본 논문은 빠르게 변화하는 사이버 위협 환경에서 기존 네트워크 침입 탐지 시스템 (NIDS)이 직면한 구조적 한계, 즉 제로데이(Zero-Day) 공격에 대한 취약성, 높은 오탐률, 그리고 데이터 희소성...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17407206
홍성 : 청운대학교 대학원, 2025
2025
한국어
충청남도
; 26 cm
지도교수: 박종진
I804:44028-200000973667
0
상세조회0
다운로드본 논문은 빠르게 변화하는 사이버 위협 환경에서 기존 네트워크 침입 탐지 시스템 (NIDS)이 직면한 구조적 한계, 즉 제로데이(Zero-Day) 공격에 대한 취약성, 높은 오탐률, 그리고 데이터 희소성...
본 논문은 빠르게 변화하는 사이버 위협 환경에서 기존 네트워크 침입 탐지 시스템 (NIDS)이 직면한 구조적 한계, 즉 제로데이(Zero-Day) 공격에 대한 취약성, 높은 오탐률, 그리고 데이터 희소성 문제를 극복하기 위한 유연하고 혁신적인 대안을 제시한다. 기존의 시그니처 기반 및 머신러닝(ML) 기반 이상 행위 탐지 기법은 신종 위협의 변형 패턴이나 데이터 부족으로 인해 탐지 모델의 일반화 능력이 저하되는 실무적 한계를 가진다.
이에 본 연구는 벡터 데이터베이스(Vector Database)와 대규모 언어 모델 기반 생성형 인공지능(LLM)을 결합한 적응형 하이브리드 위협 분석 프레임워크를 제안한다. 제안된 방법론은 네트워크 트래픽 데이터를 고차원 임베딩(Embedding)으로 변환하여 벡터 데이터 베이스에 저장하고, 이를 통해 실시간 유사도 검색 기반의 신속하고 유연한 위협 분류를 수행한다. 특히, LLM은 레이블이 없는 비정상 트래픽에 대한 심층 행위 분석을 수행하여, 단순 패턴 매칭의 한계를 넘어 복잡하고 미묘한(subtle) 위협 행위의 맥락을 유연하게 해석하고 설명하는 핵심 역할을 담당한다. 이 하이브리드 결합 기법은 기존 학습 데이터에 존재하지 않는 신종 및 변형된 공격 유형에 대한 뛰어난 적응력과 탐지 성능을 제공하며, 실험 결과 기존 최신 ML 기반 NIDS 대비 탐지 정확도 및 오탐률 측면에서 뚜렷한 성능 향상을 입증하였다. 이는 실질적인 사이버 보안 운용 환경에서 탐지 시스템의 효용성을 극적으로 개선하는 학술적 및 실무적 기여를 제공한다.
다국어 초록 (Multilingual Abstract)
This paper presents a flexible and innovative alternative to overcome the structural limitations of existing Network Intrusion Detection Systems (NIDS) in a rapidly evolving cyber threat landscape: vulnerability to zero-day attacks, high false positiv...
This paper presents a flexible and innovative alternative to overcome the structural limitations of existing Network Intrusion Detection Systems (NIDS) in a rapidly evolving cyber threat landscape: vulnerability to zero-day attacks, high false positive rates, and data scarcity. Existing signature-based and machine learning (ML)-based anomaly detection techniques suffer from practical limitations, such as reduced generalization capabilities due to variations in new threat patterns and data insufficiency.
In response, this study proposes an adaptive hybrid threat analysis framework that combines a vector database and large-scale language model-based generative artificial intelligence (LLM). The proposed methodology transforms network traffic data into high-dimensional embeddings and stores them in a vector database, enabling rapid and flexible threat classification based on real-time similarity search. Specifically, LLM performs in-depth behavioral analysis of unlabeled anomalous traffic, transcending the limitations of simple pattern matching to flexibly interpret and explain the context of complex and subtle threat behavior. This hybrid combination technique offers outstanding adaptability and detection performance for new and modified attack types do not present in existing training data. Experimental results demonstrate significant performance improvements in detection accuracy and false positive rates compared to existing state-of-the-art ML-based NIDS. This provides academic and practical contributions that dramatically improve the effectiveness of detection systems in real-world cybersecurity operational environments.
목차 (Table of Contents)