년 - 년
[Kisti 연계] 한국항행학회 한국항행학회논문지 Vol.18 No.4 2014 pp.353-358
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
과거의 제어 시스템은 제어 시스템의 망을 외부의 망과 분리함으로써 외부의 접근을 원천 차단하여 외부공격에 대한 보안을 보장받았다. 그러나 제어 시스템의 디바이스들이 다양해지고 디바이스 간의 상호 운용이 필요해짐에 따라 효율적인 관리 시스템이 필요해 졌으며 이는 제어 시스템 또한 외부의 망과 연결되는 요인이 되었다. 따라서 효율적인 관리는 용이해졌으나 보안 사항이 포함되지 않은 다수의 제어 시스템의 프로토콜이 각종 사이버 공격의 위험에 놓이게 되어 각 프로토콜에 대한 보안 기능 추가 및 공격 탐지에 관한 연구가 활발히 진행 되어 왔다. 본 논문에서는 컨트롤 센터와 변전소간 통신에 쓰이는 DNP(distributed network protocol)3 프로토콜을 중점으로 다루며 프로토콜의 특징과 보안 현황 분석 및 현재까지 공개된 취약점 분석과 취약점을 이용한 공격 탐지 방안을 제시한다.
In the past, security on control system was guaranteed by isolation of control system networks from external networks. However as devices of the control systems became more various and interaction between the devices became necessary, effective management system for such network emerged and this triggered connection between control system networks and external system networks. This made management of control system easier but also made control system exposed to various cyber attack threats, Therefore researches on appending security measures on each protocols are in progress. This paper focused on DNP(distributed network protocol)3 protocol which is used for communication between control center and substations. It describes characteristics of DNP3 protocol and research on adding security elements to the protocol. It also analyzed known vulnerabilities of DNP3 protocol and proposed data mining methodology for detecting such vulnerabilities.
프로토콜 공격에 대한 계층적 침입탐지 시스템의 설계 및 구현
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제5권 제2호 2005.11 pp.61-70
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.3 2013.05 pp.1-10
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
This paper proposes a DTSA(Detection Technique against a Sybil Attack) protocol so that it can provide vehicles with the secure information for the road situation and the traffic flow among vehicles and by detecting a Sybil attack. This DTSA uses SKC(Session Key based Certificate) to verify the IDs among vehicles, which generates a vehicle’s anonymous ID, a session key, the expiration date and a local server’s certificate for the detection of a Sybil attack. In conclusion, this DTSA reduces not only the detection time against a Sybil attack but also the verification time for ID by using a hash function and an XOR operation. Besides, a drivers’ privacy can be protected by using an anonymous ID. This DTSA helps drivers drive safely with the reliable information of VANET and reduce traffic accidents.
보안공학연구지원센터(IJAST) International Journal of Advanced Science and Technology Vol.82 2015.09 pp.63-70
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
A mobile Adhoc Network is a collection of various mobile nodes that can change it and configure itself on the network. In MANET, Ad-hoc On-Demand Distance Vector (AODV) floods the packets to discover route. In Ad hoc On Demand Vector (AODV) routing protocol for MANET (Mobile Ad hoc Networks), malicious nodes can easily disrupt the communication because of inherent limitations. In this paper, performance of AODV Routing Protocol is analyzed with and without malicious attack. A malicious node disrupts the limit and floods the network with false control packets. Malicious node affects the whole network as it consumes more bandwidth and drops packets which in turn degrade the performance of AODV routing protocol. Performance is carried out under various parameters like Throughput, packet delivery ratio, packets dropped and normalized routing load.
