RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    이동통신망에서의 효과적인 퍼징을 위한 시나리오 기반 테스트 케이스 생성 및 분석 기술 연구 = A fuzzing scenario-based test case generation and analysis for fuzzing in the mobile communication network

    한글로보기

    https://www.riss.kr/link?id=T15549950

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    이동통신망은 전화, 메시지, 인터넷 접속을 위한 데이터 사용 등 전 세계적으로 많은 사용자들이 사용하고 있는 무선 연결 통신 체계이다. 수많은 단말기가 연결되어 있으며 자원을 할당해주고 지속적인 서비스를 제공해주는 이동통신망에 대한 사이버 공격이나 무선 통신 방해로 인한 서비스 거부 공격이 발생할 경우, 막대한 피해를 초래할 수 있다. 통신이 마비될 경우 세계적으로 재난 상황에 빠질 수 있기 때문에 이동통신망은 국가적으로 중요한 자산이고 나라마다 이동통신사업자들이 독자적인 통신망을 구축하여 서비스 하고 있기 때문에 서비스에 대한 안전성 검증이 필요하다. 하지만 실제 이동통신망은 폐쇄적이며 개인정보 유출 가능성이 존재하고 안전성 검증을 위한 이동통신 테스트 망이 따로 존재하지 않는다. 따라서 실제로 구현되어 있는 이동통신망의 코어 네트워크를 분석하고 안전성을 테스트하기는 어렵다.
    본 논문에서는 LTE의 프로토콜 Layer 1, 2에 해당하는 시그널링 계층인 AS(Access Stratum)와 Layer 3에 해당하는 NAS(Non-Access Stratum)를 분석하기 위한 시뮬레이션 환경을 구축한다. 오픈소스 기반으로 구현 가능한 OpenSDR인 srsLTE, openLTE 등의 시뮬레이션 환경은 3GPP 표준에 기반 하여 개발되었기 때문에 테스트하기에 적합하다. 따라서 실제 망을 대체하여 이동통신망 구조와 프로토콜을 분석하고 발생 가능한 보안 위협을 검증한다.
    단말기와 기지국 사이의 동기화 신호 간섭을 통한 서비스 거부 공격 시나리오를 도출하고 테스트 망을 통하여 공격 시나리오를 재현한다. NAS 계층에서 전송되는 NAS 메시지를 분석하고 단말기와 기지국간에 전송되는 메시지를 통해서 이동통신망에서 보안 위협 가능성이 있는 퍼징 테스트 케이스를 도출하고 퍼징 도구를 개발한다. 이를 기반으로 발생할 수 있는 보안 위협 시나리오를 제시한다.
    번역하기

    이동통신망은 전화, 메시지, 인터넷 접속을 위한 데이터 사용 등 전 세계적으로 많은 사용자들이 사용하고 있는 무선 연결 통신 체계이다. 수많은 단말기가 연결되어 있으며 자원을 할당해...

    이동통신망은 전화, 메시지, 인터넷 접속을 위한 데이터 사용 등 전 세계적으로 많은 사용자들이 사용하고 있는 무선 연결 통신 체계이다. 수많은 단말기가 연결되어 있으며 자원을 할당해주고 지속적인 서비스를 제공해주는 이동통신망에 대한 사이버 공격이나 무선 통신 방해로 인한 서비스 거부 공격이 발생할 경우, 막대한 피해를 초래할 수 있다. 통신이 마비될 경우 세계적으로 재난 상황에 빠질 수 있기 때문에 이동통신망은 국가적으로 중요한 자산이고 나라마다 이동통신사업자들이 독자적인 통신망을 구축하여 서비스 하고 있기 때문에 서비스에 대한 안전성 검증이 필요하다. 하지만 실제 이동통신망은 폐쇄적이며 개인정보 유출 가능성이 존재하고 안전성 검증을 위한 이동통신 테스트 망이 따로 존재하지 않는다. 따라서 실제로 구현되어 있는 이동통신망의 코어 네트워크를 분석하고 안전성을 테스트하기는 어렵다.
    본 논문에서는 LTE의 프로토콜 Layer 1, 2에 해당하는 시그널링 계층인 AS(Access Stratum)와 Layer 3에 해당하는 NAS(Non-Access Stratum)를 분석하기 위한 시뮬레이션 환경을 구축한다. 오픈소스 기반으로 구현 가능한 OpenSDR인 srsLTE, openLTE 등의 시뮬레이션 환경은 3GPP 표준에 기반 하여 개발되었기 때문에 테스트하기에 적합하다. 따라서 실제 망을 대체하여 이동통신망 구조와 프로토콜을 분석하고 발생 가능한 보안 위협을 검증한다.
    단말기와 기지국 사이의 동기화 신호 간섭을 통한 서비스 거부 공격 시나리오를 도출하고 테스트 망을 통하여 공격 시나리오를 재현한다. NAS 계층에서 전송되는 NAS 메시지를 분석하고 단말기와 기지국간에 전송되는 메시지를 통해서 이동통신망에서 보안 위협 가능성이 있는 퍼징 테스트 케이스를 도출하고 퍼징 도구를 개발한다. 이를 기반으로 발생할 수 있는 보안 위협 시나리오를 제시한다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    The mobile network is a wireless connectivity communication system used by many users around the world, including the use of data for phone calls, messages and Internet access. A cyber attack or denial-of-service attack on a mobile network that has a large number of handsets connected and that allocates resources and provides continuous service can cause enormous damage. Because mobile network is an important asset for the country and mobile network operators establish and service their own communication network in each country, safety verification of service is needed. However, actual mobile network is closed and there is a possibility of personal information leakage and there are no separate test networks for safety verification. Therefore, it is difficult to analyze the core network of the mobile network that is actually implemented and test the safety.
    In this paper, the simulation environment is established for analyzing the signaling layer corresponding to LTE's protocols Layer 1 and 2, AS(Access Stratum), and NAS(Non-Access Stratum) corresponding to Layer 3. Simulation environments such as srsLTE and openLTE, which are open-source-based implementations, are suitable for testing because they are developed based on 3GPP standards. Thus, it analyzes the structure and protocols of the mobile network and validates possible security threats by replacing the actual network.
    Derives a denial-of-service attack scenario through interference of the synchronization signal between the terminal and base station and reproduces the attack scenario through the test network. Analyze NAS messages sent from the NAS layer and derive a potential security-threatening purging test case from the mobile network through messages sent between terminals and base stations and develop a fuzzing tool. Based on this, it presents a possible threat scenario.
    번역하기

