RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    사물인터넷 환경에서 침해사고 발생시 Malware에 대한 침해지표 데이터 생성 방법 = Indicators of Compromise Data Generation Method for Malware on Cyber Incident Occurrence in IoT Environments

    한글로보기

    https://www.riss.kr/link?id=A108729499

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    As cyber attacks become more intelligent and advanced, cyber attacks targeting heterogeneous systems such as Internet of Things (IoT) devices are increasing. There is a need for a technique to share detailed threat information about the incident attack. In the event of an infringement incident, a technique that can express digital forensic artifacts collected from heterogeneous IoT devices as indicators of compromise (IoC) and share them must be established. In particular, when malicious code is executed targeting various IoT devices, an efficient IoC generation method to express cyber threat information and share it among CTI systems must be presented. Therefore, in this study, the existing IoC creation method and expression method were analyzed. A classification system for generating IoC for malware and an efficient and standardized expression method were presented. Based on the proposed IoC expression and standardization method, it is expected that it will be able to actively respond to intelligent attacks when establishing an accident management framework
    번역하기

    As cyber attacks become more intelligent and advanced, cyber attacks targeting heterogeneous systems such as Internet of Things (IoT) devices are increasing. There is a need for a technique to share detailed threat information about the incident attac...

    As cyber attacks become more intelligent and advanced, cyber attacks targeting heterogeneous systems such as Internet of Things (IoT) devices are increasing. There is a need for a technique to share detailed threat information about the incident attack. In the event of an infringement incident, a technique that can express digital forensic artifacts collected from heterogeneous IoT devices as indicators of compromise (IoC) and share them must be established. In particular, when malicious code is executed targeting various IoT devices, an efficient IoC generation method to express cyber threat information and share it among CTI systems must be presented. Therefore, in this study, the existing IoC creation method and expression method were analyzed. A classification system for generating IoC for malware and an efficient and standardized expression method were presented. Based on the proposed IoC expression and standardization method, it is expected that it will be able to actively respond to intelligent attacks when establishing an accident management framework

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    사이버 공격이 지능화·고도화됨에 따라 사물인터넷(IoT) 기기 등 이기종 시스템을 대상으로 한 사이버 공격이발생하였을 경우 해당 침해사고 공격에 대한 상세 위협 정보를 공유할 수 있는 기법이 필요하다. 침해사고 발생시 이기종 IoT 기기로부터 수집된 디지털 포렌식 아티팩트를 침해지표(Indicators of Compromise : IoC)로 표현하고 이를공유할 수 있는 기법이 구축되어야 한다. 특히 각종 IoT 기기를 대상으로 악성코드가 실행될 경우 사이버 위협 정보를표현하고 CTI 시스템 간에 공유하기 위한 효율적인 침해지표 생성 방법이 제시되어야 한다. 이에 본 연구에서는 기존의침해지표 생성 방식 및 표현 방식에 대해 분석하여 Malware에 대한 침해지표 데이터를 생성하기 위한 분류체계 및효율적이고 규격화된 표현 방식을 제시하였다. 앞으로 제시된 침해지표 표현 및 규격화 방안을 토대로 사고관리 프레임워크 구축 시 지능화된 공격에 능동적으로 대응할 수 있을 것을 기대된다.
    번역하기

    사이버 공격이 지능화·고도화됨에 따라 사물인터넷(IoT) 기기 등 이기종 시스템을 대상으로 한 사이버 공격이발생하였을 경우 해당 침해사고 공격에 대한 상세 위협 정보를 공유할 수 있는 ...

    사이버 공격이 지능화·고도화됨에 따라 사물인터넷(IoT) 기기 등 이기종 시스템을 대상으로 한 사이버 공격이발생하였을 경우 해당 침해사고 공격에 대한 상세 위협 정보를 공유할 수 있는 기법이 필요하다. 침해사고 발생시 이기종 IoT 기기로부터 수집된 디지털 포렌식 아티팩트를 침해지표(Indicators of Compromise : IoC)로 표현하고 이를공유할 수 있는 기법이 구축되어야 한다. 특히 각종 IoT 기기를 대상으로 악성코드가 실행될 경우 사이버 위협 정보를표현하고 CTI 시스템 간에 공유하기 위한 효율적인 침해지표 생성 방법이 제시되어야 한다. 이에 본 연구에서는 기존의침해지표 생성 방식 및 표현 방식에 대해 분석하여 Malware에 대한 침해지표 데이터를 생성하기 위한 분류체계 및효율적이고 규격화된 표현 방식을 제시하였다. 앞으로 제시된 침해지표 표현 및 규격화 방안을 토대로 사고관리 프레임워크 구축 시 지능화된 공격에 능동적으로 대응할 수 있을 것을 기대된다.

