우리는 지금 4차 산업혁명 시대에 살고 있다. 인공 지능, 사물 인터넷, 빅 데이터, 모바일 등이 이미 주목 받기 시작했으며, 우리 생활 속 에서도 많은 부분 실 사용되고 있다. 4차 산업혁명에 ...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T15393019
용인 : 단국대학교 정보·지식재산대학원, 2019
학위논문(석사) -- 단국대학교 정보·지식재산대학원 , 정보통신학과 , 2019. 8
2019
한국어
621.382 판사항(23)
경기도
A Study on Effective Security Audit for Public Cloud Environments : Focused on Amazon Web Services
vi, 38장 : 삽화, 도표 ; 30 cm.
단국대학교 논문은 저작권에 의해 보호받습니다.
지도교수: 양재수
참고문헌: 장 36
I804:11017-000000194342
0
상세조회0
다운로드우리는 지금 4차 산업혁명 시대에 살고 있다. 인공 지능, 사물 인터넷, 빅 데이터, 모바일 등이 이미 주목 받기 시작했으며, 우리 생활 속 에서도 많은 부분 실 사용되고 있다. 4차 산업혁명에 ...
우리는 지금 4차 산업혁명 시대에 살고 있다. 인공 지능, 사물 인터넷, 빅 데이터, 모바일 등이 이미 주목 받기 시작했으며, 우리 생활 속 에서도 많은 부분 실 사용되고 있다. 4차 산업혁명에 있어 기반 기술은 단연 클라우드라 할 수 있다. 글로벌 기업뿐만 아니라 국내 기업들 또한 클라우드 전환을 가속화 하고 있다. 기존의 인프라 구성 방식은 인프라 소유 방식 이였다면, 클라우드를 사용함으로 임대 형식으로 전환되고 있으며, 비즈니스의 성패에 따라 클라우드 형태의 임대 자산을 손 쉽게 확장하거나, 축소 하는데 있어 효율적이다.
기업의 정보자산을 퍼블릭 클라우드로 전환함에 있어 정보보안의 우선 순위가 높아졌다. 기업 내부에 존재하던 정보자산을 공용공간에 위치한 상황이라고 볼 수 있으며, 그에 따른 보안의 기술과 관점이 기존 환경과는 다르게 변화하였다. 우리는 퍼블릭 클라우드의 환경보다 물리적 인프라 환경에서의 정보서비스 제공에 익숙해져 있으며, 정보보안의 기술적, 관리적 관점 또한 물리적 환경에 초점 되어있다. 하지만 퍼블릭 클라우드가 급속하게 발전한지 10년의 기간이 되지 않았고 정보보안의 기술적, 관리적 관점보다는 서비스를 빠르게 전개하고, 확장의 관점으로 발전해왔다. 따라서 개인정보를 포함한 기업의 중요정보를 퍼블릭 클라우드 환경에서 저장, 활용 하고 있는 현 시점에서는 정보보안의 중요성이 대두되는 시점이라고 할 수 있으며, 퍼블릭 클라우드 환경에 맞는 정보보안 체계를 수립해야 할 것이다.
퍼블릭 클라우드 환경에서 사용되는 각 서비스들에 대한 승인 받지 않은 자산의 생성과 변경, 삭제, 인가 받지 않은 사용자의 접근 등 오남용과 접근통제에 대한 부분은 선행 되어야 할 정보보안 체계이다.
따라서 퍼블릭 클라우드 환경에서의 효과적인 정보보안 감사방법을 주제로 연구를 진행 하였다. 효과적인 감사방법으로 퍼블릭 클라우드 환경에서 발생하는 로그를 취합하여 빠르게 조회함으로 업무의 생산성을 높이는 방안과 위협을 모니터링 할 수 있는 가시성 제공, 중요하게 모니터링이 필요한 대상에 대해 선정하는 것을 중점적으로 연구 하였다. 또한 연구 결과를 바탕으로 프로세스를 수립하고 실무에 적용하여 효과성을 검토하였다.
다국어 초록 (Multilingual Abstract)
We are now living in the era of the Fourth Industrial Revolution. Artificial intelligence, the Internet of Things, big data, mobile, etc. Many parts of our lives are also being used. In the fourth industrial revolution, the underlying technology is by...
We are now living in the era of the Fourth Industrial Revolution. Artificial intelligence, the Internet of Things, big data, mobile, etc. Many parts of our lives are also being used. In the fourth industrial revolution, the underlying technology is by far the cloud. Not only global companies but also domestic companies are speeding up their cloud transformation. If the traditional way to configure infrastructure was to own the infrastructure, the cloud is being used to convert to leasing. Rental assets in the form of the cloud can easily be expanded or scaled down depending on the success or failure of the business.
Information security has become a priority in transforming an entity's information assets into a public cloud. I'm not going to let you know what information was available information. It can be seen as a situation located in a public space, and the resulting technology and perspective of security have changed differently than in a traditional environment. We are accustomed to providing information services in physical infrastructure environments rather than in public cloud environments, and the technical and administrative view of information security is focused on the physical environment. However, it has not been 10 years since the public cloud has developed rapidly, and services have been passed on quickly rather than technical and administrative perspectives on information security, and have evolved to a perspective of expansion.
Therefore, information security is critical to the public cloud environment at a time when sensitive information, including personal information, is being stored and utilized in a public cloud environment, and information security mechanisms should be established to suit the public cloud environment.
The portion of misuse and control of unauthorized assets, such as the creation and modification of, deletion of, and access by unauthorized users for each service used in public cloud environments, is an information security framework that must precede.
Therefore, research was conducted on effective information security auditing methods in public cloud environments. As an effective audit method, we focused on how to increase productivity of our business by gathering logs from public cloud environments and quickly viewing them, providing visibility to monitor threats, and selecting targets that require critical monitoring. In addition, the effectiveness was reviewed by establishing processes and applying them to practice based on the results of the study.
목차 (Table of Contents)