보안공학연구지원센터(IJSH) International Journal of Smart Home Vol.7 No.3 2013.05 pp.105-120
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The VCM (Vessel Communication Manager) proposed in this paper consists of ARP (Azimuth based Routing Protocol) and NATF (Network Attack Traceback Facility). The ARP can transmit accident information from a source to a headquarter rapidly and accurately by using Azimuths. It designs the Ac-RREQ message that appends an azimuth, a cumulation S/N, and a standby packet count field to the exiting RREQ message and the Ac-RREP message that appends an azimuth and a cumulation S/N field to the existing RREP message. It adjusts the transmission scope of the Ac-RREQ message with azimuths and decides the optimal path by judging the priority of Ac- RREP with the standby packet count and the cumulation S/N. Therefore, its simulation shows that the transmission time of the Ac -RREQ message is reduced more largely than the existing RREQ by using azimuths. In collision, as it transmits data through optimal paths, not only unexpected accidents are prevented with an urgent action, but also the life of nodes is prolonged due to the energy- saving of nodes. And, the NATF can trace back network attacks happening inter-vessel by recording the routes of routers with marking and logging function and can reduce a traceback overhead because of not marking all the packets.
Advanced Protocol to Prevent Man-in-the-middle Attack in SCADA System SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.2 2014.03 pp.1-8
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
SCADA system is a computer system that monitors and controls the national infrastructure or industrial process including transportation facilities, water treatment and distribution, electrical power transmission and distribution, and gas pipelines. If a SCADA system is infected by a malicious worm, such as the Stuxnet, disaster is inevitable. Since the appearance of Stuxnet, researchers focused on detecting this intrusion in SCADA networks. As a result, various methods have been presented by researchers. One of them is to monitor traffic and detect anomalous patterns. However, it is not able to detecting a spoofed packet. This study present three cases of system anomaly by example of pattern based on real data of PROFINET/DCP protocol. And propose protection method using the authentication.
Desynchronization Attack on Hash-based RFID Mutual Authentication Protocol KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.9 No.4 2012.08 pp.357-366
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
A radio frequency identification (RFID) system is a promising automatic identification technology that uses communication via radio waves to identify and track moving objects. Privacy and security concerns inhibit the fast adaption of RFID technology for many applications. Although many EPCgen2 compliant protocols have been proposed in a quest to ensure security of low cost tags, still more the optimum security is not achieved as many protocols are found prone to well-known attacks. Recently, Cho et al. proposed a hash-based RFID mutual authentication protocol and the protocol is secure. However, this paper shows that Cho et al.’s protocol is weak against desynchronization attack and provides remedy for it.
보안공학연구지원센터(IJFGCN) International Journal of Future Generation Communication and Networking Vol.9 No.1 2016.01 pp.157-166
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
MANET is multi-hop network in which collection of mobile nodes is self configurable and co-operates together for communicating data without the need of any centralized component for management. Due to this dynamic nature of topology and infrastructure less frame in MANET, these nodes have to rely on each other for data transmission in multi-hop fashion and thus are prone to packet drop attacks like Blackhole attack, Co-Operative Blackhole attack, etc and various types of data security attacks. In this paper, Solutions are proposed to detect Collaborative co-operative Blackhole attack in MANET. We introduced the mechanism of TRACEROUTE that helps in detecting the source of collaborative Blackhole attack and thus break the collaboration by eliminating and marking source of Collaboration between those malicious nodes. AODV routing protocol is enhanced by introducing new field that helps in finding the optimal, secure and reliable routes. These Solutions are compared with W-AODV for Packet Delivery Ratio, Control load, accuracy in Blackhole detection and accuracy in Blackhole detection.
보안공학연구지원센터(IJFGCN) International Journal of Future Generation Communication and Networking Vol.8 No.4 2015.08 pp.155-160
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Mobile ad-hoc networks (MANET) they can be deploy simply in a few environment without any determination. A major point that affectssuch a networks that characterize by dynamic change in topologyis the performance where routing worth forcefulperformance is one of the key challenges in deploying MANET. Black hole attacks node false advertises that they have secured path source to destination. In this paper the performance of proactive routing protocols Destination-Sequenced Distance Vector (DSDV) and Improved Destination-Sequenced Distance Vector (I-DSDV) evaluated under Ipv6 environment using black hole attack under different performance metrics Packet delivery Fraction (PDF), Delay, Routing Overhead (RO). The study in MANET is done with network simulator version 2 simulator.
