RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    화이트리스트 기반의 안전한 응용 프로그램 실행 제어 시스템 설계 및 구현 = Design and Implementation of the Safety Application Execution Control System based on the White-list

    한글로보기

    https://www.riss.kr/link?id=T14545343

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    최근 개인용 PC 및 스마트 단말 등 다양한 디바이스를 통해 인터넷 활용이 급속히 증가함에 따라 해킹 등의 사이버 공격으로 인한 물리적, 사회적 피해가 끊임없이 발생되고 있다. 이러한 보안에 대한 공격을 미연에 방지하고 피해를 최소화하기 위해 기업에서는 다양한 보안 솔루션들을 도입하여 자체적인 방어 시스템을 갖추고 있지만 피해 사례와 피해규모는 지속적으로 증가하고 있다. 이러한 사이버 공격을 통한 주요파일 유출은 단말 PC에 설치된 악성코드에서 출발하며, 인가된 프로그램 실행 여부, 인가된 프로그램의 위․변조 여부, 운영체제의 주요 파일에 대한 악의적인 변경 여부 등 다양한 탐지와 식별 기법을 이용하여 세밀한 분석을 통해 악성코드 행위를 차단하는 기술개발의 필요성이 대두되고 있다.
    기존의 정보 보호 및 보안 시스템들은 기 확보된 시그니처 또는 이전에 분석되어있는 정보를 이용하여 악성코드 등 사이버 공격에 대응해 오고 있기 때문에, 시그니처가 공개되지 않은 악성코드나 시그니처가 변형된 신규 악성코드의 경우 악성코드의 탐지 및 식별이 어렵다.
    본 논문에서는 상기한 기존의 정보보호 및 보안시스템의 한계를 해결할 수 있도록 응용 프로그램의 무결성을 검증할 수 있는 응용프로그램의 실행 제어, 매체 제어, 레지스트리 보호, 운영체제의 주요 파일 변경 차단, 프로세스 접근을 위한 역접속 IP/Port 통제 등의 기술을 통합적으로 적용한 White-list 기반의 Endpoint의 응용 프로그램 실행 통제 시스템을 제안한다. 제안하는 시스템은 악성코드의 공격뿐만 아니라 운영체제 및 응용 프로그램 취약점을 이용한 익스플로잇 공격으로부터 Endpoint의 단말 PC를 더욱 안전하게 보호할 수 있다. 또한 White-list에 사용자로부터 안전하다고 판단되는 응용 프로그램을 등록하기 전에 에이전트의 응용 프로그램의 위험도를 계산하고 학습할 수 있는 기법을 제안한다.
    제안하는 White-list 기반의 Endpoint 응용프로그램 실행 통제 기법을 적용한 시스템은 응용프로그램 실행 시 White-list에 등록되지 않은 비인가 응용 프로그램과 식별되지 않는 응용 프로그램의 실행 파일이 실행되지 못하도록 사전에 차단하는 에이전트와 응용 프로그램 정상적인 실행 또는 실행 중지 명령을 전송하는 이벤트 서버, 그리고 정책 운영관리, White-list 등록, 응용프로그램 관리 등의 기능을 제공하는 모니터링 콘솔 등 세 부분으로 구성하여 설계하였다.
    구현된 시스템의 성능평가를 위해 검증 에이전트 설치 후 White-list에 응용 프로그램을 등록하여 Endpoint의 메모리 점유율, 부팅속도, 응용 프로그램 로딩 속도, 보안성을 측정한 후 기존 상용 시스템과의 성능을 비교 분석하여 제안시스템의 우수성을 검증하였다.
    본 논문에서 제안한 시스템은 White-list 기반의 보안 솔루션 연구 및 개발 부문에 있어 도움이 될 것으로 판단된다.
    번역하기

    최근 개인용 PC 및 스마트 단말 등 다양한 디바이스를 통해 인터넷 활용이 급속히 증가함에 따라 해킹 등의 사이버 공격으로 인한 물리적, 사회적 피해가 끊임없이 발생되고 있다. 이러한 보...

    최근 개인용 PC 및 스마트 단말 등 다양한 디바이스를 통해 인터넷 활용이 급속히 증가함에 따라 해킹 등의 사이버 공격으로 인한 물리적, 사회적 피해가 끊임없이 발생되고 있다. 이러한 보안에 대한 공격을 미연에 방지하고 피해를 최소화하기 위해 기업에서는 다양한 보안 솔루션들을 도입하여 자체적인 방어 시스템을 갖추고 있지만 피해 사례와 피해규모는 지속적으로 증가하고 있다. 이러한 사이버 공격을 통한 주요파일 유출은 단말 PC에 설치된 악성코드에서 출발하며, 인가된 프로그램 실행 여부, 인가된 프로그램의 위․변조 여부, 운영체제의 주요 파일에 대한 악의적인 변경 여부 등 다양한 탐지와 식별 기법을 이용하여 세밀한 분석을 통해 악성코드 행위를 차단하는 기술개발의 필요성이 대두되고 있다.
    기존의 정보 보호 및 보안 시스템들은 기 확보된 시그니처 또는 이전에 분석되어있는 정보를 이용하여 악성코드 등 사이버 공격에 대응해 오고 있기 때문에, 시그니처가 공개되지 않은 악성코드나 시그니처가 변형된 신규 악성코드의 경우 악성코드의 탐지 및 식별이 어렵다.
    본 논문에서는 상기한 기존의 정보보호 및 보안시스템의 한계를 해결할 수 있도록 응용 프로그램의 무결성을 검증할 수 있는 응용프로그램의 실행 제어, 매체 제어, 레지스트리 보호, 운영체제의 주요 파일 변경 차단, 프로세스 접근을 위한 역접속 IP/Port 통제 등의 기술을 통합적으로 적용한 White-list 기반의 Endpoint의 응용 프로그램 실행 통제 시스템을 제안한다. 제안하는 시스템은 악성코드의 공격뿐만 아니라 운영체제 및 응용 프로그램 취약점을 이용한 익스플로잇 공격으로부터 Endpoint의 단말 PC를 더욱 안전하게 보호할 수 있다. 또한 White-list에 사용자로부터 안전하다고 판단되는 응용 프로그램을 등록하기 전에 에이전트의 응용 프로그램의 위험도를 계산하고 학습할 수 있는 기법을 제안한다.
    제안하는 White-list 기반의 Endpoint 응용프로그램 실행 통제 기법을 적용한 시스템은 응용프로그램 실행 시 White-list에 등록되지 않은 비인가 응용 프로그램과 식별되지 않는 응용 프로그램의 실행 파일이 실행되지 못하도록 사전에 차단하는 에이전트와 응용 프로그램 정상적인 실행 또는 실행 중지 명령을 전송하는 이벤트 서버, 그리고 정책 운영관리, White-list 등록, 응용프로그램 관리 등의 기능을 제공하는 모니터링 콘솔 등 세 부분으로 구성하여 설계하였다.
    구현된 시스템의 성능평가를 위해 검증 에이전트 설치 후 White-list에 응용 프로그램을 등록하여 Endpoint의 메모리 점유율, 부팅속도, 응용 프로그램 로딩 속도, 보안성을 측정한 후 기존 상용 시스템과의 성능을 비교 분석하여 제안시스템의 우수성을 검증하였다.
    본 논문에서 제안한 시스템은 White-list 기반의 보안 솔루션 연구 및 개발 부문에 있어 도움이 될 것으로 판단된다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    With the recent increase of the Internet use through various devices, including personal computers and smart devices, continuous cyber-attacks are occurring, which result in various physical and social losses. Companies are adopting various security solutions to establish self-defense systems to defend such cyber-attacks and minimize damage, but the number of cases and the scale of losses are continuously increasing.
    The leakage of important files through such cyber-attacks begins from the malicious codes installed in the personal computers, and there is an increasing need of developing technology to block the activities of malicious codes by detecting and identifying process through integrated analyses, such as the identification of whether or not the executed program is authorized, the authorized program is manipulated, or the key files in the operating system are changed.
    The existing information protection systems are dealing with the malicious codes based on the already collected signatures or the previously analyzed information, so there are limitations in detecting and distinguishing the malicious codes when the signature is unknown or the codes are manipulated.
    In this thesis, we suggest the endpoint application program controlling method that enables a more secure protection of PC not only from the malicious codes, but also from the exploit attacks based on the vulnerabilities of the OS or the application program, by applying various integration of protection technologies, such as the white-list-based application program execution control method to verify integrity, media control, registry protection, important file manipulation prevention, and the process access inverse connection IP/Port control. Also, we suggest a method of measuring and learning the riskiness of the agent application program before registering the user-proven safe application programs on the white-list.
    The system with the white-list based endpoint application program control method consists of the following three parts: The agent blocking the execution of unauthorized programs that is not on the white-list or the unidentified programs when running an application program, the event server that delivers the execution or stop orders of the application program, and the monitoring console for the policy operation management, white-list registration, and the application program management. The realized system blocks the execution of the unauthorized programs that are not registered on the white-list, and the unidentified executive files through the execution control agent, when running an application program.
    For the performance evaluation of the realized system, after installing the verification agent and measuring the memory usage, booting speed, the execution program loading speed at the endpoint, and security, the performance comparison with the conventional commercial system was conducted to verify the excellence of the proposed system.
    It is expected that the method suggested in this thesis, and the system designed and realized in this study will be helpful in the research and development of white-list-based security solutions.
    번역하기

