RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    검색결과 좁혀 보기

    선택해제

    오늘 본 자료

    • 오늘 본 자료가 없습니다.
    더보기
    • 보안 위협 검증 및 대응을 위한 차량 사이버 보안 교육 플랫폼 개발

      고예지 순천향대학교 일반대학원 2023 국내석사

      RANK : 250719

      차량 기술의 발전으로 자율 주행 자동차가 등장하고 이와 관련된 연구가 활 발히 진행되고 있다. 하지만 기술의 발전과 함께 다수의 외부 접점이 생겨났 으며, 이는 외부에서 공격자가 접점을 악용하여 악성으로 접근할 수 있다는 사실을 의미한다. 이러한 보안 위험성으로 인해 차량 보안과 관련된 표준에서 는 자동차 내부 네트워크의 공격을 탐지할 수 있는 보안 요소를 적응시키는 것을 정규화하여 피해를 예방하려 하고 있으며, 차량 내부 네트워크에 대한 보안을 강화하도록 권고하고 있다. 차량 내부 네트워크를 안전하게 유지하고 보안을 강화하기 위한 연구가 활 발히 진행되고 있지만, 단편적인 부분에 국한된 연구가 아닌 전체적인 범주를 고려하며 연구를 진행하기 위해서는 차량 분야에 대한 자세한 구조 및 보안 위협 방식 등에 기초 정보에 대한 파악이 전제되어야 한다. 따라서 본 논문에 서는 자동차 내부 네트워크를 대상으로 Fuzzing, DoS 등과 같은 보안 위협 검 증과 대응 및 교육을 위한 차량 사이버 보안 교육 플랫폼을 개발하였다. 본 논문에서는 자동차 내부 네트워크를 대상으로 보안 위협 검증과 대응을 위한 차량 내부 네트워크 보안 교육 플랫폼을 개발하였다. 차량 내부 네트워 크 및 차량 보안 관련 표준 기초 지식을 설명하며, 자동차 내부 네트워크에 메시지를 수집할 수 있도록 각 프로토콜에 맞춰 수집 환경을 구축하여 실제 주행 데이터를 수집하였다. 해당 데이터 패킷을 바탕으로 프로토콜별 담당하 는 기능을 파악하였으며, 이러한 과정을 위한 분석 방법을 설명하였다. 이후 분석한 기능 메시지를 기반으로 차량 내부 네트워크에서 이상 탐지를 위한 프 로토콜별 보안 위협 가능성에 대해 검증하였다. The advancement of vehicle technology has led to the emergence of autonomous cars, and related research in this field is progressing. However, with the evolution of technology, numerous external interfaces have been created, indicating the possibility of malicious exploitation by attackers from outside. Due to these security risks, standards related to vehicle security aim to normalize the incorporation of security elements capable of detecting attacks on the internal networks of automobiles to prevent potential harm. Recommendations are made to strengthen security measures for vehicles' internal networks in response to the security threats associated with the increasing external interfaces in the context of advancing vehicle technology. Research on maintaining the safety of vehicles' internal networks and enhancing security measures is actively underway. A foundational understanding of detailed structures and security threat methodologies in the automotive field is essential to conduct comprehensive research that goes beyond isolated aspects and encompasses the entire scope. Therefore, this paper has developed a cyber security education platform for vehicles, focusing on security threat verification, response, and education targeted at the internal networks of automobiles, including aspects like Fuzzing and DoS. In this paper, we have developed a vehicle internal network security education platform for security threat verification and response. We explain the foundational knowledge of automotive internal networks and vehicle security-related standards, and we establish a collection environment tailored to each protocol within the automotive internal network to collect actual driving data. Utilizing the data packets, we identify the functionalities assigned to each protocol and describe the analysis methods for this process. Subsequently, we verify the potential security threats for each protocol in the vehicle's internal network based on the analyzed functional messages to detect anomalies.

