RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    퍼블릭 클라우드 환경의 효과적인 보안 감사방법에 대한 연구 : 아마존 웹 서비스를 중심으로

    한글로보기

    https://www.riss.kr/link?id=T15393019

    • 저자
    • 발행사항

      용인 : 단국대학교 정보·지식재산대학원, 2019

    • 학위논문사항
    • 발행연도

      2019

    • 작성언어

      한국어

    • DDC

      621.382 판사항(23)

    • 발행국(도시)

      경기도

    • 기타서명

      A Study on Effective Security Audit for Public Cloud Environments : Focused on Amazon Web Services

    • 형태사항

      vi, 38장 : 삽화, 도표 ; 30 cm.

    • 일반주기명

      단국대학교 논문은 저작권에 의해 보호받습니다.
      지도교수: 양재수
      참고문헌: 장 36

    • UCI식별코드

      I804:11017-000000194342

    • 소장기관
      • 국립중앙도서관 국립중앙도서관 우편복사 서비스
      • 단국대학교 율곡기념도서관(천안) 소장기관정보
      • 단국대학교 퇴계기념도서관(중앙도서관) 소장기관정보
    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    우리는 지금 4차 산업혁명 시대에 살고 있다. 인공 지능, 사물 인터넷, 빅 데이터, 모바일 등이 이미 주목 받기 시작했으며, 우리 생활 속 에서도 많은 부분 실 사용되고 있다. 4차 산업혁명에 있어 기반 기술은 단연 클라우드라 할 수 있다. 글로벌 기업뿐만 아니라 국내 기업들 또한 클라우드 전환을 가속화 하고 있다. 기존의 인프라 구성 방식은 인프라 소유 방식 이였다면, 클라우드를 사용함으로 임대 형식으로 전환되고 있으며, 비즈니스의 성패에 따라 클라우드 형태의 임대 자산을 손 쉽게 확장하거나, 축소 하는데 있어 효율적이다.
    기업의 정보자산을 퍼블릭 클라우드로 전환함에 있어 정보보안의 우선 순위가 높아졌다. 기업 내부에 존재하던 정보자산을 공용공간에 위치한 상황이라고 볼 수 있으며, 그에 따른 보안의 기술과 관점이 기존 환경과는 다르게 변화하였다. 우리는 퍼블릭 클라우드의 환경보다 물리적 인프라 환경에서의 정보서비스 제공에 익숙해져 있으며, 정보보안의 기술적, 관리적 관점 또한 물리적 환경에 초점 되어있다. 하지만 퍼블릭 클라우드가 급속하게 발전한지 10년의 기간이 되지 않았고 정보보안의 기술적, 관리적 관점보다는 서비스를 빠르게 전개하고, 확장의 관점으로 발전해왔다. 따라서 개인정보를 포함한 기업의 중요정보를 퍼블릭 클라우드 환경에서 저장, 활용 하고 있는 현 시점에서는 정보보안의 중요성이 대두되는 시점이라고 할 수 있으며, 퍼블릭 클라우드 환경에 맞는 정보보안 체계를 수립해야 할 것이다.
    퍼블릭 클라우드 환경에서 사용되는 각 서비스들에 대한 승인 받지 않은 자산의 생성과 변경, 삭제, 인가 받지 않은 사용자의 접근 등 오남용과 접근통제에 대한 부분은 선행 되어야 할 정보보안 체계이다.
    따라서 퍼블릭 클라우드 환경에서의 효과적인 정보보안 감사방법을 주제로 연구를 진행 하였다. 효과적인 감사방법으로 퍼블릭 클라우드 환경에서 발생하는 로그를 취합하여 빠르게 조회함으로 업무의 생산성을 높이는 방안과 위협을 모니터링 할 수 있는 가시성 제공, 중요하게 모니터링이 필요한 대상에 대해 선정하는 것을 중점적으로 연구 하였다. 또한 연구 결과를 바탕으로 프로세스를 수립하고 실무에 적용하여 효과성을 검토하였다.
    번역하기

    우리는 지금 4차 산업혁명 시대에 살고 있다. 인공 지능, 사물 인터넷, 빅 데이터, 모바일 등이 이미 주목 받기 시작했으며, 우리 생활 속 에서도 많은 부분 실 사용되고 있다. 4차 산업혁명에 ...

