RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    검색결과 좁혀 보기

    선택해제

    오늘 본 자료

    • 오늘 본 자료가 없습니다.
    더보기
    • LTE 음성서비스 취약점 분석 및 대응

      이영준 순천향대학교 대학원 2015 국내석사

      RANK : 247615

      글로벌 네트워크의 확대가 급진전됨으로 인하여 모든 정보는 누구나 접근할 수 있는 공간에 공유되었고 기존에 정보를 탈취하기 위한 악의적인 공격과 달리 공유 시스템 자체의 자원을 탈취하기 위한 악의적인 트래픽, 비정상적인 트래픽이 발생하였다. 이에 따라 1990년대 이후까지 많은 공유 시스템들이 접근 제어에 대한 발전을 이룸과 동시에 네트워크 접근 제어(NAC) 기술의 발전이 이루어졌다. 2010년 이후 LTE 네트워크가 보편화 되고 내부자 공격의 심각성이 고조되고 이를 해결하기 위한 통합위협관리시스템(UTM)을 기반으로 하는 행위 분석 기반 보안 기술이 시도되었다. 하지만 기존 인터넷과 일체화되는 LTE 네트워크에서의 다양하고 광범위한 악성행위를 차단하는 것은 기존의 통합위협관리시스템만으로는 불가능하다. 따라서 LTE 네트워크만의 특징과 트래픽 처리 과정, 구조를 이용하고 표준 기술에 합당하는 정교한 트래픽 제어 기술과 단말 접근제어 메커니즘 구현기술의 개발이 필수적으로 요구된다. 본 논문에서는 LTE 모바일 네트워크상에서의 트래픽 제어의 중요성을 인지하고, LTE 모바일 네트워크의 구조를 파악하고, LTE 음성서비스(VoLTE)를 통한 비정상적 데이터 사용 가능성을 비정상 트래픽 유도를 통해 분석하며, 이를 탐지하기 위한 방안을 EPC망 내의 제어 장비를 통해 제시한다.

