WO2014157797A1 - 시스템의 취약점 정량화 장치 및 그 방법 - Google Patents
시스템의 취약점 정량화 장치 및 그 방법 Download PDFInfo
- Publication number
- WO2014157797A1 WO2014157797A1 PCT/KR2013/009389 KR2013009389W WO2014157797A1 WO 2014157797 A1 WO2014157797 A1 WO 2014157797A1 KR 2013009389 W KR2013009389 W KR 2013009389W WO 2014157797 A1 WO2014157797 A1 WO 2014157797A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- score
- vulnerability
- safety
- calculating
- quantifying
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1433—Vulnerability analysis
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/577—Assessing vulnerabilities and evaluating computer system security
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F30/00—Computer-aided design [CAD]
- G06F30/20—Design optimisation, verification or simulation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
Definitions
- the present invention relates to an apparatus for quantifying a vulnerability of a system and a method thereof, and more particularly, to an apparatus and a method for quantifying a vulnerability of a system so as to intuitively and objectively express a state of a system. .
- the technology for analyzing or evaluating vulnerabilities on information and communication systems is to identify vulnerabilities existing in the system in advance and to eliminate the vulnerabilities through the identified results.
- techniques for analyzing or evaluating vulnerabilities on systems can be eliminated before they are exploited for piracy, ultimately preventing various forms of breaches.
- the results of analyzing or evaluating the vulnerability of the system can be applied to the method of intuitively communicating the safety status of the system to the management of the organization.
- Korean Patent No. 0851521 is a security technology for a network system, and a technology related to a cyber attack system and an attack method that provides an active and automated integrated cyber attack model that can detect and analyze vulnerabilities inherent in networks and systems. Introduced.
- analyzing or evaluating vulnerabilities is not a one-time task, but a routine one.
- results of tasks performed periodically it is necessary to compare the present and past results in addition to the present results.
- a result such as "a particular system is in danger of lacking access control such as insufficient password management and unnecessary services exists” may confuse the listener.
- Quantification of the results of analyzing or evaluating vulnerabilities is essential, but research and development have not been done.
- the first reason is the need to correct the results of analyzing or evaluating vulnerabilities.
- the second reason is that no attempt has been made on how to quantify vulnerabilities and breaches, and how to maintain their objectivity.
- the results of analyzing or evaluating vulnerabilities in their own way were quantified, but it was difficult to maintain objectivity.
- the first reason is that the vulnerabilities used to calculate the scores are limited. Among the identified vulnerabilities, only a few characteristic vulnerabilities that have a big impact on exploitation are used for scoring, so vulnerabilities other than a few characteristic vulnerabilities are excluded from scoring.
- the second cause is that the subjective factor of the analyst may be excessively involved. In the case of requiring scoring after providing the same vulnerability identification result for the same system, different analysts calculate different weights of the vulnerabilities.
- the calculating of the target organization safety score may include calculating the target organization safety score by summing according to a ratio of setting the technical field safety score and the management field safety score.
- the calculating of the target organization safety score may include converting a technically identified vulnerability from the vulnerability identification result of the system into the technical field safety score; And converting a vulnerability related to management of the system from the vulnerability identification result of the system into the management field safety score.
- the step of converting to the technical field safety score is characterized by using the sum of the score corresponding to the technically identified vulnerability and the vulnerability score.
- the step of converting the management field safety score is characterized by using the sum of the score corresponding to the vulnerability of the management of the system and the vulnerability score.
- the step of quantifying the vulnerability of the system characterized in that for calculating the composite score by applying a weight to the intermediate score according to the simulation penetration grade.
- a vulnerability calculation unit for converting each of the vulnerability identification results of the system into a vulnerability score so as to be applied to the score calculation;
- a target agency safety calculator configured to calculate a target agency safety score corresponding to the system based on a technical field safety score and a management field safety score among the vulnerability scores;
- Network separation status calculation unit for converting the separation of the work network and the external network of the system into a network separation score;
- An intermediate calculator configured to calculate an intermediate score based on the target organization safety score and the network separation score;
- a final score calculator for quantifying the vulnerability of the system by finally calculating a comprehensive score of the system using the intermediate score and the simulated penetration grade.
- the target engine safety calculator calculates the target engine safety score by summing according to a ratio of setting the technical field safety score and the management field safety score.
- the vulnerability quantification device of the system includes: a technical field safety calculation unit for scoring a technically identified vulnerability from the vulnerability identification result of the system by the technical field safety score; And a management field safety calculation unit for scoring a vulnerability related to management of the system among the vulnerability identification results of the system by the management field safety score.
- the vulnerability quantification device of the system combines the vulnerabilities corresponding to each of the vulnerability identification results of the system, attempts to penetrate the combined vulnerabilities in a plurality of paths, the position of the penetration attempt in the simulation penetration successful in the attempt And a mother grade management unit for calculating the simulated penetration grade according to the penetration result.
- the final score calculator is characterized in that to calculate the composite score by applying a weight to the intermediate score according to the simulation penetration grade.
- the apparatus and method for quantifying the vulnerability of the system to minimize the part that the subject's subjectivity can be involved to minimize the problem that the evaluation results vary depending on the person.
- the present invention provides an apparatus and method for quantifying the vulnerability of the system can provide a visible result to the administrator of the system, for example, "if any protection measures are implemented, the overall score can go up to several points.” .
- FIG. 1 is a block diagram schematically illustrating an apparatus for quantifying a vulnerability of a system according to an embodiment of the present invention.
- 2 to 4 are reference diagrams applied to the vulnerability quantification device of the system according to an embodiment of the present invention.
- FIG. 5 is a flowchart illustrating a method of quantifying a vulnerability of a system according to an embodiment of the present invention.
- 1 is a block diagram schematically illustrating an apparatus for quantifying a vulnerability of a system according to an embodiment of the present invention.
- 2 to 4 are reference diagrams applied to a vulnerability quantification device of a system according to an embodiment of the present invention.
- the vulnerability quantification device 10 of the system may include a result of analyzing or evaluating a vulnerability of the system (hereinafter, also referred to as "a vulnerability identification result of the system”) or may be transmitted from the outside, but is not limited thereto.
- the vulnerability quantification device 100 of the system includes a vulnerability calculation unit 110, a technical field safety calculator 120, a management field safety calculator 130, and a target institution safety calculator 140. ), A network separation status calculator 150, an intermediate calculator 160, a grade manager 170, and a final score calculator 180.
- the vulnerability calculation unit 110 converts each vulnerability identification result of the system into a vulnerability score so that the vulnerability identification result of the system is applied to the score calculation.
