RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    웹 API 보안 강화를 위한 다층 방어형 침입 탐지 기술 연구: 금융 마이데이터 환경을 중심으로 = A Study on Multi-Layered Intrusion Detection Technology for Enhancing Web API Security: Focusing on the Financial MyData Environment

    한글로보기

    https://www.riss.kr/link?id=T17372473

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    클라우드 기반 기술의 확산으로 웹 API 기반 데이터 통신이 보편화됨에 따라, 웹 API에 대한 공격 표면이 확대되어 접근 토큰 탈취, 파라미터 변조 등 웹 API 도메인에 특화된 보안 취약점이 증가하고 있다. 특히 국내에서 널리 활용되는 금융 마이데이터 서비스는 표준화된 API를 통해 분산된 개인 금융정보를 수집, 제공하므로 이러한 취약점이 대규모 개인정보 유출 및 프라이버시 침해로 이어질 가능성이 높다.
    이에 대응하기 위해 침입 탐지 기술이 활발하게 연구되고 있다. 그러나 웹 API 대상 침입 탐지 연구는 초기 단계로서, 공격 시그니처 데이터베이스가 웹 API 도메인에 대한 공격에 대응할 수 있도록 다양하게 구성되지 못했으며, 명세 기반 탐지에서 활용되는 정상 행위 규칙은 도메인별로 상이한 구성을 갖는 웹 API의 특성상 체계적인 모델링이 부족하여 완전성 있는 명세가 구현되기에 어려움이 있다. 또한 연구를 위한 고품질 데이터셋의 부족으로 인해 데이터셋에 의존하는 머신러닝 기반 탐지 방식에서는 공격 유형별 분류나 해석이 제한적이다. 본 연구에서는 금융 마이데이터 환경에서 발생할 수 있는 다양한 공격 시나리오를 구성하고, 이에 대한 공격 시그니처 생성을 통해 대부분의 알려진 공격에 대해 대응할 수 있도록 하며, 정상 행위 규칙을 정교하게 수립하여 명세 기반 탐지 방식의 한계인 오탐률을 개선하고 상세한 흐름 단위까지 탐지할 수 있도록 한다. 또한 거대 언어 모델을 활용하여 문맥 기반의 이해를 통해 데이터셋 의존성을 줄이고, APT 및 제로데이 공격에 대한 탐지 성능을 향상하고자 한다. 또한, 이러한 탐지 모델을 다층적으로 구현하여 각 탐지 방식의 성능을 극대화한 다층 방어형 침입 탐지 기술을 제안한다. 시그니처, 명세 기반 탐지 방식을 결합한 하이브리드 탐지 레이어를 통해 신속하고 효율적인 1차 탐지를 수행하고, 2차 탐지로서 백그라운드에서 입력 데이터의 맥락을 파악하여 고도화된 공격을 심층적으로 식별하는 거대 언어 모델 기반 정밀 탐지 레이어를 다층적으로 설계하여 웹 API 보안 취약점 대응 기술을 제시한다. 이를 검증하기 위해 대표적 고위험 도메인인 금융 마이데이터 환경을 구성하였으며, 하이브리드, 거대 언어 모델, 다층 방어형 침입 탐지 모델 등 탐지 기술별 침입 탐지 실험을 통해 탐지 성능, 리소스 소비, 탐지 소요 시간 트레이드오프를 분석하였다.
    실험 결과, 본 논문에서 제안한 다층 방어형 침입 탐지 기술은 정확도 97.36%, 정밀도 98.03% 등 6가지의 탐지 성능 지표 중 4가지의 지표에서 가장 우수한 결과를 달성하였다. 또한 거대 언어 모델 대비 약 85% 감소한 탐지 소요 시간으로 API 요청-응답 소요 시간과 비교하여 실시간 탐지가 가능함을 보였으며, GPU 평균 사용률은 약 27%가 감소하여 리소스 소비 측면에서도 개선되었음을 확인하였다.
    이러한 결과는 기존의 웹 API 대상 탐지 기술 대비 유의미한 성능 향상을 달성하였음을 보여주며, 금융 마이데이터와 같은 실제 웹 API 도메인에서 본 논문에서 제안한 다층 방어형 침입 탐지 기술이 적용 가능함을 확인하였다.
    번역하기

    클라우드 기반 기술의 확산으로 웹 API 기반 데이터 통신이 보편화됨에 따라, 웹 API에 대한 공격 표면이 확대되어 접근 토큰 탈취, 파라미터 변조 등 웹 API 도메인에 특화된 보안 취약점이 증...