패킷 인젝션 공격을 탐지하는 GSK(Group Secret Key) 기반 SAODV(Secure AODV) 라우팅 프로토콜 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.10 No.6 2013.12 pp.681-694
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
본 논문에서는 모바일 애드 혹 네트워크에서 RREQ/RREP 메시지의 무결성 검증으로 패킷 인젝션 공격을 탐지하는 GSK(Group Secret Key) 기반 SAODV(Secure AODV)를 설계를 제안한다. SAODV는 첫째, 모바일 애드 혹 네트워크를 관리하는 베이스 스테이션에 GSK(Group Secret Key)를 배포하는 기능을 부여하고, 둘째, 패킷 인젝션 공격을 탐지하기 위하여 RREQ/RREP 메시지에 Authentication value 필드를 추가하여 RREQ/RREP 메시지 무결성을 검증한다. 셋째, 데이터의 전송경로를 왜곡하는 패킷 인젝션 공격을 탐지하기 위하여 라우팅 테이블에 Neighbor node list 필드와 Malicious node list 필드를 추가하였다. 그 결과, SAODV는 인젝션 공격 탐지뿐만 아니라 노드들의 불필요한 메시지 전달을 방지함으로써 에너지 효율을 향상시킬 수 있다.
This paper proposes a design of the SAODV(Secure AODV) based on GSK(Group Secret Key) detecting a Packet Injection Attack by the integrity verification of an RREQ/RREP message on the MANET. The SAODV has the following functions. First, it provides the function to distribute GSK to a Base Station which manages the MANET. Second, it verifies the integrity of an RREQ/RREP message by adding an Authentication Value field to the RREQ/RREP message to prevent Packet Injection attack, Third, a Neighbor Node List field and Malicious Node List field are added to a Routing Table to detect a Packet Injection Attack which distorts the transmission route of data. Consequently, the SAODV improves energy efficiency not only by detecting a Packet Injection Attack but also by preventing unnecessary message transmission.
[Kisti 연계] 한국정보처리학회 정보처리학회논문지 C Vol.c11 No.4 2004 pp.439-446
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
인터넷에서의 사용자 인증은 안전한 통신을 위해 가장 중요한 서비스 중의 하나이다. 비록 패스워드 기반 메커니즘이 네트워크 상에서의 사용자 인증을 위해 가장 많이 쓰이는 방법이기는 하나, 사용자들이 기억하기 쉬운 패스워드(easy-to-remember)를 사용하므로, 사전공격(dictionary attack)에 취약한 것과 같은 근본적인 문제점들을 가지고 있다. 이러한 사전공격을 방지하기 위만 방법들의 경우에는 높은 계산량을 필요로 한다. 본 논문에서는 이러한 문제를 해결하기 위한 최근에 발표된 OSPA 프로토콜에 대하여 설명하고, OSPA 프로토콜이 stolen-verifier 공격과 impersonation 공격에 취약함을 보인다. 그리고 이러한 공격들에 안전한 개선된 OSPA 프로토콜을 제안한다. 제안하는 프로토콜은 스마트 카드에 탑재된 co-processor를 통해 암호학적 연산이 수행되므로 사용자에게 낮은 계산량을 제공한다.
In the Internet, user authentication is the most important service in secure communications. Although password-based mechanism is the most widely used method of the user authentication in the network, people are used to choose easy-to-remember passwords, and thus suffers from some Innate weaknesses. Therefore, using a memorable password it vulnerable to the dictionary attacks. The techniques used to prevent dictionary attacks bring about a heavy computational workload. In this paper, we describe a recent solution, the Optimal Strong-Password Authentication (OSPA) protocol, and that it is vulnerable to the stolen-verifier attack and an impersonation attack. Then, we propose an Improved Optimal Strong-Password Authentication (I-OSPA) protocol, which is secure against stolen-verifier attack and impersonation attack. Also, since the cryptographic operations are computed by the processor in the smart card, the proposed I-OSPA needs relatively low computational workload and communicational workload for user.