- the vulnerability score can be expressed as a score from 0 to 10 points, for example.
- vulnerability identification results for servers and web applications can be calculated based on the Common Vulnerability Scoring System (CVSS) 2.0.
- Vulnerability identification results for management, network, and DB can be used separately.
- the technical field safety calculation unit 120 calculates the technical field safety score by synthesizing the technically identified vulnerabilities among the vulnerability identification results of the system.
- technically identified vulnerabilities are the results of analyzing or evaluating vulnerabilities on technical parts of the system.
- the technical field safety calculator 120 may calculate the technical field safety score as shown in Equation 1.
- the technically identified vulnerability score is a result of converting the technically identified vulnerability into a score
- the maximum vulnerability score is a sum of vulnerability scores corresponding to the vulnerability identification result of the system.
- system A is a Unix server
- the sum of the vulnerability scores corresponding to the results of analyzing or evaluating the vulnerabilities of the Unix server is 1000 points.
- the technical field safety score of the A system is 92 points according to Equation (1).
- the management field safety calculation unit 130 calculates a management field safety score by synthesizing the vulnerabilities corresponding to the management field among the vulnerability identification results of the system.
- the vulnerability corresponding to the management field is the result of analyzing or evaluating the vulnerability regarding the management of the system.
- the management field safety calculation unit 130 may calculate a management field safety score as shown in Equation 2.
- Equation 2 the maximum vulnerability score is the same as the maximum vulnerability score of Equation 1, which is the sum of the vulnerability scores corresponding to the vulnerability identification result of the system.
- the target organization safety calculation unit 140 calculates the target organization safety score by summing according to the ratio ( ⁇ , ⁇ ) of setting the technical field safety score and the management field safety score.
- the sum of the set ratio that is, the ratio applied to the technical field safety score and the ratio applied to the management field safety score ( ⁇ + ⁇ ) is set to be 1.
- the target institution safety score is calculated as in Equation 3.
- the network separation status calculation unit 150 converts the separation status of the work network and the external network (for example, the Internet) of the system into a network separation score.
- the network separation status calculation unit 150 may allocate the network separation score as shown in FIG. 2 according to the form in which the work network and the external network are separated (network separation situation of FIG. 2).
- the intermediate calculation unit 160 calculates the intermediate score by summing according to the ratio ⁇ that sets the target organization safety score and the network separation score.
- the rating manager 170 combines the vulnerabilities corresponding to the vulnerability identification result of the system, and calculates the simulation penetration rating by applying the combined vulnerabilities to the simulation penetration of the plurality of paths.
- the rating management unit 170 attempts to simulate penetration of a plurality of paths by combining vulnerabilities corresponding to the vulnerability identification result of the system.
- the grade management unit 170 calculates the simulation penetration grade according to the penetration attempt position and the penetration result in the simulation penetration successful in such an attempt.
- the rating manager 170 calculates a simulation penetration grade as shown in FIG. 3 according to the penetration result and the penetration attempt position in the successful simulation penetration.
- the penetration result may include a case in which the administrator obtains the authority, a case in which the general user acquires the authority, or a case in which normal operation of the system may be prevented due to the simulation penetration, and the penetration attempt location may be external (Internet).
- the system may be the same system as other systems in the institution to which the system is applied.
- the final score calculator 180 calculates a composite score by applying a simulated penetration grade to the intermediate score. Specifically, the final score calculation unit 180 calculates a composite score by applying a weight ( ⁇ ⁇ 80%, 85%, 90%, 95%, 100% ⁇ ) to the intermediate score according to the simulation penetration grade. For example, as shown in FIG. 4, the final score calculator 180 calculates a comprehensive score according to the simulated penetration grade when the intermediate score is 94 points.
- FIG. 5 is a flowchart illustrating a method of quantifying a vulnerability of a system according to an embodiment of the present invention.
- the vulnerability quantification apparatus 100 of the system converts the vulnerability identification result of the system into a vulnerability score (S510).
- the vulnerability score can be expressed as a score from 0 to 10 points, for example.
- Vulnerability quantification device 100 of the system calculates the technical field safety score by combining the technically identified vulnerabilities of the vulnerability identification results of the system (S520).
- the technical field safety score is calculated as in Equation 1.
- the vulnerability quantification device 100 of the system calculates a management field safety score by synthesizing a vulnerability corresponding to a management field among the vulnerability identification results of the system (S530).
- the management field safety score is calculated as in Equation 2.
- Vulnerability quantification device 100 of the system calculates the target organization safety score by summing according to the ratio ( ⁇ , ⁇ ) set the technical field safety score and management field safety score (S540).
- the sum of the set ratio that is, the ratio applied to the technical field safety score and the ratio applied to the management field safety score ( ⁇ + ⁇ ) is set to be 1.
- the target organ safety score is calculated as in Equation 3.
- Vulnerability quantification device 100 of the system converts the separation status of the work network and the external network (for example, the Internet) of the system (S550).
- the vulnerability quantification apparatus 100 of the system may assign a network separation score according to the form in which the work network and the external network are separated as shown in FIG. 2.
- Vulnerability quantification device 100 of the system calculates the intermediate score by summing according to the ratio ( ⁇ ) to set the target organization safety score and network separation score (S560).
- the apparatus 100 for quantifying the vulnerability of the system attempts to simulate penetration of a plurality of paths by combining the vulnerabilities corresponding to the vulnerability identification result of the system, and simulates penetration grade according to the penetration attempt position and penetration result in the successful simulation penetration among the attempted results.
- the vulnerability quantification device 100 of the system may calculate a simulated penetration grade as shown in FIG. 3 according to the penetration attempt position and the penetration result.
- the vulnerability quantification device 100 of the system quantifies the vulnerability of the system by calculating a comprehensive score by applying a simulated penetration grade to the intermediate score (S580).
- the apparatus 100 for quantifying vulnerability of a system may quantify a result of analyzing or evaluating a vulnerability of a system, so that the state of the system may be intuitively and objectively expressed.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- Computing Systems (AREA)
- General Physics & Mathematics (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Virology (AREA)
- Geometry (AREA)
- Evolutionary Computation (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Computer And Data Communications (AREA)
- Storage Device Security (AREA)
Abstract
본 발명은 시스템의 상태를 직관적 및 객관적으로 표현할 수 있도록 시스템의 취약점을 정량화하는 장치 및 그 방법에 관한 것이다. 시스템의 취약점 정량화 장치는 시스템의 취약점 식별 결과 각각을 취약점 점수로 변환하는 취약점 계산부, 취약점 점수 중 기술분야 안전도 점수와 관리분야 안전도 점수를 토대로 시스템에 해당하는 대상기관 안전도 점수를 계산하는 대상기관 안전도 계산부, 시스템의 업무망과 외부망의 분리 상황을 망 분리 점수로 변환하는 망 분리 현황 계산부, 대상기관 안전도 점수와 상기 망 분리 점수를 토대로 중간 점수를 계산하는 중간 계산부 및 중간 점수와 모의 침투 등급을 이용하여 최종적으로 시스템의 종합 점수를 계산하여 시스템의 취약점을 정량화하는 최종 점수 계산부를 포함한다.
