상세 보기
연구 환경 내 침투형 악성코드의 행위 기반 분석과 자동 탐지 프레임워크
- 이지민;
- 장항배
초록
Research data and technical know-how are concentrated in laboratories across universities, institutes, and industry. As a result, they are increasingly targeted. Reports describe repeated APT intrusions and insider-error leaks, and major threat surveys note rising risk to research institutions. Signature-based detection has limits against infiltrating malware and covert, behavior-centric attacks.We emulated a laboratory network and replayed normal and malicious scenarios. Publicly available infiltrating malware was executed under containment to produce realistic logs. Key Windows event channels were collected and analyzed, with Sysmon as the primary source. We built and validated machine-learning detectors that combine n-gram text patterns with core behavioral features. Modeling used SMOTE on the training split only, and both hyperparameters and decision thresholds were tuned. Across models, we observed high accuracy with balanced F1 and AUC. This work presents a behavior-based anomaly-detection framework that can operate in real environments. The examples highlight threats characteristic of laboratories, and the framework offers a practical basis for strengthening organizational security.
키워드
- 제목
- 연구 환경 내 침투형 악성코드의 행위 기반 분석과 자동 탐지 프레임워크
- 제목 (타언어)
- Automated Behavioral Analysis and Detection of Infiltration Malware in Research Laboratory Environments
- 저자
- 이지민; 장항배
- 발행일
- 2025-11
- 유형
- Y
- 저널명
- 한국전자거래학회지
- 권
- 30
- 호
- 4
- 페이지
- 1 ~ 17