    우리는 지금 4차 산업혁명 시대에 살고 있다. 인공 지능, 사물 인터넷, 빅 데이터, 모바일 등이 이미 주목 받기 시작했으며, 우리 생활 속 에서도 많은 부분 실 사용되고 있다. 4차 산업혁명에 있어 기반 기술은 단연 클라우드라 할 수 있다. 글로벌 기업뿐만 아니라 국내 기업들 또한 클라우드 전환을 가속화 하고 있다. 기존의 인프라 구성 방식은 인프라 소유 방식 이였다면, 클라우드를 사용함으로 임대 형식으로 전환되고 있으며, 비즈니스의 성패에 따라 클라우드 형태의 임대 자산을 손 쉽게 확장하거나, 축소 하는데 있어 효율적이다.
    기업의 정보자산을 퍼블릭 클라우드로 전환함에 있어 정보보안의 우선 순위가 높아졌다. 기업 내부에 존재하던 정보자산을 공용공간에 위치한 상황이라고 볼 수 있으며, 그에 따른 보안의 기술과 관점이 기존 환경과는 다르게 변화하였다. 우리는 퍼블릭 클라우드의 환경보다 물리적 인프라 환경에서의 정보서비스 제공에 익숙해져 있으며, 정보보안의 기술적, 관리적 관점 또한 물리적 환경에 초점 되어있다. 하지만 퍼블릭 클라우드가 급속하게 발전한지 10년의 기간이 되지 않았고 정보보안의 기술적, 관리적 관점보다는 서비스를 빠르게 전개하고, 확장의 관점으로 발전해왔다. 따라서 개인정보를 포함한 기업의 중요정보를 퍼블릭 클라우드 환경에서 저장, 활용 하고 있는 현 시점에서는 정보보안의 중요성이 대두되는 시점이라고 할 수 있으며, 퍼블릭 클라우드 환경에 맞는 정보보안 체계를 수립해야 할 것이다.
    퍼블릭 클라우드 환경에서 사용되는 각 서비스들에 대한 승인 받지 않은 자산의 생성과 변경, 삭제, 인가 받지 않은 사용자의 접근 등 오남용과 접근통제에 대한 부분은 선행 되어야 할 정보보안 체계이다.
    따라서 퍼블릭 클라우드 환경에서의 효과적인 정보보안 감사방법을 주제로 연구를 진행 하였다. 효과적인 감사방법으로 퍼블릭 클라우드 환경에서 발생하는 로그를 취합하여 빠르게 조회함으로 업무의 생산성을 높이는 방안과 위협을 모니터링 할 수 있는 가시성 제공, 중요하게 모니터링이 필요한 대상에 대해 선정하는 것을 중점적으로 연구 하였다. 또한 연구 결과를 바탕으로 프로세스를 수립하고 실무에 적용하여 효과성을 검토하였다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    We are now living in the era of the Fourth Industrial Revolution. Artificial intelligence, the Internet of Things, big data, mobile, etc. Many parts of our lives are also being used. In the fourth industrial revolution, the underlying technology is by far the cloud. Not only global companies but also domestic companies are speeding up their cloud transformation. If the traditional way to configure infrastructure was to own the infrastructure, the cloud is being used to convert to leasing. Rental assets in the form of the cloud can easily be expanded or scaled down depending on the success or failure of the business.
    Information security has become a priority in transforming an entity's information assets into a public cloud. I'm not going to let you know what information was available information. It can be seen as a situation located in a public space, and the resulting technology and perspective of security have changed differently than in a traditional environment. We are accustomed to providing information services in physical infrastructure environments rather than in public cloud environments, and the technical and administrative view of information security is focused on the physical environment. However, it has not been 10 years since the public cloud has developed rapidly, and services have been passed on quickly rather than technical and administrative perspectives on information security, and have evolved to a perspective of expansion.
    Therefore, information security is critical to the public cloud environment at a time when sensitive information, including personal information, is being stored and utilized in a public cloud environment, and information security mechanisms should be established to suit the public cloud environment.
    The portion of misuse and control of unauthorized assets, such as the creation and modification of, deletion of, and access by unauthorized users for each service used in public cloud environments, is an information security framework that must precede.
    Therefore, research was conducted on effective information security auditing methods in public cloud environments. As an effective audit method, we focused on how to increase productivity of our business by gathering logs from public cloud environments and quickly viewing them, providing visibility to monitor threats, and selecting targets that require critical monitoring. In addition, the effectiveness was reviewed by establishing processes and applying them to practice based on the results of the study.
    번역하기