    • 실차 수준의 차량 네트워크 보안 위협 분석을 위한 테스트베드 기반 데이터셋 수집 방법

      김윤정 순천향대학교 일반대학원 2024 국내석사

      RANK : 250719

      정보 통신 기술의 급속한 발전에 따라 현대 자동차는 단순한 기계적 장치에서 다양한 전자 제어 장치(ECU: Electronic Control Unit)를 포함한 복잡한 커넥티드 카로 변모하고 있다. 이러한 차량은 내부에서 CAN(Controller Area Network), LIN(Local Interconnect Network), FlexRay와 같은 네트워크를 통해 ECU들 간의 효율적인 통신을 지원한다. 특히 CAN 통신은 1980년대 Bosch 사가 개발한 프로토콜로, 배선 축소, 브로드캐스트 방식의 효율성 향상, 고속 통신, 노이즈 저항성 및 높은 신뢰성 등의 장점을 제공하여 현대 차량 시스템에서 필수적인 요소로 자리 잡고 있다. 현대 차량은 카메라, 레이더, 라이다 등 다양한 센서를 추가로 장착하여 내부 네트워크뿐만 아니라 다양한 IoT 기기와 외부 네트워크와의 연결성이 크게 증가하고 있다. 이러한 연결성의 증가는 자율주행차와 첨단 운전자 보조 시스템(ADAS)의 발전을 가능하게 했으며, 현재 자율주행차 기술은 구글 웨이모, 테슬라, 우버, 아마존 등 여러 기업의 참여로 급속도로 발전하고 있다. 글로벌 자율주행차 시장은 매년 확대되고 있으며, 주요 기업들의 투자 및 협업이 꾸준히 증가하고 있다. 그러나 이러한 기술 발전과 외부와의 연결성 증가에 따라 보안 취약점과 위협 요소도 함께 증가하고 있다. 이러한 보안 위협을 방지하기 위해 국제 표준과 규제가 중요해지고 있으며, UNECE, ISO, SAE 등 다양한 기구들이 차량 사이버 보안 표준을 개발하고 있다. 이를 통해 침입 탐지 시스템(IDS), 암호화 보안 등 다양한 보안 기술이 도입되고 있으며, Dos, Fuzzy 테스트와 같은 사이버 보안 위협 분석도 필요하다. 이에 따라 테스트를 위한 데이터셋 또한 중요한데, 데이터셋을 생성하고 수집하는 과정들을 실차량에서 할 경우 높은 위험과 어려움이 따르기 때문에, 본 논문에서는 COTS(Commercial Off The Shelf) 기반 차량 데이터셋 수집용 테스트베드를 구축하여 신뢰성 있는 데이터를 수집하고 분석하는 방법을 제시한다. 이를 통해 차량 네트워크 보안 위협 분석을 위한 DoS, Fuzzing, Replay 공격을 수행하고, 쉽게 라벨링 할 수 있는 공격 도구 및 수집 도구를 설정하여 데이터셋을 수집한다. 본 논문은 차량 사이버 보안 위협 분석의 필요성과 국제 표준 현황을 서술하고, COTS 기반 테스트베드를 설계 및 구축하여 공격 데이터셋 생성 방법을 제시하며, 연구의 결론을 도출한다. With the rapid advancement of information and communication technology, modern vehicles have evolved from simple mechanical devices to complex connected cars equipped with various Electronic Control Units (ECUs). These vehicles utilize networks such as CAN (Controller Area Network), LIN (Local Interconnect Network), and FlexRay to enable efficient communication between ECUs. CAN communication, developed by Bosch in the 1980s, offers significant advantages including reduced wiring, improved efficiency through broadcast messaging, high-speed communication, noise resistance, and high reliability, making it essential in modern vehicle systems. Today's vehicles are increasingly equipped with additional sensors like cameras, radars, and LiDAR, enhancing both internal and external network connectivity. This connectivity has enabled advancements in autonomous vehicles and advanced driver assistance systems (ADAS). Companies such as Google’s Waymo, Tesla, Uber, and Amazon are heavily involved in the rapid development of autonomous vehicle technology. The global autonomous vehicle market is expanding annually, with significant investments and collaborations among major companies. However, the increased connectivity also brings heightened security vulnerabilities and threats. To mitigate these threats, international standards and regulations are becoming increasingly important. Organizations like UNECE, ISO, and SAE are developing cybersecurity standards for vehicles, promoting the implementation of security technologies such as intrusion detection systems (IDS) and encryption. Despite the need for robust cybersecurity measures, collecting security datasets from real vehicles poses significant risks and challenges. To address this, this paper proposes the development of a COTS-based testbed for collecting vehicle datasets. This testbed aims to gather reliable data by demonstrating real vehicle operations and performing security threat analyses through DoS, Fuzzing, and Replay attacks. The tools and methodologies for easy labeling of collected data are also established. This paper outlines the necessity of vehicle cybersecurity threat analysis and the current state of international standards. It details the design and construction of the COTS-based testbed and discusses the methods for environment setup and attack dataset generation. Finally, the paper concludes with the findings and implications of the research.