Description
본 발명은 시스템의 취약점 정량화 장치 및 그 방법(APPARATUS AND METHOD FOR QUANTIFYING VULNERABILITY OF SYSTEM)에 관한 것으로, 특히 시스템의 상태를 직관적 및 객관적으로 표현할 수 있도록 시스템의 취약점을 정량화하는 장치 및 그 방법에 관한 것이다.
정보통신 시스템에 대한 취약점을 분석하거나 평가하는 기술은 해당 시스템에 존재하는 취약점을 미리 식별하고, 식별한 결과를 통해 취약점을 제거하기 위함이다. 이와 같이, 시스템에 대한 취약점을 분석하거나 평가하는 기술은 취약점이 불법침해에 악용되기 이전에 제거함으로써, 궁극적으로 다양한 형태의 침해를 미연에 방지할 수 있다. 또한, 시스템에 대한 취약점을 분석하거나 평가한 결과는 해당 조직의 경영진에게 시스템의 안전 상태를 직관적으로 전달하는 방법에 적용할 수 있다.
한국등록특허 제0851521호는 네트워크 시스템에 대한 보안 기술로서 네트워크 및 시스템에 내재된 취약성을 탐지하고 분석할 수 있는 능동적이고 자동화된 통합적인 사이버 공격 모델을 제공하는 사이버 공격 시스템 및 그 공격 방법에 관한 기술을 소개하였다.
그러나, 이와 같은 종래의 취약점을 분석하거나 평가하는 기술은 취약성을 탐지하고 분석할 수 있는 능동적이고 자동화된 통합적인 사이버 공격 모델을 제공하고 있을 뿐, 취약점에 대한 직관적 또는 객관적인 평가 결과를 획득하는 기술에 관하여 제시하고 있지 못하다.
따라서, 시스템에 대한 취약점을 분석하거나 평가한 결과는 정량화되지 않으면 시스템의 상태를 대표값으로 표현하기 어렵다.
그리고, 취약점을 분석하거나 평가하는 것은 일회성으로 하는 것이 아니라, 주기적으로 수행하는 것이 일반적이다. 주기적으로 수행되는 업무의 결과를 표현할 때에는 현재의 결과 이외에 현재와 과거의 결과를 비교하여 설명하는 부분이 필요하다. 예를 들어, "특정 시스템은 패스워드 관리가 미비하고, 불필요한 서비스가 존재하는 등 접근통제가 미흡하여 위험한 상태이다"와 같은 결과는 청취자를 혼돈스럽게 한다. 이와 같은 경우에는 정량화를 통해 설명하는 것이 가능하다. 예를 들어, "2년 전에는 85점(우수 등급)이었으나, 이번에는 77점(미흡 등급)으로 취약점이 악화되어 있다"와 같이, 현재와 과거의 상황을 수치 또는 등급으로 비교, 설명함으로써 상세한 내용은 표현되지 않지만 현재의 상태를 직관적, 객관적으로 표현할 수 있다.
취약점을 분석하거나 평가한 결과의 정량화는 반드시 필요한 부분이나, 이를 위한 연구 및 개발은 이루어지지 않고 있다. 첫번째 이유는 취약점을 분석하거나 평가한 결과에 대한 수정 요구를 꼽을 수 있다. 기술적으로 취약점을 식별하고, 모의침투를 통해 취약점의 악용여부를 확인한 후 계산된 결과를 해당 시스템의 관리자가 수정해 달라고 요구하는 것이 일반적이다. 여기서, 시스템의 관리자는 낮은 점수가 경영진에게 보고되는 것을 원하지 않거나, 낮은 점수가 경영진에게 보고되게 함으로써 예산, 인력 등 자원 보충을 요구하기 위한 근거로 사용하려는 의도가 있기 때문이다. 두번째 이유는 취약점과 모의침투 결과를 수치화하는 방법, 그리고 이러한 방법의 객관성을 유지하는 방법에 대한 시도가 이루어지지 않았기 때문이다.
이전에도 나름대로의 방법으로 취약점을 분석하거나 평가한 결과를 수치화 하였으나, 객관성을 유지하기 어려웠다. 첫번째 원인은 점수 계산에 사용되는 취약점이 제한적이다. 식별된 취약점들 중에서 악용시 큰 영향을 발생시키는 소수의 특징적인 취약점만을 점수 계산에 활용하므로, 소수의 특징적인 취약점 이외의 취약점들은 점수화에서 배제된다. 두번째 원인은 분석자의 주관적 요소가 과다하게 개입될 수 있다. 동일한 시스템에 대해 동일한 취약점 식별 결과를 제공한 후에 점수화를 요구하는 경우에는 분석자마다 취약점들의 비중을 다르게 판단하므로, 사람마다 상이한 점수를 계산한다
이와 같은, 문제점으로 인하여 지금까지의 취약점을 분석하거나 평가한 결과는 객관성이 저하 되어있으며, 수정 요구에 반박할 수 있는 논리가 없어서 결과를 수정해 줄 수 밖에 없었다.
따라서, 시스템의 수준을 수치로 정량화하여 전달할 수 있는 기술의 필요성이 절실하게 대두된다.
본 발명의 목적은 시스템의 상태를 직관적 및 객관적으로 표현할 수 있도록 시스템의 취약점을 정량화하는 장치 및 그 방법을 제공하는 것이다.
상기한 목적을 달성하기 위한 본 발명에 따른 시스템의 취약점 정량화 방법은
시스템의 취약점 식별 결과 각각을 해당 시스템의 취약점 식별 결과를 점수계산에 적용되도록 취약점 점수로 변환하는 단계; 상기 취약점 점수 중 상기 시스템에 해당하는 기술분야 안전도 점수와 관리분야 안전도 점수를 토대로 상기 시스템에 해당하는 대상기관 안전도 점수를 계산하는 단계; 상기 시스템의 업무망과 외부망의 분리 상황을 망 분리 점수로 변환하는 단계; 상기 대상기관 안전도 점수와 상기 망 분리 점수를 토대로 중간 점수를 계산하는 단계; 및 상기 중간 점수와 모의 침투 등급을 이용하여 최종적으로 상기 시스템의 종합 점수를 계산하여 시스템의 취약점을 정량화하는 단계를 포함한다.