    클라우드 기반 기술의 확산으로 웹 API 기반 데이터 통신이 보편화됨에 따라, 웹 API에 대한 공격 표면이 확대되어 접근 토큰 탈취, 파라미터 변조 등 웹 API 도메인에 특화된 보안 취약점이 증가하고 있다. 특히 국내에서 널리 활용되는 금융 마이데이터 서비스는 표준화된 API를 통해 분산된 개인 금융정보를 수집, 제공하므로 이러한 취약점이 대규모 개인정보 유출 및 프라이버시 침해로 이어질 가능성이 높다.
    이에 대응하기 위해 침입 탐지 기술이 활발하게 연구되고 있다. 그러나 웹 API 대상 침입 탐지 연구는 초기 단계로서, 공격 시그니처 데이터베이스가 웹 API 도메인에 대한 공격에 대응할 수 있도록 다양하게 구성되지 못했으며, 명세 기반 탐지에서 활용되는 정상 행위 규칙은 도메인별로 상이한 구성을 갖는 웹 API의 특성상 체계적인 모델링이 부족하여 완전성 있는 명세가 구현되기에 어려움이 있다. 또한 연구를 위한 고품질 데이터셋의 부족으로 인해 데이터셋에 의존하는 머신러닝 기반 탐지 방식에서는 공격 유형별 분류나 해석이 제한적이다. 본 연구에서는 금융 마이데이터 환경에서 발생할 수 있는 다양한 공격 시나리오를 구성하고, 이에 대한 공격 시그니처 생성을 통해 대부분의 알려진 공격에 대해 대응할 수 있도록 하며, 정상 행위 규칙을 정교하게 수립하여 명세 기반 탐지 방식의 한계인 오탐률을 개선하고 상세한 흐름 단위까지 탐지할 수 있도록 한다. 또한 거대 언어 모델을 활용하여 문맥 기반의 이해를 통해 데이터셋 의존성을 줄이고, APT 및 제로데이 공격에 대한 탐지 성능을 향상하고자 한다. 또한, 이러한 탐지 모델을 다층적으로 구현하여 각 탐지 방식의 성능을 극대화한 다층 방어형 침입 탐지 기술을 제안한다. 시그니처, 명세 기반 탐지 방식을 결합한 하이브리드 탐지 레이어를 통해 신속하고 효율적인 1차 탐지를 수행하고, 2차 탐지로서 백그라운드에서 입력 데이터의 맥락을 파악하여 고도화된 공격을 심층적으로 식별하는 거대 언어 모델 기반 정밀 탐지 레이어를 다층적으로 설계하여 웹 API 보안 취약점 대응 기술을 제시한다. 이를 검증하기 위해 대표적 고위험 도메인인 금융 마이데이터 환경을 구성하였으며, 하이브리드, 거대 언어 모델, 다층 방어형 침입 탐지 모델 등 탐지 기술별 침입 탐지 실험을 통해 탐지 성능, 리소스 소비, 탐지 소요 시간 트레이드오프를 분석하였다.
    실험 결과, 본 논문에서 제안한 다층 방어형 침입 탐지 기술은 정확도 97.36%, 정밀도 98.03% 등 6가지의 탐지 성능 지표 중 4가지의 지표에서 가장 우수한 결과를 달성하였다. 또한 거대 언어 모델 대비 약 85% 감소한 탐지 소요 시간으로 API 요청-응답 소요 시간과 비교하여 실시간 탐지가 가능함을 보였으며, GPU 평균 사용률은 약 27%가 감소하여 리소스 소비 측면에서도 개선되었음을 확인하였다.
    이러한 결과는 기존의 웹 API 대상 탐지 기술 대비 유의미한 성능 향상을 달성하였음을 보여주며, 금융 마이데이터와 같은 실제 웹 API 도메인에서 본 논문에서 제안한 다층 방어형 침입 탐지 기술이 적용 가능함을 확인하였다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    With the widespread adoption of cloud-based technologies, web API–based data communication has become prevalent, expanding the attack surface and increasing security vulnerabilities specific to web APIs, such as access token theft and parameter tampering. In particular, financial MyData services widely used in South Korea collect and provide distributed personal financial information through standardized APIs, making them highly susceptible to large-scale data breaches and privacy violations.
    Although intrusion detection technologies have been actively studied, web API–oriented intrusion detection remains at an early stage and faces several limitations. Existing approaches suffer from insufficient attack signature coverage, incomplete specification modeling due to domain-dependent API structures, and limited effectiveness of machine learning–based methods caused by a lack of high-quality datasets.
    To address these challenges, this thesis proposes a multi-layered defense intrusion detection approach for web API security in financial MyData environments. The proposed system enhances signature-based detection through scenario-driven attack signature generation, refines specification-based detection by establishing precise normal behavior rules, and incorporates a large language model to improve contextual understanding and detection of APT and zero-day attacks. These techniques are integrated into a multi-layered architecture consisting of a hybrid detection layer for rapid primary detection and a large language model–based precision detection layer for in-depth analysis.
    To evaluate the proposed approach, a financial MyData environment was implemented, and experiments were conducted using hybrid, large language model–based, and multi-layered defense detection models. The proposed approach achieved superior performance in four out of six evaluation metrics, including an accuracy of 97.36% and a precision of 98.03%. Detection latency was reduced by approximately 85% compared to the large language model–based approach, enabling real-time detection, while average GPU utilization was reduced by approximately 27%.
    These results demonstrate that the proposed multi-layered defense intrusion detection approach significantly improves web API security and is applicable to real-world financial MyData services.
    번역하기

    With the widespread adoption of cloud-based technologies, web API–based data communication has become prevalent, expanding the attack surface and increasing security vulnerabilities specific to web APIs, such as access token theft and parameter tamp...

