사회공학 공격의 위험도 평가를 위한 지표 개발

초록

Due to the development of system performance and security technology, the first target of recent security attacks tends to be the people who operate the system, rather than the system itself. Therefore, one of the most crucial vulnerabilities is the people, which reflects the need for the human-centric security. To the best our knowledge, however, there is no previous works for such social engineering attacks through the analysis of risk assessment. In this paper, first we analyze the technologies of social engineering attacks and methodologies for common vulnerability assessment such as CVSS, CWSS, OWSAP Risk Rating Methodology. Then, based on the analysis, we develop risk assesment indexes for social engineering attacks.

키워드

Social engineering attack; Attack Risk assessment; Attack risk assessment index; Cyber security; Human-centric security; 사회공학 공격; 공격 위험도; 공격 위험도 평가지표; 사이버 보안; 사람 중심 보안
제목
사회공학 공격의 위험도 평가를 위한 지표 개발
저자
신동천; 박영후
DOI
10.14257/jse.2017.04.01
발행일
2017
저널명
보안공학연구논문지
권
14
호
2
페이지
143 ~ 156