RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    산업제조 환경에서 SBOM 기반 보안모델에 관한 연구 = A Study on an SBOM-Based Security Model for Industrial Manufacturing Environments

    한글로보기

    https://www.riss.kr/link?id=T17380473

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    최근 공급망 보안 위협(Log4j, SolarWinds 등)의 확산으로 인해, 소프트 웨어 구성요소 명세서(SBOM)의 필요성이 산업제조 환경에서도 강조되고 있다. 그러나 산업제어시스템(ICS) 환경은 폐쇄망, 무중단 운영, 인력 부족 등의 특수성으로 인해 기존 자동화 중심의 보안 모델을 적용하기 어렵다. 본 연구에서는 이러한 한계를 극복하고자, 실행 중심의 SBOM 기반 보안 모델(SMS-I)을 제안하였다. SMS-I는 SBOM의 수집, 분석, 대응, 운영 관리 의 전 과정을 네 계층 구조로 재정의하고, 각 계층에 대해 폐쇄망 대응성, 수기 기반 운영, 실질적 영향도 판단, 보안 책임 분리 등 ICS 특화 설계 원 칙을 반영하였다. 또한 실무자 대상 설문조사를 통해 OT 보안의 현실적 제약과 SBOM 활 용의 한계를 분석하고, 모델의 적용 가능성과 향후 과제를 도출하였다. 본 연구는 기술적 모델 제시에 그치지 않고, 현장 중심의 실행 구조 설계와 조 직적·제도적 여건의 중요성을 함께 제시함으로써, 향후 산업제조 분야의 실 효적 보안 정책 수립을 위한 기초자료를 제공할 수 있을 것으로 기대된다.
    번역하기

    최근 공급망 보안 위협(Log4j, SolarWinds 등)의 확산으로 인해, 소프트 웨어 구성요소 명세서(SBOM)의 필요성이 산업제조 환경에서도 강조되고 있다. 그러나 산업제어시스템(ICS) 환경은 폐쇄망, 무...

    최근 공급망 보안 위협(Log4j, SolarWinds 등)의 확산으로 인해, 소프트 웨어 구성요소 명세서(SBOM)의 필요성이 산업제조 환경에서도 강조되고 있다. 그러나 산업제어시스템(ICS) 환경은 폐쇄망, 무중단 운영, 인력 부족 등의 특수성으로 인해 기존 자동화 중심의 보안 모델을 적용하기 어렵다. 본 연구에서는 이러한 한계를 극복하고자, 실행 중심의 SBOM 기반 보안 모델(SMS-I)을 제안하였다. SMS-I는 SBOM의 수집, 분석, 대응, 운영 관리 의 전 과정을 네 계층 구조로 재정의하고, 각 계층에 대해 폐쇄망 대응성, 수기 기반 운영, 실질적 영향도 판단, 보안 책임 분리 등 ICS 특화 설계 원 칙을 반영하였다. 또한 실무자 대상 설문조사를 통해 OT 보안의 현실적 제약과 SBOM 활 용의 한계를 분석하고, 모델의 적용 가능성과 향후 과제를 도출하였다. 본 연구는 기술적 모델 제시에 그치지 않고, 현장 중심의 실행 구조 설계와 조 직적·제도적 여건의 중요성을 함께 제시함으로써, 향후 산업제조 분야의 실 효적 보안 정책 수립을 위한 기초자료를 제공할 수 있을 것으로 기대된다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    In response to the increasing software supply chain threats—such as the Log4j vulnerability and the SolarWinds incident—the Software Bill of Materials (SBOM) has emerged as a critical tool for enhancing transparency and visibility in industrial cybersecurity. However, Industrial Control Systems (ICS) operate under unique constraints including airgapped networks, continuous operation requirements, and limited security personnel, which make the direct application of conventional, execution oriented security model impractical.
    This study proposes SMS-I (SBOM-based Mitigation Structure for ICS), an execution-oriented security model tailored to the operational characteristics of ICS environments. The model defines a four-layer architecture—collection, threat mitigation, and intelligence, operation/management—designed to reflect the realities of offline environments, manual processes, and limited automation. Key principles include VEX-based impact filtering, role and responsibility separation (R&R), and mitigation strategies that prioritize system availability over
    immediate patching.
    A field survey of security practitioners revealed critical obstacles to SBOM adoption in Korean manufacturing sectors, including lack of awareness, insufficient dedicated personnel, and the absence of structured security governance. These findings indicate that technical readiness alone is insufficient for SBOM implementation, and that organizational and policy-level changes are equally necessary.
    Ultimately, this study provides a practical model and initial design guideline for applying SBOM-based security in ICS, and emphasizes the importance of environment-specific security frameworks beyond tool centric approaches.
    번역하기

    In response to the increasing software supply chain threats—such as the Log4j vulnerability and the SolarWinds incident—the Software Bill of Materials (SBOM) has emerged as a critical tool for enhancing transparency and visibility in industrial cy...

