guest executes. In this paper, we implement shadow page tables using the latter method and apply this shadow page table technique to the virtual machine monitor for ARM architecture that we are working on. Furthermore, we run Linux kernel on the virtual machine monitor and evaluate performance on a BeagleBoard-xM using QEMU emulator. The results of the evaluation show that the performance of our virtual machine monitor is slower than the virtual machine monitor using paravirtualization. However, this virtual machine monitor has good performance among the virtual machine monitors using full-virtualization.
스마트TV와 N스크린 서비스를 위한 Open Cloud 가상화 기반 사용자 서비스(STVS) 플랫폼 개발 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.10 No.4 2014.08 pp.28-39
TV에 컴퓨팅 기능을 추가하여 다양한 형태의 사용자 요구를 수용하기 위해 탄생한 스마트TV는 포스트PC의 대안으로 사용자 플랫폼의 중심을 차지할 것으로 예측되는 유력한 단말 중의 하나이다. 스마트TV와 Set-top box등을연동하여 On-demand형의 드라마 및 영화 등의 동영상 콘텐츠를 활용하거나 인터넷을 서핑하는 형태는 이미 상용화되어 서비스되고 있으며, 별도의 스마트TV용 앱을 제작하여 스마트TV의 활용도를 높이는 시도도 진행되고 있다. 그러나 스마트TV가 포스트PC의 대안으로 자리잡기 위해서는 오피스에서도 사용할 수 있는 문서작업이 가능한 환경을 제공해야 하며, 다양화된 각각의 OS에 익숙해진 사용자들을 통합하여 지원하고 기존의 리소스들인 Android및 iOS 기반 앱들을 활용할 수 있는 플랫폼이 필요하다. 본 논문에서는 상기 기능을 만족하여 스마트TV를 포스트PC의 대안으로 제시할 수 있는 시스템인 STVS(Smart TV Service) 플랫폼을 구현한다.
Smart TV has been discussed as a promising device of Post PC category to handle various user needsby adding computing power to general TV. Smart TV is already commercialized and used inweb-surfing, on-demand requests on multimedia contents like movies combined with internet enabledset-top box devices. There has been specific approach to increase its effectiveness by adding TV appsfor specific Smart TV hardware. However, in the point of view in Post PC concept, current Smart TVplatform and architecture need new paradigm. The architecture should provide office-work friendlyenvironment, cover various OS-dependent users and apps based on Android OS & iOS together, andsupport legacy IT resources. Thus, we design and develop new platform and architecture called STVS(Smart TV Service) platform to achieve the goal to make Smart TV as a Post PC device.
Performance of OCI Container Runtimes Across CPU, Memory, and Database Workloads
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 학술대회 ICNGC 2025 The 11th International Conference on Next Generation Computing 2025 2025.12 pp.178-181
This study evaluates the performance characteristics of five OCI compliant container runtimes—runc, crun, youki, gVisor (runsc), and Kata Containers—through CPU, memory, and database benchmarks executed on an identical host environment. Sysbench CPU tests show that runc, crun, youki, and gVisor deliver nearly identical performance, while Kata Containers exhibits significantly lower throughput due to its virtualization-based architecture. Memory and PostgreSQL pgbench results highlight clearer differences: native runtimes achieve the highest throughput and lowest latency, gVisor shows moderate degradation due to system call mediation in user space, and Kata Containers demonstrates the greatest performance loss because of guest-to-host transitions and virtio based processing. Overall, the findings provide practical guidance for selecting container runtimes based on workload requirements, showing that native runtimes are optimal for latency-sensitive database services, while gVisor and Kata Containers are suitable for environments prioritizing stronger isolation at the cost of reduced performance.
