RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    윈도우 CE 기반 스마트폰의 SMS 관리 취약점 분석 = Vulnerability Analysis of SMS Management for Windows CE Operating Smartphones

    한글로보기

    https://www.riss.kr/link?id=A82583342

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    최근 스마트폰은 PC만큼 강력한 연산장치와 Wi-Fi, 3G 등의 무선통신 기술을 통해 사용자가 인터넷 기반의 정보를 더욱 효율적으로 활용할 수 있는 서비스 및 어플리케이션을 제공한다. 반면에 스마트폰에는 신용카드, 연락처, ID정보 등 PC보다 더 많은 개인 정보를 보유하고 있기 때문에 그만큼 악성코드에 의한 해킹사고에 노출될 개연성이 높다. 실제로 국내에서 Terdial과 같이 의도하지 않은 국제전화를 유도하는 모바일 악성코드가 출현한 바 있다. 본 논문에서는 윈도우 CE 커널에서 SMS 관리 기능의 취약점을 분석하고, 이를 이용한 모바일 결제 승인용 SMS 인증코드를 가로채어 금전적 손실을 유발하는 악성코드가 윈도우 모바일이 탑재된 스마트폰에 동작 가능함을 실험을 통해 보고한다. 또한 실험 분석결과를 토대로 응용프로그램 및 OS 계층에서의 스마트폰 해킹 대응방안에 대해 고찰해 본다.
    번역하기

    최근 스마트폰은 PC만큼 강력한 연산장치와 Wi-Fi, 3G 등의 무선통신 기술을 통해 사용자가 인터넷 기반의 정보를 더욱 효율적으로 활용할 수 있는 서비스 및 어플리케이션을 제공한다. 반면에...

    최근 스마트폰은 PC만큼 강력한 연산장치와 Wi-Fi, 3G 등의 무선통신 기술을 통해 사용자가 인터넷 기반의 정보를 더욱 효율적으로 활용할 수 있는 서비스 및 어플리케이션을 제공한다. 반면에 스마트폰에는 신용카드, 연락처, ID정보 등 PC보다 더 많은 개인 정보를 보유하고 있기 때문에 그만큼 악성코드에 의한 해킹사고에 노출될 개연성이 높다. 실제로 국내에서 Terdial과 같이 의도하지 않은 국제전화를 유도하는 모바일 악성코드가 출현한 바 있다. 본 논문에서는 윈도우 CE 커널에서 SMS 관리 기능의 취약점을 분석하고, 이를 이용한 모바일 결제 승인용 SMS 인증코드를 가로채어 금전적 손실을 유발하는 악성코드가 윈도우 모바일이 탑재된 스마트폰에 동작 가능함을 실험을 통해 보고한다. 또한 실험 분석결과를 토대로 응용프로그램 및 OS 계층에서의 스마트폰 해킹 대응방안에 대해 고찰해 본다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Recently smartphones provide a variety of Internet-based personalized services and applications with the benefit of the advanced wireless technologies such as Wi-Fi and 3G, and the advance of computation power as much as a personal computer. They necessarily contain lots of personal information such as credit cards, contacts, personal identities for the intelligent service provisioning. However, the intensive belonging of valuable private data on the smartphone will be hacking target by the potential attackers. For example, the mobile malware called Terdial which makes unintentional international calls has been introduced. In this paper, we analyze vulnerabilities of SMS management on Windows CE kernel. Using these, we develop a potential malware that incurs financial theft by intercepting the SMS authorization code for mobile payments. Also, we propose the countermeasure against such malicious attacks at the different viewpoints of application and OS layers with thorough analysis of our experimental results.
    번역하기

    Recently smartphones provide a variety of Internet-based personalized services and applications with the benefit of the advanced wireless technologies such as Wi-Fi and 3G, and the advance of computation power as much as a personal computer. They nece...

