폐쇄망 환경에서는 외부 네트워크와 물리적 단절로 인해 내부 네트워크 보안이 중요하며, IDS/IPS 솔루션 기반 탐지 로그가 수십만 건 이상이 발생한다. 그러나 기존 시그니처 기반 탐지 시스...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17380304
서울 : 건국대학교 정보통신대학원, 2026
학위논문(석사) -- 건국대학교 정보통신대학원 , 정보보안학과 , 2026. 2
2026
한국어
서울
46 ; 26 cm
지도교수: 남기효
I804:11004-200000966453
0
상세조회0
다운로드폐쇄망 환경에서는 외부 네트워크와 물리적 단절로 인해 내부 네트워크 보안이 중요하며, IDS/IPS 솔루션 기반 탐지 로그가 수십만 건 이상이 발생한다. 그러나 기존 시그니처 기반 탐지 시스...
폐쇄망 환경에서는 외부 네트워크와 물리적 단절로 인해 내부 네트워크 보안이 중요하며, IDS/IPS 솔루션 기반 탐지 로그가 수십만 건 이상이 발생한다. 그러나 기존 시그니처 기반 탐지 시스템은 높은 오탐률과 신규 공격 패턴에 대한 대응 한계로 인해 보안 담당자의 분석 효율이 떨어지고, 늦은 대응 속도를 발생시킨다.
본 연구는 특정 AI 모델 간의 성능 비교가 아닌, 폐쇄망 환경 내 대규모 IDS/IPS 로그의 의미 기반 위험도 분석 효율을 향상시키기 위한 실용적 위험도 분석 시스템 구축을 구축하는 데 목적을 두고 있다.
SecurityBERT는 RoBERTa 아키텍처를 기반으로 보안 도메인 텍스트로 사전 학습된 언어 모델이며, 보안 용어와 공격 패턴에 대한 분석에 특화되어 있다. 본 연구에서는 해당 모델을 기반으로 폐쇄망 환경에서 수집된 IDS/IPS 로그를 Fine-Tuning 하여 Low, Medium, High 세 가지 위험도로 분류하는 시스템을 구축하였다.
150,000건의 Test Set을 대상으로 성능을 검증한 결과, 미탐 1건 이외에 정확한 판단을 이루어 냈으며, 실제 미탐 페이로드 분석 결과 오탐으로 SecurityBERT 모델 시스템이 문맥적 특징을 분석하여 판단한 것으로 검증했다. 실무 적용 시 일평균 10,000건 이상의 분석 검토에서 High 약 10건 우선 검토로 전환하여 분석 시간 90% 이상 절감과 대응 속도를 단축할 수 있음을 확인하였다.
본 연구는 폐쇄망 환경에서 대규모 IDS 로그를 효율적으로 분석하고 긴급 위협에 대응할 수 있는 실무에 적합한 시스템의 가능성을 제시하였다. SecurityBERT 모델의 의미론적 이해 능력은 규칙에 명시되지 않은 신규 공격 패턴도 유사성 기반으로 부분 탐지가 가능하다. 향후 지속적 학습 체계 구축과 일반화 성능 검증을 통해 좀 더 실용적인 분석 시스템으로 발전시킬 수 있을 것으로 예상한다.
다국어 초록 (Multilingual Abstract)
In enterprise closed network environments, internal network security is critical due to physical isolation from external networks, generating hundreds of thousands of detection logs through IDS/IPS solutions. However, existing signature-based detectio...
In enterprise closed network environments, internal network security is critical due to physical isolation from external networks, generating hundreds of thousands of detection logs through IDS/IPS solutions. However, existing signature-based detection systems suffer from high false positive rates and limited capability to respond to novel attack patterns, resulting in reduced analytical efficiency for security personnel and delayed response times.
This study proposes a SecurityBERT-based infection risk classification system to address these challenges. SecurityBERT is a language model based on the RoBERTa architecture, pre-trained on security domain texts and specialized in analyzing security terminologies and attack patterns. In this research, we developed a system that fine-tunes this model with IDS/IPS logs collected from closed network environments to classify infection risks into three levels: Low, Medium, and High.
Performance evaluation on a test set of 150,000 logs demonstrated accurate classification with only one false negative case. Upon detailed payload analysis, this case was confirmed to be a false positive that SecurityBERT correctly classified by analyzing contextual features. Practical application shows that converting from daily analysis of over 10,000 logs to prioritized review of approximately 10 High-risk alerts can reduce analysis time by over 90% and significantly shorten response times.
This study demonstrates the feasibility of a practical system capable of efficiently analyzing large-scale IDS logs and responding to urgent threats in closed network environments. SecurityBERT's semantic understanding capability enables partial detection of novel attack patterns not explicitly defined in rules through similarity-based analysis. Future work on continuous learning frameworks and generalization performance validation is expected to advance this system into a more practical analytical solution.
목차 (Table of Contents)