    The mobile network is a wireless connectivity communication system used by many users around the world, including the use of data for phone calls, messages and Internet access. A cyber attack or denial-of-service attack on a mobile network that has a ...

    The mobile network is a wireless connectivity communication system used by many users around the world, including the use of data for phone calls, messages and Internet access. A cyber attack or denial-of-service attack on a mobile network that has a large number of handsets connected and that allocates resources and provides continuous service can cause enormous damage. Because mobile network is an important asset for the country and mobile network operators establish and service their own communication network in each country, safety verification of service is needed. However, actual mobile network is closed and there is a possibility of personal information leakage and there are no separate test networks for safety verification. Therefore, it is difficult to analyze the core network of the mobile network that is actually implemented and test the safety.
    In this paper, the simulation environment is established for analyzing the signaling layer corresponding to LTE's protocols Layer 1 and 2, AS(Access Stratum), and NAS(Non-Access Stratum) corresponding to Layer 3. Simulation environments such as srsLTE and openLTE, which are open-source-based implementations, are suitable for testing because they are developed based on 3GPP standards. Thus, it analyzes the structure and protocols of the mobile network and validates possible security threats by replacing the actual network.
    Derives a denial-of-service attack scenario through interference of the synchronization signal between the terminal and base station and reproduces the attack scenario through the test network. Analyze NAS messages sent from the NAS layer and derive a potential security-threatening purging test case from the mobile network through messages sent between terminals and base stations and develop a fuzzing tool. Based on this, it presents a possible threat scenario.

    더보기

    목차 (Table of Contents)

    • 제 1 장 서론 1
    • 제 2 장 이동통신망 구조 및 프로토콜 분석 4
    • 제 1 절 AS(Access-Stratum) 계층 분석 6
    • 1. PHY Layer 7
    • 2. MAC Layer 11
    • 제 1 장 서론 1
    • 제 2 장 이동통신망 구조 및 프로토콜 분석 4
    • 제 1 절 AS(Access-Stratum) 계층 분석 6
    • 1. PHY Layer 7
    • 2. MAC Layer 11
    • 제 2 절 NAS(Non-Access Stratum) 계층 분석 15
    • 1. NAS 메시지 구조 분석 17
    • 제 3 장 AS 계층 보안 위협 분석 20
    • 제 1 절 테스트 환경 구축 및 보안 위협 분석 20
    • 1. srsLTE를 통한 테스트 환경 구축 21
    • 2. 주파수 측정을 통한 동기화 신호 확인 24
    • 제 2 절 시그널링 계층 보안 위협 시나리오 29
    • 1. PSS/SSS 동기화 신호 발생 조건 29
    • 제 3 절 신호 간섭을 통한 서비스 거부 보안 위협 테스트 34
    • 1. 이동통신 테스트 망 34
    • 2. 시그널링 계층 보안 위협 가능성 테스트 35
    • 제 4 절 신호 간섭 테스트 요구 사항 도출 41
    • 1. 테스트 요구 사항 41
    • 2. 신호 간섭 테스트 요구사항 평가 42
    • 제 4 장 NAS 계층 보안 위협 분석 44
    • 제 1 절 GSM/LTE 테스트 망 구축 44
    • 1. OpenLTE를 통한 LTE 테스트 망 구축 44
    • 제 2 절 NAS 메시지 보안 위협 가능성 52
    • 1. NAS 메시지 퍼징 테스트 케이스 도출 52
    • 2. GSM NAS 메시지 퍼징 테스트 케이스 53
    • 3. LTE NAS 메시지 퍼징 테스트 케이스 55
    • 제 3 절 NAS 메시지 퍼징 도구 개발 57
    • 1. OpenBTS를 통한 NAS 메시지 퍼징 도구 개발 57
    • 2. OpenLTE를 통한 NAS 메시지 퍼징 도구 개발 59
    • 3. 기존 연구와 비교 분석 62
    • 제 5 장 결론 64
    • 참고문헌
    • 부록.색인
    • 영문요약
    • 감사의글
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