    With the recent increase of the Internet use through various devices, including personal computers and smart devices, continuous cyber-attacks are occurring, which result in various physical and social losses. Companies are adopting various security s...

    With the recent increase of the Internet use through various devices, including personal computers and smart devices, continuous cyber-attacks are occurring, which result in various physical and social losses. Companies are adopting various security solutions to establish self-defense systems to defend such cyber-attacks and minimize damage, but the number of cases and the scale of losses are continuously increasing.
    The leakage of important files through such cyber-attacks begins from the malicious codes installed in the personal computers, and there is an increasing need of developing technology to block the activities of malicious codes by detecting and identifying process through integrated analyses, such as the identification of whether or not the executed program is authorized, the authorized program is manipulated, or the key files in the operating system are changed.
    The existing information protection systems are dealing with the malicious codes based on the already collected signatures or the previously analyzed information, so there are limitations in detecting and distinguishing the malicious codes when the signature is unknown or the codes are manipulated.
    In this thesis, we suggest the endpoint application program controlling method that enables a more secure protection of PC not only from the malicious codes, but also from the exploit attacks based on the vulnerabilities of the OS or the application program, by applying various integration of protection technologies, such as the white-list-based application program execution control method to verify integrity, media control, registry protection, important file manipulation prevention, and the process access inverse connection IP/Port control. Also, we suggest a method of measuring and learning the riskiness of the agent application program before registering the user-proven safe application programs on the white-list.
    The system with the white-list based endpoint application program control method consists of the following three parts: The agent blocking the execution of unauthorized programs that is not on the white-list or the unidentified programs when running an application program, the event server that delivers the execution or stop orders of the application program, and the monitoring console for the policy operation management, white-list registration, and the application program management. The realized system blocks the execution of the unauthorized programs that are not registered on the white-list, and the unidentified executive files through the execution control agent, when running an application program.
    For the performance evaluation of the realized system, after installing the verification agent and measuring the memory usage, booting speed, the execution program loading speed at the endpoint, and security, the performance comparison with the conventional commercial system was conducted to verify the excellence of the proposed system.
    It is expected that the method suggested in this thesis, and the system designed and realized in this study will be helpful in the research and development of white-list-based security solutions.

    더보기

    목차 (Table of Contents)

