Browse > Article
http://dx.doi.org/10.5573/ieek.2013.50.2.060

A Security Monitoring System for Security Information Sharing and Cooperative Countermeasure  

Kim, Ki-Young (Cyber Security-Convergence Research Laboratory, Electronics and Telecommunications Research Institute)
Lee, Sung-Won (Cyber Security-Convergence Research Laboratory, Electronics and Telecommunications Research Institute)
Kim, Jong-Hyun (Cyber Security-Convergence Research Laboratory, Electronics and Telecommunications Research Institute)
Publication Information
Journal of the Institute of Electronics and Information Engineers / v.50, no.2, 2013 , pp. 60-69 More about this Journal
Abstract
Highlighted by recent security breaches including Google, Western Energy Company, and the Stuxnet infiltration of Iranian nuclear sites, Cyber warfare attacks pose a threat to national and global security. In particular, targeted attacks such as APT exploiting a high degree of stealthiness over a long period, has extended their victims from PCs and enterprise servers to government organizations and critical national infrastructure whereas the existing security measures exhibited limited capabilities in detecting and countermeasuring them. As a solution to fight against such attacks, we designed and implemented a security monitoring system, which shares security information and helps cooperative countermeasure. The proposed security monitoring system collects security event logs from heterogeneous security devices, analyses them, and visualizes the security status using 3D technology. The capability of the proposed system was evaluated and demonstrated throughly by deploying it under real network in a ISP for a week.
Keywords
통합보안관리;전역네트워크 위협;협력대응기반;보안정보공유;
Citations & Related Records
연도 인용수 순위
  • Reference
1 블루코트 보안 보고서: APT(지능형 타깃 지속 공격, Advanced Persistent Threat), 2011년 11월
2 시만텍, ISTR 제17호, "인터넷 보안위협 보고서", 2011년 5월
3 NARS 현안보고서, 제48호, "7.7 DDoS 사고"대응의 문제점과 재발방지 방안. 2009년 12월
4 조희정, 국회입법조사처, 3.4 DDos. 공격과 네트워크 보안의 과제. 2011년 3월.
5 정일안, 오진태, 장종수, "보안 정보 공유 기술 및 표준화 동향," 전자통신동향분석, 23권 4호, pp. 30-38, 2008년 8월.   과학기술학회마을
6 KISA 제2010-13호, 침해사고대응팀(CERT) 구축/ 운영 안내서. 2010년 1월
7 2012년 국가 정보보호백서
8 국가사이버안전센터, http://www.ncsc.go.kr/
9 인터넷침해대응센터, http://www.krcert.or.kr/
10 2012년 보안위협 전망, http://dailysecu.com/
11 IETF, RFC 3164, "The BSD Syslog Protocol", 2001년
12 IETF, RFC 6045, "Real-time Inter-network Defense," 2010년
13 IETF, RFC 4765, "The Intrusion Detection Message Exchange Format", 2007년
14 안철수연구소 보안매거진, "APT 공격의 비밀을 파헤치다", 2011년 10월.
15 IDG Tech Report, "은밀하고 끈질긴 위협 APT의 이해", 2011년 12월