Intelligent Internal Stealthy Attack and its Countermeasure for Multicast Routing Protocol in MANET
[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.37 No.6 2015 pp.1108-1119
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Multicast communication of mobile ad hoc networks is vulnerable to internal attacks due to its routing structure and high scalability of its participants. Though existing intrusion detection systems (IDSs) act smartly to defend against attack strategies, adversaries also accordingly update their attacking plans intelligently so as to intervene in successful defending schemes. In our work, we present a novel indirect internal stealthy attack on a tree-based multicast routing protocol. Such an indirect stealthy attack intelligently makes neighbor nodes drop their routing-layer unicast control packets instead of processing or forwarding them. The adversary targets the collision avoidance mechanism of the Medium Access Control (MAC) protocol to indirectly affect the routing layer process. Simulation results show the success of this attacking strategy over the existing "stealthy attack in wireless ad hoc networks: detection and countermeasure (SADEC)" detection system. We design a cross-layer automata-based stealthy attack on multicast routing protocols (SAMRP) attacker detection system to identify and isolate the proposed attacker. NS-2 simulation and analytical results show the efficient performance, against an indirect internal stealthy attack, of SAMRP over the existing SADEC and BLM attacker detection systems.
네트워크 기반 프로토콜 공격에 대한 침입탐지 시스템의 설계
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2002 pp.523-525
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
DOS (Denial Of Service)에 대한 공격은 시스템의 정상적인 동작을 방해하여 시스템 사용자에 대한 서비스 제공을 거부하도록 만드는 공격으로 현재 이의 공격에 대한 탐지 알고리즘 및 연구들이 많이 제시되고 있다. 본 논문에서는 네트워크 또는 트랜스포트 계층에 해당하는 프로토콜(TCP/IP, ICMP, UDP) 공격을 분석하고 이들 프로토콜의 취약점을 공격하는 DOS 공격 이외의 다른 공격을 탐지하기 위하여 프로토콜의 기능별, 계층별에 따른 모듈화 작업을 통하여 네트워크 침입탐지 시스템을 설계하였다.
네트워크 기반 프로토콜 공격에 대한 침입탐지 시스템의 구성 방안
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2001 pp.883-886
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
DOS (Denial Of Service)에 대한 공격은 시스템의 정상적인 동작을 방해하여 시스템 사용자에 대한 서비스 제공을 거부하도록 만드는 공격으로 현재 이의 공격에 대한 탐지 알고리즘 및 연구들이 많이 제시되고 있다. 본 논문에서는 네트워크 또는 트랜스포트 계층에 해당하는 프로토콜(TCP/IP, ICMP, UDP) 공격을 분석하고 이들 프로토콜의 취약점을 공격하는 DOS 공격 이외의 다른 공격을 탐지하기 위하여 프로토콜의 기능별, 계층별에 따른 모듈화 작업을 통하여 네트워크 침입탐지 시스템을 구성하였다.
리소스 레코드 부분암호화를 이용한 DNS 변조공격 탐지 프로토콜 연구
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2013 pp.683-686
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 인터넷을 이용한 금융거래가 활발해지면서 피싱이나 파밍과 같은 공격을 통한 개인정보 유출 사고가 빈번히 발생하고 있다. 특히 파밍의 경우, 공격자가 DNS 정보를 변조하여 사용자가 올바른 URL을 입력하더라도 악의적 사이트로 컴퓨터가 접속을 하기 때문에 위험성이 매우 높다. 이러한 공격들을 방지하기위하여 여러 연구가 진행되었지만, DNS 정보의 검증을 위한 추가적인 절차를 필요로 하거나 과도한 네트워크 트래픽을 유발할 수 있는 문제점을 가지고 있다. 따라서 본 논문에서는 이러한 문제점을 극복하고자 DNS 리소스 레코드(Resource Record)의 부분 암호화를 이용하여 DNS 변조 공격을 탐지 하는 프로토콜을 제안한다.