    In response to the increasing software supply chain threats—such as the Log4j vulnerability and the SolarWinds incident—the Software Bill of Materials (SBOM) has emerged as a critical tool for enhancing transparency and visibility in industrial cybersecurity. However, Industrial Control Systems (ICS) operate under unique constraints including airgapped networks, continuous operation requirements, and limited security personnel, which make the direct application of conventional, execution oriented security model impractical.
    This study proposes SMS-I (SBOM-based Mitigation Structure for ICS), an execution-oriented security model tailored to the operational characteristics of ICS environments. The model defines a four-layer architecture—collection, threat mitigation, and intelligence, operation/management—designed to reflect the realities of offline environments, manual processes, and limited automation. Key principles include VEX-based impact filtering, role and responsibility separation (R&R), and mitigation strategies that prioritize system availability over
    immediate patching.
    A field survey of security practitioners revealed critical obstacles to SBOM adoption in Korean manufacturing sectors, including lack of awareness, insufficient dedicated personnel, and the absence of structured security governance. These findings indicate that technical readiness alone is insufficient for SBOM implementation, and that organizational and policy-level changes are equally necessary.
    Ultimately, this study provides a practical model and initial design guideline for applying SBOM-based security in ICS, and emphasizes the importance of environment-specific security frameworks beyond tool centric approaches.

    더보기

    목차 (Table of Contents)

    • 표 목차 ⅲ
    • 그 림목차 ⅳ
    • 국문 초록 v
    • 제1장 서론 1
    • 제1절 연구의 배경 1
    • 표 목차 ⅲ
    • 그 림목차 ⅳ
    • 국문 초록 v
    • 제1장 서론 1
    • 제1절 연구의 배경 1
    • 제2절 연구의 필요성 3
    • 제3절 연구 목적 5
    • 제2장 SBOM 기반 산업제조 보안 관련 연구 및 적용 현황 분석 6
    • 제1절 SBOM 개념과 표준 정의 6
    • 1. SBOM의 개념, 목적, 필요성 6
    • 2. 주요표준 8
    • 3. SBOM이 산업제조 환경에서 갖는 의미 12
    • 제2절 최근OT/ICS 보안 동향 14
    • 1. IT-OT 융합과 최근 보안 동향 14
    • 제3절 SBOM 기반 공급망 보안 관련 연구 현황 15
    • 1. SBOM 기반 정책 동향 및 국가별 활용 현황 분석 15
    • 2. 기존 연구의 한계점 및 연구 격차 (Research Gap) 17
    • 제4절 산업제조 환경에서의 SBOM 적용 한계 및 문제점 20
    • 1. 기술적 및 운영적 문제점 분석 20
    • 2. 정책적 규제적 한계와 연구의 당위성 21
    • 제3장 산업제어시스템(ICS) 환경을 위한 SBOM 기반 모델 (SMS-I) 24
    • 제1절 SBOM 기반 위협 대응 방안 24
    • 제2절 ICS 환경에 적합한 SBOM 보안 실행 모델(SMS-I설계) 25
    • 제3절 운영 환경 기반 SMS-I 실행 전략 28
    • 1. 폐쇄망 기반 ICS환경 – SMS-I 적용 시나리오 29
    • 2. 일반 IT 환경 – SMS-I 적용 시나리오 33
    • 제4장 연구결과 검증 37
    • 제1절 설문조사 개요 및 응답자 구성 37
    • 제2절 설문조사 결과 및 분석 38
    • 제3절 전문가 인터뷰 분석 44
    • 제5장 결론 47
    • 제1절 연구결과 요약 47
    • 제2절 향후 연구 및 정책·실무적 과제 48
    • 참고문헌 50
    • 부록 54
    • ABSTRACT59
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