RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    사이버 해킹 및 테러 공격 대응을 위한 논리적 망분리 기법 = A Logical Network Partition Scheme for Cyber Hacking and Terror Attacks

    한글로보기

    https://www.riss.kr/link?id=A60018257

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    인터넷의 급속한 발달로 빈번히 발생하고 있는 해킹 및 악성프로그램과 같은 사이버 공격으로 부터 중요 정보를 보호하기 위한 망분리 기술이 요구되고 있다. 망분리에는 외부와 내부망을 물리적으로 분리하는 물리적 망분리와 가상화를 이용하여 분리하는 논리적 망분리가 있다. 물리적 망분리는 망구축 및 유지비용이 높으며, 논리적 망분리는 보안 신뢰성이 낮다. 본 논문에서는 트래픽 유형 분석을 통해 물리적이 아닌 논리적(가상적)으로 망을 분리하는 논리적 망분리(Logical Network Partition, LNP)기법을 제안한다. LNP는 실시간 트래픽 분석으로 공격 트래픽 탐지, 공격 트래픽의 경로 차단과 우회경로를 제공하는 망분리, 공격 트래픽 해결 후 경로 복구와 우회경로를 차단하는 망분리 해제를 수행한다. 따라서 LNP는 트래픽을 식별하여 공격의 위협으로부터 중요하게 유지되어야 하는 망을 보호하여 망의 안전성과 높은 보안 신뢰성을 제공해준다.
    번역하기

    인터넷의 급속한 발달로 빈번히 발생하고 있는 해킹 및 악성프로그램과 같은 사이버 공격으로 부터 중요 정보를 보호하기 위한 망분리 기술이 요구되고 있다. 망분리에는 외부와 내부망을 ...

    인터넷의 급속한 발달로 빈번히 발생하고 있는 해킹 및 악성프로그램과 같은 사이버 공격으로 부터 중요 정보를 보호하기 위한 망분리 기술이 요구되고 있다. 망분리에는 외부와 내부망을 물리적으로 분리하는 물리적 망분리와 가상화를 이용하여 분리하는 논리적 망분리가 있다. 물리적 망분리는 망구축 및 유지비용이 높으며, 논리적 망분리는 보안 신뢰성이 낮다. 본 논문에서는 트래픽 유형 분석을 통해 물리적이 아닌 논리적(가상적)으로 망을 분리하는 논리적 망분리(Logical Network Partition, LNP)기법을 제안한다. LNP는 실시간 트래픽 분석으로 공격 트래픽 탐지, 공격 트래픽의 경로 차단과 우회경로를 제공하는 망분리, 공격 트래픽 해결 후 경로 복구와 우회경로를 차단하는 망분리 해제를 수행한다. 따라서 LNP는 트래픽을 식별하여 공격의 위협으로부터 중요하게 유지되어야 하는 망을 보호하여 망의 안전성과 높은 보안 신뢰성을 제공해준다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Network Partition technology is required to protect major information from the cyber attacks such as hacking and malignant program that occurs frequently due to the rapid development of the internet. There are a physical network partition which physically separates the internet network from the business network and a logical network partition which separates by using a virtualization. The physical network partition is very expensive in establishing of network and cost of maintenance. The logical network partition has little reliability of security. In this paper, we suggest the Logical Network Partition scheme which separates logically network, but not physically, through analyzing a type of traffic. LNP performs detection of the attack traffic with analyzing the type of attack in real time, the network partition that offers the detour route as well as blocks the route of the attack traffic and removing of the network partition that blocks a detour route and a route restoration after removing the attack traffic. Therefore, LNP offers high security reliability and network safety by protecting the network that have to be maintained virtually from threat of attack by distinguishing the traffic.
    번역하기

    Network Partition technology is required to protect major information from the cyber attacks such as hacking and malignant program that occurs frequently due to the rapid development of the internet. There are a physical network partition which physic...

