
http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
윈도우즈 서버 취약점 분석을 위한 배치 파일(Batch File) 구현에 관한 연구
This paper is a treatise on the realization of batch file which can quickly and easily perform the vulnerability analysis of Windows Server. Administrators can quickly and easily determine the vulnerability of Windows Server and apply security settings to it through the batch file for vulnerability analysis. The batch file for vulnerability analysis which is realized in this treatise will be distributed free in order to improve the security level of corporations which do not have the exclusive organ for information security.
금융분야의 보안 취약점 분석평가 기술정보 공유에 관한 연구
금융분야는 사이버위협에 대응하기 위하여 2001년 「정보통신기반보호법」 제16조 (정보공유·분석 센터, 2001년 7월1일 시행)에 의거하여 금융ISAC이 금융결제원, 코스콤, 금융보안연구원 3개 기관에서 운영되고 있었다. 이후 지속적으로 금융보안사고가 발생하며 금융ISAC의 사이버위협에 대한 대응체계 문제가 제기되었고, 2014년 대형카드3사의 개인정보유출사고가 발생하자 국무회의에서 금융ISAC업무의 통합운영이 본격적으로 논의되었다. 그리고, 2015년 금융보안원에 설립되면서 3개 기관의 금융ISAC업무를 통합운영하게 되었으며 그 이후로 전자금융사고의 수치는 감소추세로 돌아서게 되었다. 하지만, 2017년 ATM(자동화기기) 해킹사고, 2016년 스위프트망을 통한 방글라데시 은행 해킹사고 등 국내/외 적으로 금융분야의 사고는 지능화, 고도화 되고 있으므로 금융분야의 해킹사고에 대한 통계상의 수치가 작아진 반면, 단위 건 당 위협은 높아지고 있다. 따라서, 보안취약점의 선제적 대응을 위하여 금융ISAC의 보안취약점분석평가와 사이버위협정보공유 기능을 연계할 수 있는 관리체계와 시스템을 연구하였다. 금융분야의 특성상 보안취약점분석평가에서 발견된 보안취약점이 공유되지 못하고 있는 것이 현실이나 발견된 보안취약점이 노출된 소프트웨어/하드웨어를 공통적으로 사용하는 금융기관이 다수 존재하기 때문에 해당 보안취약점이 최초로 발견된 기관명을 삭제하는 등의 민감정보의 비식별조치 단계와 환경요소를 고려한 위험도를 측정하는 등의 정보를 검증하는 단계를 거쳐서 금융기관과 평가기관 양측의 이익을 도모할 수 있는 취약점정보공유 프로세스와 시스템에 대한 모델을 제시하였다. 본 논문에서는 최근 금융분야의 지능화, 고도화 되는 악성코드에 의한 해킹위협에 대해서 금융ISAC의 취약점분석평가 업무와 사이버위협정보공유시스템을 연계한 보안취약점정보공유시스템을 제안함으로써 그 피해를 최소화 할 수 있는 단계에 기여할 것으로 본다.