이 때, 상기 대상기관 안전도 점수를 계산하는 단계는 상기 기술분야 안전도 점수와 상기 관리분야 안전도 점수를 설정한 비율에 따라 합산하여 상기 대상기관 안전도 점수를 계산하는 것을 특징으로 한다.
이 때, 상기 대상기관 안전도 점수를 계산하는 단계는 상기 시스템의 취약점 식별 결과 중에서 기술적으로 식별된 취약점을 상기 기술분야 안전도 점수로 변환하는 단계; 및 상기 시스템의 취약점 식별 결과 중에서 상기 시스템의 관리에 관한 취약점을 상기 관리분야 안전도 점수로 변환하는 단계를 포함한다.
이 때, 상기 기술분야 안전도 점수로 변환하는 단계는 상기 기술적으로 식별된 취약점에 해당하는 점수와 상기 취약점 점수의 합을 이용하여 하는 것을 특징으로 한다.
이 때, 상기 관리분야 안전도 점수로 변환하는 단계는 상기 시스템의 관리에 관한 취약점에 해당하는 점수와 상기 취약점 점수의 합을 이용하여 하는 것을 특징으로 한다.
이 때, 상기 시스템의 종합 점수를 계산하는 단계 이전에 상기 시스템의 취약점 식별 결과 각각에 해당하는 취약점을 조합하고, 조합한 취약점을 복수개의 경로의 모의 침투를 시도하는 단계; 및 상기 시도에서 성공한 모의 침투에서의 침투시도 위치 및 침투 결과에 따라 상기 모의 침투 등급을 산출하는 단계를 더 포함하는 것을 특징으로 한다.
이 때, 상기 시스템의 취약점을 정량화하는 단계는 상기 모의 침투 등급에 따라 상기 중간 점수에 가중치를 적용하여 상기 종합 점수를 계산하는 것을 특징으로 한다.
또한, 본 발명의 일실시예에 따른 시스템의 취약점 정량화 장치는
시스템의 취약점 식별 결과 각각을 해당 시스템의 취약점 식별 결과를 점수계산에 적용되도록 취약점 점수로 변환하는 취약점 계산부; 상기 취약점 점수 중 기술분야 안전도 점수와 관리분야 안전도 점수를 토대로 상기 시스템에 해당하는 대상기관 안전도 점수를 계산하는 대상기관 안전도 계산부; 상기 시스템의 업무망과 외부망의 분리 상황을 망 분리 점수로 변환하는 망 분리 현황 계산부; 상기 대상기관 안전도 점수와 상기 망 분리 점수를 토대로 중간 점수를 계산하는 중간 계산부; 및 상기 중간 점수와 모의 침투 등급을 이용하여 최종적으로 상기 시스템의 종합 점수를 계산하여 상기 시스템의 취약점을 정량화하는 최종 점수 계산부를 포함한다.
이 때, 상기 대상기관 안전도 계산부는 상기 기술분야 안전도 점수와 상기 관리분야 안전도 점수를 설정한 비율에 따라 합산하여 상기 대상기관 안전도 점수를 계산하는 것을 특징으로 한다.
이 때, 상기 시스템의 취약점 정량화 장치는 상기 시스템의 취약점 식별 결과 중에서 기술적으로 식별된 취약점을 상기 기술분야 안전도 점수로 점수화하는 기술분야 안전도 계산부; 및 상기 시스템의 취약점 식별 결과 중에서 상기 시스템의 관리에 관한 취약점을 상기 관리분야 안전도 점수로 점수화하는 관리분야 안전도 계산부를 더 포함한다.
이 때, 상기 시스템의 취약점 정량화 장치는 상기 시스템의 취약점 식별 결과 각각에 해당하는 취약점을 조합하고, 조합한 취약점을 복수개의 경로의 모의 침투를 시도하여, 상기 시도에서 성공한 모의 침투에서의 침투시도 위치 및 침투 결과에 따라 상기 모의 침투 등급을 산출하는 모 등급 관리부를 더 포함한다.
이 때, 상기 최종 점수 계산부는 상기 모의 침투 등급에 따라 상기 중간 점수에 가중치를 적용하여 상기 종합 점수를 계산하는 것을 특징으로 한다.
본 발명에 따르면, 시스템의 취약점을 정량화하는 장치 및 그 방법은 수행자의 주관이 개입될 수 있는 부분을 최소화하여 사람에 따라 평가결과가 달라지는 문제점을 최소화하였다.
또한, 본 발명은 시스템의 취약점을 정량화하는 장치 및 그 방법은 시스템의 관리자에게 예를 들어, "어떠한 보호대책이 구현되면 종합 점수가 몇점까지 올라갈 수 있다"와 같이 가시적인 결과를 제공할 수 있다.
도 1은 본 발명의 실시예에 따른 시스템의 취약점 정량화 장치를 개략적으로 나타내는 구성도이다.
도 2 내지 도 4는 본 발명의 실시예에 따른 시스템의 취약점 정량화 장치에 적용되는 참고도이다.
도 5는 본 발명의 실시예에 따른 시스템의 취약점을 정량화하는 방법을 나타내는 흐름도이다.
본 발명을 첨부된 도면을 참조하여 상세히 설명하면 다음과 같다. 여기서, 반복되는 설명, 본 발명의 요지를 불필요하게 흐릴 수 있는 공지 기능, 및 구성에 대한 상세한 설명은 생략한다. 본 발명의 실시형태는 당 업계에서 평균적인 지식을 가진 자에게 본 발명을 보다 완전하게 설명하기 위해서 제공되는 것이다. 따라서, 도면에서의 요소들의 형상 및 크기 등은 보다 명확한 설명을 위해 과장될 수 있다.
이하, 본 발명에 따른 바람직한 실시예 따른 시스템의 취약점 정량화 장치 및 그 방법에 대하여 첨부한 도면을 참조하여 상세하게 설명한다.
도 1은 본 발명의 실시예에 따른 시스템의 취약점 정량화 장치를 개략적으로 나타내는 구성도이다. 또한, 도 2 내지 도 4는 본 발명의 실시예에 따른 시스템의 취약점 정량화 장치에 적용되는 참고도이다.