    • 이동통신 단말기 및 브로드밴드 장비에서의 취약점 분석 기술 연구

      안영호 순천향대학교 2020 국내석사

      RANK : 247615

      The complexity of many systems has been increased, as computing power has been enhanced, due to the drastic development of hardware and software. Normalized technologies at all kinds of binary levels, including Fuzzing, Symbolic Execution, BAP(Binary Analysis Platform), which can automatically diagnose vulnerabilities based on binaries were studied, because it was difficult for a person to directly analyze the whole systems, as the systems to be analyzed were gradually enlarged and complicated. On the basis of such technologies, efficient technologies to analyze vulnerabilities, which can test them by automatically verifying and directly testing the points in which they are likely to occur, were used. For such normalized analysis technologies, however, the effect range and the importance of vulnerabilities found are often narrow and low, respectively. In addition, they are usually studied in the architectures which have been often used, so it is difficult to apply them to other architectures such as cores or assemblies customized by certain manufacturers. For example, separate chip sets should be developed for mobile communication devices, and all kinds of processors including ARM are often customized. The development of mobile communication chip sets is monopolized by some manufacturers which are closed to prevent the original technology leaking, so related information is not often opened. In this case, non-normalized analysis technologies are required, since normalized analysis technologies are difficult to use. This paper examined technologies to analyze the vulnerabilities of Femto-cells, indoor base stations, among baseband processors and broadband for wireless communication within mobile communication terminals, among many mobile communication devices. Studies testing the vulnerabilities of mobile communication devices have been relatively limited, in spite of their substantial impact and hazard. Tests of systems' entire stability cannot but be left to manufacturers, and therefore, very serious national problems in which there are no measures to verify information leaking are likely to occur, as shown in some previous accidents such as the backdoor of Huawei's communication devices. This paper, therefore, aims to clarify that there is the possibility of firmware falsification in a lot of mobile terminals with some missed security configurations in the development process, by analyzing the integrity verification and the firmware structures of baseband processors in mobile communication terminals. There is simultaneously establish the analysis environment in which the stability is checked by accessing system authority through hardware interruption in Femto-cells, small broadband devices and by verifying the possible bypass through GPS signal modulation, based on an analysis on internal structures. It will provide the foundation for technologies to analyze security threats that can occur in mobile communication devices in the future. 하드웨어와 소프트웨어 기술의 급격한 발전으로 인해 컴퓨팅 파워가 증가하면서 구성되는 여러 시스템의 복잡도가 증가하였다. 취약점 분석 관점에서 분석 대상 시스템이 점점 커지고 복잡해짐에 따라 사람이 직접 시스템 전체에 대한 분석을 수행하기에는 어려움이 존재하였기 때문에 바이너리를 기반으로 취약점을 자동으로 진단하는 Fuzzing, Symbolic Execution, BAP(Binary Analysis Platform)을 비롯한 각종 바이너리 레벨에서의 정규화된 기술들이 연구되었다. 이러한 기술들을 기반으로 취약점 발생 가능성이 존재하는 지점을 자동으로 확인하고 해당 지점에 대한 직접적인 테스팅을 수행함으로써 취약점을 검증하는 형태의 효율적인 취약점 분석 기술이 활용되었다. 하지만 이러한 형태의 정규화된 분석 기술의 경우 찾아낸 취약점의 영향 범위가 작거나 중요성이 낮은 경우가 대부분이다. 또한, 주로 사용되는 아키텍처에서 연구되기 때문에 특정 제조사에서 커스텀한 코어나 어셈블리어 등의 일부 아키텍처에서 적용하기에는 어렵다는 한계점이 존재한다. 그 예로 이동통신 관련 장비의 경우 별도의 칩셋이 개발되어 사용되며 대부분 ARM을 비롯한 각종 프로세서를 커스텀하여 사용하는 경우가 대부분이다. 이동통신 칩셋의 개발은 기술력 있는 일부 제조사에서 독점하고 있는데 제조사에서는 원천 기술 유출의 문제로 인해 폐쇄성을 가지고 있어 관련 정보가 대부분 공개되지 않는다. 이러한 경우 정규화된 분석 기술을 활용하기에는 어려움이 존재하기 때문에 분석 대상에 맞는 비 정규화된 분석 기술이 필요하다. 본 논문에서는 여러 이동통신 장비 중 이동통신 단말기 내 무선 통신을 담당하는 베이스밴드 프로세서와 브로드밴드 장비 중 옥내 기지국인 펨토셀을 대상으로 취약점 분석 기술 연구를 수행하였다. 이동통신 관련 장비에 대한 취약점 검증 연구는 가지고 있는 파급력과 위험도에 비해 비교적으로 제한되어 수행되고 있다. 시스템에 대한 전반적인 안전성 검증은 제조사에 일임할 수밖에 없는 실정이며 이는 지난 화웨이 통신장비 백도어 등의 사태와 같이 정보 유출에 대해 검증할 수단이 없는 크나큰 범국가적 문제의 원인이 될 가능성이 존재한다. 따라서 본 논문에서는 이동통신 단말의 베이스밴드 프로세서에서의 펌웨어 구조, 무결성 검증 과정 분석을 수행함으로써 개발 프로세스상에서 일부 보안 설정이 누락된 다수의 모바일 단말에서의 펌웨어 변조 가능성이 존재함을 확인한다. 동시에 소형 브로드밴드 장비인 펨토셀에 대한 하드웨어 인터럽트를 통해 시스템 권한에 접근함으로써 안전성을 점검하는 분석 환경을 구축하고 내부 구조 분석을 통해 GPS 신호 변조를 통한 우회 가능성을 확인함으로써 추후 이동통신 장비에서 발생 가능한 보안 위협에 대한 분석 기술의 기반을 제공하고자 한다.

