인터넷 환경의 IT 서비스 인프라들은 항시 외부의 공격에 노출되어 있다. 그 중 취약점을 이용한 공격들은 항상 존재하였으며 앞으로도 그 빈도가 줄어들지 않을 거라는 예측은 보안을 다루...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T15650359
서울 : 숭실대학교 정보과학대학원, 2020
학위논문(석사) -- 숭실대학교 정보과학대학원 , 정보보안학과(정원) , 2020. 8
2020
한국어
서울
24 ; 26 cm
지도교수: 박재표
I804:11044-200000321025
0
상세조회0
다운로드인터넷 환경의 IT 서비스 인프라들은 항시 외부의 공격에 노출되어 있다. 그 중 취약점을 이용한 공격들은 항상 존재하였으며 앞으로도 그 빈도가 줄어들지 않을 거라는 예측은 보안을 다루...
인터넷 환경의 IT 서비스 인프라들은 항시 외부의 공격에 노출되어 있다. 그 중 취약점을 이용한 공격들은 항상 존재하였으며 앞으로도 그 빈도가 줄어들지 않을 거라는 예측은 보안을 다루는 업무를 수행하다 보면 쉽게 예측해 볼 수 있다.
취약점을 이용한 공격에 대비한 가장 효율적인 방법은 취약점을 진단하고 조치하는 것이며 조치를 취할 수 없는 상황에 환경이라면 존재하는 취약점에 대해 알고 이를 대응 할 수 있는 다른 방안을 대체 하는 것이다. 하지만 현재 많은 취약점 진단에 업무는 정보보호 컨설턴트에 의존하여 연 1-2회 많게는 3-4회 등 하나의 사업으로 수행하는 형식으로 수행 되고 있고 이는 상시 변하는 인프라 환경에서 새로 생긴 취약점, 변경된 취약점 등에 빠른 대응을 하기가 어려운 상황이다.
공격자는 취약점을 발견하면 새롭게 컨설턴트가 들어와서 진단하고 조치 할 기회를 줄만큼 자비로운 사람들이 아니기에 우리는 인프라 취약점에 대해 상시 진단하고 조치 할 수 있는 프로세스로 이러한 위협에 대응하여야 한다.
본 논문은 이러한 프로세스를 수립하는데 있어 가장 큰 역할을 할 자동화 취약점 진단 시스템에 대한 내용을 다루고 있으며 기존 진단 방법에 단점을 극복 할 수 있는 방안에 대해 설명한다.
다국어 초록 (Multilingual Abstract)
IT service infrastructures in the Internet environment are always exposed to external attacks. Among them, attacks using vulnerabilities have always existed, and predictions that the frequency will not decrease in the future can be easily predicted wh...
IT service infrastructures in the Internet environment are always exposed to external attacks. Among them, attacks using vulnerabilities have always existed, and predictions that the frequency will not decrease in the future can be easily predicted when they are engaged in security tasks.
The most efficient way to prepare for an attack using a vulnerability is to diagnose and take action on a vulnerability, and if the environment is in a situation where it can not take action, it will know about the vulnerability that exists and replace other measures to cope with it. However, the current work is performed in a form of one project, such as 1-2 times a year, 3-4 times, depending on the information security consultant, and it is difficult to respond quickly to new vulnerabilities and changed vulnerabilities in the ever-changing infrastructure environment.
As attackers are not gracious enough to give new consultants the opportunity to come in, diagnose and take action when they discover vulnerabilities, we must respond to these threats with a process that allows them to constantly diagnose and take action against infrastructure vulnerabilities.
This thesis deals with the automation vulnerability diagnosis system which will play the biggest role in establishing this process and explains the way to overcome the disadvantages of existing diagnosis method.
목차 (Table of Contents)