    Recently smartphones provide a variety of Internet-based personalized services and applications with the benefit of the advanced wireless technologies such as Wi-Fi and 3G, and the advance of computation power as much as a personal computer. They necessarily contain lots of personal information such as credit cards, contacts, personal identities for the intelligent service provisioning. However, the intensive belonging of valuable private data on the smartphone will be hacking target by the potential attackers. For example, the mobile malware called Terdial which makes unintentional international calls has been introduced. In this paper, we analyze vulnerabilities of SMS management on Windows CE kernel. Using these, we develop a potential malware that incurs financial theft by intercepting the SMS authorization code for mobile payments. Also, we propose the countermeasure against such malicious attacks at the different viewpoints of application and OS layers with thorough analysis of our experimental results.

    더보기

    목차 (Table of Contents)

    • 요약
    • Abstract
    • 1. 서론
    • 2. 관련연구
    • 3. 윈도우 모바일 취약점 분석 시나리오
    • 요약
    • Abstract
    • 1. 서론
    • 2. 관련연구
    • 3. 윈도우 모바일 취약점 분석 시나리오
    • 4. 윈도우 모바일 SMS 취약점 분석
    • 5. SMS 취약점 공격 실험 결과
    • 6. 대응방안
    • 7. 결론
    • 참고문헌
    더보기

    참고문헌 (Reference)

    1 KBS 뉴스, "스마트폰, 개인정보 유출 무방비"

    2 김익수, "모바일 악성코드 분석 방법과 대응 방안" 한국통신학회 35 (35): 599-609, 2010

    3 MBC 뉴스, "국내 스마트폰 해킹 무방비"

    4 "WireShark"

    5 D. Suryakant, "Windows mobile device security model"

    6 "Windows CE Remote Process Viewer"

    7 R. Kuster, "Three ways to inject your code into another process"

    8 H. Lee, "Technology Trends on Smartphone Security" 17 (17): 61-72, 2010

    9 "SSnap"

    10 B. Morris, "Platform security and symbian signed: foundation for a secure platform" Symbian Developer Netwrok 2008

    1 KBS 뉴스, "스마트폰, 개인정보 유출 무방비"

    2 김익수, "모바일 악성코드 분석 방법과 대응 방안" 한국통신학회 35 (35): 599-609, 2010

    3 MBC 뉴스, "국내 스마트폰 해킹 무방비"

    4 "WireShark"

    5 D. Suryakant, "Windows mobile device security model"

    6 "Windows CE Remote Process Viewer"

    7 R. Kuster, "Three ways to inject your code into another process"

    8 H. Lee, "Technology Trends on Smartphone Security" 17 (17): 61-72, 2010

    9 "SSnap"

    10 B. Morris, "Platform security and symbian signed: foundation for a secure platform" Symbian Developer Netwrok 2008

    11 M. Pietrek, "Peering inside the PE: A tour of the win32 portable executable file format"

    12 A. Schmidt, "Malicious software for smartphones"

    13 M. Becher, "Kernel-level interception and applications on windows mobile devices"

    14 "IDA Pro"

    15 W. Jansen, "Guidelines on cell phone and PDA security"

    16 M. Thompson, "FIO43-C. Do not create temporary files in shared directories" CERT Coordination Center 2010

    17 "CommView"

    18 "Cellular Emulator"

    19 M. Pietrek, "An in-depth look into the win32 portable executable file format, part 2"

    20 M. Bishop, "A clinic for secure programming" 2010

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    인용정보 인용지수 설명보기

    학술지 이력

    학술지 이력
    연월일 이력구분 이력상세 등재구분
    2014-09-01 등재 학술지 통합(기타)
    2013-04-26 학술지명변경 한글명 : 정보과학회논문지 : 정보통신 </br>외국어명 : Journal of KIISE : Information Networking KCI등재
    2011-01-01 등재 등재학술지 유지(등재유지) KCI등재
    2009-01-01 등재 등재학술지 유지(등재유지) KCI등재
    2007-01-01 등재 등재학술지 유지(등재유지) KCI등재
    2005-01-01 등재 등재학술지 유지(등재유지) KCI등재
    2002-01-01 등재 등재학술지 선정(등재후보2차) KCI등재
    더보기

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