TCP/IP 프로토콜 취약성 공격 탐지를 위한 실시간 접근 로그 설계 및 구현
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2001 pp.733-735
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
네트워크가 보편화되면서 사이버 공간을 이용한 테러가 전 세계적으로 발생하고 있다. TCP/IP 프로토콜은 현재 가장 많이 사용되고 있는 네트워크 기술중의 하나로 인터넷뿐만 아니라, 많은 소규모의 사설 컴퓨터네트워크에서도 많이 사용되고 있다. 그러나 TCP 자체가 가지고 있는 보안 취약점 때문에 SYN 공격, TCP Sequence Number 공격, IP Spoofing, TCP Connection hijacking, Sniffing 과 같은 다양한 해킹 기법이 등장하고 있다. 본 논문에서는 TCP/IP 프로토콜 취약점을 이용하여 공격할 경우 이를 탐지하거나 차단하지 못하는 경우에 대비하여 실시간 접근 로그 파일을 생성하여 시스템 관리자가 의사결정을 할 수 있는 것과 동시에 시스템 스스로 대처할 수 있는 시스템을 구현하여 타당성을 검증하고 그에 따른 기대효과를 제시 한다.
GOOSE 프로토콜의 취약성을 이용한 공격 및 탐지방안
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2013 pp.879-881
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
SCADA 시스템과 같은 제어 시스템의 일반 네트워크와의 연결은 시스템의 제어 및 관리에 효율성을 높여주었으나 일반 네트워크를 사용하기 때문에 고전적인 네트워크의 취약성에 노출되어 취약성을 이용한 사이버 공격이 가능하게 되었다. 따라서 기존 네트워크 환경과는 다른 제어 시스템의 환경과 보안을 고려한 프로토콜이 개발 되었거나 개발 중에 있으며 보안은 이 프로토콜들과 밀접한 관계를 가지게 되었다. 본 논문에서는 제어시스템 프로토콜 중 IEC 61850에서 정의된 GOOSE프로토콜을 대상으로 GOOSE프로토콜의 취약점 분석 및 취약점을 이용한 공격과 이러한 공격을 탐지하기 위한 방법을 제시한다.
Privileged-Insider 공격에 안전한 원격 사용자 인증 프로토콜
[Kisti 연계] 한국멀티미디어학회 멀티미디어학회논문지 Vol.20 No.4 2017 pp.614-628
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Recently, Due to the rapid development of the internet and IT technology, users can conveniently use various services provided by the server anytime and anywhere. However, these technologies are exposed to various security threat such as tampering, eavesdropping, and exposing of user's identity and location information. In 2016, Nikooghadam et al. proposed a lightweight authentication and key agreement protocol preserving user anonymity. This paper overcomes the vulnerability of Nikooghadam's authentication protocol proposed recently. This paper suggests an enhanced remote user authentication protocol that protects user's password and provides perfect forward secrecy.
Man-in-the-middle attack에 강한 변형된 AKE 프로토콜
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2003 pp.2085-2088
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
인터넷의 발전과 함께 사용자 인증 기술도 발전하였다. 이러한 사용자 인증 기술 중 패스워드 인증기술이 특정 컴퓨터 또는 통신 시스템 서버의 서비스를 요구하는 클라이언트의 신분을 확인하는 기술로 가장 널리 사용되고 있다. 그러나 일반적으로 사용되는 패스워드 인증의 약한 안전성으로 인한 보안 사고는 매년 증가하고 있고, 그 피해 또한 상당하다. 본 논문은 이런 패스워드 인증 방식 중 강한 인증으로 분류되는 AKE 프로토콜에 대해 분석하고, man-in-the-middle attack이 가능하다는 것을 보인 후, 이 취약점을 보완하여 제 3의 신뢰기관을 두지 않고 두 파티간의 상호인증이 가능한 변형된 AKE 프로토콜을 제안한다.
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2002 pp.445-447
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Lin 등이 제안한 키 교환 프로토콜 및 SAKA 변형 키 교환 프로토콜은 오프라인 패스워드 추측 공격에 대응하지 못했다. 본 논문에서는 기존의 SAKA 변형 키 교환 프로토콜의 취약점을 해결하기 위한 새로운 키 교환 프로토콜을 제안한다. 제안한 프로토콜은 키 검증단계에서 일방향 해쉬 함수를 이용함으로서 기존 프로토콜의 문제점들을 해결하였다. 본 논문에서 제안한 프로토콜은 키 교환 프로토콜에서 요구되는 재전송 공격과 오프라인 패스워드 추측 공격에 강한 특징을 갖고 완전한 전방향 보안(perfect forward secrecy)을 제공한다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.