년 - 년
코드 유사성 비교 기반의 스마트 컨트랙트 공격 표면 분석 프레임워크 KCI 등재
한국융합보안학회 융합보안논문지 제24권 제5호 2024.12 pp.161-169
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
스마트 컨트랙트의 활용이 증가함에 따라 이를 복제하고 수정하는 과정에서 다양한 보안 문제가 발생하고 있다. 본 연구는 스마트 컨트랙트의 변경 사항을 효과적으로 감지하고 공격 표면을 식별할 수 있는 프레임워크를 제안한다. 제안된 방법론은 AST(Abstract Syntax Tree), CFG(Control Flow Graph), GNN(Graph Neural Network)을 통합적으로 활용하여 코드 구조를 심층 분석한다. 실증 연구로서 Uniswap V2 프로토콜과 이를 기반으로 파생된 프로젝트들의 보안 위험성을 평가하였으며, 특 히 Uranium Finance와 BurgerSwap 사례를 중심으로 코드 유사도 분석과 보안 취약점 진단을 수행하였다. 이를 통해 제안된 분석 체계가 스마트 컨트랙트의 보안 감사에 적용될 가능성을 평가하였다.
As smart contracts become increasingly widespread, security issues frequently arise during their duplication and modifi cation. This study presents a framework for effectively detecting alterations in smart contracts and identifying associated attack surfaces. By employing a combination of AST (Abstract Syntax Tree), CFG (Control Flow Graph), and GNN (Grap h Neural Network) analysis, the framework offers a comprehensive approach to examining contract code structures. Using the Uniswap V2 protocol and its derivative projects as case studies, including Uranium Finance and BurgerSwap, this rese arch conducted code similarity comparisons and identified critical vulnerabilities. The results highlight the potential of the proposed framework as a robust tool for smart contract security auditing and vulnerability detection.
문서화되지 않은 macOS 인터페이스 식별을 통한 퍼블릭 프레임워크-XPC 서비스 의존성 그래프 생성 및 공격 표면 분석
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.3 2026 pp.857-868
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
macOS는 퍼블릭·프라이빗 프레임워크, XPC 서비스 등 다층적 구성요소로 이루어지며, 프라이빗 프레임워크는 공식 문서와 헤더 없이 배포되어 실제 시스템에서 노출되는 인터페이스의 상당 부분이 SDK 범위 밖에 존재한다. 이처럼 문서화되지 않은 인터페이스는 공격자가 악용 가능한 현실적인 공격 대상이 되지만, 기존 공격 표면 분석 연구는 시스템 호출이나 IOKit와 같은 단일 계층에 집중되어 숨겨진 공격 표면을 충분히 식별하지 못하고 있다. 이를 해결하기 위해 본 연구는 XPC 서비스·엔드포인트 식별, 정적·동적 프레임워크 의존성 분석, ObjC 메타데이터 분석을 통합하여 퍼블릭 프레임워크에서 프라이빗 프레임워크를 경유해 XPC 서비스로 이어지는 의존성 그래프 생성 방식을 제안하고, 2,918개 바이너리를 대상으로 유효성을 정량적으로 검증한다.
macOS consists of multi-layered components including public and private frameworks and XPC services. Private frameworks are distributed without official documentation or headers, leaving a substantial portion of the interfaces exposedin the actual system outside the scope of the SDK (Software Development Kit). Such undocumented interfaces represent realistic attack targets that adversaries can exploit. However, existing attack surface analysis research has focused onsingle-layer interfaces such as system calls and IOKit, failing to sufficiently identify hidden attack surfaces. To address this, the present study proposes a dependency graph construction approach that integrates XPC service and endpoint identification, static and dynamic framework dependency analysis, and ObjC metadata analysis to trace paths from public frameworks through private frameworks to XPC services, and quantitatively validates the methodology against a dataset of 2,918 binaries.
항적추적어뢰에 대항하는 하드킬 방식의 수상함 수중방어체계 효과도 분석
[NRF 연계] 광운대학교 방위사업연구소 선진국방연구 Vol.6 No.2 2023.08 pp.1-15
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구는 적의 항적추적어뢰 공격에 대항하기 위한 우군 수상함의 하드킬 방식 수중방어체계의 효과를 분석하기 위한 시뮬레이션을 수행한다. 항적추적어뢰 공격 시 수상함은 하드킬 방어체계인 음향추적어뢰를 발사함과 동시에 회피기동을 하는 것으로 가정하며, 어뢰의 발사각 계산에 확률적 오차를 부여하여 몬테카를로 반복 시뮬레이션을 통해 수상함의 생존율에 대한 효과도 분석을 실시한다. 이때 수상함이 회피기동만 실시할 경우와 회피기동을 하며 하드킬 방어체계를 함께 사용하는 경우로 구분하여 시뮬레이션을 수행하였다. 수상함의 어뢰 최대탐지거리 및 적 어뢰 최초위치를 변수로 설정하여 생존율을 관측하였으며, 실험 결과 수상함이 항적추적어뢰의 공격을 받을 때, 하드킬 방어체계가 없는 경우 함정의 생존율이 최대 34% 수준인 반면 하드킬 수중방어체계가 있는 경우 최소 61% 이상의 생존율을 나타냈다. 이를 바탕으로 하드킬 방어체계가 항적추적어뢰의 공격으로부터 생존율을 더욱 높일 수 있음을 수치적으로 입증하였다.
We conducted simulations to analyze the effects of a hard-kill-type underwater defense system that defends friendly warships against an enemy wake-homing torpedo. Assuming that the enemy torpedo is a wake-homing torpedo, our surface warship detours to the prespecified evasive course by firing a hard-kill-type system, which is modeled as a passive acoustic homing-torpedo, to attack the enemy torpedo. We analyzed the effectiveness of a warship’s survival probability via Monte Carlo simulation, given the probabilistic angles of the launched torpedoes, to compare two cases where one used only evasive maneuvering and the other used the hard-kill-type underwater defense system with evasion at the same time. By changing the maximum torpedo detection range of a warship and the torpedo’s initial location, we observed that the resulting survival probability of a warship was above 61% with a hard-kill-type defense system, whereas it remained at 34% without a hard-kill defense system, the necessity of a hard-kill underwater defense system, especially against wake-homing torpedoes.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.