    With the widespread adoption of cloud-based technologies, web API–based data communication has become prevalent, expanding the attack surface and increasing security vulnerabilities specific to web APIs, such as access token theft and parameter tampering. In particular, financial MyData services widely used in South Korea collect and provide distributed personal financial information through standardized APIs, making them highly susceptible to large-scale data breaches and privacy violations.
    Although intrusion detection technologies have been actively studied, web API–oriented intrusion detection remains at an early stage and faces several limitations. Existing approaches suffer from insufficient attack signature coverage, incomplete specification modeling due to domain-dependent API structures, and limited effectiveness of machine learning–based methods caused by a lack of high-quality datasets.
    To address these challenges, this thesis proposes a multi-layered defense intrusion detection approach for web API security in financial MyData environments. The proposed system enhances signature-based detection through scenario-driven attack signature generation, refines specification-based detection by establishing precise normal behavior rules, and incorporates a large language model to improve contextual understanding and detection of APT and zero-day attacks. These techniques are integrated into a multi-layered architecture consisting of a hybrid detection layer for rapid primary detection and a large language model–based precision detection layer for in-depth analysis.
    To evaluate the proposed approach, a financial MyData environment was implemented, and experiments were conducted using hybrid, large language model–based, and multi-layered defense detection models. The proposed approach achieved superior performance in four out of six evaluation metrics, including an accuracy of 97.36% and a precision of 98.03%. Detection latency was reduced by approximately 85% compared to the large language model–based approach, enabling real-time detection, while average GPU utilization was reduced by approximately 27%.
    These results demonstrate that the proposed multi-layered defense intrusion detection approach significantly improves web API security and is applicable to real-world financial MyData services.

    더보기

    목차 (Table of Contents)

    • 제 1 장 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구의 차별점 및 기여 5
    • 1.3 논문의 구성 6
    • 제 2 장 웹 API 7
    • 제 1 장 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구의 차별점 및 기여 5
    • 1.3 논문의 구성 6
    • 제 2 장 웹 API 7
    • 2.1 웹 API 아키텍처 7
    • 2.1.1 설계 유형 7
    • 2.1.2 구조 및 통신 요소 8
    • 2.1.3 데이터 표현 규격 10
    • 2.1.4 인증 및 권한 부여 메커니즘 11
    • 2.2 보안 취약점 및 대응 기술 14
    • 2.2.1 OWASP API Security Top 10: 2023 14
    • 2.2.2 기존 연구 16
    • 2.2.3 API 게이트웨이 17
    • 제 3 장 금융 마이데이터 19
    • 3.1 금융 마이데이터 서비스 19
    • 3.2 금융 마이데이터 API 20
    • 3.2.1 전체 아키텍처 20
    • 3.2.2 데이터 표준 API 기본 규격 22
    • 3.2.3 API 정상 행위 명세 22
    • 3.3 공격 시나리오 26
    • 3.4 보안 강화 전략 27
    • 제 4 장 침입 탐지 기술 28
    • 4.1 전통적 침입 탐지 기술 28
    • 4.2 거대 언어 모델 기반 침입 탐지 기술 32
    • 4.2.1 딥러닝 기반 시퀀스 모델 32
    • 4.2.2 거대 언어 모델의 개념 및 설계 원리 33
    • 4.2.3 거대 언어 모델 기반 침입 탐지 메커니즘 35
    • 4.3 다층 방어형 API 침입 탐지 프레임워크 38
    • 제 5 장 실험 및 검증 40
    • 5.1 실험 설계 40
    • 5.2 금융 마이데이터 API 환경 구축 41
    • 5.3 데이터셋 생성 42
    • 5.4 침입 탐지 모델 구현 45
    • 5.4.1 시그니처, 명세, 하이브리드 기반 침입 탐지 모델 45
    • 5.4.2 거대 언어 모델 기반 침입 탐지 모델 46
    • 5.5 평가 지표 48
    • 5.6 침입 탐지 실험 수행 50
    • 5.7 실험 결과 51
    • 제 6 장 결론 및 향후 연구 55
    • 참고 문헌 57
    • Abstract 67
    • 부록 A – API 명세 69
    • 부록 B – 정상 행위 규칙 79
    • 부록 C – 공격 시나리오 92
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