최근 IT기술의 발전과 인터넷 이용의 확산으로 각 분야의 사이버공간에 대한 의존도가 높아짐에 따라 사이버공간에 대한 위협은 국민생활과 경제는 물론, 국가안보에 새로운 위험요소로 대...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T10840470
수원: 경기대학교, 2007
2007
한국어
005.8 판사항(4)
005.8 판사항(21)
경기도
ix, 133 p.: 삽화, 도표; 26 cm
권말부록으로 "상대비교 행렬 데이터 수집 설문지" 등 수록
참고문헌: p. 106-108
0
상세조회0
다운로드최근 IT기술의 발전과 인터넷 이용의 확산으로 각 분야의 사이버공간에 대한 의존도가 높아짐에 따라 사이버공간에 대한 위협은 국민생활과 경제는 물론, 국가안보에 새로운 위험요소로 대...
최근 IT기술의 발전과 인터넷 이용의 확산으로 각 분야의 사이버공간에 대한 의존도가 높아짐에 따라 사이버공간에 대한 위협은 국민생활과 경제는 물론, 국가안보에 새로운 위험요소로 대두되고 있다. 이에 국내?외 보안기관 및 업체에서는 자체적인 분석을 통한 위협등급을 산정하고, 필요시 조기 예?경보를 발령함으로써 사용자에게 해당 위험성을 경고하고 있지만, 주관적 판단이나 직관적 해석에 의존함으로써 평가결과에 대한 신뢰도가 현저히 저하되는 문제점이 존재하고 있다.
본 논문에서는 이러한 문제점 들을 해결하기 위하여 사이버위협에 대한 정량적 위험도 산정기준을 마련하고 도출된 기준에 대한 연관성을 분석하여 체계적이고 객관적인 사이버위협 경보발령 모델을 제안한다.
먼저 사이버위협 예?경보 발령체계를 갖고 있는 국내 주요기관과 외국의 보안업체를 대상으로 위험도 산정기준 체계를 검토 분석하여, 사이버위협을 웜?바이러스, 보안취약점, 해킹기법으로 정의하고 각각의 특성을 분석하여 주요 평가항목을 도출한다. 각 평가항목은 상호배타적으로 선정함으로써 평가시 발생 가능한 중복 오류를 최대한 배제하고, 연관성 분석을 통한 가중치를 부여하여 평가 결과에 대한 변별도와 신뢰도를 향상시키고자 한다.
이를 바탕으로 사이버위협의 개별적 고유특성을 바탕으로 하는 ‘개별적 사이버위협 위험도 산정기준(ICSS:Individual Cyberthreats Scoring System)’과 위해상황을 종합 반영하여 평가하는 ‘전역적 사이버위협 위험도 산정기준(GCSS:Generic Cyberthreats Scoring System)’을 제안한다.
제안된 위험도 산정기준은 실증분석(Case Study)을 통해 지속적인 보정 작업을 수행하고, 정부기관에서 발령한 경보 등급과의 일치여부를 확인함으로써 객관성을 입증한다. 또한, 최근 美 정부 주도하에 30여개 업체가 참여하여 보안표준화를 추진하고 있는 취약점평가시스템(CVSS)과의 비교 분석을 통해 산정기준의 신뢰성을 입증하고, 마지막으로 계층분석과정(Analytic Hierarchy Process)에 의한 통계적 기법을 활용하여 정량화된 점수에 대한 타당성을 검증하고자 한다.
다국어 초록 (Multilingual Abstract)
In this paper, we proposed the computational criterion for risk assessment of various threats in cyberspace and systematized cyber threats working model based on the correlative analysis scheme. First of all, we classified the cyber threats as the wo...
In this paper, we proposed the computational criterion for risk assessment of various threats in cyberspace and systematized cyber threats working model based on the correlative analysis scheme.
First of all, we classified the cyber threats as the worm virus, vulnerabilities, and hacking attacks by investigating thoroughly internal and external trends of government, institutes and corporations.
Secondly we defined two types of scoring methods, one is individual risk assessment based on the dangerous characteristic of each cyber threat, and the other is generic risk assessment considering potential characteristics as well as the amount of damage, suspicious traffic increasing, important government agency and so on. Our mutual exclusive criterion could minimize the overlapping probability. Also correlative analysis could derive reliable results and improve the discrimination.
Finally, we have continued to revise the weight of each criterion of risk assessment by using case study. We analyzed results of both Cyber Vulnerability Scoring System and an official warning order by the government. We also quantitatively evaluated our method using AHP method and the concept of correlative relationship.
From the empirical results on worm-virus and vulnerability samples, proposed reasonable approval showed us reliable results. Thus we expect our proposed model can be used to estimate and evaluate dangerous threats more efficiently.
목차 (Table of Contents)