Pixhawk 등의 오픈소스 기반 드론 플랫폼은 높은 유연성과 확장성을 바탕으로 다양한 산업에서 연구 목적으로 널리 활용되고 있다. 그러나, 오픈소스 프로젝트는 태생적으로 알려진 보안 취약...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17372465
서울 : 국민대학교 일반대학원, 2025
학위논문(석사) -- 국민대학교 일반대학원 , 정보융합보안전공 , 2026. 2
2025
한국어
드론 ; SBOM ; 펌웨어 ; 오픈소스 ; Opensource ; Drone ; Vulnerability ; SBOM
서울
iv, 72 ; 26 cm
지도교수: 이옥연
I804:11014-200000960231
0
상세조회0
다운로드Pixhawk 등의 오픈소스 기반 드론 플랫폼은 높은 유연성과 확장성을 바탕으로 다양한 산업에서 연구 목적으로 널리 활용되고 있다. 그러나, 오픈소스 프로젝트는 태생적으로 알려진 보안 취약...
Pixhawk 등의 오픈소스 기반 드론 플랫폼은 높은 유연성과 확장성을 바탕으로 다양한 산업에서 연구 목적으로 널리 활용되고 있다. 그러나, 오픈소스 프로젝트는 태생적으로 알려진 보안 취약점이 존재 할 가능성이 높으므로 이러한 취약점을 악용한 공격을 완전히 벗어나기 어렵고 최종적으로는 사용자의 안전과 드론에 대한 신뢰성을 위협할 수 있다. 특히, 일반적인 소스코드 및 SBOM(Software Bill of Materials) 기반 취약점 검증 방식을 적용하기에는 드론 펌웨어의 모놀리식 구조와 오픈소스 드론 프로 젝트의 라이선스 정책상 소스코드 공개가 의무가 아니라는 점이 더해져 효율적인 검증이 불가능하다는 한계가 존재한다. 본 논문은 NIST 데이터베이스에 등재된 PX4-Autopilot 프로젝트의 CVE-2024-40427 취약점을 대상으로 SITL 환경에서 DoS(Denial of Service) 공격을 실증 시험하였으며, 소스코드가 아닌 펌웨어 빌드 과정에서 생성되는 부가적인 자료들로부터 SBOM 데이터를 추출, 검증기관이나 구매기관이 신뢰성 있게 오픈소스 드론 펌웨어의 취약점을 체계적으로 검증할 수 있는 프레임워크를 제안한다.
다국어 초록 (Multilingual Abstract)
Open-source drone platforms, such as Pixhawk, are widely utilized for various industrial and research purposes due to their high flexibility and scalability. However, the nature of open-source projects often entails the presence of known security vuln...
Open-source drone platforms, such as Pixhawk, are widely utilized for various industrial and research purposes due to their high flexibility and scalability. However, the nature of open-source projects often entails the presence of known security vulnerabilities, which, if exploited, can compromise user safety and undermine trust in the drone systems. In particular, applying conventional source code and SBOM(Software Bill of Materials)-based vulnerability verification approaches is often ineffective due to the monolithic structure of drone firmware and the fact that open-source drone project licenses do not mandate source code disclosure. This paper conducts a practical demonstration of a Denial of Service (DoS) attack in a SITL (Software-in-the-Loop) environment, targeting the CVE-2024-40427 vulnerability reported in the NIST database for the PX4-Autopilot project. Furthermore, it proposes a verification framework that allows certification and purchasing agencies to systematically and reliably assess vulnerabilities in open-source drone firmware by extracting SBOM data not from source code, but from auxiliary artifacts generated during the firmware build process.
목차 (Table of Contents)