먼저, 시스템의 취약점 정량화 장치(10)는 시스템의 취약점을 분석하거나 평가한 결과(이하, "시스템의 취약점 식별 결과"라고도 함.)를 포함하거나, 외부로부터 전달 받을 수 있으며, 이에 한정되지 않는다.
도 1을 참고하면, 시스템의 취약점 정량화 장치(100)는 취약점 계산부(110), 기술분야 안전도 계산부(120), 관리분야 안전도 계산부(130), 대상기관 안전도 계산부(140), 망 분리 현황 계산부(150), 중간 계산부(160), 등급 관리부(170) 및 최종 점수 계산부(180)를 포함한다.
취약점 계산부(110)는 시스템의 취약점 식별 결과 각각을 해당 시스템의 취약점 식별 결과를 점수 계산에 적용되도록 취약점 점수로 변환한다. 여기서, 취약점 점수는 예를 들어, 0점에서 10점까지의 점수로 표현 할 수 있다.
예를 들어, 서버, 웹 응용프로그램에 대한 취약점 식별 결과는 CVSS(Common Vulnerability Scoring System) 2.0을 기반으로 계산하고, 관리 분야와 네트워크, DB 분야에 대한 취약점 식별 결과는 별도의 방법을 사용할 수 있다.
기술분야 안전도 계산부(120)는 시스템의 취약점 식별 결과 중에서 기술적으로 식별된 취약점을 종합하여 기술분야 안전도 점수를 계산한다. 여기서, 기술적으로 식별된 취약점은 시스템의 기술적인 부분에 관한 취약점을 분석하거나 평가한 결과이다.
구체적으로, 기술분야 안전도 계산부(120)는 수학식 1과 같이 기술분야 안전도 점수를 계산할 수 있다.
[수학식 1]
기술분야 안전도 점수
= 100 - (기술적으로 식별된 취약점 점수 / 최대 취약점 점수) * 100
수학식 1에서, 기술적으로 식별된 취약점 점수는 기술적으로 식별된 취약점을 점수로 변환한 결과이고, 최대 취약점 점수는 시스템의 취약점 식별 결과에 해당하는 취약점 점수의 합이다. 예를 들어, A 시스템이 유닉스 서버이고, 유닉스 서버의 취약점을 분석하거나 평가한 결과에 해당하는 취약점 점수의 합을 1000점이라고 가정한다. 여기서, 유닉스 서버의 기술적으로 식별된 취약점의 점수의 합을 80점이라고 하면, 수학식 1에 의해 A 시스템의 기술분야 안전도 점수는 92점이 된다.
관리분야 안전도 계산부(130)는 시스템의 취약점 식별 결과 중에서 관리분야에 해당하는 취약점을 종합하여 관리분야 안전도 점수를 계산한다. 여기서, 관리분야에 해당하는 취약점은 시스템의 관리에 관한 취약점을 분석하거나 평가한 결과이다.
구체적으로, 관리분야 안전도 계산부(130)는 수학식 2와 같이 관리분야 안전도 점수를 계산할 수 있다.
[수학식 2]
관리분야 안전도 점수
= 100 - (관리분야에 해당하는 취약점 점수 / 최대 취약점 점수) * 100
수학식 2에서, 최대 취약점 점수는 수학식 1의 최대 취약점 점수와 동일한 점수로, 시스템의 취약점 식별 결과에 해당하는 취약점 점수의 합이다.
대상기관 안전도 계산부(140)는 기술분야 안전도 점수와 관리분야 안전도 점수를 설정한 비율(α, β)에 따라 합산하여 대상기관 안전도 점수를 계산한다. 여기서, 설정한 비율 즉, 기술분야 안전도 점수에 적용하는 비율과 관리분야 안전도 점수에 적용하는 비율의 합(α + β)은 1이 되도록 설정한다.
대상기관 안전도 점수는 수학식 3과 같이 계산한다.
[수학식 3]
대상기관 안전도 점수
= (기술분야 안전도 점수 * α) + (관리분야 안전도 점수 * β)
망 분리 현황 계산부(150)는 시스템의 업무망과 외부망(예를 들어, 인터넷)의 분리 현황을 망 분리 점수로 변환한다.
예를 들어, 국가, 공공기관의 경우에는 구성원이 업무를 수행하는 업무망과 인터넷을 사용할 수 있는 외부망이 분리되어 있는 경우가 있다. 여기서, 망 분리 현황 계산부(150)는 업무망과 외부망이 분리되어 있는 형태(도 2의 망 분리 상황)에 따라 망 분리 점수를 도 2와 같이 할당할 수 있다.
중간 계산부(160)는 대상기관 안전도 점수와 망 분리 점수를 설정한 비율(γ)에 따라 합산하여 중간 점수를 계산한다.
등급 관리부(170)는 시스템의 취약점 식별 결과에 해당하는 취약점을 조합하고, 조합한 취약점을 복수개의 경로의 모의 침투에 적용하여 모의 침투 등급을 산출한다.
구체적으로, 등급 관리부(170)는 시스템의 취약점 식별 결과에 해당하는 취약점을 조합하여 복수개의 경로의 모의 침투를 시도한다. 다음, 등급 관리부(170)는 이와 같은 시도에서 성공한 모의 침투에서의 침투시도 위치 및 침투 결과에 따라 모의 침투 등급을 산출한다. 예를 들어, 등급 관리부(170)는 성공한 모의 침투에서의 침투 결과 및 침투시도 위치에 따라 도 3과 같이 모의 침투 등급을 산출한다. 여기서, 침투 결과는 관리자가 권한을 획득한 경우, 일반 사용자가 권한을 획득한 경우, 모의 침투로 인하여 시스템의 정상 운영에 방해가 가능한 경우 등을 포함할 수 있으며, 침투 시도 위치는 외부(인터넷), 시스템이 적용된 기관 내 타 시스템, 동일 시스템일 수 있다.
최종 점수 계산부(180)는 중간 점수에 모의 침투 등급을 적용하여 종합 점수를 계산한다. 구체적으로, 최종 점수 계산부(180)는 모의 침투 등급에 따라 중간 점수에 가중치(δ∈{80%, 85%, 90%, 95%, 100%})를 적용하여 종합 점수를 계산한다. 예를 들어, 최종 점수 계산부(180)는 도 4와 같이, 중간 점수가 94점인 경우에 모의 침투 등급에 따라 종합 점수를 계산한다.
다음, 시스템의 취약점을 정량화하는 방법을 도 5를 참조하여 상세하게 설명한다.
도 5는 본 발명의 실시예에 따른 시스템의 취약점을 정량화하는 방법을 나타내는 흐름도이다.