사물 인터넷 스마트 기기의 취약점 분석 및 보안성 측정 방법에 관한 연구
이기택 고려대학교 정보보호대학원 2021 국내박사
최근 스마트 기기와 사물 인터넷은 전 세계에서 급속도로 발전하고, 우리의 생활에 다양한 용도로 사용되고 있다. 스마트 TV를 중심으로 가전 기기는 스마트 기기로 탈바꿈하고 있다. 또한, 이러한 가전 기기들은 사물 인터넷의 기능을 포함하거나 사물 인터넷 기기와 연결되어 가고 있다. 스마트 기기와 사물 인터넷은 인터넷 또는 클라우드로 연결되어 있다. 기기들은 사람의 생활 정보과 패턴을 포함한 빅데이터를 수집하고, 전송 또는 분석한다. 분석된 데이터를 활용하여, 사람들에게 필요한 정보들과 기능들을 예측하고, 사람들에게 신속하게 필요한 정보를 전달하거나 편의 기능을 제공하기도 한다. 하지만, 스마트 기기와 사물 인터넷이 발전하고 확산되는 것과 동시에 사이버 공격에 점점 노출되고 있다. 이러한 사이버 공격으로 개인정보와 같은 민감 정보들이 유출되고, 공격자는 기기들의 제어권을 탈취할 수 있다. 또한, 공격자들은 스마트 기기와 사물 인터넷 기기에서 획득할 수 있는 개인정보로 금융 자산을 탈취한다. 획득한 기기의 제어권으로 기기에 오동작을 발생시킴으로써 우리의 생명과 안전을 위협할 수 있다. 이러한 사물 인터넷의 정보 보안 분야의 다양한 연구들에서 스마트 기기와 사물 인터넷 기기의 사이버 공격에 대한 위협을 다루었지만, 사물 인터넷 스마트 기기에 적합한 취약점 분석과 보안성 측정을 연계한 연구가 부족하다. 또한, 사물 인터넷 기기의 취약점 분석 방법론 관련 연구들도 실제 공격자들이 사용하는 공격 방법과 기업 내에서 취약점 분석하는 방법들을 다루고 있지 못했다. 따라서, 본 연구에서는 사물 인터넷 스마트 기기의 보안성 향상을 위한 실질적인 취약점을 분석하는 방법과 보안성 수준을 측정하고 평가하기 위한 방법론을 제시하고자 한다. 이를 위해 사물 인터넷 스마트 기기의 기능 및 종류에 따른 기능 및 보안 요소, 그리고 보안 위협들을 상세하게 살펴본다. 그리고, 사물 인터넷 스마트 기기에 적합한 취약점 분석 방법론을 제안하고, 2종의 사물 인터넷 스마트 기기에 제시한 방법론을 적용하여 취약점 분석 및 보안성을 평가하여 결과를 제시한다. 이 연구 결과를 통해 향후 사물 인터넷 스마트 기기에서 발생할 수 있는 보안 취약성과 위협을 보다 효율적으로 분석할 수 있는 기반을 제공하고, 객관적인 사물 인터넷의 보안성 측정에 기여할 수 있을 것으로 기대한다.
오늘날 우리 사회는 정보통신기술 및 컴퓨터의 발달로 인해 우리 주변의 모든 사물이 인터넷으로 연결되는 사물인터넷(IoT) 시대가 도래하였다. 또한, 4차 산업혁명의 대표적인 기술인 인공지능, 빅데이터, 블록체인 등 새로운 기술의 융합과 더불어 풍요로운 기술의 서비스 환경을 누릴 수 있는 환경이 조성되고 있다. 그러나 이러한 융합 서비스 환경의 발달에 따라 사이버 공격의 피해 규모 또한, 기존의 범위를 넘어서서 개인, 기업 또는 단체에 피해를 주는 것에 국한되지 않고 국가적인 범위까지 확산될 수 있다. 따라서 앞으로의 정보통신 환경에 사이버보안은 더욱 중요한 핵심요소가 되었다. 특히, 민간·공공 분야 사이버보안의 최전선에서 날로 정교화, 고도화, 은밀화되는 각종 사이버보안 위협을 탐지·차단하고 침해사고를 사전 예방하는 보안관제 서비스는 이러한 정보통신 환경의 변화를 적극적으로 수용하고 해결방안을 고민해야한다. 그러나 현재 보안관제 프로세스는 공격자의 공격 후 대응만을 위한 수동적인 시스템으로 운용됨에 따라 공격 발생 이후 침해사고 대응이 일반적이다. 특히, 신규 자산 추가 및 실제 서비스가 이루어지는 경우 실제 해커의 관점에서 보호 자산의 보안취약점 테스트 및 사전 방어에 한계가 있다. 본 논문에서는 해킹 관련 다중 검색엔진을 활용하여 보호 자산의 사전 취약점 대응 기능을 추가한 보안관제 모델을 새롭게 제안하였다. 즉, 범용 또는 특수한 목적을 지닌 다중의 검색엔진을 이용하여 보호 대상 자산의 특수한 취약점을 사전에 점검하고, 점검결과로 나타난 자산의 취약점을 사전에 제거하도록 하였다. 그리고 실제 해커의 입장에서 인지되는 보호 자산의 객관적인 공격 취약점을 미리 점검하는 기능, IP 대역에 위치한 광범위한 시스템 관련 취약점을 사전에 발굴하여 제거하는 기능 등을 추가로 제시하였다. In today's society, the Internet of Things (IoT) era has arrived in which all things around us are connected to the Internet due to the development of information and communication technologies and computers. In addition, an environment is being created in which the service environment of rich technologies can be enjoyed along with the convergence of new technologies such as artificial intelligence, big data, and blockchain, which are representative technologies of the 4th industrial revolution. However, according to the development of such convergence service environment, the scale of cyber attacks can also be spread to the national scope, not limited to damages to individuals, companies, or organizations beyond the existing scope. Therefore, cyber security has become a more important core element in the future information communication environment. In particular, the security control service that detects and blocks various cybersecurity threats that are increasingly sophisticated, advanced, and secretly at the forefront of cybersecurity in the private and public sectors, and prevents intrusion accidents, actively accepts and resolves such changes in the