¸Þ´º °Ç³Ê¶Ù±â
Ã¥°¥ÇÇ Ãß°¡
ÆäÀÌÁö

28ÆäÀÌÁö ³»¿ë : °Ô µÇ¾ú´Ù. À̸¦ ±Øº¹Çϱâ À§ÇÏ¿©, JSON JavaScript Object Notation ±â¹ÝÀÇ STIX ¹öÀü 2.0ÀÌ »õ·ÎÀÌ Ãâ½ÃµÇ¾ú´Ù. °³¹ß °úÁ¤¿¡¼­ CybOX´Â STIX¿Í Åë ÇյǾú°í, TAXII´Â HTTP Representational State Transfer RESTful ±â¹ÝÀ¸·Î º¯°æµÇ¾ú´Ù[4]. ÇöÀç Åë¿ëµÇ´Â OASIS STIX/TAXII ÃÖÁ¾ ¹öÀüÀº 2.0À¸·Î, STIX °ü·Ã 5°³ÀÇ Ç¥ÁØ°ú TAXII °ü·Ã 1°³ ÀÇ Ç¥ÁØÀÌ 2017³â 7¿ù¿¡ ¹ß°£µÇ¾ú´Ù. °¢ Ç¥ÁØ¿¡ ´ëÇÑ °£·«ÇÑ ³»¿ëÀº ¡´Ç¥ 4¡µ¿¡¼­ ¼³¸íÇÏ°í ÀÖ´Ù. ÇöÀç ÀÏ¹Ý ¹®¼­·Î½á CTI¿¡ ´ëÇÑ ¸í¼¼¼­°¡ OASIS CTI TC¿¡¼­ °³¹ßµÇ°í ÀÖ´Ù. ÀÌ¿¡´Â FAQ¿Í Á¦Ç° ÇÁ ·Î¼¼½º, È®Àå ÇÁ·Î¼¼½º µîÀÌ Æ÷ÇԵǾî ÀÖ´Ù. ¶ÇÇÑ STIX/TAXII ¹öÀü 2.1À» À§ÇÑ ¹®¼­°¡ °³¹ßµÇ°í ÀÖÀ¸ ¸ç, ÇöÀç WD working draft ´Ü°èÀÌ´Ù. °³Á¤ ÀÛ¾÷ ÁßÀÇ ¹®¼­´Â [6]¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù. 2.3.2 TTA STIX/TAXIIÇ¥ÁØÈ­µ¿Çâ TTA¿¡¼­´Â Á¤º¸º¸È£±â¼úÀ§¿øȸ TC5 »çÀ̹öº¸¾È ÇÁ·ÎÁ§Æ®±×·ì PG503 ¿¡¼­ »çÀ̹öÀ§Çù Á¤º¸ °øÀ¯¸¦ À§ÇÑ Ç¥ÁØ°ú »çÀ̹öÀ§Çù Á¤º¸ Ç¥ÁØ ÁöÇ¥ °³¹ßÀ» ´ã ´çÇÏ°í ÀÖ´Ù. °³¹ßÇÏ´ø STIX 1.0ÀÌ STIX 2.0À¸·Î º¯ °æµÇ¾î ¹öÀü 1.0À¸·Î ÁøÇàÇÏ´ø ±¹³» ÁØ¿ëÇ¥ÁØÀ» Æó ÁöÇÏ°í STIX 2.0¿¡ ¸ÂÃß¾î ÃÑ 6°ÇÀÇ Ç¥ÁØÀ» äÅᤰ³ ¹ßµÇ¾úÀ¸¸ç, STIX ±â¹Ý »çÀ̹öÀ§Çù Á¤º¸ °øÀ¯ ü°è ¿Í ·¹°Å½Ã ŽÁö ü°è °£ ¿¬µ¿À» À§ÇÑ ½Ã½ºÅÛ ±¸Á¶¿¡ ´ëÇÑ TTA´ÜüǥÁصµ Á¦Á¤µÇ¾ú´Ù. °¢ Ç¥ÁØ¿¡ ´ëÇÑ °£ ·«ÇÑ ¼³¸íÀº ¡´Ç¥ 5¡µ¿¡¼­ ¼³¸íÇÏ°í ÀÖ´Ù. Ç¥ÁØ Ãʾȸí Ç¥ÁØ¸í ³»¿ë ºñ°í TTAE.OT-12.0019-Part1 ±¸Á¶È­µÈ À§Çù Á¤º¸ Ç¥Çö ±Ô°Ý STIXTM ¹öÀü 2.0 ? Á¦ 1ºÎSTIX ÇÙ½É °³³ä STIX Àü¹ÝÀûÀÎ °³³ä°ú STIX ¾ð¾îÀÇ Àüü ±¸Á¶¸¦ Á¤ÀÇ ÁØ¿ëÇ¥ÁØ TTAE.OT-12.0019-Part2 ±¸Á¶È­µÈ À§Çù Á¤º¸ Ç¥Çö ±Ô°Ý STIXTM ¹öÀü 2.0 ? Á¦ 2ºÎSTIX °´Ã¼ STIX°¡ »çÀ̹öÀ§Çù Á¤º¸¸¦ Ç¥ÇöÇϱâ À§ ÇÑ µµ¸ÞÀÎ ¿ÀºêÁ§Æ®¿Í °ü°è ¿ÀºêÁ§Æ® µîÀ» Á¤ÀÇ ÁØ¿ëÇ¥ÁØ TTAE.OT-12.0019-Part3 ±¸Á¶È­µÈ À§Çù Á¤º¸ Ç¥Çö ±Ô°Ý STIXTM ¹öÀü 2.0 ? Á¦ 3ºÎ»çÀ̹ö °üÃø ÄÚ¾î °³³ä STIX Cyber Observables Àü¹Ý¿¡ Àû¿ëµÇ´Â °³³ä Á¤ÀÇ ÁØ¿ëÇ¥ÁØ TTAE.OT-12.0019-Part4 ±¸Á¶È­µÈ À§Çù Á¤º¸ Ç¥Çö ±Ô°Ý STIXTM ¹öÀü 2.0 ? Á¦ 4ºÎ»çÀ̹ö °üÃø °´Ã¼ STIX ȤÀº ±× ¿Ü¿¡¼­ »ç¿ë °¡´ÉÇÑ Cyber Observable ÁýÇÕÀ» Á¤ÀÇ ÁØ¿ëÇ¥ÁØ TTAE.OT-12.0019-Part5 ±¸Á¶È­µÈ À§Çù Á¤º¸ Ç¥Çö ±Ô°Ý STIXTM ¹öÀü 2.0 ? Á¦ 5ºÎSTIX ÆÐÅÍ´× ³×Æ®¿öÅ©³ª ¿£µå Æ÷ÀÎÆ® »óÀÇ ¾ÇÀÇÀûÀÎ È° µ¿ °¨Áö¸¦ À§ÇÑ ¾ð¾î ÆÐÅÏÈ­ ÁØ¿ëÇ¥ÁØ TTAK.KO-12.0338 ±¸Á¶È­µÈ À§Çù Á¤º¸ Ç¥Çö ±Ô°Ý STIX 2.0 ¿¡ ´ëÇÑ À¯½ºÄÉÀ̽º »çÀ̹öÀ§Çù ºÐ¼®, ħÇØ ´ëÀÀ È°µ¿, »çÀ̹öÀ§Çù Á¤º¸ ±³È¯ µîÀÇ Àü¹ÝÀûÀÎ »ç À̹öÀ§Çù °ü¸® ü°è ¼ö¸³¿¡ Âü°íÇÒ ¼ö ÀÖ ´Â À¯½ºÄÉÀ̽º¸¦ Á¦½Ã °íÀ¯Ç¥ÁØ TTAK.KO-12.0326 STIX ±â¹Ý »çÀ̹öÀ§Çù Á¤º¸ °øÀ¯ ü°è ¿Í ·¹°Å½Ã ŽÁö ü°èÀÇ ¿¬µ¿À» À§ÇÑ ½Ã½ºÅÛ ±¸Á¶ STIX ±â¹Ý »çÀ̹öÀ§Çù Á¤º¸ °øÀ¯ ü°è¿Í ·¹°Å½Ã ŽÁö ü°è °£ ¿¬µ¿À» À§ÇÑ ½Ã½ºÅÛ ±¸Á¶ ¹× ¿ä±¸»çÇ×À» Á¤ÀÇ °íÀ¯Ç¥ÁØ ¡´Ç¥ 5¡µ TTA PG503¿¡¼­ °³¹ßµÈ STIX °ü·Ã Ç¥ÁØ T T A J o u r n a l v o l 1 8 626