4,000원
에뮬랩 소프트웨어는 미국 유타주립대학교에서 개발되어 전 세계 십여 개 사이트에 설치 구축되었다. 우리나라 국가과학기술연구망에서 구축한 KREONET-에뮬랩은 네트워크 프로토콜, TCP성능 테스트 등 네트워크 기술 연구는 물론 분산시스템, 보안 및 융합연구 분야의 연구자들에게 맞춤형 네트워크 토폴로지와 시스템 노드를 제공하고 있다. 테스트베드 는 실험연구에 있어 가장 중요한 역할을 하며, 실제로 연구자들은 테스트베드에서 지원 가능한 실험만을 수행할 수 있다. 본 논문에서는 지난 10년간 유타-에뮬랩을 활용한 프로젝트 목록을 토대로, 테스트베드를 활용한 연구 형태를 확인하고 연구자의 분포를 분석하여, 우리나라 KREONET-에뮬랩의 활용 동향과 비교하였다. 또한 서비스화된 테스트베드 (Testbed-As-a-Service)를 통한 차세대 테스트베드의 융합 연구 커뮤니티 서비스방안을 제시하였다.
Emulab software was developed by the team of University of Utah and it has been replicated at dozens of other sites in the world. Although KREONET Emulab, which established by the Korea Institute of Science and Technology Information, has only a modest number of compute nodes it has been provided an ideal playground to conduct various research for network protocols, cyber security and convergence research. A testbed is a critical enabler of experimental research and researchers only carry out the experiments that are supported by the testbed. This paper outlines the Utah Emulab’s status and use types among the last 10 years of operation results and compares them with the ones with the KREONET Emulab. In addition, Testbed-as-a-Service(TaaS) is discussed to upgrade the testbed for the convergence research community services.
Implementation of Domain Separation-based Security Platform for Smart Device KCI 등재
한국디지털정책학회 디지털융복합연구 제14권 제12호 2016.12 pp.471-476
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 들어, 스마트 단말에서 오피스, 화상회의 등 스마트워크 업무와 관련된 중요한 정보들을 다루는 경우 가 많아졌다. 또한 스마트 단말의 실행환경이 공개 소프트웨어 환경 위주로 발전하면서, 사용자들이 임의의 응용소프 트웨어를 다운받아 사용하는 것이 용이하게 됨에 따라, 스마트 단말이 보안적 측면에서 취약하게 되었다. 본 논문에 서는 TEE(Trusted Execution Environment) 기반의 격리된 안전실행환경 영역을 가지는 모바일 단말 플랫폼인 가상화 기반 스마트 단말 보안 기술의 특징을 알아본다. 또한, 본 논문에서는 스마트 단말에서 실행되는 응용프로그램을 위 한 도메인 분리 기반의 안전한 스마트 단말 보안 플랫폼에 대한 구현방법을 제안한다. 본 논문의 도메인 분리 기반 스마트 단말 보안 플랫폼 기술은 단말내의 민감 정보 유출과 비인가 접근을 차단한다. 또한 이 기술은 스마트 단말 뿐만 아니라 인터넷 상의 다양한 IoT를 포함한 다양한 기기에서 악성코드의 실행과 전파를 막을 수 있는 솔루션이 될 것이다.
Recently, important information related with smart work such as office and video conference are handled in smart device quite a lot compare with before. Also, execution environment of smart devices is getting developed as open software environment. It brought convenience to download and use any kind of application software. By that, security side of smart devices became vulnerable. This paper will discuss characteristics of smart device security technology based on virtualization that is a mobile device platform with isolated secure execution area based on TEE (Trusted Execution Environment). Also, this paper will suggest an implementation method about safe smart device security platform based on domain separation for application software which can be executed in smart devices. The domain separation based smart device security platform technology in this paper blocks unauthorized access and leakage of sensitive information in device. Also it will be the solution can block transmission and execution of malicious code in various area including variety of IoT devices in internet rather than just smart devices
Mem-Shot : 악성코드 난독화 분석을 위한 API-Trigger 기반의 메모리 덤프 시스템 설계 및 구현 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.12 No.4 2016.08 pp.23-32
최근 유포되는 악성코드에는 악성코드 분석을 방해하기 한 코드삽입, 난독화, 문자열 암호화 등 다양한 악성코드 분석회피 기술이 용되고 있다. 본 논문에서는 이러한 분석회피 기술이 용된 악성코드의 분석을 해, 가상머신 에 악성코드를 구동시킨 후 악성코드가 특정 API를 호출하면 정확한 시에 가상머신의 메모리 이미지를 빠르게 추 출 할 수 있는 악성코드 분석 시스템을 구하다. 악성코드에서 특정 API가 호출된 정확한 시에 메모리 덤 일을 얻을 수 있다면, 메모리분석을 통해 악성코드가 사용한 함수의 매개변수나 암호화 된 데이터 난독화가 해 제된 코드 정보를 얻을 수 있게 된다. 실험결과 악성코드가 API호출한 정확한 시에 메모리 덤를 할 수 있었고, 메모리 분석을 통해 분석회피 기술이 용된 악성코드로부터 숨겨진 문자열과 API 매개변수를 추출 할 수 있었다.
