최근 개인용 PC 및 스마트 단말 등 다양한 디바이스를 통해 인터넷 활용이 급속히 증가함에 따라 해킹 등의 사이버 공격으로 인한 물리적, 사회적 피해가 끊임없이 발생되고 있다. 이러한 보...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T14545343
서울 : 숭실대학교 대학원, 2017
학위논문(박사) -- 숭실대학교 대학원 , IT정책경영학과(일원) , 2017. 8
2017
한국어
화이트리스트 ; 응용프로그램 실행제어 ; 프로세스 실행제어 ; 매체제어 ; 프로세스 행위기반 검증 ; 필터 드라이브 ; 중요파일 보호 ; 역접속 차단 ; 정보보호 ; 보안
005.8 판사항(23)
서울
xii, 88 p. : 삽화 ; 26 cm
숭실대학교 논문은 저작권에 의해 보호받습니다.
지도교수: 전문석
참고문헌: p. 84-88
0
상세조회0
다운로드최근 개인용 PC 및 스마트 단말 등 다양한 디바이스를 통해 인터넷 활용이 급속히 증가함에 따라 해킹 등의 사이버 공격으로 인한 물리적, 사회적 피해가 끊임없이 발생되고 있다. 이러한 보...
최근 개인용 PC 및 스마트 단말 등 다양한 디바이스를 통해 인터넷 활용이 급속히 증가함에 따라 해킹 등의 사이버 공격으로 인한 물리적, 사회적 피해가 끊임없이 발생되고 있다. 이러한 보안에 대한 공격을 미연에 방지하고 피해를 최소화하기 위해 기업에서는 다양한 보안 솔루션들을 도입하여 자체적인 방어 시스템을 갖추고 있지만 피해 사례와 피해규모는 지속적으로 증가하고 있다. 이러한 사이버 공격을 통한 주요파일 유출은 단말 PC에 설치된 악성코드에서 출발하며, 인가된 프로그램 실행 여부, 인가된 프로그램의 위․변조 여부, 운영체제의 주요 파일에 대한 악의적인 변경 여부 등 다양한 탐지와 식별 기법을 이용하여 세밀한 분석을 통해 악성코드 행위를 차단하는 기술개발의 필요성이 대두되고 있다.
기존의 정보 보호 및 보안 시스템들은 기 확보된 시그니처 또는 이전에 분석되어있는 정보를 이용하여 악성코드 등 사이버 공격에 대응해 오고 있기 때문에, 시그니처가 공개되지 않은 악성코드나 시그니처가 변형된 신규 악성코드의 경우 악성코드의 탐지 및 식별이 어렵다.
본 논문에서는 상기한 기존의 정보보호 및 보안시스템의 한계를 해결할 수 있도록 응용 프로그램의 무결성을 검증할 수 있는 응용프로그램의 실행 제어, 매체 제어, 레지스트리 보호, 운영체제의 주요 파일 변경 차단, 프로세스 접근을 위한 역접속 IP/Port 통제 등의 기술을 통합적으로 적용한 White-list 기반의 Endpoint의 응용 프로그램 실행 통제 시스템을 제안한다. 제안하는 시스템은 악성코드의 공격뿐만 아니라 운영체제 및 응용 프로그램 취약점을 이용한 익스플로잇 공격으로부터 Endpoint의 단말 PC를 더욱 안전하게 보호할 수 있다. 또한 White-list에 사용자로부터 안전하다고 판단되는 응용 프로그램을 등록하기 전에 에이전트의 응용 프로그램의 위험도를 계산하고 학습할 수 있는 기법을 제안한다.