    • 차량 침해사고 분석을 위한 CAN 취약점 분석 환경 구축

      김정현 순천향대학교 2020 국내석사

      RANK : 247615

      차량이 대중화되고 보급된 이래로, 현대에는 고성능의 차량 주행 능력뿐만 아니라 사용자의 니즈에 맞추기 위해 각종 운전 보조 기술. 편의기술을 비롯한 첨단 기술의 적용이 필수화되었다. 따라서 전 세계의 차량 제조사들은 고품질의 경쟁력을 갖춘 차량을 제조하기 위해 다양한 분야의 최첨단 기술을 차량 기술 개발에 적용하기 시작했다. 과거에는 차량 운행이 일차적인 목표였기 때문에, 그 당시 운용되던 차량은 정상적인 가속과 제동을 위한 주행 관련 기술과 최소한의 주행 안전 관련 기술만 적용되었을 뿐, 사용자의 편의를 위해 적용된 기술이 현재보다 현저히 적었다. 과거와 달리 현대에는 동급 차량 사이의 실질적인 주행 성능이 평준화되었기 때문에 차량의 경쟁력을 일반적인 기능을 통해 가늠하기 어려워졌다. 따라서 자동차 제조업체들은 생산하는 차량의 경쟁력을 갖추기 위해 차량에 ADAS(Advanced Driver Assistance System), 텔레매틱스 기능 등의 운전자를 위한 각종 안전·편의 기능을 적용하기 시작했다. 차량 내부 시스템의 전자화가 진행되고 관련 기술이 비약적으로 발전하기 시작하면서 다양한 기능 지원을 위해 장착되는 ECU(Electronic Control Unit)의 개수 또한 증가하였다. 그러나 이러한 기술의 발전은 기존의 기계식 구조와 비교해 주행 중 오작동의 발생 및 외부 공격자에 의한 보안 위협 가능성도 증가시켰다. 타 시스템에 가해지는 위협과는 달리 차량 주행 중 보안 위협이 가해지면 적게는 수 명, 많게는 수십 명의 사상자가 발생할 가능성이 있다. 또한 주변 교통 체계에까지 영향을 미쳐 원활한 교통을 방해하는 등 악영향을 끼칠 수 있다. 따라서 본 논문에서는 국내 제조사가 제조한 차량에 대한 내부 구조 분석을 수행함으로써 차량 주요 내부 네트워크인 CAN(Controller Area Network)의 취약점을 분석하기 위한 방안을 모색하고 관련된 메시지를 분석한다. 이에 그치지 않고 침해사고 분석용 프레임워크 구축 과정 및 결과에 관해 기술한다. 이를 기반으로 향후 차량에서 발생할 가능성이 존재하는 보안 위협 탐지기술 및 대응 방안 도출을 위한 차량용 분석 프레임워크 구축에 기여하고자 한다. Since motor vehicles have got into general circulation and been popularized, the application of advanced technologies has also become essential to meet the needs of drivers as well as high-performance driving abilities. These technologies include various driving assistance technologies and convenience technologies. As a result, manufacturers around the world began to apply cutting-edge technologies to produce high-quality and competitive motor vehicles. Nowadays, however, the actual driving performance of motor vehicles in the same class has been standardized, which makes it difficult to measure the competitiveness of motor vehicles based on the basic functions. Thus, manufacturers started to apply special features such as ADAS(Advanced Driver Assistance System) or telematics function to make their products more competitive and to allow drivers to drive motor vehicles safely and conveniently. As the in-vehicle systems have become digitalized and technologies related to motor vehicles are developing, the number of ECU(Electronic Control Unit) mounted to support various functions has also increased. However, the development of these technologies has also expanded the possibility of security threats by external attackers compared to the conventional mechanical structure. Unlike threats to other systems, security threats being posed on the moving motor vehicle could potentially result in serious accidents, having several casualties. Besides, it can have a demoralizing influence upon the transportation system around the attacked vehicle, interfering with the smooth traffic flow. Hence, in this thesis, I will find ways to analyze the weakness of CAN(Controller Area Network, the main motor vehicle internal network) and related messages, by performing analysis of the internal structure on the vehicles manufactured by domestic manufacturers. I will also explain the processes and results of the frameworks for analyzing security incidents. Based on this analysis, I expect that I could contribute to the establishment of the framework of analyzing a motor vehicle to derive security threat detection and countermeasures that are possible to occur in the future.