information and communication environment. You have to think about the plan. However, as the current security control process is operated as a passive system only for the response after an attacker's attack, it is common to respond to intrusion incidents after an attack occurs. In particular, when new assets are added and actual services are performed, there is a limit to testing and pre-defending security weaknesses of the protected assets from the perspective of real hackers. In this paper, a new security control model has been proposed by using multiple hacking-related search engines to add a function to respond to vulnerabilities in advance of protected assets. In other words, using multiple search engines with general purpose or special purpose, special vulnerabilities of the assets to be protected are checked in advance, and the vulnerabilities of the assets that have appeared as a result of the check are removed in advance. In addition, the function of pre-checking the objective attack vulnerabilities of the protected assets recognized from the point of view of the actual hacker, and the function of discovering and removing a wide range of system-related vulnerabilities located in the IP band in advance were additionally presented.
자바스크립트 및 하드웨어 오버레이를 이용한 키보드보안 프로그램에 대한 취약점 분석
Nowaday, to protect security information of users, the secure keyboard solutions are widely used and they are enhanced their security level by conducting with the extended end-to-end security environments. Along with the advance of secure keyboard solutions, malwares to leak secure information of users also have been steadily advanced. Today, according to the requests of the secure keyboard solutions that do not use physical keyboards, the new secure keyboard solutions working on Javascript or hardware overlay have been developed and served. In this paper, we consider the several secure keyboard solutions and show their vulnerabilities through our experiments. In addition, we discuss the possible solutions for the vulnerabilities. 현재 이용자의 비밀을 보호하기 위한 수단으로 키보드보안이 많이 이용되고 있으며, 최근에는 확장된 종단 간 암호화 기술로 인해 그 보안성이 더욱 향상되었다. 그러나 한편, 이용자의 비밀을 노리는 악성 프로그램 또한 이와 발맞추어 꾸준히 발전되어왔다. 현재에는 키보드를 직접 이용하지 않는 키보드보안 솔루션에 대한 요구로 자바스크립트나 하드웨어 오버레이를 이용하는 가상키보드가 개발되어 서비스되고 있다. 이 논문에서는 각 키보드보안 솔루션에 대하여 고찰하고 실험을 통해 여러 취약점이 존재할 수 있음을 보인다. 또한, 각 취약점을 극복하기 위한 방법에 대하여 논의한다.
노은주 성균관대학교 정보통신대학원 2024 국내석사
As the reliance on information and communication technology (ICT) in national infrastructure deepens, electronic intrusions such as hacking, malware dissemination, and DDoS attacks have emerged as new threats. Consequently, there has been an increased interest in information security among various enterprises, with a rising trend in security checks and vulnerability assessments. This paper examines the overview and evaluation criteria of security checks and vulnerability assessments for electronic financial infrastructure and major information and communication infrastructure in Korea, which serve as standards for such evaluations. By comparing these two evaluation criteria, the paper identifies similarities to propose a more efficient integrated evaluation standard. Furthermore, in order to securely protect the growing cloud market, the paper suggests adding new areas of evaluation criteria.