도 5를 참고하면, 시스템의 취약점 정량화 장치(100)는 시스템의 취약점 식별 결과를 취약점 점수로 변환변환한다(S510). 여기서, 취약점 점수는 예를 들어, 0점에서 10점까지의 점수로 표현 할 수 있다.
시스템의 취약점 정량화 장치(100)는 시스템의 취약점 식별 결과 중에서 기술적으로 식별된 취약점을 종합하여 기술분야 안전도 점수를 계산한다(S520). S520단계에서, 기술분야 안전도 점수는 수학식 1과 같이 계산된다.
시스템의 취약점 정량화 장치(100)는 시스템의 취약점 식별 결과 중에서 관리분야에 해당하는 취약점을 종합하여 관리분야 안전도 점수를 계산한다(S530). S530 단계에서, 관리분야 안전도 점수는 수학식 2와 같이 계산된다.
시스템의 취약점 정량화 장치(100)는 기술분야 안전도 점수와 관리분야 안전도 점수를 설정한 비율(α, β)에 따라 합산하여 대상기관 안전도 점수를 계산한다(S540). 여기서, 설정한 비율 즉, 기술분야 안전도 점수에 적용하는 비율과 관리분야 안전도 점수에 적용하는 비율의 합(α + β)은 1이 되도록 설정한다. S540 단계에서, 대상기관 안전도 점수는 수학식 3과 같이 계산된다.
시스템의 취약점 정량화 장치(100)는 시스템의 업무망과 외부망(예를 들어, 인터넷)의 분리 현황을 변환한다(S550). 여기서, 시스템의 취약점 정량화 장치(100)는 업무망과 외부망이 분리되어 있는 형태에 따라 망 분리 점수를 도 2와 같이 할당할 수 있다.
시스템의 취약점 정량화 장치(100)는 대상기관 안전도 점수와 망 분리 점수를 설정한 비율(γ)에 따라 합산하여 중간 점수를 계산한다(S560).
시스템의 취약점 정량화 장치(100)는 시스템의 취약점 식별 결과에 해당하는 취약점을 조합하여 복수개의 경로의 모의 침투를 시도하고, 시도한 결과 중 성공한 모의 침투에서의 침투시도 위치 및 침투 결과에 따라 모의 침투 등급을 산출한다(S570). 여기서, 시스템의 취약점 정량화 장치(100)는 침투시도 위치 및 침투 결과에 따라 도 3과 같이 모의 침투 등급을 산출할 수 있다.
시스템의 취약점 정량화 장치(100)는 중간 점수에 모의 침투 등급을 적용하여 종합 점수를 계산하여 시스템의 취약점을 정량화한다(S580).
이와 같이, 본 발명이 실시예에 따른 시스템의 취약점 정량화 장치(100)는 시스템의 취약점을 분석하거나 평가한 결과를 정량화함으로써, 시스템의 상태를 직관적 및 객관적으로 표현할 수 있다.
이상에서와 같이 도면과 명세서에서 최적의 실시예가 개시되었다. 여기서 특정한 용어들이 사용되었으나, 이는 단지 본 발명을 설명하기 위한 목적에서 사용된 것이지 의미 한정이나 특허청구범위에 기재된 본 발명의 범위를 제한하기 위하여 사용된 것은 아니다. 그러므로, 본 기술 분야의 통상의 지식을 가진자라면 이로부터 다양한 변형 및 균등한 타 실시예가 가능하다는 점을 이해할 것이다. 따라서, 본 발명의 진정한 기술적 보호범위는 첨부된 특허청구범위의 기술적 사상에 의해 정해져야 할 것이다.
Claims (12)
- 시스템의 취약점 식별 결과 각각을 해당 시스템의 취약점 식별 결과를 점수계산에 적용되도록 취약점 점수로 변환하는 단계;상기 취약점 점수 중 상기 시스템에 해당하는 기술분야 안전도 점수와 관리분야 안전도 점수를 토대로 상기 시스템에 해당하는 대상기관 안전도 점수를 계산하는 단계;상기 시스템의 업무망과 외부망의 분리 상황을 망 분리 점수로 변환하는 단계;상기 대상기관 안전도 점수와 상기 망 분리 점수를 토대로 중간 점수를 계산하는 단계; 및상기 중간 점수와 모의 침투 등급을 이용하여 최종적으로 상기 시스템의 종합 점수를 계산하여 시스템의 취약점을 정량화하는 단계를 포함하는 시스템의 취약점 정량화 방법.
- 청구항 1에 있어서,상기 대상기관 안전도 점수를 계산하는 단계는상기 기술분야 안전도 점수와 상기 관리분야 안전도 점수를 설정한 비율에 따라 합산하여 상기 대상기관 안전도 점수를 계산하는 것을 특징으로 하는 시스템의 취약점 정량화 방법.
- 청구항 1에 있어서,상기 대상기관 안전도 점수를 계산하는 단계는상기 시스템의 취약점 식별 결과 중에서 기술적으로 식별된 취약점을 상기 기술분야 안전도 점수로 변환변환하는 단계; 및상기 시스템의 취약점 식별 결과 중에서 상기 시스템의 관리에 관한 취약점을 상기 관리분야 안전도 점수로 변환하는 단계를 포함하는 것을 특징으로 하는 시스템의 취약점 정량화 방법.
- 청구항 3에 있어서,상기 기술분야 안전도 점수로 변환하는 단계는상기 기술적으로 식별된 취약점에 해당하는 점수와 상기 취약점 점수의 합을 이용하여 하는 것을 특징으로 하는 시스템의 취약점 정량화 방법.
- 청구항 3에 있어서,상기 관리분야 안전도 점수로 변환하는 단계는상기 시스템의 관리에 관한 취약점에 해당하는 점수와 상기 취약점 점수의 합을 이용하여 하는 것을 특징으로 하는 시스템의 취약점 정량화 방법.
- 청구항 1에 있어서,상기 시스템의 종합 점수를 계산하는 단계 이전에상기 시스템의 취약점 식별 결과 각각에 해당하는 취약점을 조합하고, 조합한 취약점을 복수개의 경로의 모의 침투를 시도하는 단계; 및상기 시도에서 성공한 모의 침투에서의 침투시도 위치 및 침투 결과에 따라 상기 모의 침투 등급을 산출하는 단계를 더 포함하는 것을 특징으로 하는 시스템의 취약점 정량화 방법.