    • I. 서론 1
    • 1.1 연구 배경 및 목적 1
    • 1.2 연구 내용 및 범위 4
    • 1.3 논문의 구성 5
    • II. 관련연구 6
    • I. 서론 1
    • 1.1 연구 배경 및 목적 1
    • 1.2 연구 내용 및 범위 4
    • 1.3 논문의 구성 5
    • II. 관련연구 6
    • 2.1 최근 보안 위협 6
    • 2.2 STAP 기술 10
    • 2.3 White-list 기반 보안 기술 14
    • 2.3.1 White-list 및 Black-list 보안 기술 14
    • 2.3.2 White-list 기반 보안관련 선행 연구 19
    • 2.4 Endpoint 보안 기술 24
    • 2.4.1 Endpoint 보안 요구사항 및 방안 26
    • 2.4.2 Endpoint 보안의 기본 요소 27
    • 2.5 기존 Endpoint 보안 기법의 한계 및 극복 방안 28
    • 2.5.1 기존 Endpoint 보안 기법의 한계 28
    • 2.5.2 기존 Endpoint 보안 한계의 극복 방안 29
    • III. 화이트리스트 기반의 응용 프로그램 실행 제어 시스템의 설계 32
    • 3.1 제안 시스템의 구성 32
    • 3.1.1 엔드포인트 에이전트(Endpoint Agent) 35
    • 3.1.2 이벤트 서버(Event Server) 36
    • 3.1.2 모니터링 콘솔(Monitoring Console) 37
    • 3.2 제안 시스템의 주요 프로세스 37
    • 3.2.1 Endpoint 응용 프로그램 실행제어 프로세스 37
    • 3.2.2 선 지정된 매체제어 및 White-list 기반의 무결성 검증 프로세스 39
    • 3.2.3 프로세스 행위기반 검증에 의한 응용프로그램 실행 흐름 통제 프로세스 43
    • 3.2.4 에이전트의 검증 프로세스 45
    • 3.2.5 검증에이전트와 검증 서버간 메시지 암복호화 프로세스 50
    • 3.2.6 검증 서버 검증 결과 처리 프로세스 53
    • 3.2.7 검증 서버의 탐지이벤트 실시간 처리 프로세스 54
    • 3.2.8 클라우드 기반의 정책파일 동기화 프로세스 55
    • 3.2.9 복합 검증 프로세스 56
    • 3.2.10 부가검증 및 예외처리 57
    • 3.2.11 DB 설계 58
    • 3.3 화이트리스팅을 위한 응용 프로그램 위험도 59
    • 3.3.1 화이트리스팅을 위한 응용 프로그램 위험도 계산 프로세스 59
    • 3.3.2 화이트리스팅 판단을 위한 응용 프로그램 위험도 계산 61
    • IV. 구현 및 비교 분석 65
    • 4.1 시스템 구현 65
    • 4.1.1 검증에이전트 모듈 66
    • 4.1.2 검증 서버 모듈 70
    • 4.2 비교 및 분석 73
    • 4.2.1 검증에이전트 평균 메모리 점유율 실험 73
    • 4.2.2 검증에이전트 설치 후 부팅속도 성능 실험 74
    • 4.2.3 검증에이전트 설치 후 응용 프로그램 로딩속도 성능 실험 75
    • 4.2.4 기존 시스템과의 보안 및 정책 기능 비교 77
    • 4.2.5 시스템의 보안성 성능 실험 및 비교분석 80
    • V. 결론 82
    • 참고문헌 84
    더보기

    참고문헌 (Reference)

    1. 웹, 해킹과 방어, 최경철, 프리렉, , 2008

    2. ‘이제는 사전 예방이다’, 권진욱, White Security, NETWORK TIMES, 2010. 11., , 2010

    3. MS 크래시 분석도구에 관한 연구, 나종배, Noh, Bong Nam, Jung, Gwang Un, Ryou, Jae Cheol, Noh, Myoung Sun, 노봉남, 류재철, 노명선, 정광운, Na, Jong Bae, 한국정보처리학회, 정보처리학회논문지, 제2권, 제9호, pp.399-404, , 2013

    4. 효율적인 APT 대응 시스템 운영 모델, 한은혜, 석사학위논문, 고려대학교 정보보 호대학원, , 2016

    5. 의료기기 보안 취약점에 대한 대응방안 연구, 정명섭, 석사학위논문, 고려대학교 컴퓨터정보통신대학원, , 2016

    6. Endpoint Level 의 효과적인 APT 공격 대응 방안 연구, 박세균, 고려대학교, 컴퓨터정보통신대학원 석사학위논문, , 2015

    7. “소프트웨어 동적 분석 뷰어 개선 적용 사례”, 이남용, 문중희, 한국정보과학회, 정보 과학회논문지, 제38권, 제1호, pp.1-10, , 2011