정보통신기반시설 취약점 관리체계 개선방안 연구 : 주요정보통신기반시설 취약점 분석평가에 대하여
노희관 숭실대학교 정보과학대학원 2013 국내석사
주요정보통신기반시설의 취약점 분석·평가는 최근 전문·고도화되는 사이버 위협에 대응하고 체계적이고 안전한 대응체계를 만들기 위하여 도입된 제도이다. 주요정보통신기반시설에 대한 효과적인 보호를 위해서는 발견된 취약점을 조치하고 잠재위험을 관리할 수 있어야 한다. 효과적인 주요정보통신기반시설 취약점 분석·평가를 수행하기 위해서는 취약점 원인에 대한 분석이 필요하다.. 취약점의 원인을 분석하면 기반시설 관리기관의 잠재위험을 파악할 수 있기 때문이다. 따라서, 주요정보통신기반시설의 취약점 분석·평가 체계에서 원인분석 프로세스를 도입하여 근본원인을 규명하고 정책적 관리방안을 마련해야 한다. 본 연구에서는 취약점 분석·평가 수행 시 취약점 발생 원인에 대하여 각 취약점 항목별, 카테고리별, 점검 분야별로 통계를 산출하고, 해당 관리기관이 가진 문제점들을 파악할 수 있도록 정량적인 개선 순위를 도출하였다. 이러한 방법으로 기존의 방법론에서 제시되지 못했던 관리기관의 내부 문제점에 대해 정책적 개선방향을 제시할 수 있었다. 주요정보통신기반시설의 취약점 분석·평가는 발견된 취약점이 무엇이며, 그 잠재적인 문제점은 무엇인지를 파악하고 근본적인 문제를 해결할 수 있도록 수행되어야 해야 한다. 기반시설 관리기관은 이러한 잠재위험을 인지하고 장기적인 관점에서 접근하여 문제점을 해결해 나가야 한다. Vulnerability Analysis and Evaluation of Major Information and Communications Infrastructure was introduced in order to make systematic and safe system to respond to the recent professional and sophisticated cyber threats. To protect the national infrastructure the causes of vulnerability must be eliminated and potential dangers to the infrastructure should be timely managed. To carry out an effective Vulnerability Analysis and Evaluation of Major Information and Communications Infrastructure, what can harm the infrastructure should be analysed first. With the results we can know in advance the potential dangers the management agencies have. Accordingly, root cause analysis should be used to verify the causes and prepare plans in the Vulnerability Analysis and Evaluation in case something happens to the infrastructure. In this study I collected statistics for the causes of vulnerability in a way that those causes are classified according to where and how they are found and found out what should be taken care of in terms of the repetition rate. In this way, I came up with the methods for dealing with the problems stemming from the management agencies. The Vulnerability Analysis and Evaluation should detect the vulnerability and the potential dangers and can get rid of the root causes. Management agencies of the infrastructure should be well aware of the dormant dangers and try to solve problems in the long term.