    • 자동차 사이버보안 국제 법규 대응을 위한 TARA 자동화 프레임워크 구현 및 테스트베드 기반 평가

      강유진 순천향대학교 일반대학원 2026 국내석사

      RANK : 250719

      차량의 전자/전동화 및 자율주행 기능 고도화로 인해 차량의 연결성이 확대되면서 사이버보안 위협이 중요한 규제 대응 요소로 부각되고 있다. UN Regulation No.155와 ISO/SAE 21434는 차량 생애주기 전반에서 사이버보안 관리 체계 및 위험 분석 절차를 요구하며, 이에 따라 위협 분석 및 위험 평가 결과를 실질적으로 연결할 수 있는 방법론이 필요하다. 본 논문에서는 차량 사이버보안 국제 법규 대응을 위한 TARA 자동화 프레임워크 구현 및 테스트베드 기반 평가 방법을 제안한다. 이를 위해 ISO/SAE 21434 의 TARA 수행 절차를 기반으로 자산 식별, 피해 및 위협 시나리오 도출, 공격 경로 분석, 공격 실현가능성 평가, 위험도 산정, 보안 요구사항 및 테스트 케이스 도출 과정을 수행하였다. 또한 EVITA의 Attack Potential 평가 구조와 HEAVENS의 보안 수준 산정 방식을 참고하여 위험도 및 보안 수준 산정 로직을 구성하였다. 제안한 방법론을 구현하기 위해 AutoTARA 프레임워크를 설계하였다. AutoTARA는 csv 기반 입력 데이터를 활용하여 위협 시나리오별 공격 실현가능 성, 영향도, 위험도, 보안 수준, 통합 우선순위를 산정하고 평가 결과와 보안 요구 사항 및 테스트 케이스 간의 추적성을 확보할 수 있도록 결과 산출물을 생성한다. 또한 테스트베드에서 확인한 ECU 구성, CAN 통신 흐름, Ethernet 엔드포인트, 서비스 포트 패턴을 AutoTARA 입력 데이터와 연계하여 TARA 수행에 필요한 입력 항목을 구성하였다. 이후 CAN 환경에서 DoS, Fuzzing을 수행하여 수신량 변화 및 복구 여부를 확인하였으며 Ethernet 환경에서 Replay를 수행하여 차량 동작 상황과 동일한 화면이 재현됨을 확인하였다. 최종적으로 본 논문에서 제안한 방법론은 UN R155, ISO/SAE 21434 대응을 위한 차량 사이버보안 평가, 보안 요 구사항 도출, 테스트 케이스 설계 및 평가 근거 추적에 활용될 수 있다.

