RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    제로 트러스트 아키텍처 기반의 스마트홈 보안 모델에 관한 연구 = A Study on Smart Home Security Model based on Zero Trust Architecture

    한글로보기

    https://www.riss.kr/link?id=T17380590

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Recently, with the rapid proliferation of smart homes due to the advancement of Internet of Things (IoT) technology, user convenience has significantly increased, but it has simultaneously exposed users to new security threats. Conventional smart home security largely relies on the 'boundary-based security model,' which focuses on blocking external intrusions. However, this model exhibits structural vulnerabilities to threats that have already infiltrated the internal network, such as 'Lateral Movement' by attackers or infected internal devices, as demonstrated by the large-scale 'wall-pad' hacking incident in 2021. This vulnerability has been consistently pointed out in numerous preceding studies. The purpose of this study is to propose a concrete security model that applies the core principles of the global Zero Trust standard 'NIST SP 800-207' and the domestic 'Zero Trust Guideline' to the smart home environment to overcome these limitations. To this end, this research designed architectures by classifying domestic residential environments into 'In-home (single-family)' and 'Apartment Complex' types, relocating the core components of Zero Trust Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP) to fit each environment. Furthermore, three key operational procedures 'New Device Registration,' 'Dynamic Access Control,' and 'Threat Detection and Automated Isolation' were specified through flowcharts to clarify how the proposed model operates in real-world scenarios. To validate the feasibility of the proposed model, a survey was conducted with 21 information security experts. The analysis showed highly positive evaluations for 'Effectiveness of Dynamic Access Control Procedure' (Avg. 4.10) and 'Effectiveness of Multi-layered PEP Structure' (Avg. 4.00). However, concerns regarding cost and implementation realism were raised for the 'Practical Applicability of the In-home Model' (Avg. 3.62). Open-ended responses also confirmed the need for AI-based enhancements and improvements in user convenience. This study holds academic and practical significance in that it presents a concrete architecture and operational procedures by applying the abstract Zero Trust concept based on NIST standards and prior research to the specific 'smart home' environment, and validated its feasibility through an expert survey. For the future commercialization of this model, follow-up research is needed on AI-based trust evaluation algorithms and cost-effective implementation methods, as commonly suggested by prior studies and the expert survey. Keywords: Zero Trust, Smart Home Security, Zero Trust Architecture (ZTA), NIST SP 800-207, In-home Model, Apartment Complex Model
    번역하기

    Recently, with the rapid proliferation of smart homes due to the advancement of Internet of Things (IoT) technology, user convenience has significantly increased, but it has simultaneously exposed users to new security threats. Conventional smart home...

    Recently, with the rapid proliferation of smart homes due to the advancement of Internet of Things (IoT) technology, user convenience has significantly increased, but it has simultaneously exposed users to new security threats. Conventional smart home security largely relies on the 'boundary-based security model,' which focuses on blocking external intrusions. However, this model exhibits structural vulnerabilities to threats that have already infiltrated the internal network, such as 'Lateral Movement' by attackers or infected internal devices, as demonstrated by the large-scale 'wall-pad' hacking incident in 2021. This vulnerability has been consistently pointed out in numerous preceding studies. The purpose of this study is to propose a concrete security model that applies the core principles of the global Zero Trust standard 'NIST SP 800-207' and the domestic 'Zero Trust Guideline' to the smart home environment to overcome these limitations. To this end, this research designed architectures by classifying domestic residential environments into 'In-home (single-family)' and 'Apartment Complex' types, relocating the core components of Zero Trust Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP) to fit each environment. Furthermore, three key operational procedures 'New Device Registration,' 'Dynamic Access Control,' and 'Threat Detection and Automated Isolation' were specified through flowcharts to clarify how the proposed model operates in real-world scenarios. To validate the feasibility of the proposed model, a survey was conducted with 21 information security experts. The analysis showed highly positive evaluations for 'Effectiveness of Dynamic Access Control Procedure' (Avg. 4.10) and 'Effectiveness of Multi-layered PEP Structure' (Avg. 4.00). However, concerns regarding cost and implementation realism were raised for the 'Practical Applicability of the In-home Model' (Avg. 3.62). Open-ended responses also confirmed the need for AI-based enhancements and improvements in user convenience. This study holds academic and practical significance in that it presents a concrete architecture and operational procedures by applying the abstract Zero Trust concept based on NIST standards and prior research to the specific 'smart home' environment, and validated its feasibility through an expert survey. For the future commercialization of this model, follow-up research is needed on AI-based trust evaluation algorithms and cost-effective implementation methods, as commonly suggested by prior studies and the expert survey. Keywords: Zero Trust, Smart Home Security, Zero Trust Architecture (ZTA), NIST SP 800-207, In-home Model, Apartment Complex Model