제안하는 White-list 기반의 Endpoint 응용프로그램 실행 통제 기법을 적용한 시스템은 응용프로그램 실행 시 White-list에 등록되지 않은 비인가 응용 프로그램과 식별되지 않는 응용 프로그램의 실행 파일이 실행되지 못하도록 사전에 차단하는 에이전트와 응용 프로그램 정상적인 실행 또는 실행 중지 명령을 전송하는 이벤트 서버, 그리고 정책 운영관리, White-list 등록, 응용프로그램 관리 등의 기능을 제공하는 모니터링 콘솔 등 세 부분으로 구성하여 설계하였다.
구현된 시스템의 성능평가를 위해 검증 에이전트 설치 후 White-list에 응용 프로그램을 등록하여 Endpoint의 메모리 점유율, 부팅속도, 응용 프로그램 로딩 속도, 보안성을 측정한 후 기존 상용 시스템과의 성능을 비교 분석하여 제안시스템의 우수성을 검증하였다.
본 논문에서 제안한 시스템은 White-list 기반의 보안 솔루션 연구 및 개발 부문에 있어 도움이 될 것으로 판단된다.
다국어 초록 (Multilingual Abstract)
With the recent increase of the Internet use through various devices, including personal computers and smart devices, continuous cyber-attacks are occurring, which result in various physical and social losses. Companies are adopting various security s...
With the recent increase of the Internet use through various devices, including personal computers and smart devices, continuous cyber-attacks are occurring, which result in various physical and social losses. Companies are adopting various security solutions to establish self-defense systems to defend such cyber-attacks and minimize damage, but the number of cases and the scale of losses are continuously increasing.
The leakage of important files through such cyber-attacks begins from the malicious codes installed in the personal computers, and there is an increasing need of developing technology to block the activities of malicious codes by detecting and identifying process through integrated analyses, such as the identification of whether or not the executed program is authorized, the authorized program is manipulated, or the key files in the operating system are changed.
The existing information protection systems are dealing with the malicious codes based on the already collected signatures or the previously analyzed information, so there are limitations in detecting and distinguishing the malicious codes when the signature is unknown or the codes are manipulated.
In this thesis, we suggest the endpoint application program controlling method that enables a more secure protection of PC not only from the malicious codes, but also from the exploit attacks based on the vulnerabilities of the OS or the application program, by applying various integration of protection technologies, such as the white-list-based application program execution control method to verify integrity, media control, registry protection, important file manipulation prevention, and the process access inverse connection IP/Port control. Also, we suggest a method of measuring and learning the riskiness of the agent application program before registering the user-proven safe application programs on the white-list.
The system with the white-list based endpoint application program control method consists of the following three parts: The agent blocking the execution of unauthorized programs that is not on the white-list or the unidentified programs when running an application program, the event server that delivers the execution or stop orders of the application program, and the monitoring console for the policy operation management, white-list registration, and the application program management. The realized system blocks the execution of the unauthorized programs that are not registered on the white-list, and the unidentified executive files through the execution control agent, when running an application program.
For the performance evaluation of the realized system, after installing the verification agent and measuring the memory usage, booting speed, the execution program loading speed at the endpoint, and security, the performance comparison with the conventional commercial system was conducted to verify the excellence of the proposed system.
It is expected that the method suggested in this thesis, and the system designed and realized in this study will be helpful in the research and development of white-list-based security solutions.
