클라우드 기반 기술의 확산으로 웹 API 기반 데이터 통신이 보편화됨에 따라, 웹 API에 대한 공격 표면이 확대되어 접근 토큰 탈취, 파라미터 변조 등 웹 API 도메인에 특화된 보안 취약점이 증...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17372473
서울 : 국민대학교 일반대학원, 2025
학위논문(석사) -- 국민대학교 일반대학원 , 정보융합보안전공 , 2026. 2
2025
한국어
서울
vi, 98 ; 26 cm
지도교수: 유일선
I804:11014-200000962781
0
상세조회0
다운로드클라우드 기반 기술의 확산으로 웹 API 기반 데이터 통신이 보편화됨에 따라, 웹 API에 대한 공격 표면이 확대되어 접근 토큰 탈취, 파라미터 변조 등 웹 API 도메인에 특화된 보안 취약점이 증...
클라우드 기반 기술의 확산으로 웹 API 기반 데이터 통신이 보편화됨에 따라, 웹 API에 대한 공격 표면이 확대되어 접근 토큰 탈취, 파라미터 변조 등 웹 API 도메인에 특화된 보안 취약점이 증가하고 있다. 특히 국내에서 널리 활용되는 금융 마이데이터 서비스는 표준화된 API를 통해 분산된 개인 금융정보를 수집, 제공하므로 이러한 취약점이 대규모 개인정보 유출 및 프라이버시 침해로 이어질 가능성이 높다.
이에 대응하기 위해 침입 탐지 기술이 활발하게 연구되고 있다. 그러나 웹 API 대상 침입 탐지 연구는 초기 단계로서, 공격 시그니처 데이터베이스가 웹 API 도메인에 대한 공격에 대응할 수 있도록 다양하게 구성되지 못했으며, 명세 기반 탐지에서 활용되는 정상 행위 규칙은 도메인별로 상이한 구성을 갖는 웹 API의 특성상 체계적인 모델링이 부족하여 완전성 있는 명세가 구현되기에 어려움이 있다. 또한 연구를 위한 고품질 데이터셋의 부족으로 인해 데이터셋에 의존하는 머신러닝 기반 탐지 방식에서는 공격 유형별 분류나 해석이 제한적이다. 본 연구에서는 금융 마이데이터 환경에서 발생할 수 있는 다양한 공격 시나리오를 구성하고, 이에 대한 공격 시그니처 생성을 통해 대부분의 알려진 공격에 대해 대응할 수 있도록 하며, 정상 행위 규칙을 정교하게 수립하여 명세 기반 탐지 방식의 한계인 오탐률을 개선하고 상세한 흐름 단위까지 탐지할 수 있도록 한다. 또한 거대 언어 모델을 활용하여 문맥 기반의 이해를 통해 데이터셋 의존성을 줄이고, APT 및 제로데이 공격에 대한 탐지 성능을 향상하고자 한다. 또한, 이러한 탐지 모델을 다층적으로 구현하여 각 탐지 방식의 성능을 극대화한 다층 방어형 침입 탐지 기술을 제안한다. 시그니처, 명세 기반 탐지 방식을 결합한 하이브리드 탐지 레이어를 통해 신속하고 효율적인 1차 탐지를 수행하고, 2차 탐지로서 백그라운드에서 입력 데이터의 맥락을 파악하여 고도화된 공격을 심층적으로 식별하는 거대 언어 모델 기반 정밀 탐지 레이어를 다층적으로 설계하여 웹 API 보안 취약점 대응 기술을 제시한다. 이를 검증하기 위해 대표적 고위험 도메인인 금융 마이데이터 환경을 구성하였으며, 하이브리드, 거대 언어 모델, 다층 방어형 침입 탐지 모델 등 탐지 기술별 침입 탐지 실험을 통해 탐지 성능, 리소스 소비, 탐지 소요 시간 트레이드오프를 분석하였다.
실험 결과, 본 논문에서 제안한 다층 방어형 침입 탐지 기술은 정확도 97.36%, 정밀도 98.03% 등 6가지의 탐지 성능 지표 중 4가지의 지표에서 가장 우수한 결과를 달성하였다. 또한 거대 언어 모델 대비 약 85% 감소한 탐지 소요 시간으로 API 요청-응답 소요 시간과 비교하여 실시간 탐지가 가능함을 보였으며, GPU 평균 사용률은 약 27%가 감소하여 리소스 소비 측면에서도 개선되었음을 확인하였다.
이러한 결과는 기존의 웹 API 대상 탐지 기술 대비 유의미한 성능 향상을 달성하였음을 보여주며, 금융 마이데이터와 같은 실제 웹 API 도메인에서 본 논문에서 제안한 다층 방어형 침입 탐지 기술이 적용 가능함을 확인하였다.
다국어 초록 (Multilingual Abstract)
With the widespread adoption of cloud-based technologies, web API–based data communication has become prevalent, expanding the attack surface and increasing security vulnerabilities specific to web APIs, such as access token theft and parameter tamp...
With the widespread adoption of cloud-based technologies, web API–based data communication has become prevalent, expanding the attack surface and increasing security vulnerabilities specific to web APIs, such as access token theft and parameter tampering. In particular, financial MyData services widely used in South Korea collect and provide distributed personal financial information through standardized APIs, making them highly susceptible to large-scale data breaches and privacy violations.
Although intrusion detection technologies have been actively studied, web API–oriented intrusion detection remains at an early stage and faces several limitations. Existing approaches suffer from insufficient attack signature coverage, incomplete specification modeling due to domain-dependent API structures, and limited effectiveness of machine learning–based methods caused by a lack of high-quality datasets.
To address these challenges, this thesis proposes a multi-layered defense intrusion detection approach for web API security in financial MyData environments. The proposed system enhances signature-based detection through scenario-driven attack signature generation, refines specification-based detection by establishing precise normal behavior rules, and incorporates a large language model to improve contextual understanding and detection of APT and zero-day attacks. These techniques are integrated into a multi-layered architecture consisting of a hybrid detection layer for rapid primary detection and a large language model–based precision detection layer for in-depth analysis.
To evaluate the proposed approach, a financial MyData environment was implemented, and experiments were conducted using hybrid, large language model–based, and multi-layered defense detection models. The proposed approach achieved superior performance in four out of six evaluation metrics, including an accuracy of 97.36% and a precision of 98.03%. Detection latency was reduced by approximately 85% compared to the large language model–based approach, enabling real-time detection, while average GPU utilization was reduced by approximately 27%.
These results demonstrate that the proposed multi-layered defense intrusion detection approach significantly improves web API security and is applicable to real-world financial MyData services.
목차 (Table of Contents)