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    제로 트러스트 아키텍처 기반의 스마트홈 보안 모델에 관한 연구 최근 사물인터넷(IoT) 기술의 발전으로 스마트홈 보급이 급격히 확산되 면서, 사용자의 편의성은 크게 증대되었으나 동시에 새로운 보안 위협에 노출되고 있다. 기존 스마트홈 보안은 대부분 외부의 침입을 차단하는 ' 경계 기반 보안 모델'에 의존하고 있다. 그러나 경계 기반 보안 모델은 2021년 발생한 대규모 월패드 해킹 사건처럼 내부망에 침투한 공격자의 ' 횡적 이동(Lateral Movement)'이나 악성코드에 감염된 내부 기기에는 구 조적인 취약점을 보이며, 이는 다수의 선행 연구에서도 지속적으로 지적 되어 왔다. 본 연구는 경계 기반 보안 모델의 한계를 극복하기 위해, 제로 트러스 트의 글로벌 표준인 'NIST SP 800-207'과 국내 '제로트러스트 가이드라인'의 핵심 원칙을 스마트홈 환경에 적용한 구체적인 보안 모델을 제안하 는 것을 목적으로 한다. 이를 위해 국내 주거 환경을 '댁내형'과 '단지형' 으로 구분하여, 제로 트러스트의 핵심 구성요소인 정책결정지점(PDP), 정 책시행지점(PEP), 정책정보지점(PIP)을 각 환경에 맞게 재설계한 아키텍처 를 제시하였다. 또한, 제안 모델이 실제 환경에서 동작하는 방식을 명확 히 하기 위해 '신규 기기 등록', '동적 접근 통제', '위협 탐지 및 자동 격 리'의 3가지 핵심 운영 절차를 순서도를 통해 구체화하였다. 제안 모델의 타당성을 검증하기 위해 21명의 정보보호 전문가를 대상으 로 설문조사를 수행하였다. 분석 결과, '동적 접근 통제 절차의 효과성'(평 균 4.10점)과 '다층적 PEP 구조의 효과성'(평균 4.00점) 항목에서 매우 긍 정적인 평가를 받았다. 다만, '댁내형 모델의 현실적 보급 가능성'(평균 3.62점) 항목에서는 비용 및 구현의 현실성에 대한 우려가 제기되었으며, 서술형 응답을 통해 AI 기반 고도화 및 사용자 편의성 보완의 필요성이 확인되었다. 본 연구는 추상적인 제로 트러스트 개념을 NIST 표준 및 국내외 선행 연구에 기반하여 '스마트홈'이라는 구체적인 환경에 적용한 아키텍처와 운영 절차를 제시하고, 전문가 설문을 통해 그 타당성을 입증했다는 점에 서 학술적·실용적 의의가 있다. 향후 본 모델의 상용화를 위해 선행 연구 및 전문가 설문에서 공통적으로 제안된 AI 기반 신뢰도 평가 알고리 즘과 비용 효율적인 구현 방안에 대한 후속 연구가 필요하다. 주제어 : 제로 트러스트, 스마트홈 보안, 제로 트러스트 아키텍처, NIST SP 800-207, 댁내형 모델, 단지형 모델
    번역하기

    제로 트러스트 아키텍처 기반의 스마트홈 보안 모델에 관한 연구 최근 사물인터넷(IoT) 기술의 발전으로 스마트홈 보급이 급격히 확산되 면서, 사용자의 편의성은 크게 증대되었으나 동시에 ...