목차 (Table of Contents)
참고문헌 (Reference)
1. 웹, 해킹과 방어, 최경철, 프리렉, , 2008
2. ‘이제는 사전 예방이다’, 권진욱, White Security, NETWORK TIMES, 2010. 11., , 2010
4. 효율적인 APT 대응 시스템 운영 모델, 한은혜, 석사학위논문, 고려대학교 정보보 호대학원, , 2016
5. 의료기기 보안 취약점에 대한 대응방안 연구, 정명섭, 석사학위논문, 고려대학교 컴퓨터정보통신대학원, , 2016
6. Endpoint Level 의 효과적인 APT 공격 대응 방안 연구, 박세균, 고려대학교, 컴퓨터정보통신대학원 석사학위논문, , 2015
7. “소프트웨어 동적 분석 뷰어 개선 적용 사례”, 이남용, 문중희, 한국정보과학회, 정보 과학회논문지, 제38권, 제1호, pp.1-10, , 2011
8. “칼리 리눅스와 백 트랙을 활용한 모의 해킹”, 임종민, 최우석, 박병욱, 이경철, 조정원, 에이콘, 에이콘출판사, , 2014
9. “네트워크 보안: 끝점 보안의 네 가지 기본 요소”, Dan Griffin, TechNet Magazine, October, , 2010
10. APT 공격 대응을 위한 상황인식 알고리즘에 관한 연구, 강찬구, 공주대학교 대학원, 석사학위논문, 공 주대학교 대학원, , 2014
1. 웹, 해킹과 방어, 최경철, 프리렉, , 2008
2. ‘이제는 사전 예방이다’, 권진욱, White Security, NETWORK TIMES, 2010. 11., , 2010
4. 효율적인 APT 대응 시스템 운영 모델, 한은혜, 석사학위논문, 고려대학교 정보보 호대학원, , 2016
5. 의료기기 보안 취약점에 대한 대응방안 연구, 정명섭, 석사학위논문, 고려대학교 컴퓨터정보통신대학원, , 2016
6. Endpoint Level 의 효과적인 APT 공격 대응 방안 연구, 박세균, 고려대학교, 컴퓨터정보통신대학원 석사학위논문, , 2015
7. “소프트웨어 동적 분석 뷰어 개선 적용 사례”, 이남용, 문중희, 한국정보과학회, 정보 과학회논문지, 제38권, 제1호, pp.1-10, , 2011
8. “칼리 리눅스와 백 트랙을 활용한 모의 해킹”, 임종민, 최우석, 박병욱, 이경철, 조정원, 에이콘, 에이콘출판사, , 2014
9. “네트워크 보안: 끝점 보안의 네 가지 기본 요소”, Dan Griffin, TechNet Magazine, October, , 2010
10. APT 공격 대응을 위한 상황인식 알고리즘에 관한 연구, 강찬구, 공주대학교 대학원, 석사학위논문, 공 주대학교 대학원, , 2014
11. 제조업 생산 설비 PC 의 효과적인보안 강화 방안 연구, 김병주, 고 려대학교 컴퓨터정보통신대학원 석사학위논문, , 2016
12. ‘위협 고도화로 화이트리스트 보안 기술 ’재조명‘’, 오현식, White Security, NETWORK TIMES, 2010. 11., , 2010
13. “국가 사이버보안 피해금액 분석과 대안, 국가정보연구”, 신영웅, 전상훈, 임채호, 김명철, 제6권 1호, 한국국가정보학회, , 2013
14. 어플리케이션을 위한 지능형 취약점 분석 기법에 관 한 연구, 안전한, 추연수, 박사학위논문, 숭실대학교 대학원, , 2016
15. “정적분석 도구를 이용한 지역 SW개발 업체의 결함 유형 분석”, 노정현, 동의대학교, 동의대학교 대학원 학위논문(석사), , 2015
16. “화이트리스트 기법을 이용한 효과적인 보안강화 방안 연 구”, 최재우, 동국대학교 국제정보대학원, 석사학위논문, , 2014
17. “제어망에서 화이트리스트기법을 이용한 이상 징후 탐지에 관한 연구", 이동휘, 최경호, 한국사이버테러정보전학회, 융합보안논문지, 제12권, 제4호, , 2012
18. POS 시스템의 보안강화를 위한 화이트리스트 기반 프로세 스 제어 기법에 관한 연구, 박승수, 성균관대학교, 성균관대학교 대학원. 석사학위논문, , 2016
19. 안전한 모바일 전자정부 서비스를 위한 화이트리스트 자동 화 검증시스템 아키텍처 설계, 정구춘, 석사학 위논문, 숭실대학교 정보과학대학원, , 2014