    • 차량 세대별 IVI 시스템의 펌웨어 보안 분석 및 업데이트 메커니즘 우회

      푸레브바타르 순천향대학교 일반대학원 2025 국내석사

      RANK : 250703

      차량이 지능적이고 상호 연결된 플랫폼으로 계속 진화함에 따라, 차량 내 인포테인먼트 시스템(IVI, In-Vehicle Infotainment)은 사용자 경험 향상, 내비게이션, 미디어 제어, 차량 시스템 통합 등을 제공하는 핵심 구성 요소로 자리 잡고 있다. 그러나 이러한 시스템의 복잡성이 증가함에 따라, 특히 펌웨어 업데이트 메커니즘에서 심각한 보안 문제가 발생하고 있다. 본 논문은 2016년부터 2021년 사이에 출시된 세 가지 상용 차량에 탑재된 IVI 시스템을 대상으로, 역공학 및 펌웨어 보안 분석을 수행하였다. 먼저, 공식적인 펌웨어 획득 방법을 조사하고, 업데이트 패키지를 분석하여 시스템 구조, 암호화 방식, 검증 절차 등을 파악하였다. 또한 부트로더와 업데이트 데몬 등 주요 바이너리 구성 요소에 대한 분석을 통해 해시 검증, 키 관리, 권한 제어 등의 취약점을 식별하였다. 본 연구는 펌웨어 무결성 검사를 우회하고, 암호화된 업데이트 패키지를 복호화하며, 시스템 파티션을 수정하는 실제 기법을 제시한다. 최신 세대 시스템에서는 엔지니어링 모드 및 UART 포트와 같은 숨겨진 개발자 인터페이스를 통해 보다 깊은 수준의 시스템 접근과 펌웨어 조작이 가능함을 입증하였다. 본 연구는 체계적인 역공학, 펌웨어 추출, 실제 차량 테스트를 통해 IVI 플랫폼에서 노출되는 공격 지점을 규명하고, 이러한 취약점이 자동차 사이버 보안에 미치는 영향을 분석한다. 아울러 차량 세대 간 일관된 보안 업데이트 표준의 부재를 지적하며, 향후 자동차 시스템에는 강력한 펌웨어 인증, 견고한 암호화 방식, 그리고 강화된 시스템 보안 메커니즘의 도입이 필요함을 강조한다. As vehicles continue to evolve into intelligent and interconnected platforms, In-Vehicle Infotainment (IVI) systems have become central to delivering enhanced user experiences, including navigation, media control, and integration with core vehicle functions. However, their growing complexity introduces critical security challenges, particularly within firmware update mechanisms. This thesis presents a comprehensive reverse engineering and firmware security analysis of three generations of IVI systems deployed in commercially available vehicles released between 2016 and 2021. The analysis begins by examining official firmware acquisition methods and analyzing update packages to understand system structures, encryption schemes, and verification workflows. Through binary analysis of key components—including bootloaders and update daemons—this research uncovers vulnerabilities in hash verification, key management, and privilege enforcement. Practical methods are demonstrated for bypassing firmware integrity checks, decrypting update packages, and modifying system partitions. In later-generation systems, hidden developer interfaces such as UART ports and Engineering Mode menus are identified, enabling deeper system access and firmware manipulation. Through systematic reverse engineering, firmware extraction, and on-vehicle testing, this research exposes critical firmware-level attack surfaces and examines their implications for automotive cybersecurity. The findings highlight the absence of consistent secure update standards across vehicle generations and emphasize the urgent need for stronger firmware authentication, robust encryption, and hardened system-level protections in future automotive platforms.

    • CTGAN 및 XGBoost를 활용한 SOME/IP 네트워크 비정상 행위 탐지 프레임워크

      김서연 순천향대학교 일반대학원 2024 국내석사

      RANK : 250703

      CTGAN 및 XGBoost를 활용한 SOME/IP 네트워크 비정상 행위 탐지 프레임워크 김 서 연 순천향대학교 대학원 모빌리티융합보안학과 지도교수 정 재 열 차량 내 이더넷 기반 통신을 위해 SOA 기반으로 설계된 미들웨어 프로토콜 인 SOME/IP가 채택되었다. 그러나 SOME/IP는 설계 단계에서 보안 메커니즘이 충분히 고려되지 않아 인증 및 암호화 부재로 인해 패킷 도청, 중간자 공격, 악성 패킷 전송 등 다양한 보안 취약점에 노출되어 있다. 특히 SOME/IP-SD는 IP 주소와 MAC 주소와 같은 식별 정보를 UDP 멀티캐스트로 전송하여 공격자 가 접근할 가능성을 높인다. 본 연구에서는 SOME/IP 프로토콜의 보안 취약점 을 분석하기 위해 SOME/IP 대상 Fuzzer를 개발하여 해당 취약점을 분석하고 공격 시나리오를 구축하였다. 이를 바탕으로, SOME/IP 침입 탐지 프레임워크 를 제안한다. 제안된 프레임워크는 SOME/IP 통신 과정에서 발생할 수 있는 비 정상 패턴을 탐지하며, 데이터 불균형 문제를 해결하기 위해 CTGAN을 활용하 여 비정상 데이터를 생성하고 학습 데이터의 다양성을 확보한다. 또한, XGBoost 알고리즘을 통해 높은 정확도의 비정상 행위 탐지 모델을 구축한다.