    더보기

    참고문헌 (Reference)

    1 박정규 ; 김재호, "저 사양 IoT 장치간의 암호화 알고리즘 성능 비교" 한국사물인터넷학회 8 (8): 79-85, 2022

    2 이형우, "악성 랜섬웨어 SW에 사용된 암호화 모듈에 대한 탐지 및 식별 메커니즘" 한국사물인터넷학회 9 (9): 1-7, 2023

    3 Brown, R, "The Evolution of Cyber Threat Intelligence (CTI): 2019 SANS CTI Survey" SANS Institute 2019

    4 Burger, E. W., "Taxonomy model for cyber threat intelligence information exchange technologies" 51-60, 2017

    5 Harrington, C., "Sharing indicators of compromise : An overview of standards and formats"

    6 이형우, "SIEM 기반 사이버 침해사고 대응을 위한 데이터 보완 메커니즘 비교 분석" 한국사물인터넷학회 8 (8): 1-9, 2022

    7 C. Beaman, "Ransomware : Recent advances, analysis, challenges and future research directions" 111 : 2021

    8 "Open IOC: Back to the Basics" Mandiant

    9 S. Ghernaouti, "Information sharing in cybersecurity : Enhancing security, trust and privacy by capacity building" 58-62, 2019

    10 A. Pala, "Information sharing in cybersecurity : A review" 16 (16): 172-196, 2019

    1 박정규 ; 김재호, "저 사양 IoT 장치간의 암호화 알고리즘 성능 비교" 한국사물인터넷학회 8 (8): 79-85, 2022

    2 이형우, "악성 랜섬웨어 SW에 사용된 암호화 모듈에 대한 탐지 및 식별 메커니즘" 한국사물인터넷학회 9 (9): 1-7, 2023

    3 Brown, R, "The Evolution of Cyber Threat Intelligence (CTI): 2019 SANS CTI Survey" SANS Institute 2019

    4 Burger, E. W., "Taxonomy model for cyber threat intelligence information exchange technologies" 51-60, 2017

    5 Harrington, C., "Sharing indicators of compromise : An overview of standards and formats"

    6 이형우, "SIEM 기반 사이버 침해사고 대응을 위한 데이터 보완 메커니즘 비교 분석" 한국사물인터넷학회 8 (8): 1-9, 2022

    7 C. Beaman, "Ransomware : Recent advances, analysis, challenges and future research directions" 111 : 2021

    8 "Open IOC: Back to the Basics" Mandiant

    9 S. Ghernaouti, "Information sharing in cybersecurity : Enhancing security, trust and privacy by capacity building" 58-62, 2019

    10 A. Pala, "Information sharing in cybersecurity : A review" 16 (16): 172-196, 2019

    11 Johnson, C., "Guide to Cyber Threat Information Sharing"

    12 "FSEC, Financial Security Institute API"

    13 Wagner, T. D., "Cyber threat intelligence sharing : Survey and research directions" 87 : 1-13, 2019

    14 Mavroeidis, V., "Cyber threat intelligence model : An evaluation of taxonomies, sharing standards, and ontologies within cyber threat intelligence" 91-98, 2017

    15 "C-TAS, Cyber Threat Analysis and Sharing System"

    16 Abu, S, "An Enhancement of Cyber Threat Intelligence Framework" 10 : 96-104, 2018

    17 Maria Stoyanova, "A Survey on the Internet of Things(IoT)Forensics : Challenges, Approaches, and Open Issues" 22 (22): 1191-1221, 2020

    18 김태연 ; 한경현 ; 황성운, "A New Association Rule Mining based on Coverage and Exclusion for Network Intrusion Detection" 한국사물인터넷학회 9 (9): 77-87, 2023

    더보기

    동일학술지(권/호) 다른 논문

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