ÆäÀÌÁö
Ã¥°¥ÇÇ Ãß°¡

29ÆäÀÌÁö ³»¿ë : 3. ¸ÎÀ½¸» º»°í¿¡¼­´Â »çÀ̹öÀ§Çù Á¤º¸ °øÀ¯ ü°è¿¡ ´ëÇÏ¿© ITU-T, OASIS¿¡¼­ °³¹ßµÈ ±¹Á¦ Ç¥ÁØÀÇ ÁÖ¿ä ³»¿ë°ú TTA PG503 »çÀ̹öº¸¾È ÇÁ·ÎÁ§Æ®±×·ì ¿¡¼­ Á¦Á¤µÈ STIX °ü·Ã ±¹³» Ç¥ÁØÀÇ ÁÖ¿ä ³»¿ëµéÀ» »ìÆ캸¾Ò´Ù. »çÀ̹öÀ§Çù Á¤º¸ °øÀ¯ ±â¼úÀº ±¹³» °¢ Á¤ºÎ ¹× ¹Î°£ ±â°üº° ħÇØ´ëÀÀ¼¾ÅÍÀÇ °íµµÈ­¿¡ ÇØ´çµÇ´Â °ÍÀ¸·Î ½á ¼Ò±Ô¸ð ³×Æ®¿öÅ© Â÷¿ø¿¡¼­ ´Ü¼ø ¸ð´ÏÅ͸µ ¹× º¸¾È Á¤Ã¥À» Àû¿ëÇÏ´Â ÇüŸ¦ ÃÊ¿ùÇÏ¿© ÇâÈÄ¿¡´Â ³×Æ®¿ö Å© Àüü¸¦ º¸¾È Á¦¾î ¿µ¿ªÀ¸·Î È®ÀåÇÏ¿© ¼­·Î ´Ù¸¥ °ü¸® µµ¸ÞÀÎ °£ »çÀ̹öÀ§Çù Á¤º¸ °øÀ¯¸¦ ÅëÇÑ Çù·Â ±â¹ÝÀÇ Á¾ÇÕÀûÀÎ ÅëÇÕ º¸¾ÈÁ¦¾î ü°è¸¦ ±¸ÃàÇϱâ À§ ÇØ ÇÊ¿äÇÏ´Ù. °á·ÐÀûÀ¸·Î ÁøÈ­ÇÏ´Â »çÀ̹öÀ§Çù¿¡ ÀûÀýÇϸ鼭 ½Å¼ÓÇÏ°Ô ´ëÀÀÇϱâ À§Çؼ­´Â »çÀ̹öÀ§Çù Á¤º¸ ±³È¯ Àº ÇʼöÀûÀ̸ç, Á¤º¸¸¦ °øÀ¯Çϴ ü°è°¡ ÇÊ¿äÇÏ´Ù. °øÀ¯Ã¼°è¸¦ ¼ö¸³Çϱâ À§Çؼ­´Â Ç¥ÁØÈ­µÈ Á¤º¸ ±Ô°Ý À» °®´Â °Í ¶ÇÇÑ ¸Å¿ì Áß¿äÇϸç, Ç¥ÁØÈ­µÈ Á¤º¸ ±Ô°Ý À» ±â¹ÝÀ¸·Î ±¸ÃàµÈ »çÀ̹öÀ§Çù Á¤º¸ °øÀ¯ ü°è¸¦ ¼ö¸³Çϸé ÀÌÀüº¸´Ù ¾Ë·ÁÁø °ø°Ý È®»ê ¹æÁö, ¾Ë·ÁÁø °ø°Ý ¹æ¾î ÀÚ¿ø Àý¾à, Á¤±³ÇÑ °ø°Ý ¹æ¾î¿¡ ÁýÁßÇÒ ¼ö ÀÖ´Â ±â´ëÈ¿°ú¸¦ °¡Áú ¼ö ÀÖ´Ù. ¡Ø º» ¿¬±¸´Â 2019³âµµ °úÇбâ¼úÁ¤º¸Åë½ÅºÎÀÇ Àç¿øÀ¸·Î Á¤º¸Åë½Å±âȹÆò °¡¿øÀÇ Áö¿øÀ» ¹Þ¾Æ ¼öÇàµÊ[No. 2016-0- 00078, ¸ÂÃãÇü º¸¾È¼­ºñ½º Á¦°ø À» À§ÇÑ Å¬¶ó¿ìµå ±â¹Ý Áö´ÉÇü º¸¾È ±â¼ú °³¹ß]. [Âü°í¹®Çå]] [ 1] ±èµ¿Èñ, ¹Ú»óµ·, ±è¼ÒÁ¤, À±¿ÀÁØ. 