    • ISO/SAE 21434 기반 사이버보안 이벤트 중심 TARA 프레임워크 연구

      류상형 순천향대학교 일반대학원 2026 국내석사

      RANK : 250703

      차량의 기능 확장과 외부 연결성 증가는 사이버보안 위협을 지속적으로 증가시키고 있다. ISO/SAE 21434는 차량 개발 라이프사이클 전반의 사이버 보안 위험 관리를 위한 절차를 정의하고 있으며, 그 핵심 활동으로 위협 분 석 및 위험 평가(TARA)를 제시한다. 그러나 실제 개발 환경에서는 TARA가 개발 초기 단계에 수행되는 일회성 활동으로 활용되는 경향이 있으며, 개발 및 운영 과정에서 발생하는 시스템 변경 사항과 신규 위협 정보가 위험 평 가 결과에 충분히 반영되지 못하는 한계가 존재한다. 본 연구에서는 ISO/SAE 21434의 TARA 수행 구조를 분석하여 절차적, 내용적 및 협업적 한계를 도출하고, 차량 개발 라이프사이클 전반에서 발생 하는 정보 변화를 기반으로 TARA를 지속적으로 갱신할 수 있는 프레임워크 를 제안하였다. 제안한 프레임워크는 사이버보안 이벤트 식별, 변경 영향 분 석, 재평가 범위 결정, TARA 재수행 및 결과 갱신 절차를 포함한다. 또한 Digital Key System을 활용한 적용 시나리오를 통해 프레임워크를 적용한 결과, 사이버보안 이벤트 유형에 따라 재평가 범위를 효율적으로 결 정하고 신규 자산 및 위협 시나리오를 반영하여 TARA 결과를 갱신할 수 있 음을 확인하였다. 이를 바탕으로 ISO/SAE 21434의 지속적인 TARA 운영을 위한 표준 개선 방향을 제안하였다. 본 연구는 차량 개발 라이프사이클 전 반에서 TARA 결과를 지속적으로 관리하기 위한 방법을 제시하였다는 점에 서 의의를 가진다. The expansion of vehicle functionalities and external connectivity has continuously increased cybersecurity threats in modern vehicles. ISO/SAE 21434 defines a framework for managing cybersecurity risks throughout the vehicle lifecycle and identifies Threat Analysis and Risk Assessment (TARA) as a core activity. However, in practical development environments, TARA is often conducted as a one-time activity during the early development phase, making it difficult to adequately reflect system changes and newly identified threats that arise during development and operation. This study analyzes the TARA process defined in ISO/SAE 21434 and identifies its limitations from procedural, informational, and collaborative perspectives. Based on these findings, a framework is proposed to enable the continuous update of TARA results by utilizing information generated throughout the vehicle lifecycle. The proposed framework consists of cybersecurity event identification, change impact analysis, re-evaluation scope determination, TARA re-assessment, and result update procedures. To evaluate the applicability of the proposed framework, a Digital Key System use case was examined. The results show that the framework can efficiently determine re-evaluation scopes according to different types of cybersecurity events and update TARA results by incorporating newly identified assets and threat scenarios. Based on these findings, improvements to support continuous TARA operation within ISO/SAE 21434 are proposed. This study contributes by providing a method for continuously maintaining and updating TARA results throughout the vehicle lifecycle.