    • 이동통신망에서의 효과적인 퍼징을 위한 시나리오 기반 테스트 케이스 생성 및 분석 기술 연구

      오인수 순천향대학교 2020 국내석사

      RANK : 247615

      이동통신망은 전화, 메시지, 인터넷 접속을 위한 데이터 사용 등 전 세계적으로 많은 사용자들이 사용하고 있는 무선 연결 통신 체계이다. 수많은 단말기가 연결되어 있으며 자원을 할당해주고 지속적인 서비스를 제공해주는 이동통신망에 대한 사이버 공격이나 무선 통신 방해로 인한 서비스 거부 공격이 발생할 경우, 막대한 피해를 초래할 수 있다. 통신이 마비될 경우 세계적으로 재난 상황에 빠질 수 있기 때문에 이동통신망은 국가적으로 중요한 자산이고 나라마다 이동통신사업자들이 독자적인 통신망을 구축하여 서비스 하고 있기 때문에 서비스에 대한 안전성 검증이 필요하다. 하지만 실제 이동통신망은 폐쇄적이며 개인정보 유출 가능성이 존재하고 안전성 검증을 위한 이동통신 테스트 망이 따로 존재하지 않는다. 따라서 실제로 구현되어 있는 이동통신망의 코어 네트워크를 분석하고 안전성을 테스트하기는 어렵다. 본 논문에서는 LTE의 프로토콜 Layer 1, 2에 해당하는 시그널링 계층인 AS(Access Stratum)와 Layer 3에 해당하는 NAS(Non-Access Stratum)를 분석하기 위한 시뮬레이션 환경을 구축한다. 오픈소스 기반으로 구현 가능한 OpenSDR인 srsLTE, openLTE 등의 시뮬레이션 환경은 3GPP 표준에 기반 하여 개발되었기 때문에 테스트하기에 적합하다. 따라서 실제 망을 대체하여 이동통신망 구조와 프로토콜을 분석하고 발생 가능한 보안 위협을 검증한다. 단말기와 기지국 사이의 동기화 신호 간섭을 통한 서비스 거부 공격 시나리오를 도출하고 테스트 망을 통하여 공격 시나리오를 재현한다. NAS 계층에서 전송되는 NAS 메시지를 분석하고 단말기와 기지국간에 전송되는 메시지를 통해서 이동통신망에서 보안 위협 가능성이 있는 퍼징 테스트 케이스를 도출하고 퍼징 도구를 개발한다. 이를 기반으로 발생할 수 있는 보안 위협 시나리오를 제시한다. The mobile network is a wireless connectivity communication system used by many users around the world, including the use of data for phone calls, messages and Internet access. A cyber attack or denial-of-service attack on a mobile network that has a large number of handsets connected and that allocates resources and provides continuous service can cause enormous damage. Because mobile network is an important asset for the country and mobile network operators establish and service their own communication network in each country, safety verification of service is needed. However, actual mobile network is closed and there is a possibility of personal information leakage and there are no separate test networks for safety verification. Therefore, it is difficult to analyze the core network of the mobile network that is actually implemented and test the safety. In this paper, the simulation environment is established for analyzing the signaling layer corresponding to LTE's protocols Layer 1 and 2, AS(Access Stratum), and NAS(Non-Access Stratum) corresponding to Layer 3. Simulation environments such as srsLTE and openLTE, which are open-source-based implementations, are suitable for testing because they are developed based on 3GPP standards. Thus, it analyzes the structure and protocols of the mobile network and validates possible security threats by replacing the actual network. Derives a denial-of-service attack scenario through interference of the synchronization signal between the terminal and base station and reproduces the attack scenario through the test network. Analyze NAS messages sent from the NAS layer and derive a potential security-threatening purging test case from the mobile network through messages sent between terminals and base stations and develop a fuzzing tool. Based on this, it presents a possible threat scenario.