    Network Partition technology is required to protect major information from the cyber attacks such as hacking and malignant program that occurs frequently due to the rapid development of the internet. There are a physical network partition which physically separates the internet network from the business network and a logical network partition which separates by using a virtualization. The physical network partition is very expensive in establishing of network and cost of maintenance. The logical network partition has little reliability of security. In this paper, we suggest the Logical Network Partition scheme which separates logically network, but not physically, through analyzing a type of traffic. LNP performs detection of the attack traffic with analyzing the type of attack in real time, the network partition that offers the detour route as well as blocks the route of the attack traffic and removing of the network partition that blocks a detour route and a route restoration after removing the attack traffic. Therefore, LNP offers high security reliability and network safety by protecting the network that have to be maintained virtually from threat of attack by distinguishing the traffic.

    더보기

    목차 (Table of Contents)

    • 요약
    • Abstract
    • 1. 서론
    • 2. 관련 연구
    • 3. 제안하는 논리적 망분리(Logical Network Partition, LNP)
    • 요약
    • Abstract
    • 1. 서론
    • 2. 관련 연구
    • 3. 제안하는 논리적 망분리(Logical Network Partition, LNP)
    • 4. 기존 망분리 기술과 LNP 기법 비교분석
    • 6. 결론
    • 참고문헌
    더보기

    참고문헌 (Reference)

    1 Samuel T. King, "SubVirt: Implementing Malware with Virtual Machines" 2006

    2 S. Banerjee, "Order-P: An Algorithm To Order Network Partitionings" 1 : 432-436, 1992

    3 NIS, "National Information Security White Paper" National Intelligence Service 2009

    4 National Cyber ​​Security Center, "National Cyber ​​Security Manual"

    5 J.S. Moon, "Cyber ​​Terrorism Trends and Countermeasures" 20 (20): 21-27, 2010

    6 NETAN, "Cyber Crime Classification" Cyber ​​Terror Response Center 2007

    7 Kuhl M.E, "Cyber Attack Modeling and Simulation for Network Security Analysis" (Winter) : 1180-1188, 2007

    8 C.Y. An, "Comparison of Vitualization Method" 35 (35): 446-450, 2008

    9 E.B. Lee, "A Study on Information Security of Network Partition Based" 20 (20): 39-46, 2010

    10 Guangda Lai, "A Service Based Lightweight Desktop Virtualization System" 277-282, 2010

    1 Samuel T. King, "SubVirt: Implementing Malware with Virtual Machines" 2006

    2 S. Banerjee, "Order-P: An Algorithm To Order Network Partitionings" 1 : 432-436, 1992

    3 NIS, "National Information Security White Paper" National Intelligence Service 2009

    4 National Cyber ​​Security Center, "National Cyber ​​Security Manual"

    5 J.S. Moon, "Cyber ​​Terrorism Trends and Countermeasures" 20 (20): 21-27, 2010

    6 NETAN, "Cyber Crime Classification" Cyber ​​Terror Response Center 2007

    7 Kuhl M.E, "Cyber Attack Modeling and Simulation for Network Security Analysis" (Winter) : 1180-1188, 2007

    8 C.Y. An, "Comparison of Vitualization Method" 35 (35): 446-450, 2008

    9 E.B. Lee, "A Study on Information Security of Network Partition Based" 20 (20): 39-46, 2010

    10 Guangda Lai, "A Service Based Lightweight Desktop Virtualization System" 277-282, 2010

    더보기

    동일학술지(권/호) 다른 논문

    동일학술지 더보기

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    인용정보 인용지수 설명보기

    학술지 이력

    학술지 이력
    연월일 이력구분 이력상세 등재구분
    2014-09-01 등재 학술지 통합(기타)
    2013-04-26 학술지명변경 한글명 : 정보과학회논문지 : 정보통신 </br>외국어명 : Journal of KIISE : Information Networking KCI등재
    2011-01-01 등재 등재학술지 유지(등재유지) KCI등재
    2009-01-01 등재 등재학술지 유지(등재유지) KCI등재
    2007-01-01 등재 등재학술지 유지(등재유지) KCI등재
    2005-01-01 등재 등재학술지 유지(등재유지) KCI등재
    2002-01-01 등재 등재학술지 선정(등재후보2차) KCI등재
    더보기

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