    제로 트러스트 아키텍처 기반의 스마트홈 보안 모델에 관한 연구 최근 사물인터넷(IoT) 기술의 발전으로 스마트홈 보급이 급격히 확산되 면서, 사용자의 편의성은 크게 증대되었으나 동시에 새로운 보안 위협에 노출되고 있다. 기존 스마트홈 보안은 대부분 외부의 침입을 차단하는 ' 경계 기반 보안 모델'에 의존하고 있다. 그러나 경계 기반 보안 모델은 2021년 발생한 대규모 월패드 해킹 사건처럼 내부망에 침투한 공격자의 ' 횡적 이동(Lateral Movement)'이나 악성코드에 감염된 내부 기기에는 구 조적인 취약점을 보이며, 이는 다수의 선행 연구에서도 지속적으로 지적 되어 왔다. 본 연구는 경계 기반 보안 모델의 한계를 극복하기 위해, 제로 트러스 트의 글로벌 표준인 'NIST SP 800-207'과 국내 '제로트러스트 가이드라인'의 핵심 원칙을 스마트홈 환경에 적용한 구체적인 보안 모델을 제안하 는 것을 목적으로 한다. 이를 위해 국내 주거 환경을 '댁내형'과 '단지형' 으로 구분하여, 제로 트러스트의 핵심 구성요소인 정책결정지점(PDP), 정 책시행지점(PEP), 정책정보지점(PIP)을 각 환경에 맞게 재설계한 아키텍처 를 제시하였다. 또한, 제안 모델이 실제 환경에서 동작하는 방식을 명확 히 하기 위해 '신규 기기 등록', '동적 접근 통제', '위협 탐지 및 자동 격 리'의 3가지 핵심 운영 절차를 순서도를 통해 구체화하였다. 제안 모델의 타당성을 검증하기 위해 21명의 정보보호 전문가를 대상으 로 설문조사를 수행하였다. 분석 결과, '동적 접근 통제 절차의 효과성'(평 균 4.10점)과 '다층적 PEP 구조의 효과성'(평균 4.00점) 항목에서 매우 긍 정적인 평가를 받았다. 다만, '댁내형 모델의 현실적 보급 가능성'(평균 3.62점) 항목에서는 비용 및 구현의 현실성에 대한 우려가 제기되었으며, 서술형 응답을 통해 AI 기반 고도화 및 사용자 편의성 보완의 필요성이 확인되었다. 본 연구는 추상적인 제로 트러스트 개념을 NIST 표준 및 국내외 선행 연구에 기반하여 '스마트홈'이라는 구체적인 환경에 적용한 아키텍처와 운영 절차를 제시하고, 전문가 설문을 통해 그 타당성을 입증했다는 점에 서 학술적·실용적 의의가 있다. 향후 본 모델의 상용화를 위해 선행 연구 및 전문가 설문에서 공통적으로 제안된 AI 기반 신뢰도 평가 알고리 즘과 비용 효율적인 구현 방안에 대한 후속 연구가 필요하다. 주제어 : 제로 트러스트, 스마트홈 보안, 제로 트러스트 아키텍처, NIST SP 800-207, 댁내형 모델, 단지형 모델

    더보기

    목차 (Table of Contents)

    • 표목차 ⅲ
    • 그림목차 ⅳ
    • 국문초록 ⅴ
    • 제1장 서론 1
    • 제1절 연구의 배경 및 필요성 1
    • 표목차 ⅲ
    • 그림목차 ⅳ
    • 국문초록 ⅴ
    • 제1장 서론 1
    • 제1절 연구의 배경 및 필요성 1
    • 제2절 연구의 목적 및 범위 2
    • 제3절 논문의 구성 3
    • 제2장 관련 연구 4
    • 제1절 스마트홈 보안 기술 동향 4
    • 1. 스마트홈의 개념 및 구성요소 4
    • 2. 기존 스마트홈 보안 위협 사례 및 취약점 분석 5
    • 3. 최신 스마트홈 보안 기술 동향 및 한계 7
    • 제2절 기존 스마트홈 보안 연구 및 대응 방안 9
    • 1. 접근 통제 및 인증 강화 연구 9
    • 2. 네트워크 구조 개선 연구 9
    • 3. 기존 연구의 한계 9
    • 제3절 제로 트러스트 아키텍처 10
    • 1. 제로 트러스트의 개념과 핵심 원칙 10
    • 2. 제로 트러스트 가이드라인 분석 12
    • 가. 논리적 구성요소(PDP, PEP, PIP) 12
    • 나. 제로트러스트 6대 핵심 요소 14
    • 다. 제로트러스트 성숙도 모델 15
    • 제3장 제로 트러스트 기반 스마트홈 보안 모델 제안 17
    • 제1절 제안 모델의 아키텍처 17
    • 1. 댁내형 스마트홈 환경의 제로 트러스트 적용 구조 17
    • 2. 단지형 스마트홈 환경의 제로 트러스트 적용 구조 19
    • 제2절 제안 모델의 운영 절차 21
    • 1. 초기 신뢰 설정 및 신규 기기 등록 절차 21
    • 2. 동적 접근 통제 절차 22
    • 3. 위협 탐지 및 대응 절차 23
    • 제4장 제안 모델의 타당성 검증 25
    • 제1절 전문가 설문 설계 25
    • 1. 설문 목적 및 대상 선정 25
    • 2. 주요 용어 정의 25
    • 3. 설문 문항 구성 26
    • 제2절 설문 결과 분석 28
    • 1. 분석 개요 및 방법 소개 28
    • 2. 응답자 특성 분석 28
    • 3. 객관식 문항(Q1~Q5) 분석 29
    • 4. 서술형 문항(Q6) 분석 34
    • 제3절 검증 결과 요약 및 시사점 36
    • 제5장 결론 37
    • 제1절 연구 요약 및 의의 37
    • 제2절 연구의 한계 및 향후 과제 38
    • 참고문헌 40
    • 부록 41
    • ABSTRACT 45
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