- 청구항 1에 있어서,상기 시스템의 취약점을 정량화하는 단계는상기 모의 침투 등급에 따라 상기 중간 점수에 가중치를 적용하여 상기 종합 점수를 계산하는 것을 특징으로 하는 시스템의 취약점 정량화 방법.
- 시스템의 취약점 식별 결과 각각을 해당 시스템의 취약점 식별 결과를 점수계산에 적용되도록 취약점 점수로 변환하는 취약점 계산부;상기 취약점 점수 중 기술분야 안전도 점수와 관리분야 안전도 점수를 토대로 상기 시스템에 해당하는 대상기관 안전도 점수를 계산하는 대상기관 안전도 계산부;상기 시스템의 업무망과 외부망의 분리 상황을 망 분리 점수로 변환하는 망 분리 현황 계산부;상기 대상기관 안전도 점수와 상기 망 분리 점수를 토대로 중간 점수를 계산하는 중간 계산부; 및상기 중간 점수와 모의 침투 등급을 이용하여 최종적으로 상기 시스템의 종합 점수를 계산하여 상기 시스템의 취약점을 정량화하는 최종 점수 계산부를 포함하는 시스템의 취약점 정량화 장치.
- 청구항 8에 있어서,상기 대상기관 안전도 계산부는상기 기술분야 안전도 점수와 상기 관리분야 안전도 점수를 설정한 비율에 따라 합산하여 상기 대상기관 안전도 점수를 계산하는 것을 특징으로 하는 시스템의 취약점 정량화 장치.
- 청구항 8에 있어서,상기 시스템의 취약점 식별 결과 중에서 기술적으로 식별된 취약점을 상기 기술분야 안전도 점수로 변환하는 기술분야 안전도 계산부; 및상기 시스템의 취약점 식별 결과 중에서 상기 시스템의 관리에 관한 취약점을 상기 관리분야 안전도 점수로 변환하는 관리분야 안전도 계산부를 더 포함하는 시스템의 취약점 정량화 장치.
- 청구항 8에 있어서,상기 시스템의 취약점 식별 결과 각각에 해당하는 취약점을 조합하고, 조합한 취약점을 복수개의 경로의 모의 침투를 시도하여, 상기 시도에서 성공한 모의 침투에서의 침투시도 위치 및 침투 결과에 따라 상기 모의 침투 등급을 산출하는 모 등급 관리부를 더 포함하는 시스템의 취약점 정량화 장치.
- 청구항 8에 있어서,상기 최종 점수 계산부는상기 모의 침투 등급에 따라 상기 중간 점수에 가중치를 적용하여 상기 종합 점수를 계산하는 것을 특징으로 하는 시스템의 취약점 정량화 장치.
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US14/779,435 US9692779B2 (en) | 2013-03-26 | 2013-10-21 | Device for quantifying vulnerability of system and method therefor |
| CN201380076524.2A CN105210078B (zh) | 2013-03-26 | 2013-10-21 | 用于量化系统的漏洞的装置及其方法 |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR10-2013-0031955 | 2013-03-26 | ||
| KR1020130031955A KR101442691B1 (ko) | 2013-03-26 | 2013-03-26 | 시스템의 취약점 정량화 장치 및 그 방법 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014157797A1 true WO2014157797A1 (ko) | 2014-10-02 |
Family
ID=51624730
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2013/009389 Ceased WO2014157797A1 (ko) | 2013-03-26 | 2013-10-21 | 시스템의 취약점 정량화 장치 및 그 방법 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US9692779B2 (ko) |
| KR (1) | KR101442691B1 (ko) |
| CN (1) | CN105210078B (ko) |
| WO (1) | WO2014157797A1 (ko) |
Families Citing this family (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP3100192B1 (en) * | 2014-01-27 | 2018-10-31 | Cronus Cyber Technologies Ltd. | Automated penetration testing device, method and system |
| WO2016064919A1 (en) * | 2014-10-21 | 2016-04-28 | Abramowitz Marc Lauren | Dynamic security rating for cyber insurance products |
| US11070592B2 (en) * | 2015-10-28 | 2021-07-20 | Qomplx, Inc. | System and method for self-adjusting cybersecurity analysis and score generation |
| CN106611126A (zh) * | 2016-12-22 | 2017-05-03 | 西北大学 | 一种漏洞严重性评估及修补方法 |
| KR102153926B1 (ko) | 2017-08-10 | 2020-09-10 | 한국전자통신연구원 | 네트워크 보안 강화 장치 및 그 방법 |
| US10776495B2 (en) * | 2018-05-10 | 2020-09-15 | Microsoft Technology Licensing, Llc | Systems and methods for attributing security vulnerabilities to a configuration of a client device |
| US11741196B2 (en) | 2018-11-15 | 2023-08-29 | The Research Foundation For The State University Of New York | Detecting and preventing exploits of software vulnerability using instruction tags |
| KR102324489B1 (ko) | 2019-11-22 | 2021-11-11 | 한국전자통신연구원 | 산업 제어 시스템을 위한 위험도 산출 방법 및 이를 위한 장치 |
| KR102650732B1 (ko) | 2020-08-06 | 2024-03-26 | 한국전자통신연구원 | 컴퓨터 네트워크의 공격 취약점 예측 방법 및 장치 |
| CN112491916B (zh) * | 2020-12-04 | 2023-03-14 | 北京天融信网络安全技术有限公司 | 漏洞评估方法、装置、设备及存储介质 |
| KR102712981B1 (ko) * | 2021-10-26 | 2024-10-02 | 한충희 | 봉쇄와 방어 수준 분석을 기반으로 한 사이버보안 위험평가 시스템 및 그 방법 |
| US12326941B2 (en) * | 2022-01-04 | 2025-06-10 | International Business Machines Corporation | Dynamic prioritization of vulnerability exclusion renewals |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20060067124A (ko) * | 2004-12-14 | 2006-06-19 | 한국전자통신연구원 | 가입자 네트워크 정보 보호 수준 평가를 위한 방법 및 그장치 |
| US20090024663A1 (en) * | 2007-07-19 | 2009-01-22 | Mcgovern Mark D | Techniques for Information Security Assessment |
| US20090024627A1 (en) * | 2007-07-17 | 2009-01-22 | Oracle International Corporation | Automated security manager |
| US20120151594A1 (en) * | 2002-01-15 | 2012-06-14 | Mcafee, Inc. | System and method for network vulnerability detection and reporting |
| KR101199967B1 (ko) * | 2011-12-23 | 2012-11-12 | 주식회사 한생화장품 | 식물성 전분 시트 |
Family Cites Families (15)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| AU2002243763A1 (en) * | 2001-01-31 | 2002-08-12 | Internet Security Systems, Inc. | Method and system for configuring and scheduling security audits of a computer network |
