연구 환경 내 침투형 악성코드의 행위 기반 분석과 자동 탐지 프레임워크

Automated Behavioral Analysis and Detection of Infiltration Malware in Research Laboratory Environments

초록

Research data and technical know-how are concentrated in laboratories across universities, institutes, and industry. As a result, they are increasingly targeted. Reports describe repeated APT intrusions and insider-error leaks, and major threat surveys note rising risk to research institutions. Signature-based detection has limits against infiltrating malware and covert, behavior-centric attacks.We emulated a laboratory network and replayed normal and malicious scenarios. Publicly available infiltrating malware was executed under containment to produce realistic logs. Key Windows event channels were collected and analyzed, with Sysmon as the primary source. We built and validated machine-learning detectors that combine n-gram text patterns with core behavioral features. Modeling used SMOTE on the training split only, and both hyperparameters and decision thresholds were tuned. Across models, we observed high accuracy with balanced F1 and AUC. This work presents a behavior-based anomaly-detection framework that can operate in real environments. The examples highlight threats characteristic of laboratories, and the framework offers a practical basis for strengthening organizational security.

키워드

침투형 악성코드Sysmon 로그행위 기반 탐지머신러닝자동화대응Fileless MalwareSysmon LogBehavior-Based DetectionMachine LearningAutomated Response
제목
연구 환경 내 침투형 악성코드의 행위 기반 분석과 자동 탐지 프레임워크
제목 (타언어)
Automated Behavioral Analysis and Detection of Infiltration Malware in Research Laboratory Environments
저자
이지민장항배
DOI
10.7838/jsebs.2025.30.4.001
발행일
2025-11
유형
Y
저널명
한국전자거래학회지
30
4
페이지
1 ~ 17