금융 폐쇄망 환경에서의 비인가 인터넷 접속 노드 탐지 기법

A Method for Detecting Unauthorized Internet Access Node in Private Financial Network

초록

Recently, many companies make efforts to enhance security to detect and prevent an APT(Advanced Persistent Treat) attack that mainly target on the companies' PC devices. Most global companies run several branch offices that have numerous PC devices, but they are not easily controlled by a central security policy. Although security policies enforce to prevent unauthorized internet access, there are various detour techniques such as using tethering, open VPN or RogueAP. If a company fails to control all end user's PC devices, this can threaten the company's overall security. Especially, this can be the most critical problem in finance business domain. In this paper, we introduce a method to detect unauthorized internet access node in the closed private network. We conduct this method to find out the unauthorized nodes against the security policy. We deploy this detection method in the real network of a finance company in South Korea. As a result, we can classify several types of unauthorized nodes, and improve the detection techniques.

키워드

Rogue APNACWhite listUnauthorized internet access nodeWIPS
제목
금융 폐쇄망 환경에서의 비인가 인터넷 접속 노드 탐지 기법
제목 (타언어)
A Method for Detecting Unauthorized Internet Access Node in Private Financial Network
저자
조형진김은진김휘강
발행일
2015
저널명
한국지식정보기술학회 논문지
10
6
페이지
653 ~ 664