    • 의사결정트리 및 CNN 알고리즘을 활용한 악성코드 탐지에 관한 연구

      고석민 순천향대학교 일반대학원 2024 국내석사

      RANK : 250687

      의사결정트리 및 CNN 알고리즘을 활용한 악성코드 탐지에 관한 연구 고 석 민 순천향대학교 대학원 모빌리티융합보안학과 지도교수 김 태 근 ICT의 발전으로 다양한 디바이스들이 연결됨에 따라, 많은 악성코드가 해당 목표를 대상으로 증가하고 있다. 특히, 랜섬웨어, 인포스틸러 등의 악성코드는 네트워크에 연결된 디바이스를 중간 매개체로 사용하여 실제 대상으로 하는 윈도우 기반 컴퓨터에 침입하여 감염시켜 정보를 훔치거나 파일을 감염시킨 다. 더불어, 랜섬웨어는 변종이 많아 기존의 시그니처 기반 악성코드 탐지 방 법으로 탐지하기 어렵다는 단점이 존재한다. 이러한 단점을 극복하기 위해 본 논문에서는 의사결정트리 기반 알고리즘과 CNN 알고리즘을 활용한 악성코드 탐지 연구를 제안한다. 악성코드 패밀리의 Opcode 및 API 정보를 추출하여 P CA 알고리즘을 이용하여 데이터의 차원을 압축한다. 이후 핀포인트와 Grid Se arch 알고리즘을 적용하여 의사결정트리를 최적화하여 성능을 향상한다. 의사 결정트리의 리프 노드에 CNN 모델을 배치하고 분류된 데이터를 학습하여 악 성코드를 탐지하는 연구를 진행한다. 본 연구를 통해 유사한 데이터끼리 학습 했을 때 성능향상 효과가 있으며, 97.52%의 정확도로 악성코드를 탐지할 수 있음을 증명한다.

    • LTE-V2X 기반 자율주행 환경에서의 공격 시뮬레이터

      정다윗 순천향대학교 일반대학원 2024 국내석사

      RANK : 250687

      LTE-V2X는 도로 간 원활한 주행 환경을 제공하며 자율주행 기술의 필수적인 기술로 자리 잡고 있다. 그러나, LTE-V2X 통신 데이터로 주행 환경을 파악하고 의사결정을 내린다는 점에서 데이터 위변조, 해킹과 같은 보안 위협은 사이버 피해뿐만 아니라 물리적 피해를 초래할 수 있다. 이러한 위협에 대응하기 위해서는 실증 연구를 통한 테스트 및 평가가 수행되어야 한다. 그러나, 실증 연구를 수행하기 위해서는 인프라 구축이 되어 있어야 하며 실제 차량이 필요하기 때문에 한계가 존재한다. 또한, 주행에 영향을 가할 수 있는 보안 위협은 물리적 피해까지 이어질 수 있기 때문에 실증 연구를 수행하는데 어려움이 따른다. 따라서 본 논문에서는 이러한 위협에 대응하기 위해 보안 위협을 시뮬레이션 할 수 있는 시뮬레이터를 제안하고 구현하였다. 기존의 시뮬레이터들을 통합하여 다양한 공격을 시뮬레이션 가능한 공격 시뮬레이터를 구축하였다. 또한, 시뮬레이터를 연계하는 방법을 제시하고 시뮬레이션을 통해 잠재적인 보안 위협에 대해 공격 시나리오를 설정하여 시뮬레이션을 수행하고 주행 환경에 끼칠 수 있는 영향을 통신 지연 시간과 주행 오차 거리를 통해 평가하였다. Uu/PC5 인터페이스에 대한 DoS 공격, Sybil 공격, Replay 공격에 대한 시나리오를 시뮬레이션을 수행했을 때, PC5 인터페이스에 대한 DoS 공격이 네트워크 혼잡에 가장 큰 영향을 주었음을 실험을 통해 확인하였다.