As malware generation techniques have been advanced, malware authors utilize various malware analysis evasion techniques such as obfuscation, garbage code insertions and string encryption. To alleviate such problems, we designed and implemented a malware analysis system which is specialized in dumping memory of a virtual machine. Malware analysis based on memory dump is a promising way to deep dive into the obfuscated malwares. Our system makes it possible to take a memory snapshot at a time of a certain API called. Furthermore, it accelerated the memory dump. Consequently, users can extract hidden information such as encrypted data and functional parameters from the malware in a user friendly manner. According to our experiments, our system can detect such hidden strings and API arguments even with analysis evasion techniques.
개인정보 국외 이동에 관한 해외 입법례의 클라우드 서비스에 대한 적용 가능성 검토 KCI 등재
전북대학교 동북아법연구소 동북아법연구 제10권 제1호 2016.05 pp.445-472
※ 기관로그인 시 무료 이용이 가능합니다.
6,700원
클라우드 서비스란 인터넷을 통해 하드웨어, 소프트웨어, 정보 데이터베이스 등 모든 컴퓨팅 자원을 이용자가 별도로 보유하거나 저장하지 않고도 필요한 때에 이용할 수 있도록 하는 컴퓨팅 서비스이다. 클라우드 서비스에서 가상화 및 분산화 기술은 클라우드 서비스의 편의성을 제공하기 위한 핵심 기술이지만, 클라우드 서비스에서 개인정보 국외 이동의 주요한 원인이기도 하다. 클라우드 서비스에서 개인정보 국외 이동의 개념에는 물리적으로 국외에 위치한 서버나 데이터센터에 개인정보가 저장되는 개념과 국내에 위치한 서버나 데이터센터에 저장된 개인정보에 국외로부터 접근하는 국외 이동의 개념이 포함되어야 할 것이다. 또한 클라우드 서비스에서는 개인정보가 실시간으로 여러 국가에 걸쳐 이동하는 특수한 양상이 나타난다. 요컨대 현재의 개인정보 국외 이동과 관련한 각국 및 해외 규정들은 기존의 물리적 환경에서의 개인정보 국외 이동에 국한되어 인터넷 환경에서의 개인정보 국외 이동이 고려되지 않았을 뿐만 아니라 클라우드 서비스의 특수성이 고려되지 않은 규정이라는 점에서, 클라우드 서비스에서 개인정보 국외 이동의 개념과 특성을 포괄하는 규정이 필요하다고 본다.
Cloud service is a new computing service which supplies users with ubiquitous access to resources, such as hardware, software and databases, without requesting users to own the necessary resources. A cloud service functions on the basis of critical cloud computing’s technologies such as web service technologies, virtualization technology and decentralization technology. While such technologies are the critical technologies in the cloud computing service, the technologies are the main causes transferring personal data abroad in the cloud service, storing personal data in the cloud service provider’s datacenters abroad and moving the data from a datacenter in this country to another datacenter in that, from moment to moment. International and foreign rules on transferring personal data abroad can be applied to movements of personal data in the traditional off line and existing internet environment. However, considering the characteristics of movements of personal data in the cloud service, the existing international and foreign rules seem not to be the appropriate rules for the cases of transferring personal data abroad in the cloud service. Therefore, in the age of the cloud service, the rules to apprehend overseas transfers of personal data in the cloud service are needed, considering the characteristics of transferring personal data in the cloud service.