    • 산업제어시스템의 데이터셋 수집 방법 연구 : ICS 사이버 킬체인을 중심으로

      손병근 순천향대학교 2020 국내석사

      RANK : 247615

      국가안전보장, 행정, 국방, 치안, 금융, 운송 그리고 에너지와 같은 산업에서 제어 및 관리를 위해 사용되는 산업제어시스템(ICS, Industrial Consrol System)의 지속적인 발전과 더불어 기존 물리적으로 제어되던 산업 공정들이 PLC(Programmable Logic Controller) 및 HMI(Human Machine Interface)를 이용하여 공정에 사용되는 다양한 센서 및 액추에이터 등을 제어할 수 있게 되면서 이를 통합적으로 관리하기 위한 네트워크가 필요하게 되었다. 네트워크를 이용해 제어하는 장비가 점점 증가함에 따라 각 장비의 취약점을 이용한 공격 또한 발생하기 시작하였으며, 실제 ICS에 공격이 가해지면 경우에 따라 운영중인 공정이 영구적으로 손상되거나 심각한 금전적 피해를 초래할 수 있다. 또한, 스턱스넷(Stuxnet)을 시작으로 하벡스(Havex), 블랙에너지(BlackEnergy) 등과 같은 사이버 공격에 의하여 전 세계적으로 국가 안보와 직결되는 피해가 발생하면서 ICS를 대상으로 하는 공격을 탐지를 위하여 침입 탐지 시스템 (IDS, Intrusion Detection System) 및 침입 차단 시스템IPS(Intrusion Prevention System)이 필요하게 되었다. IDS에서 공격을 탐지하기 위한 규칙 설계를 위해서 공격 특정을 위한 데이터 셋을 필요로 하기 때문에 ICS에 정상 운영 및 공격 상황에서 발생하는 다양한 데이터 셋을 수집할 필요성이 존재한다. 기존 ICS에서 사용되는 다양한 장비들로부터 네트워크 패킷, 센싱 데이터 등을 수집하는 다양한 연구가 수행되었으나 실제 공격에 대한 시나리오 구성이 부족하였으며, 데이터 셋을 통해 공격 발생 시점을 특정할 수 있으나 어떤 경로를 통해 공격이 수행되었는지 확인하기 어렵다는 문제점이 존재하였다. 이에 본 논문에서는 수질 정화 시스템에서 사용되는 특정 컴포넌트를 유사하게 구성하여 실험 환경을 위한 ICS 테스트베드를 구축하였으며, 이를 통해 ICS 사이버 킬체인 및 ISA/IEC 62443 표준을 기반으로 한 데이터 셋을 수집할 수 있는 환경을 구성하였다. 또한, 테스트베드를 통해 ICS 운영에 필요한 다양한 컴포넌트로부터 수집한 데이터를 IDS에서 사용할 수 있도록 수집 지점, 수집 시간, 수집 항목에 따른 태깅 작업을 통해 데이터 셋을 가공하였다. Elastic Stack을 활용한 데이터 저장 및 빠른 분석을 가능하게 함으로써 정상 및 공격 상황에 대한 데이터 셋을 IDS 및 IPS 연구에 활용하기 위한 기반을 마련하였다.

    • 자동차 내부 네트워크 트래픽 특성을 활용한 이상행위 탐지

      김찬민 순천향대학교 일반대학원 2022 국내석사

      RANK : 247599

      자동차 기술의 발전으로 커넥티드 카가 등장했으며, 더 나아가 자율주행 자동차가 등장 하였다. 하지만 기술의 발전으로 자동차에는 많은 외부 접점이 생겨났으며, 이는 공격자 가 접근할 수 있는 공격 범위가 증가했다는 것을 의미한다. 하지만 현재까지도 보안이 취약한 CAN을 자동차 내부 네트워크로 사용하고 있다. 이로 인해 공격자가 외부 접점을 활용하여 내부 네트워크에 접근했을 경우 공격자는 손쉽게 자동차를 제어할 수 있다. 공 격자는 자동차를 제어하여 운전자의 생명을 앗아갈 정도로 큰 사고를 일으킬 수 있으며, 사회적 혼란을 야기할 수 있다. 이러한 보안 문제로 인해 UNECE WP.29(United Nations Economic Commission for Europe)에서는 자동차의 내부 네트워크의 공격을 탐지할 수 있 는 보안 요소를 적용시켜 피해를 예방하기 위해 공급망부터 자동차 네트워크에 대한 보 안을 강화하도록 권고하고 있다. 본 논문에서는 자동차 내부 네트워크에 메시지를 수집할 수 있도록 실제 차량에 수집 환경을 구축해 주행 데이터를 수집한다. 수집한 데이터를 바탕으로 CAN 메시지의 기능 을 식별한다. 주행 데이터를 통해 당시 주행 상황과 동일하게 동작하는 테스트 프레임워 크를 구축하여 각종 주입 공격 및 공격 데이터를 수집할 수 있도록 했다. CAN의 우선순 위 특성을 활용한 DoS, 비정상 행위를 유발하는 퍼징 공격도구를 개발하여 테스트 프레 임워크에 공격을 수행함으로써 내부 네트워크의 취약성에 대해 증명한다. 자동차 내부 네트워크를 보호하기 위해 보안 요소를 포함한 CAN 프로토콜, 머신 러닝 기법 이상 행위 탐지 등과 같은 연구가 진행되었으나, 모든 차량에 적용시키기 어렵고 제한적인 자동차 환경에 적합하지 않은 단점이 있다. 따라서 본 논문에서는 자동차 내부 네트워크 메시지의 시간 간격 특성을 활용하여 제조사 및 각 모델에 통합적으로 활용할 수 있는 시간 간격 기반 IDS를 개발하고 IDS의 성능을 테스트한다. With the development of automobile technology, connected cars have emerged, and further, self-driving cars have emerged. However, advances in technology have created many external contacts for automobiles, which means that the range of attacks accessible to attackers has increased. However, CAN, which is still weak in security, is still being used as an internal network for automobiles. Therefore, when an attacker accesses an internal network using an external contact point, the attacker can easily control the car. Attackers can control their cars to cause physical damage to drivers, cause accidents that are big enough to kill lives, and cause social confusion. Due to these security issues, UNECE WP.29 recommends strengthening security for automobile networks from supply chains to prevent damage by applying security elements that can detect attacks from automobile internal networks. In this paper, driving data is collected by establishing a collection environment in actual vehicles so that messages can be collected in the internal network of automobiles. The function of the CAN message is identified based on the collected data. Through driving data, a test framework that operates the same as the driving situation at the time was established so that various injection attacks and attack data can be collected. We demonstrate the vulnerability of internal networks by developing DoS using CAN's priority characteristics, fuzzing attack tools that cause abnormal behavior, and performing attacks on the test framework. Research has been conducted to protect the internal network of automobiles, such as CAN protocols including security elements and detection of machine learning abnormalities, but it is difficult to apply to all vehicles and is not suitable for limited automobile environments. Therefore, this paper develops a time interval-based IDS that can be integrally used by manufacturers and each model by utilizing the time interval characteristics of the internal network message of automobiles and tests the performance of the IDS.

