임베디드 소프트웨어 보안성 검증을 위한 위협 기반 테스트 시나리오 설계 방법론 연구

A Threat-Based Test Scenario Methodology for Security Verification of Embedded Software
  • 이상태
  • 박지혜
  • 장항배
  • 장우현
  • 김사연
  • 외 1명

초록

Embedded systems are widely used as core infrastructures in various domains such as defense, automotive, healthcare, and industrial control, and as their proliferation increases, so do the associated security threats. Existing security evaluation studies have largely been limited to functional quality assessments or the detection of individual vulnerabilities, failing to adequately reflect the complex threats present in real operational environments. To address this limitation, this study proposes a threat-based methodology for systematically verifying the security of embedded software. The methodology consists of step-by-step procedures including target analysis, threat analysis, test scenario design, scenario-based test execution, and subsequent modification and improvement. It incorporates the STRIDE and Attack Tree techniques, while also leveraging OWASP, CWE/SANS, NVD, and the “Software Development Security Guide” to integrate the latest threat factors. Furthermore, a survey-based validation with 12 experts confirmed that the methodology was highly rated in terms of systematic structure, effectiveness of the verification process, and scalability, while applicability to diverse environments and risk management aspects were identified as areas for future refinement. This research holds significance in logically and systematically structuring embedded software security evaluation, contributing not only to academic advancement but also to practical applicability.

키워드

Advancement of TechnologyEmbedded SoftwareTest ScenarioSecurity ThreatSecurity Verification
제목
임베디드 소프트웨어 보안성 검증을 위한 위협 기반 테스트 시나리오 설계 방법론 연구
제목 (타언어)
A Threat-Based Test Scenario Methodology for Security Verification of Embedded Software
저자
이상태박지혜장항배장우현김사연이올미
DOI
10.23023/JPT.2025.13.5.113
발행일
2025-10
유형
Y
저널명
Journal of Platform Technology
13
5
페이지
113 ~ 123