클라우드 데이터센터를 위한 네트워킹 기술에 관한 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제14권 제2호 2016.02 pp.235-243
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
모바일 및 사물인터넷 기술의 발전, 대용량 빅데이터 처리, 그리고 클라우드 컴퓨팅 기술의 발전에 힘입어 기존 데이터센터는 클라우드 데이터센터로 변모하고 있다. 클라우드 데이터센터는 ICT 자원들을 가상화하여 운영함으로써 에너지 및 시설 자원을 효율적으로 관리하고 사용자들의 서비스 요구에 빠르게 대응하는 것을 목표로 하고 있다. 이에 따라 클라우드 데이터센터 네트워크는 가상화된 ICT 자원을 효율적으로 제공할 수 있도록 구성되어야 한다. 본 논문은 클라우드 데이터센터에 적합한 네트워크 구조 및 네트워킹 기술을 분석하고 이를 효과적으로 운용하기 위한 방안을 제시한다.
Legacy data centers are transforming toward cloud data centers according to the advance of mobile and Internet of Things technology, processing of big data, and development of cloud computing technology. The goal of cloud data centers is to efficiently manage energy and facility, and to rapidly provide service demands to users by operating virtualized ICT(Information and Communication Technology) resources. Accordingly, it requires to configure and operate networks for efficiently providing virtualized ICT resources. This paper analyzes networking technologies suitable for cloud data centers and presents ways to efficiently operate the data center.
그린 IT를 위한 IT 컨버전스 사례 분석에 관한 연구 KCI 등재후보
한국융합학회 한국융합학회논문지 제6권 제6호 2015.12 pp.147-152
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근에 우리 사회에서 관심을 끌고 있는 키워드는 친환경 혹은 그린이라는 단어일 것이다. 오늘날 우리사회는 산업화에 따른 무분별한 자원의 개발등으로 환경오염에 대한 우려가 가속화되고 있는 상황이다. 그린 IT는 환경을 비롯한 에너지 관련 문제들을 해결하고 기업의 생산성을 높일 수 있는 방법으로 미래 산업 발전에 필요하다. 따라서 본 연구에서는 그린 IT와 관련된 내용을 연구하였다. 그린 IT는 변천과정을 통해 IT에 대한 그린화를 시작으로 현재는 IT를 이용한 타 산업에서의 그린화가 활발히 진행되고 있다. 본 연구에서는 그린 IT에 대한 변천과정 및 각 과정에서의 특성, 대표적 사례들에 대해 기술하였다. 마지막으로 그린 IT에 대한 대표적 융합사례인 스마트워크(smart work)에 대해 조사, 분석하였다.
Eco-friendly or green is a key word which we use in our life. There are examples such as eco-friendly laundry detergent and agricultural products or green car and home, Due to the indiscriminate development, it was caused severe environmental pollution. Green IT is a necessary technology to solve the energy and environmental problems and to increase the productivity of corporations. Therefore, we studied contents related with green IT. The history for green IT has changed from ‘Green of IT’ to ‘IT for Green’. Studies for ‘IT for Green’ progress extensively on today. In this paper, we described a transition progress and characteristics of green IT. Lastly, we analyzed smart work in the examples of the top.
클라우드 플랫폼 기반 스마트 모바일 결제 서비스 모델 제안 및 분석
한국경영정보학회 한국경영정보학회 정기 학술대회 사물인터넷 시대의 ICT 융합과 정보보호 2014.11 pp.699-708
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 Research-in-Progress는 국제공동기술개발 사업(유럽기술협력사업, ‘EUREKA’)에서 ‘스마트카 드 가상화’ 연구 개발 과제에 대한 연구 과정을 소 개한다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.