    • 영상보안시스템에서의 개인정보보호를 위한 키 분배 서버 설계

      최영태 순천향대학교 대학원 2012 국내석사

      RANK : 247599

      영상보안시스템은 영상수집 장치, 영상보안서버, 클라이언트로 구성되어 있는 영상서비스 시스템을 말한다. 이 시스템은 CCTV가 널리 보급됨에 따라 이에 대한 관제 및 원활한 서비스 공급을 위해 필수적인 요소가 되었다. 현재 구성요소들의 각 통신 지점에서 해킹에 대한 위험성이 존재하고 있으며, 대량의 CCTV로 인한 개인 프라이버시 침해 문제가 발생하고 있다. 이를 해결하고자 암호화와 프라이버시 마스킹에 대한 연구가 활발히 진행 중이다. 하지만 마스킹 기술은 CCTV의 본 기능인 감시를 약화시키며, 범죄가 발생하였을 시 포렌식 수사를 위해서는 마스킹된 영상의 언마스킹이 반드시 필요하다. 또한, 전송 과정에서의 영상데이터에 대한 보호도 생각하여야 한다. 본 논문에서는 전송과정의 보호와 프라이버시 마스킹, 언마스킹을 위해 영상수집 장치, 영상보안서버, 인증서버, 키 관리 서버, 클라이언트로 구성되는 영상보안시스템을 설계하였다. 제안하는 시스템은 악의적인 공격자의 보안위협으로부터 영상정보를 보호할 수 있으며 여러 수준의 마스킹과 안전한 키 분배 구조를 통하여 포렌식 수사의 디지털 증거로써 무결성, 기밀성을 제공한다. 또한, 워터마킹 등의 기술을 삽입하는데 있어 높은 유동성을 제공한다.