    We are now living in the era of the Fourth Industrial Revolution. Artificial intelligence, the Internet of Things, big data, mobile, etc. Many parts of our lives are also being used. In the fourth industrial revolution, the underlying technology is by...

    We are now living in the era of the Fourth Industrial Revolution. Artificial intelligence, the Internet of Things, big data, mobile, etc. Many parts of our lives are also being used. In the fourth industrial revolution, the underlying technology is by far the cloud. Not only global companies but also domestic companies are speeding up their cloud transformation. If the traditional way to configure infrastructure was to own the infrastructure, the cloud is being used to convert to leasing. Rental assets in the form of the cloud can easily be expanded or scaled down depending on the success or failure of the business.
    Information security has become a priority in transforming an entity's information assets into a public cloud. I'm not going to let you know what information was available information. It can be seen as a situation located in a public space, and the resulting technology and perspective of security have changed differently than in a traditional environment. We are accustomed to providing information services in physical infrastructure environments rather than in public cloud environments, and the technical and administrative view of information security is focused on the physical environment. However, it has not been 10 years since the public cloud has developed rapidly, and services have been passed on quickly rather than technical and administrative perspectives on information security, and have evolved to a perspective of expansion.
    Therefore, information security is critical to the public cloud environment at a time when sensitive information, including personal information, is being stored and utilized in a public cloud environment, and information security mechanisms should be established to suit the public cloud environment.
    The portion of misuse and control of unauthorized assets, such as the creation and modification of, deletion of, and access by unauthorized users for each service used in public cloud environments, is an information security framework that must precede.
    Therefore, research was conducted on effective information security auditing methods in public cloud environments. As an effective audit method, we focused on how to increase productivity of our business by gathering logs from public cloud environments and quickly viewing them, providing visibility to monitor threats, and selecting targets that require critical monitoring. In addition, the effectiveness was reviewed by establishing processes and applying them to practice based on the results of the study.

    더보기

    목차 (Table of Contents)

    • 국문요약 ⅰ
    • 표 목 차 Ⅴ
    • 그림목차 ⅵ
    • Ⅰ. 서론 1
    • 국문요약 ⅰ
    • 표 목 차 Ⅴ
    • 그림목차 ⅵ
    • Ⅰ. 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구 방법 3
    • Ⅱ. 퍼블릭 클라우드 환경에서의 보안 현황 4
    • 2.1 퍼블릭 클라우드 개념 및 특징 4
    • 2.2 클라우드 환경에서의 보안 위협 4
    • 2.3 클라우드 환경의 보안 규제 9
    • 2.4 페이스북 개인정보 유출 사건 11
    • 2.5 유니버설 뮤직 그룹 정보자산 유출 사건 11
    • Ⅲ. 퍼블릭 클라우드의 형태와 보안감사 방안 12
    • 3.1 퍼블릭 클라우드 환경에서의 서비스 구성 형태 12
    • 3.2 퍼블릭 클라우드 환경의 보안감사 기능 14
    • Ⅳ. 보안감사 및 위협탐지의 자동화 구현 19
    • 4.1 Cloudtrail을 활용한 보안 규제 준수 및 위협 모니터링 19
    • 4.2 Cloudtrail의 기존 감사 형태 26
    • 4.3 Cloudtrail의 실시간 감사의 중요성 26
    • 4.4 Cloudtrail의 실시간 모니터링 구성 27
    • 4.5 모니터링 대시보드의 구현 구현 32
    • Ⅵ. 결론 35
    • 참고문헌 36
    • Abstract 37
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