    8. “칼리 리눅스와 백 트랙을 활용한 모의 해킹”, 임종민, 최우석, 박병욱, 이경철, 조정원, 에이콘, 에이콘출판사, , 2014

    9. “네트워크 보안: 끝점 보안의 네 가지 기본 요소”, Dan Griffin, TechNet Magazine, October, , 2010

    10. APT 공격 대응을 위한 상황인식 알고리즘에 관한 연구, 강찬구, 공주대학교 대학원, 석사학위논문, 공 주대학교 대학원, , 2014

    1. 웹, 해킹과 방어, 최경철, 프리렉, , 2008

    2. ‘이제는 사전 예방이다’, 권진욱, White Security, NETWORK TIMES, 2010. 11., , 2010

    3. MS 크래시 분석도구에 관한 연구, 나종배, Noh, Bong Nam, Jung, Gwang Un, Ryou, Jae Cheol, Noh, Myoung Sun, 노봉남, 류재철, 노명선, 정광운, Na, Jong Bae, 한국정보처리학회, 정보처리학회논문지, 제2권, 제9호, pp.399-404, , 2013

    4. 효율적인 APT 대응 시스템 운영 모델, 한은혜, 석사학위논문, 고려대학교 정보보 호대학원, , 2016

    5. 의료기기 보안 취약점에 대한 대응방안 연구, 정명섭, 석사학위논문, 고려대학교 컴퓨터정보통신대학원, , 2016

    6. Endpoint Level 의 효과적인 APT 공격 대응 방안 연구, 박세균, 고려대학교, 컴퓨터정보통신대학원 석사학위논문, , 2015

    7. “소프트웨어 동적 분석 뷰어 개선 적용 사례”, 이남용, 문중희, 한국정보과학회, 정보 과학회논문지, 제38권, 제1호, pp.1-10, , 2011

    8. “칼리 리눅스와 백 트랙을 활용한 모의 해킹”, 임종민, 최우석, 박병욱, 이경철, 조정원, 에이콘, 에이콘출판사, , 2014

    9. “네트워크 보안: 끝점 보안의 네 가지 기본 요소”, Dan Griffin, TechNet Magazine, October, , 2010

    10. APT 공격 대응을 위한 상황인식 알고리즘에 관한 연구, 강찬구, 공주대학교 대학원, 석사학위논문, 공 주대학교 대학원, , 2014

    11. 제조업 생산 설비 PC 의 효과적인보안 강화 방안 연구, 김병주, 고 려대학교 컴퓨터정보통신대학원 석사학위논문, , 2016

    12. ‘위협 고도화로 화이트리스트 보안 기술 ’재조명‘’, 오현식, White Security, NETWORK TIMES, 2010. 11., , 2010

    13. “국가 사이버보안 피해금액 분석과 대안, 국가정보연구”, 신영웅, 전상훈, 임채호, 김명철, 제6권 1호, 한국국가정보학회, , 2013

    14. 어플리케이션을 위한 지능형 취약점 분석 기법에 관 한 연구, 안전한, 추연수, 박사학위논문, 숭실대학교 대학원, , 2016

    15. “정적분석 도구를 이용한 지역 SW개발 업체의 결함 유형 분석”, 노정현, 동의대학교, 동의대학교 대학원 학위논문(석사), , 2015

    16. “화이트리스트 기법을 이용한 효과적인 보안강화 방안 연 구”, 최재우, 동국대학교 국제정보대학원, 석사학위논문, , 2014

    17. “제어망에서 화이트리스트기법을 이용한 이상 징후 탐지에 관한 연구", 이동휘, 최경호, 한국사이버테러정보전학회, 융합보안논문지, 제12권, 제4호, , 2012

    18. POS 시스템의 보안강화를 위한 화이트리스트 기반 프로세 스 제어 기법에 관한 연구, 박승수, 성균관대학교, 성균관대학교 대학원. 석사학위논문, , 2016

    19. 안전한 모바일 전자정부 서비스를 위한 화이트리스트 자동 화 검증시스템 아키텍처 설계, 정구춘, 석사학 위논문, 숭실대학교 정보과학대학원, , 2014

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