    • IoT 기기 인증을 위한 강조된 스펙트럼 데이터 기반 신호 핑거프린팅 방법

      박현 순천향대학교 일반대학원 2024 국내석사

      RANK : 250687

      IoT 기기 인증을 위한 강조된 스펙트럼 데이터 기반 신호 핑거프린팅 방법 본 연구는 Bluetooth Low Energy 기술에서 발생할 수 있는 보안 위협에 대 처하기 위해 딥러닝 기반의 BLE Fingerprint 방법을 제안한다. BLE 기술은 저전 력에서도 고성능 데이터 전송을 가능하게 하여 다양한 IoT(Internet of Things) 기 기의 핵심 기술로 자리 잡고 있으나 무선 신호의 위조 또는 변조에 의한 보안 위 협이 존재하며 이는 공격자가 합법적인 기기의 신호를 모방하거나 변조하여 시스 템에 침투하는 것을 가능하게 한다. 이러한 위협은 사용자의 민감한 정보 유출이 나 물리적 보안 손상을 초래할 수 있다. 본 연구에서는 이러한 위협에 대응하기 위해 IoT 기기 등 BLE 신호 송신 기기 에서 송출된 BLE 신호의 주파수 성분에서 스펙트럼 데이터를 추출한 후, 이를 이용해 신호의 이상 탐지를 수행하여 기기를 인증 및 식별하는 인공지능 모델을 제안한다. BLE 신호가 송출될 때 하드웨어적 미세한 차이로 인해 발생하는 고유 의 신호 특성을 분석하여 강조하는 필터 뱅크를 설계하고 해당 필터 뱅크로 추출 된 데이터를 기반으로 BLE 신호의 이상 탐지를 수행한다. This study proposes a deep learning-based BLE (Bluetooth Low Energy) Fingerprint method to address security threats in Bluetooth Low Energy technology. Security threats exist due to the spoofing or tampering of wireless signals, allowing attackers to mimic or alter legitimate device signals to infiltrate systems. To counter these threats, this study proposes an AI model that extracts Cepstral Coefficients from the frequency components of BLE signals to determine whether the signals are legitimate or forged/tampered. By designing a filter bank that emphasizes the unique signal characteristics caused by minute hardware differences when BLE signals are transmitted, this method identifies BLE signals based on the data extracted through this filter bank.

