본 연구는 클라우드 환경에서 실시간 조건에 최적화된 보안 검사 정책 (Policy)을 AI 기반으로 자동 생성·실행하는 동적 보안 점검 프레임워크를 제안한다. 기존 보안 도구는 자동화 수준이 제...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17282054
서울 : 건국대학교 정보통신대학원, 2025
학위논문(석사) -- 건국대학교 정보통신대학원 , 정보보안학과 , 2025. 8
2025
한국어
동적 스크립트 ; 클라우드 보안 자동화 ; AI
서울
50 ; 26 cm
지도교수: 남기효
I804:11004-200000891806
0
상세조회0
다운로드본 연구는 클라우드 환경에서 실시간 조건에 최적화된 보안 검사 정책 (Policy)을 AI 기반으로 자동 생성·실행하는 동적 보안 점검 프레임워크를 제안한다. 기존 보안 도구는 자동화 수준이 제...
본 연구는 클라우드 환경에서 실시간 조건에 최적화된 보안 검사 정책 (Policy)을 AI 기반으로 자동 생성·실행하는 동적 보안 점검 프레임워크를 제안한다. 기존 보안 도구는 자동화 수준이 제한적이며, 변화가 잦은 클 라우드 시스템 구성에 민감하게 대응하지 못해 전문가의 수동 개입이 필 요하고, 이는 응답 지연과 취약점 누락의 주요 원인이 된다. 이를 해결하 기 위해, 제안된 프레임워크는 클라우드 자원에서 실시간 로그 및 구성을 수집하고, AI 분석을 통해 동적으로 위협을 판단하며, 자동으로 보안 점검 정책을 생성·실행한다. 특히, MITRE ATT&CK 프레임워크를 기반으로 한 위협 탐지 체계와 자 동 대응 로직을 통합함으로써, 공격자의 행위 기반 탐지를 체계화하고 대 응 정확도를 높였다. 또한 자동 생성된 정책에 대해 디지털 서명 검증 및 샌드박스 테스트를 수행하여 2차 보안 위협(예: 공급망 공격)에도 대응할 수 있는 구조를 갖추었다. 본 연구는 정적 보안 도구의 한계를 극복하고, 클라우드 네이티브 환경 에서 적용 가능한 AI 기반 정책 자동화 시스템으로써 학술적·실무적 기 여를 목표로 한다.
This study proposes an AI-based dynamic security policy automation and inspection framework optimized for real-time conditions in cloud environments. Traditional security tools often lack sufficient automation capabilities and fail to adapt to the highly dynamic nature of cloud systems, leading to delayed responses and overlooked vulnerabilities due to the need for expert intervention.
The proposed framework addresses these limitations by collecting real-time logs and configuration data from various cloud resources, analyzing potential threats using AI models, and dynamically generating and executing security policies tailored to the environment.
In particular, the framework incorporates the MITRE ATT&CK framework to structure threat detection based on attacker behavior patterns, improving the accuracy and consistency of detection and response. Furthermore, the system integrates digital signature verification and sandbox testing to defend against secondary security threats, such as supply chain attacks during the policy generation and deployment processes.
By overcoming the limitations of static tools, this research presents a flexible, adaptive, and practical security automation system for cloud-native environments, contributing to both academic and real-world security operations.
목차 (Table of Contents)