최근 스마트폰은 PC만큼 강력한 연산장치와 Wi-Fi, 3G 등의 무선통신 기술을 통해 사용자가 인터넷 기반의 정보를 더욱 효율적으로 활용할 수 있는 서비스 및 어플리케이션을 제공한다. 반면에...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=A82583342
2011
Korean
스마트폰 ; 악성코드 ; 취약점 분석 ; 윈도우 CE ; 문자메시지 ; Smartphone ; Malware ; Vulnerability Analysis ; Windows CE ; SMS
569
KCI등재
학술저널
147-156(10쪽)
1
0
상세조회0
다운로드최근 스마트폰은 PC만큼 강력한 연산장치와 Wi-Fi, 3G 등의 무선통신 기술을 통해 사용자가 인터넷 기반의 정보를 더욱 효율적으로 활용할 수 있는 서비스 및 어플리케이션을 제공한다. 반면에...
최근 스마트폰은 PC만큼 강력한 연산장치와 Wi-Fi, 3G 등의 무선통신 기술을 통해 사용자가 인터넷 기반의 정보를 더욱 효율적으로 활용할 수 있는 서비스 및 어플리케이션을 제공한다. 반면에 스마트폰에는 신용카드, 연락처, ID정보 등 PC보다 더 많은 개인 정보를 보유하고 있기 때문에 그만큼 악성코드에 의한 해킹사고에 노출될 개연성이 높다. 실제로 국내에서 Terdial과 같이 의도하지 않은 국제전화를 유도하는 모바일 악성코드가 출현한 바 있다. 본 논문에서는 윈도우 CE 커널에서 SMS 관리 기능의 취약점을 분석하고, 이를 이용한 모바일 결제 승인용 SMS 인증코드를 가로채어 금전적 손실을 유발하는 악성코드가 윈도우 모바일이 탑재된 스마트폰에 동작 가능함을 실험을 통해 보고한다. 또한 실험 분석결과를 토대로 응용프로그램 및 OS 계층에서의 스마트폰 해킹 대응방안에 대해 고찰해 본다.
다국어 초록 (Multilingual Abstract)
Recently smartphones provide a variety of Internet-based personalized services and applications with the benefit of the advanced wireless technologies such as Wi-Fi and 3G, and the advance of computation power as much as a personal computer. They nece...
Recently smartphones provide a variety of Internet-based personalized services and applications with the benefit of the advanced wireless technologies such as Wi-Fi and 3G, and the advance of computation power as much as a personal computer. They necessarily contain lots of personal information such as credit cards, contacts, personal identities for the intelligent service provisioning. However, the intensive belonging of valuable private data on the smartphone will be hacking target by the potential attackers. For example, the mobile malware called Terdial which makes unintentional international calls has been introduced. In this paper, we analyze vulnerabilities of SMS management on Windows CE kernel. Using these, we develop a potential malware that incurs financial theft by intercepting the SMS authorization code for mobile payments. Also, we propose the countermeasure against such malicious attacks at the different viewpoints of application and OS layers with thorough analysis of our experimental results.
목차 (Table of Contents)
참고문헌 (Reference)
1 KBS 뉴스, "스마트폰, 개인정보 유출 무방비"
2 김익수, "모바일 악성코드 분석 방법과 대응 방안" 한국통신학회 35 (35): 599-609, 2010
3 MBC 뉴스, "국내 스마트폰 해킹 무방비"
4 "WireShark"
5 D. Suryakant, "Windows mobile device security model"
6 "Windows CE Remote Process Viewer"
7 R. Kuster, "Three ways to inject your code into another process"
8 H. Lee, "Technology Trends on Smartphone Security" 17 (17): 61-72, 2010
9 "SSnap"
10 B. Morris, "Platform security and symbian signed: foundation for a secure platform" Symbian Developer Netwrok 2008
1 KBS 뉴스, "스마트폰, 개인정보 유출 무방비"
2 김익수, "모바일 악성코드 분석 방법과 대응 방안" 한국통신학회 35 (35): 599-609, 2010
3 MBC 뉴스, "국내 스마트폰 해킹 무방비"
4 "WireShark"
5 D. Suryakant, "Windows mobile device security model"
6 "Windows CE Remote Process Viewer"
7 R. Kuster, "Three ways to inject your code into another process"
8 H. Lee, "Technology Trends on Smartphone Security" 17 (17): 61-72, 2010
9 "SSnap"
10 B. Morris, "Platform security and symbian signed: foundation for a secure platform" Symbian Developer Netwrok 2008
11 M. Pietrek, "Peering inside the PE: A tour of the win32 portable executable file format"
12 A. Schmidt, "Malicious software for smartphones"
13 M. Becher, "Kernel-level interception and applications on windows mobile devices"
14 "IDA Pro"
15 W. Jansen, "Guidelines on cell phone and PDA security"
16 M. Thompson, "FIO43-C. Do not create temporary files in shared directories" CERT Coordination Center 2010
17 "CommView"
18 "Cellular Emulator"
19 M. Pietrek, "An in-depth look into the win32 portable executable file format, part 2"
20 M. Bishop, "A clinic for secure programming" 2010
NetVis: ns-3 기반의 무선 네트워크 시뮬레이션을 위한 시각화 도구
IEEE 802.11 무선 네트워크에서의 전송속도 이상 완화를 위한 다중 채널 프로토콜의 성능 비교
광대역 무선네트워크에서 미디어 품질 향상을 위한 우선순위 기반의 적응적 데이터 전송 기법
학술지 이력
| 연월일 | 이력구분 | 이력상세 | 등재구분 |
|---|---|---|---|
| 2014-09-01 | 등재 | 학술지 통합(기타) | |
| 2013-04-26 | 학술지명변경 | 한글명 : 정보과학회논문지 : 정보통신 </br>외국어명 : Journal of KIISE : Information Networking | ![]() |
| 2011-01-01 | 등재 | 등재학술지 유지(등재유지) | ![]() |
| 2009-01-01 | 등재 | 등재학술지 유지(등재유지) | ![]() |
| 2007-01-01 | 등재 | 등재학술지 유지(등재유지) | ![]() |
| 2005-01-01 | 등재 | 등재학술지 유지(등재유지) | ![]() |
| 2002-01-01 | 등재 | 등재학술지 선정(등재후보2차) | ![]() |