| KR100450209B1 (ko) * | 2002-09-27 | 2004-09-30 | 한국정보보호진흥원 | 네트워크 취약성 진단 시스템 및 방법 |
| US20060129810A1 (en) | 2004-12-14 | 2006-06-15 | Electronics And Telecommunications Research Institute | Method and apparatus for evaluating security of subscriber network |
| KR100902116B1 (ko) | 2006-11-23 | 2009-06-09 | 한국전자통신연구원 | 정보 자산 식별 및 평가 방법 |
| US7937353B2 (en) * | 2007-01-15 | 2011-05-03 | International Business Machines Corporation | Method and system for determining whether to alter a firewall configuration |
| KR100851521B1 (ko) | 2007-01-31 | 2008-08-11 | 성균관대학교산학협력단 | 취약점 분석을 위한 사이버 공격 시스템 및 그 공격 방법 |
| KR101013077B1 (ko) * | 2007-07-30 | 2011-02-14 | 채문창 | 정량적 안전지수 산출에 근거한 it 위험 관리 방법 및시스템 |
| KR100955281B1 (ko) | 2007-10-18 | 2010-04-30 | 한국정보보호진흥원 | 위협 관리를 위한 보안 위험도 평가 방법 |
| KR100961180B1 (ko) * | 2008-05-22 | 2010-06-09 | 한국전자통신연구원 | Pc 보안 점검 장치 및 방법 |
| US8160855B2 (en) * | 2008-06-26 | 2012-04-17 | Q1 Labs, Inc. | System and method for simulating network attacks |
| CN101447898B (zh) * | 2008-11-19 | 2012-12-05 | 中国人民解放军信息安全测评认证中心 | 一种用于网络安全产品的测试系统及测试方法 |
| US9317692B2 (en) * | 2009-12-21 | 2016-04-19 | Symantec Corporation | System and method for vulnerability risk analysis |
| KR20110130203A (ko) * | 2010-05-27 | 2011-12-05 | 전덕조 | It 보안 위험 관리 장치 및 방법 |
| KR101189967B1 (ko) | 2011-06-30 | 2012-10-12 | 에스케이씨앤씨 주식회사 | 시스템 자동 감사 방법 및 이를 적용한 자동 감사 시스템 |
| CN102238038A (zh) * | 2011-07-26 | 2011-11-09 | 北京神州绿盟信息安全科技股份有限公司 | 一种网络设备的安全性评估方法及装置 |
-
2013
- 2013-03-26 KR KR1020130031955A patent/KR101442691B1/ko active Active
- 2013-10-21 CN CN201380076524.2A patent/CN105210078B/zh not_active Expired - Fee Related
- 2013-10-21 WO PCT/KR2013/009389 patent/WO2014157797A1/ko not_active Ceased
- 2013-10-21 US US14/779,435 patent/US9692779B2/en not_active Expired - Fee Related
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20120151594A1 (en) * | 2002-01-15 | 2012-06-14 | Mcafee, Inc. | System and method for network vulnerability detection and reporting |
| KR20060067124A (ko) * | 2004-12-14 | 2006-06-19 | 한국전자통신연구원 | 가입자 네트워크 정보 보호 수준 평가를 위한 방법 및 그장치 |
| US20090024627A1 (en) * | 2007-07-17 | 2009-01-22 | Oracle International Corporation | Automated security manager |
| US20090024663A1 (en) * | 2007-07-19 | 2009-01-22 | Mcgovern Mark D | Techniques for Information Security Assessment |
| KR101199967B1 (ko) * | 2011-12-23 | 2012-11-12 | 주식회사 한생화장품 | 식물성 전분 시트 |
Also Published As
| Publication number | Publication date |
|---|---|
| US9692779B2 (en) | 2017-06-27 |
| CN105210078B (zh) | 2018-07-24 |
| CN105210078A (zh) | 2015-12-30 |
| US20160057164A1 (en) | 2016-02-25 |
| KR101442691B1 (ko) | 2014-09-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2014157797A1 (ko) | 시스템의 취약점 정량화 장치 및 그 방법 | |
| Modi et al. | A novel framework for intrusion detection in cloud | |
| KR102381277B1 (ko) | 사이버 공격을 방어하기 위한 보안 방법 및 장치 | |
| CN109040119B (zh) | 一种智能楼宇网络的漏洞检测方法和装置 | |
| CN107483484A (zh) | 一种攻击防护演练方法和装置 | |
| Bitton et al. | Evaluating the information security awareness of smartphone users | |
| CN113992414A (zh) | 数据的访问方法、装置及设备 | |
| CN104852916A (zh) | 一种基于社会工程学的网页验证码识别方法及系统 | |
| WO2011090329A2 (ko) | 악성 코드 감염 차단 장치 및 시스템과 그 방법 | |
| Hussain et al. | Penetration testing in system administration | |
| Anselmi et al. | Copsec: Compliance-oriented iot security and privacy evaluation framework | |
| CN108900328A (zh) | 一种电网网络数据安全测试系统及方法 | |
| WO2014175704A1 (ko) | 웹사이트 로그인 및 개인정보 보안을 위한 홍채인증 시스템 및 그 방법 | |
| CN109120626A (zh) | 安全威胁处理方法、系统、安全感知服务器及存储介质 | |
| CN114756866A (zh) | 动态安全防护的方法、装置、存储介质及电子设备 | |
| Labuschagne et al. | Developing a capability to classify technical skill levels within a cyber range | |
| KR102020986B1 (ko) | 블록체인기반의 신뢰 네트워크 시스템 | |
| WO2020197097A1 (ko) | 단일 인증 서비스 시스템 및 방법 | |
| Savaglia et al. | CYBERSECURITY VULNERABILITY ANALYSIS VIA VIRTUALIZATION. | |
| CN105487936A (zh) | 云环境下面向等级保护的信息系统安全性测评方法 | |
| CN117610003A (zh) | 一种基于国产桌面终端的可信度量及认证方法 | |
| WO2015076522A1 (ko) | Otid를 이용한 인터넷 보안 방법 및 시스템 | |
| CN113055366A (zh) | 一种社会工程学攻击仿真与验证量化评估方法 | |
| WO2015080378A1 (ko) | 공유 단말 식별 방법 및 그 시스템 | |
| CN117336097B (zh) | 一种基于大数据的网络信息安全管理方法及系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13879744 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 14779435 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 13879744 Country of ref document: EP Kind code of ref document: A1 |