크롬OS의 보안 강화를 위한 취약점 분석 스크립트 구현
이슬기 고려대학교 컴퓨터정보통신대학원 2017 국내석사
OS의 취약점을 탐지하여 잠재적으로 내재되어 있는 보안위협들을 막아내기 위한 방법으로 쉘 스크립트 구현을 통한 취약점 분석 및 개선 강화가 필요하다. 웹OS의 특징을 가지고 있는 크롬OS로서는 이 부분을 가장 최우선시 해야 하지만 현재까지는 크롬OS의 환경에 최적화 되어진 쉘 스크립트는 존재하지 않다. 따라서 본 논문에서는 이러한 문제점을 해결하기 위해 사용하기 편리하면서 편집이 자유로운 취약점 분석 쉘 스크립트를 작성하고자 한다. 또 기존의 취약점 분석 쉘 스크립트에서 행정안전부 취약점 분석평가 기술적 점검 항목들만을 활용하였던 것과는 달리, 다른 취약점 분석평가 항목들도 사용하여 판단을 한다. 이 목적을 실현하기 위하여 이 논문에서는 행정안전부의 취약점 분석평가 기술적 점검 항목과 NSA의 Guide to the Secure Configuration of Red Hat Enterprise Linux 5를 이용해서, 크롬OS에 적합한 취약점 분석 쉘 스크립트를 구현한다. 이와 함께 기존의 서버OS 개념이 아닌 클라이언트OS 성향의 특징을 반영하여, 소프트웨어 패키지 설치를 최소화한 OS의 환경을 감안해서 쉘 스크립트를 구현한다. 본 논문은 작성한 취약점 분석 쉘 스크립트를 Virtual box 가상머신 환경과 ARM 크롬북, USB 메모리를 활용한 넷북 환경에서 실험했으며 실행 결과는 다음과 같다. 취약점 보안 강화를 수행하기 전에는 행정안전부 기준의 경우 보안 성능 평점이 105 ~ 110점 그리고 NSA 기준의 경우는 51점 이었던 반면에, 취약점 보안 강화를 수행한 후에는 행정안전부 기준과 NSA 기준 보안 성능 평점이 각각 155점과 170점으로 상승하였음을 확인할 수 있었다. 이 논문에서는 크롬OS에 최적화된 취약점 분석 및 개선 강화를 위한 쉘 스크립트의 설계와 구현에 대해서 기술한다. 이 쉘 스크립트를 이용하면 콘솔에서 해당 항목의 경로를 하나씩 찾아가는 번거로움을 해소할 수 있다.
천우성 호서대학교 벤처전문대학원 2010 국내석사
우리나라 WiBro가 IEEE 802.16e로 국제표준화 되어 수도권부터 WiBro 네트워크 사업을 수행하고 있다. 본 논문은 2008년과 2009년 7월 7일에 발생했던, 금융기관과 정부기관에 대한 DoS 공격과 DDoS 공격에 대한 연구이다. 실험실 환경에서 실제 DoS 공격 툴을 이용하여 DoS 공격과 DDoS 공격을 실시한다. DoS 공격을 탐지하기 위하여 유선과 무선 인터넷 네트워크에서 Snort를 이용한 N-IDS를 설치한다. 패킷을 탐지하기 위한 WinPcap과 패킷의 저장 및 분석하기 위한 MySQL, HSC, .NET Framework 등을 설치한다. e-Watch 등의 패킷 분석 도구를 통해 해커의 DoS 공격에 대한 패킷량과 TCP, UDP 등의 정보, Port, MAC과 IP 정보 등을 분석한다. 본 논문에서는 WiBro 네트워크에서 빈번하게 일어나는 메신저 프로그램과 VoIP를 통한 음성 및 화상 통화에 대해 도청을 실시하였다. 패킷 수집과 분석기인 Wireshark를 통해서 패킷의 도청을 실시하고 SIP, H.263, TCP, UDP 프로토콜을 바탕으로 도청자료를 재생한다. 패킷이 위변조 되지 않았다는 무결성을 시간을 기준으로 검증하여 도청된 VoIP 음성 패킷의 복사본의 시간과 패킷의 시간 그리고 X-Lite 통화 기록의 시간이 일치함을 증명하여 무결성을 검증한다. 무결성이 검증된 자료는 밀봉 봉투에 넣어서 수사 자료로서 활용하기 위해 밀봉 후에 수사관의 간인을 실시하여 법정에서의 증거자료로 사용 할 수 있도록 준비한다. 본 논문에서는 WiBro 네트워크에서 모바일 주식거래시스템에 대한 공격 실시하고, 취약점을 분석하여 침해사고를 연구한다. WiBro 네트워크에서 모바일 주식거래를 분석하기 위해, 실제 주식 거래과정을 Wireshark를 이용해 모니터링 하고 분석하여 취약점을 찾아내고 패킷을 분석하는 포렌식 자료 생성을 한다. NetScan Tools를 이용한 스캐닝을 통해 열려있는 port를 찾아내고 바이러스 침투 공격 분석, 인증패킷 분석, DDoS 네트워크 공격 분석, WiBro 모바일단말기 공격 분석, HTS 프로그램 공격 분석을 통해 취약점을 찾아내어 분석하여, 범죄수사와 법정의 자료로 활용될 수 있는 연구의 기초를 확보한다. 본 연구를 통하여 향후 휴대인터넷 이동단말의 취약점을 보완하고 보안성이 강화된 안정된 서비스를 통하여 세계에서 휴대인터넷 이동단말 서비스를 할 수 있는 국가적인 경쟁력을 갖는 계기를 마련 할 수 있을 것이다. Our country WiBro becomes international standard anger to IEEE 802.16e and you are carrying out a WiBro network business from capital regions. This paper is study regarding banking institution and DoS aggressive DDoS attack regarding government organization which occurred on 2008 and 2009 July 7th. You use a tool aggressive actual DoS, and you execute a DoS aggressive DDoS attack in laboratory environments. You install you are wire in order to detect a DoS attack N-IDS which used Snort in wireless Internet networks. You install storages of