2017. »çÀ̹ö À§ÇùÁ¤º¸ °øÀ¯Ã¼ °è ±¸Ãà¹æ¾È¿¡ °üÇÑ ¿¬±¸ ¹Ì±¹ »ç·Ê¸¦ Áß½ÉÀ¸·Î -. À¶ÇÕº¸¾È³í ¹®Áö 17, no.253-68 [ 2 ] ITU-T Recommendation X.1500, ¡®Overview of cybersecurity information exchange¡¯, 2011. [ 3 ] ¾çÁØÈ£, ±èÂùÁø, ±è¹Ì¿¬, ±èÁöÇý, ±èÁ¾Çö, ¿°Èï¿­, ¡®»çÀ̹ö À§Çù ÀÎ ÅÚ¸®Àü½º °øÀ¯ ü°è ¿¬±¸¡¯, Çѱ¹Á¤º¸Åë½ÅÇÐȸ, Á¾ÇÕÇмú´ëȸ³í ¹®Áý Vol. 22. No. 2., 2018.10.18. [ 4 ] OASIS Cyber Threat Intelligence CTI TC, WD 01STIX¢â and TAXII¢â Version 2FAQ, October 2017. https//docs.google. com/document/d/1V5tE78N10McUq1xUOHV1RTVsOoYm iq_xt2PY1YI8bsU/edit?usp=sharing [ 5 ] OASIS Cyber Threat Intelligence CTI TC, ¡®Resources¡¯, Accessed 2018.11.19., https//oasis-open.github.io/ctidocumentation/resources#taxii-20-specification [ 6 ] OASIS Cyber Threat Intelligence CTI TC, ¡®CTI-TC Cover Page¡¯, Accessed 18.11.21 https//docs.google.com/document/ d/1yvqWaPPnPW-2NiVCLqzRszcx91ffMowfT5MmE9Nsy_ w/edit [ÁÖ¿ä ¿ë¾î Ç®ÀÌ] ? CYBEX Cybersecurity Information Exchange »çÀ̹öº¸¾È Á¤ º¸ ±³È¯ ? STIX Structured Threat Information Expression ±¸Á¶È­µÈ À§ Çù Á¤º¸ Ç¥Çö ±Ô°Ý ? TAXII Trusted Automated eXchange of Indicator Information À§Çù Á¤º¸ÀÇ ½Å·Ú ±â¹Ý ÀÚµ¿ ±³È¯ ? CybOX Cyber Observable eXpression »çÀ̹ö °üÂûÁ¤º¸ÀÇ Ç¥Çö 2 0 1 9 N o v E M B E R + d e c e B E R27

Ž »ö