최근 공급망 보안 위협(Log4j, SolarWinds 등)의 확산으로 인해, 소프트 웨어 구성요소 명세서(SBOM)의 필요성이 산업제조 환경에서도 강조되고 있다. 그러나 산업제어시스템(ICS) 환경은 폐쇄망, 무...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17380473
서울 : 건국대학교 정보통신대학원, 2026
학위논문(석사) -- 건국대학교 정보통신대학원 , 정보보안학과 , 2026. 2
2026
한국어
서울
60 ; 26 cm
지도교수: 남기효
I804:11004-200000966018
0
상세조회0
다운로드최근 공급망 보안 위협(Log4j, SolarWinds 등)의 확산으로 인해, 소프트 웨어 구성요소 명세서(SBOM)의 필요성이 산업제조 환경에서도 강조되고 있다. 그러나 산업제어시스템(ICS) 환경은 폐쇄망, 무...
최근 공급망 보안 위협(Log4j, SolarWinds 등)의 확산으로 인해, 소프트 웨어 구성요소 명세서(SBOM)의 필요성이 산업제조 환경에서도 강조되고 있다. 그러나 산업제어시스템(ICS) 환경은 폐쇄망, 무중단 운영, 인력 부족 등의 특수성으로 인해 기존 자동화 중심의 보안 모델을 적용하기 어렵다. 본 연구에서는 이러한 한계를 극복하고자, 실행 중심의 SBOM 기반 보안 모델(SMS-I)을 제안하였다. SMS-I는 SBOM의 수집, 분석, 대응, 운영 관리 의 전 과정을 네 계층 구조로 재정의하고, 각 계층에 대해 폐쇄망 대응성, 수기 기반 운영, 실질적 영향도 판단, 보안 책임 분리 등 ICS 특화 설계 원 칙을 반영하였다. 또한 실무자 대상 설문조사를 통해 OT 보안의 현실적 제약과 SBOM 활 용의 한계를 분석하고, 모델의 적용 가능성과 향후 과제를 도출하였다. 본 연구는 기술적 모델 제시에 그치지 않고, 현장 중심의 실행 구조 설계와 조 직적·제도적 여건의 중요성을 함께 제시함으로써, 향후 산업제조 분야의 실 효적 보안 정책 수립을 위한 기초자료를 제공할 수 있을 것으로 기대된다.
다국어 초록 (Multilingual Abstract)
In response to the increasing software supply chain threats—such as the Log4j vulnerability and the SolarWinds incident—the Software Bill of Materials (SBOM) has emerged as a critical tool for enhancing transparency and visibility in industrial cy...
In response to the increasing software supply chain threats—such as the Log4j vulnerability and the SolarWinds incident—the Software Bill of Materials (SBOM) has emerged as a critical tool for enhancing transparency and visibility in industrial cybersecurity. However, Industrial Control Systems (ICS) operate under unique constraints including airgapped networks, continuous operation requirements, and limited security personnel, which make the direct application of conventional, execution oriented security model impractical.
This study proposes SMS-I (SBOM-based Mitigation Structure for ICS), an execution-oriented security model tailored to the operational characteristics of ICS environments. The model defines a four-layer architecture—collection, threat mitigation, and intelligence, operation/management—designed to reflect the realities of offline environments, manual processes, and limited automation. Key principles include VEX-based impact filtering, role and responsibility separation (R&R), and mitigation strategies that prioritize system availability over
immediate patching.
A field survey of security practitioners revealed critical obstacles to SBOM adoption in Korean manufacturing sectors, including lack of awareness, insufficient dedicated personnel, and the absence of structured security governance. These findings indicate that technical readiness alone is insufficient for SBOM implementation, and that organizational and policy-level changes are equally necessary.
Ultimately, this study provides a practical model and initial design guideline for applying SBOM-based security in ICS, and emphasizes the importance of environment-specific security frameworks beyond tool centric approaches.
목차 (Table of Contents)