방위산업분야 사이버보안 프레임워크 연구
A Study on Cybersecurity Frameworks in the Defense Industry
- 주제(키워드) Cybersecurity , Defense Industry , MITRE ATT&CK , MITRE D3FEND , MITRE ENGAGE , CMMC
- 주제(DDC) 005.8
- 발행기관 아주대학교 정보통신대학원
- 지도교수 손태식
- 발행년도 2026
- 학위수여년월 2026. 8
- 학위명 석사
- 학과 및 전공 정보통신대학원 사이버보안
- 실제URI http://www.dcollection.net/handler/ajou/000000036210
- 본문언어 한국어
- 저작권 아주대학교 논문은 저작권에 의해 보호받습니다.
초록/요약
최근 K-방산의 비약적인 성장과 글로벌 방산 수출 확대로 인해 대한민국의 방위산업 기술을 노리는 북한 배후 지능형 지속 위협(APT) 그룹의 사이버 공격이 점차 고도화되고 있다. 망 연계 시스템 및 하위 협력업체의 공급망을 우회하는 등 정교해진 사이버 공격은 기존의 경계 기반 방어 체계만으로는 탐지 및 대응에 명백한 한계가 있다. 또한, 미국 국방부의 사이버보안 성숙도 모델 인증(CMMC) 제도가 본격화됨에 따라 국내 방산업체들은 지능형 위협에 대한 방어 역량 확보와 더불어 글로벌 컴플라이언스 충족이라는 이중의 과제에 직면해 있다. 이에 본 연구는 지능화되는 방위산업 사이버 위협에 선제적으로 대처하고 미국 CMMC 체계에 효과적으로 대응할 수 있도록, 공격자와 방어자의 관점을 통합한 능동적 방어체계의 적용 방안을 분석하는 데 목적이 있다. 이를 위해 경찰청에서 발표한 북한 해킹조직(라자루스, 안다리엘, 김수키)의 실제 방산업체 침해 사례를 바탕으로 침투 경로를 MITRE ATT&CK 공격 체인으로 매핑하고, 초기 접근부터 데이터 유출에 이르는 각 단계별로 MITRE D3FEND 및 ENGAGE 프레임워크를 연계하여 실효성 있는 기술적 대응 방안을 분석한다. 나아가 분석된 능동 방어 체계의 요소들과 CMMC 프레임워크 간의 통합 매핑을 수행하여, 도출된 보안 체계가 글로벌 보안 요건을 어느 정도 충족할 수 있는지 그 연관성을 검증한다. 결과적으로 본 연구의 분석 결과는 국내 방산업체의 사이버 침해사고 예방 및 대응력을 높이고, K-방산의 성공적인 해외 진출과 핵심 기술 보호를 위한 전략적 방향성을 모색하는 기초 자료로 활용될 수 있을 것으로 기대된다. Keywords : Cybersecurity, Defense Industry, Information Sharing & Analysis Center, Advanced Persistent Threat, MITRE ATT&CK, MITRE D3FEND, MITRE ENGAGE, CMMC
more초록/요약
The rapid growth of the K-defense industry and the expansion of global defense exports have led to increasingly sophisticated cyberattacks by North Korean state-sponsored Advanced Persistent Threat (APT) groups targeting South Korea’s defense industry technologies. These sophisticated attacks, which bypass network interconnection systems and exploit supply chain vulnerabilities through lower-tier subcontractors, reveal clear limitations in the detection and response capabilities of conventional perimeter-based defense architectures. Furthermore, as the U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) framework is being implemented, Korean defense contractors face the dual challenge of strengthening their defensive capabilities against advanced threats while simultaneously meeting global compliance requirements. Accordingly, this study aims to analyze the application of an active defense framework that integrates both attacker and defender perspectives, enabling proactive responses to evolving cyber threats in the defense industry and effective alignment with the U.S. CMMC framework. To this end, this study maps the intrusion pathways identified in actual defense-contractor breach cases attributed to North Korean hacking groups, including Lazarus, Andariel, and Kimsuky, as reported by the Korean National Police Agency, onto a MITRE ATT&CK-based attack chain. For each phase, from initial access to data exfiltration, the MITRE D3FEND and MITRE ENGAGE frameworks are applied to derive practical technical countermeasures. Furthermore, this study conducts an integrated mapping between the identified active defense components and the CMMC framework to assess the extent to which the proposed security framework aligns with global cybersecurity requirements. Ultimately, the findings of this study are expected to serve as a foundational resource for strengthening cyber incident prevention and response capabilities among Korean defense contractors, while also informing strategic directions for the successful global expansion of the K-defense industry and the protection of core defense technologies.
more목차
제1장 서론 1
제2장 이론적 배경 2
제1절 CMMC 와 NIST SP 800-171/172 체계 2
제2절 MITRE ATT&CK 프레임워크 3
제3절 MITRE D3FEND 프레임워크 3
제4절 MITRE ENGAGE 프레임워크 4
제3장 방위산업 사이버 위협 분석 7
제1절 북한 배후 위협 그룹 분석 7
1. 라자루스 (Lazarus Group) 7
2. 안다리엘 (Andariel) 8
3. 김수키 (Kimsuky) 8
제2절 주요 공격그룹의 MITRE ATT&CK TTP 분석 9
1. 라자루스(Lazarus) 해킹조직 침해사례 9
2. 안다리엘(Andariel) 해킹조직 침해사례 11
3. 김수키(Kimsuky) 해킹조직 침해사례 12
제3절 MITRE D3FEND 프레임워크 적용 15
1. 초기 접근 및 자원 개발 단계 대응 17
2. 내부 이동 및 시스템 장악 단계 방어 18
3. 데이터 수집 및 유출 단계 저지 19
제4절 위협분석 종합 및 시사점 23
1. 방어 패러다임의 전환 23
2. 전술적 실행 및 강화 우선순위 24
제4장 CMMC 와 MITRE 프레임워크 매핑 분석 27
제1절 방위산업 위협 분석 기반 고위협 공격기술 27
제2절 통합 추적 매핑 결과 28
제5장 ENGAGE 기반 능동적 방어 대응 분석 30
제1절 ENGAGE 기반 기만헌팅 대응 매핑 30
1. 설계 원리와 ENGAGE 프레임워크 구조 30
2. ENGAGE 교전 활동 매핑 30
3. 교전 목표 분포 분석 32
4. 다계층 기만 자산 배치 32
제2절 적용성 분석 33
1. 단계별 기만·헌팅 대응 분석 33
2. SP 800-172 주요 강화 요건 대응 방안 34
3. 적용 제약 요인 분석 35
제6장 발전방안 및 결론 36
제1절 발전방안 36
제2절 결론 37
참고 문헌 38
Abstract 40