    • 차량 세대별 IVI 시스템의 펌웨어 보안 분석 및 업데이트 메커니즘 우회

      푸레브바타르 순천향대학교 일반대학원 2025 국내석사

      RANK : 247599

      차량이 지능적이고 상호 연결된 플랫폼으로 계속 진화함에 따라, 차량 내 인포테인먼트 시스템(IVI, In-Vehicle Infotainment)은 사용자 경험 향상, 내비게이션, 미디어 제어, 차량 시스템 통합 등을 제공하는 핵심 구성 요소로 자리 잡고 있다. 그러나 이러한 시스템의 복잡성이 증가함에 따라, 특히 펌웨어 업데이트 메커니즘에서 심각한 보안 문제가 발생하고 있다. 본 논문은 2016년부터 2021년 사이에 출시된 세 가지 상용 차량에 탑재된 IVI 시스템을 대상으로, 역공학 및 펌웨어 보안 분석을 수행하였다. 먼저, 공식적인 펌웨어 획득 방법을 조사하고, 업데이트 패키지를 분석하여 시스템 구조, 암호화 방식, 검증 절차 등을 파악하였다. 또한 부트로더와 업데이트 데몬 등 주요 바이너리 구성 요소에 대한 분석을 통해 해시 검증, 키 관리, 권한 제어 등의 취약점을 식별하였다. 본 연구는 펌웨어 무결성 검사를 우회하고, 암호화된 업데이트 패키지를 복호화하며, 시스템 파티션을 수정하는 실제 기법을 제시한다. 최신 세대 시스템에서는 엔지니어링 모드 및 UART 포트와 같은 숨겨진 개발자 인터페이스를 통해 보다 깊은 수준의 시스템 접근과 펌웨어 조작이 가능함을 입증하였다. 본 연구는 체계적인 역공학, 펌웨어 추출, 실제 차량 테스트를 통해 IVI 플랫폼에서 노출되는 공격 지점을 규명하고, 이러한 취약점이 자동차 사이버 보안에 미치는 영향을 분석한다. 아울러 차량 세대 간 일관된 보안 업데이트 표준의 부재를 지적하며, 향후 자동차 시스템에는 강력한 펌웨어 인증, 견고한 암호화 방식, 그리고 강화된 시스템 보안 메커니즘의 도입이 필요함을 강조한다. As vehicles continue to evolve into intelligent and interconnected platforms, In-Vehicle Infotainment (IVI) systems have become central to delivering enhanced user experiences, including navigation, media control, and integration with core vehicle functions. However, their growing complexity introduces critical security challenges, particularly within firmware update mechanisms. This thesis presents a comprehensive reverse engineering and firmware security analysis of three generations of IVI systems deployed in commercially available vehicles released between 2016 and 2021. The analysis begins by examining official firmware acquisition methods and analyzing update packages to understand system structures, encryption schemes, and verification workflows. Through binary analysis of key components—including bootloaders and update daemons—this research uncovers vulnerabilities in hash verification, key management, and privilege enforcement. Practical methods are demonstrated for bypassing firmware integrity checks, decrypting update packages, and modifying system partitions. In later-generation systems, hidden developer interfaces such as UART ports and Engineering Mode menus are identified, enabling deeper system access and firmware manipulation. Through systematic reverse engineering, firmware extraction, and on-vehicle testing, this research exposes critical firmware-level attack surfaces and examines their implications for automotive cybersecurity. The findings highlight the absence of consistent secure update standards across vehicle generations and emphasize the urgent need for stronger firmware authentication, robust encryption, and hardened system-level protections in future automotive platforms.

    • 레벨 3 자율주행 자동차에서의 CAN 데이터 기반 주행 모드 식별에 관한 연구

      유근영 순천향대학교 일반대학원 2025 국내석사

      RANK : 247599

      최근 자율주행 기술은 교통 효율성 향상과 사고 감소라는 기대 속에서 급격 한 발전을 거듭하고 있으며, 그 중에서도 레벨 3 자율주행 자동차는 일정 조 건하에서 시스템이 운전 업무를 수행하되 필요시 운전자의 개입이 요구된다는 점에서 기술적, 법적 측면 모두에서 중요한 전환점을 맞이하고 있다. 그러나 레벨 3 자율주행의 특성상 시스템과 운전자 간의 역할이 유동적으로 전환되기 때문에 사고가 발생할 경우 책임 소재를 명확히 규정하기 어렵다는 점이 가장 큰 쟁점으로 대두되고 있다. 특히 현행 법, 제도는 급변하는 자율주행 기술의 복잡성과 운행 시나리오의 다양성을 충분히 반영하지 못하고 있기 때문에 사 고 책임 분담과 관련한 불확실성이 운전자와 제조사 간의 법적 분쟁으로 이어 질 가능성이 높아지고 있다. 이러한 문제를 해결하기 위해서는 단순히 기술적 안전성만을 고려하는 것을 넘어 사고 당시 차량의 주행 모드와 운전자 개입 여부를 객관적으로 증빙할 수 있는 기술적 장치와 이를 뒷받침할 수 있는 법, 제도적 기반이 함께 마련되어야 한다. 본 논문에서는 자율주행 모드를 정확하 게 식별하고 차량 안전성과 신뢰성을 높이기 위한 차량 내부 네트워크인 CAN (Controller Area Network) 기반으로 사고 원인의 주체를 확실히 밝힐 수 있는 방안을 제시하는 것을 목적으로 한다. 제안된 시스템은 주행 모드 식별의 정 확성을 높이고 사고 발생시 소비자와 제조사 간의 책임 소재 문제를 해결하는 데 도움이 될 것이다.

    연관 검색어 추천

    이 검색어로 많이 본 자료

    활용도 높은 자료

    해외이동버튼