년 - 년
상용 OS기반 제어시스템 확률론적 취약점 평가 방안 연구 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제9권 제8호 2019.08 pp.35-44
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 즉시 패치가 어려운 상용 운영체제 기반의 계측제어시스템의 취약점 평가 방안 및 시간의 경과에 따른 위험의 크기를 정량적으로 파악하는 것이다. 연구 대상은 상용 OS가 탑재된 계측제어시스템의 취약점 발견과 영향의 크기 이다. 연구에서는 즉각 취약점 조치가 힘든 디지털 계측제어시스템의 취약점 분석 및 조치방법을 연구함으로써, 계측제어 시스템이 존재하는 핵심기반시설의 전체적인 사이버보안 위험과 취약점을 정량적으로 파악하는 것이다. 본 연구에서 제 안한 확률론적 취약점 평가 방안은 즉각적인 취약점 패치가 어려운 상용 운영체제 기반의 계측제어시스템에서 취약점 패치 우선 순위 및 패치가 불 가능시 수용 가능한 취약점의 임계값 설정, 공격 경로에 대한 파악을 가능하게 하는 모델링 방안을 제시한다.
The purpose of this study is to find out quantitative vulnerability assessment about COTS(Commercial Off The Shelf) O/S based I&C System. This paper analyzed vulnerability's lifecycle and it's impact. this paper is to develop a quantitative assessment of overall cyber security risks and vulnerabilities I&C System by studying the vulnerability analysis and prediction method. The probabilistic vulnerability assessment method proposed in this study suggests a modeling method that enables setting priority of patches, threshold setting of vulnerable size, and attack path in a commercial OS-based measurement control system that is difficult to patch an immediate vulnerability.
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.35 No.2 2025 pp.265-275
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
오늘날 인공지능의 활용도가 무궁무진하게 발전하며, 다양한 분야에서 사용되고 있다. 개중에 보안 분야에서는 악성 파일을 탐지하고 해당 악성 파일에 의한 피해가 없도록 인공지능 모델을 활용한다. 본 연구에서는 특정 악성 파일 탐지 모델에 대해 Gradient Based한 상황과 Gradient Free한 상황으로 나누어 적대적 공격을 수행하고 취약성을 분석하는 프레임워크 및 악성 파일 탐지 모델에 대한 방어 기법을 제안하여 적용한다. 실험 결과 공격에 대해 최대 98%의 공격 성공률을, 방어 기법 적용 이후 최대 2%의 공격 성공률을 보였다. 이 과정에서 취약성 분석 레포트가 작성됨을 확인했다. 본 논문에서 산출된 프레임워크를 이용하여 더욱이 효과적으로 보안 분야에서 인공지능을 활용하고, 기존에 있던 악성 파일 탐지 모델의 안정성 및 미특정 모델들에 대한 안정성을 확보하고자 한다.
Today, the use of artificial intelligence is endless and is used in various fields. Among them, artificial intelligence models are used in the security field to detect malicious files and prevent damage caused by the malicious files. In this study, a framework for performing hostile attacks and analyzing vulnerabilities by dividing into gradient-based and gradient-free situations for specific malicious file detection models and defense techniques for malicious file detection models are proposed and applied. As a result of the experiment, it showed an attack success rate of up to 98% against attack and a maximum attack success rate of 2% after applying the defense technique. It was confirmed that a vulnerability analysis report was created in this process. Using the framework calculated in this paper, we intend to more effectively utilize artificial intelligence in the security field and secure the stability of the existing malicious file detection model and the stability of unspecified models.
C언어 소스코드 보안 취약점 탐지를 위한 LSTM 딥러닝 하이브리드 모델의 성능 비교 분석: GNN, CNN, GRU
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.3 2026 pp.949-958
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
C언어의 메모리 직접 접근 특성으로 발생하는 보안 취약점 탐지를 위해, 본 논문은 LSTM의 한계를 보완하는 하이브리드 딥러닝 모델들을 비교 분석하였다. LSTM을 기반으로 CNN, GRU, GNN을 각각 결합한 모델들을 소스코드에 적용하였으며, 탐지 성능을 다각도로 분석하기 위해 클래스 불균형 조건에서 성능을 실험적으로 평가하였다. 실험 결과, 소스코드의 전역적 문맥과 CPG(코드 속성 그래프) 기반의 구조적 정보를 적응형 게이트(Adaptive Gate)로 융합한 LSTM-GNN 모델('CPGate Keeper' 프레임워크)이 가장 뛰어난 성능을 보였다. 이를 통해 구조 중심적 하이브리드 접근법이 LSTM 경로가 추출한 '문맥 정보'와 GNN이 추출한 '구조적 특징' 중 탐지에 더 결정적인 요소가 무엇인지 모델이 스스로 판단하게 노이즈와 오탐을 최소화할 수 있다.
This paper compared and analyzed hybrid deep learning models that complement the limitations of LSTM in order to detect security vulnerabilities arising from the direct access characteristics of memory in C language. Based on LSTM, models that combine CNN, GRU, and GNN were applied to the source code, and the performance was experimentally evaluated under class imbalance conditions to analyze the detection performance from various angles. As a result of the experiment, the LSTM-GNN model ('CPGate Keeper' framework), which combines the global context of the source code and structural information based on CPG (code attribute graph) with an adaptive gate, showed the best performance. Through this, the structure-oriented hybrid approach can minimize noise and false positives so that the model can judge for itself what is more decisive in detection among the 'contextual information' extracted by the LSTM path and the 'structural features' extracted by GNN.
Design Model for Extensible Architecture of Smart Contract Vulnerability Detection Tool
국제인공지능학회(구 한국인터넷방송통신학회) International Journal of Internet, Broadcasting and Communication Vol.12 No.3 2020.08 pp.189-195
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Smart contract, one of the applications of blockchain, is expected to be used in various industries. However, there is risks of damages caused by attacks on vulnerabilities in smart contract codes. Tool support is essential to detect vulnerabilities, and as new vulnerabilities emerge and smart contract implementation languages increase, the tools must have extensibility for them. We propose a design model for extensible architecture of smart contract vulnerability detection tools that detect vulnerabilities in smart contract source codes. The proposed model is composed of design pattern-based structures that provides extensibility to easily support extension of detecting modules for new vulnerabilities and other implementation languages of smart contract. In the model, detecting modules are composed of independent module, so modifying or adding of module do not affect other modules and the system structure.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.