RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    리눅스 환경에서의 Configuration Drift 탐지 및 승인 기반 대응을 위한 보안 통제 메커니즘 연구

    한글로보기

    https://www.riss.kr/link?id=A110411637

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    본 논문은 주요정보통신기반시설 보안 기준을 리눅스 서버의 지속 관리 기준선으로 활용하기 위한 Configuration Drift 탐지 및 승인 기반 대응 시스템을 제안한다. 제안 시스템은 주요 설정 파일의 원본, 해시값, 권한, 소유자 정보를 Golden Baseline으로 저장하고, inotify 기반 실시간 감시, cron 기반 주기 해시 검사, Audit Server의 원격 교차 검사를 병행하여 Drift를 탐지한다. Drift가 확인되면 관리자는 원복, 유지, 보류 중 하나의 대응을 선택하며, 탐지와 승인 및 조치 결과는 감사 로그로 기록된다. 이를 통해 일회성 점검 중심의 보안 관리를 운영 중 지속 가능한 기준선 관리 방식으로 확장하고자 한다.
    번역하기

    본 논문은 주요정보통신기반시설 보안 기준을 리눅스 서버의 지속 관리 기준선으로 활용하기 위한 Configuration Drift 탐지 및 승인 기반 대응 시스템을 제안한다. 제안 시스템은 주요 설정 파일...

    본 논문은 주요정보통신기반시설 보안 기준을 리눅스 서버의 지속 관리 기준선으로 활용하기 위한 Configuration Drift 탐지 및 승인 기반 대응 시스템을 제안한다. 제안 시스템은 주요 설정 파일의 원본, 해시값, 권한, 소유자 정보를 Golden Baseline으로 저장하고, inotify 기반 실시간 감시, cron 기반 주기 해시 검사, Audit Server의 원격 교차 검사를 병행하여 Drift를 탐지한다. Drift가 확인되면 관리자는 원복, 유지, 보류 중 하나의 대응을 선택하며, 탐지와 승인 및 조치 결과는 감사 로그로 기록된다. 이를 통해 일회성 점검 중심의 보안 관리를 운영 중 지속 가능한 기준선 관리 방식으로 확장하고자 한다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    This paper proposes a Configuration Drift detection and approval-based response system that repurposes critical information infrastructure security standards as a continuous baseline for Linux server management. The proposed system stores the original files, hash values, permission and ownership information of key configuration files as a Golden Baseline, and detects drift by combining inotify-based real-time monitoring, cron-based periodic hash verification, and remote cross-verification on a separate audit server. When drift is detected, the administrator selects a response option among restoration, acceptance, or hold, and the detection, approval, and response results are recorded in audit logs. Through this approach, the study aims to extend one-time, assessment-oriented security management into a continuous baseline management method that is sustainable during operation.
    번역하기

    This paper proposes a Configuration Drift detection and approval-based response system that repurposes critical information infrastructure security standards as a continuous baseline for Linux server management. The proposed system stores the original...

    This paper proposes a Configuration Drift detection and approval-based response system that repurposes critical information infrastructure security standards as a continuous baseline for Linux server management. The proposed system stores the original files, hash values, permission and ownership information of key configuration files as a Golden Baseline, and detects drift by combining inotify-based real-time monitoring, cron-based periodic hash verification, and remote cross-verification on a separate audit server. When drift is detected, the administrator selects a response option among restoration, acceptance, or hold, and the detection, approval, and response results are recorded in audit logs. Through this approach, the study aims to extend one-time, assessment-oriented security management into a continuous baseline management method that is sustainable during operation.

    더보기

    목차 (Table of Contents)

    • ABSTRACT
    • 1. 서론
    • 2. 본론
    • 3. 결론
    • References
    • ABSTRACT
    • 1. 서론
    • 2. 본론
    • 3. 결론
    • References
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