    • 차량 네트워크 내 침입 감지를 위한 딥러닝 기반 접근 방법

      Hoang, Thien Nu 순천향대학교 대학원 2023 국내석사

      RANK : 250671

      In modern vehicles, the controller area network (CAN) bus is one of the most important means of communication between electronic control units (ECUs). Despite its speed and simplicity, the critical drawback of the CAN bus is the security problem. In the CAN bus, the ECUs send and receive messages based on broadcasting and priority mechanisms without authentication and encryption. Hence, the system is vulnerable to various attacks. To address the problem, this thesis introduces three deep learning-based approaches for designing a robust intrusion detection system (IDS) in the CAN bus. Firstly, this thesis proposes a semi-supervised deep learning model, named convolutional adversarial autoencoder (CAAE), to tackle the issue of lacking labeled attack data, which commonly occurs in the intrusion detection problem. Concretely, the model is trained with unlabeled data to learn the manifolds of normal and attack patterns. Then, only a small number of labeled samples are used in supervised training. The proposed model can detect various kinds of message injection attacks, such as DoS, fuzzy, and spoofing, as well as unknown attacks. The experimental results show that the proposed model achieves the highest F1 score of 0.9984 and a low error rate of 0.1% with limited labeled data compared to other supervised methods. Moreover, the model can meet the real-time requirement by analyzing the model complexity in terms of the number of trainable parameters and inference time. This study successfully reduced the number of model parameters by five times and the inference time by eight times, compared to a state-of-the-art model. Next, the thesis aims to design a universal IDS which can be applied to all car models. As a result of the different distribution of car models, the goal is difficult to achieve. Therefore, the thesis utilizes transfer learning techniques on a supervised contrastive model. In detail, we proposed a novel deep learning model called supervised contrastive (SupCon) ResNet, which can handle multiple attack classifications on the CAN bus. Furthermore, the model can be used to improve the performance of a limited-size dataset using a transfer learning technique. The capability of the proposed model is evaluated on two real car datasets. When tested with the car hacking dataset, the experiment results show that the SupCon ResNet model improves the overall false-negative rates of four types of attack by five times on average, compared to other models. In addition, the model achieves the highest F1 score on both the vehicle models of the survival dataset by utilizing transfer learning. Finally, the model can adapt to hardware constraints in terms of memory size and running time to be deployed in real devices. Finally, we extend the transfer learning idea in the previous study by developing a personalized federated learning scheme to aggregate all the datasets from different car models. The proposed model can provide global knowledge that can be transferred to any model’s participant to increase its performance. In comparison to baseline models, the proposed model achieves 4% higher F1 scores overall. Besides, the results also suggest that the proposed model provides significant advantages when the local dataset of each participant is relatively small. According to our experiments, the proposed models can achieve F1 scores of more than 90% with at least 30k training samples on each client. 최신 차량에서 CAN(Controller Area Network) 버스는 전자 제어 장치(ECU) 간의 가장 중요한 통신 수단 중 하나이다. CAN 버스는 빠른 속도와 단순한 구조를 가지고 있지만 보안 상 문제점을 가지고 있다. CAN 버스에서 ECU는 인증 및 암호화 없이 브로드캐스팅 및 우선 순위 메커니즘을 기반으로 메시지를 송수신하므로, 다양한 공격에 취약하다. 이 문제를 해결하기 위해 이 논문에서는 CAN 버스에서 견고한 침입 탐지 시스템(Intrusion Detection System, IDS)을 설계하기 위한 세 가지 딥 러닝 기반 접근 방식을 소개한다. 첫 번째 방법에서는 침입탐지 문제에서 흔히 발생하는 레이블 공격 데이터의 부족 문제를 해결하기 위해 CAAE(convolutional adversarial autoencoder)라는 준지도 딥러닝 모델을 제안한다. 제안하는 모델은 정상 및 공격 패턴의 다양성을 학습하기 위해 먼저 레이블이 없는 데이터로 훈련된다. 그런 다음 지도학습에 소수의 레이블이 지정된 샘플만 사용된다. 제안하는 모델은 알려지지 않은 공격 뿐만 아니라 DoS, fuzzy, spoofing과 같은 다양한 종류의 메시지 주입 공격을 탐지할 수 있다. 실험 결과, 제안된 모델이 다른 지도학습 방법에 비해 제한된 수의 레이블 데이터로 가장 높은 F1 점수인 0.9984와 0.1%의 낮은 오류율을 달성함을 보여준다. 또한, 제안하는 모델에 대해 훈련 가능한 매개변수의 수와 실행 시간 측면에서 모델 복잡성을 분석하여 실시간 요구 사항을 충족하는 것을 확인하였다. 본 연구에서는 최신 모델에 비해 모델 매개변수의 수를 5배, 실행 시간을 8배 줄이는 데 성공하였다. 두 번째 방법에서는 모든 차종에 적용 가능한 범용 IDS를 설계하는 것을 목표로 한다. 자동차 모델에 따라 CAN 데이터의 구조가 다르기 때문에 범용 IDS를 설계하는 것은 쉽지 않다. 따라서 본 논문에서는 Supervised Contrastive(SupCon) 모델에 전이 학습 기법을 활용한다. 세부적으로는 CAN 버스에서 다중 공격 분류를 처리할 수 있는 Supervised Contrastive ResNet이라는 새로운 딥 러닝 모델을 제안하고, 이 모델을 전이 학습 기법을 사용하여 제한된 크기의 데이터 세트의 성능을 개선하는 데 사용한다. 제안된 모델의 성능은 두 개의 실제 자동차 데이터 세트에서 평가된다. Car Hacking 데이터셋으로 테스트한 결과, SupCon ResNet 모델이 다른 모델에 비해 4가지 유형의 공격에 대한 전반적인 위음성 비율을 평균 5배 향상시키는 것으로 나타났고, 전이 학습을 활용하여 Survival 데이터 세트의 두 차량 모델 모두에서 가장 높은 F1 점수를 얻었다. 마지막으로 제안하는 모델은 배포할 메모리 크기 및 실행 시간 측면에서 차량 용 하드웨어 제약 조건을 만족하는 것을 확인하였다. 마지막으로, 서로 다른 자동차 모델의 모든 데이터 세트를 활용하기 위해 개인화된 연합 학습 체계를 개발하여 이전 연구의 전이 학습 아이디어를 확장한다. 제안된 모델은 성능을 향상시키기 위해 모든 모델의 참여자에게 전달될 수 있는 글로벌 지식을 제공할 수 있다. 기본 모델과 비교하여 제안된 모델은 전반적으로 4% 더 높은 F1 점수를 달성한다. 또한 해당 결과는 제안된 모델이 각 참가자의 로컬 데이터 세트가 상대적으로 작을 때 상당한 이점을 제공함을 시사한다. 우리의 실험에 따르면, 제안된 모델은 각 클라이언트에서 최소 30,000개의 훈련 샘플로 90% 이상의 F1 점수를 달성할 수 있었다.

    연관 검색어 추천

    이 검색어로 많이 본 자료

    활용도 높은 자료

    해외이동버튼