WinPcap and a packet to detect a packet and MySQL, HSC, .NET Framework to analyze etc. e-Watch etc. analyzes packet quantity regarding a DoS attack of a hacker and TCP, UDP etc. information, Port, MAC and IP information etc. through packet analysis tools. You executed a provincial office about voices and burn calls through a messenger program and the VoIP which frequently happened in WiBro networks at these papers. You execute a provincial office of a packet, and you reproduce provincial office data with bases to a SIP, H.263, TCP, UDP protocol through the Wireshark which is a packet collection and an analyzer. In time of between cities of in time of a copy of a packet negative the VoIP which you verify time with bases, and was eavesdropped on integrity packet and a X-Lite call record, be matched that a packet did not become forgery, and you demonstrate, and you verify integrity. The data which integrity was verified put in a seaming envelope, and you prepare so as it is to a liver of investigator, and you execute, and to be able to do use to proof data after seaming in courts in order to utilize as criminal investigation data. You execute an attack regarding mobile stocks transactions system in WiBro networks at these papers, and you analyze weakness, and you study an infringement accident. You generate Forensic data you use Wireshark, and monitoring calls an actual stock trading process in WiBro networks in order to analyze mobile stocks transactions, and you analyze, and you detect weakness, and analyzing a packet. You ensure a basis of study you detect port, and you detect weakness through analyses aggressive analysis aggressive viral penetration, authentication packet analysis, analysis aggressive a DDoS network, analysis aggressive a terminal mobile WiBro, a HTS program that there was in order to open through the scanning that used NetScan Tools, and you analyze, and to be able to be uesed as to criminal investigation and legal data. Preparation may do the gauge which has from now on the national competitiveness that can serve a terminal mobile the carrying Internet through the stable service that you supplement weakness of a terminal mobile the carrying Internet, and security anger was strengthened in the world through this study.
금융회사 전자금융기반시설 취약점 분석·평가 점검기준의 합리적 개선방안
김광배 고려대학교 정보보호대학원 2018 국내석사
금융회사는 전자금융거래의 안전성 및 신뢰성을 확보하기 위하여 전자금융기반시설에 대해 취약점 분석·평가를 실시하고 그 결과에 따른 필요한 보완조치의 이행계획을 수립·시행하여 전자금융기반시설에 대한 보안 취약점을 개선해 나가고 있다. 그러나 금융회사에서 전자금융기반시설 취약점 분석·평가 시 활용하는 금융분야 취약점 분석·평가 기준은 2002년도에 배포된 이후 업데이트되지 않고 있으며, 금융분야 정보공유·분석센터, 정보보호 전문서비스 기업 등 취약점 분석·평가 전문기관이 자체적으로 현행화 작업은 진행하고 있으나 표준화되어 있지 않아 금융회사에서 취약점 분석·평가 시 혼란을 야기하고 있다. 본 논문에서는 현행 전자금융기반시설 취약점 분석·평가 점검기준의 문제점에 대해 분석하고 금융회사 전자금융기반시설 특성에 맞는 합리적인 점검기준을 위한 방안과 정보보호관리체계를 활용한 보완점을 제안하였다. 또한, 금융회사 자율보안체계에 따른 취약점 분석·평가 자체 점검기준 수립사례를 제시하였다.