검색 상세

제로트러스트 기반 상용 SDP 제품의 보안 인증을 위한 보안요구사항 개발

초록/요약

본 연구는 제로트러스트 기반 SDP(Software Defined Perimeter) 제품에 대한 국가용 보안요구사항을 개발하는 것을 목적으로 한다. 현재 SDP 제품은 전용 보안요구사항이 부재하여 VPN과 NAC의 복합제품 인증을 받거나 일반보안요구사항을 별도로 작성해야 하는 실무적 어려움이 있다. 본 연구는 NIST SP 800-207, CSA SDP 표준, 국가용 보안요구사항 문서를 종합 분석하여 SDP의 독립적 제품군으로서의 보안요구사항을 도출하였다. SDP 컨트롤러, SDP 클라이언트, SDP 게이트웨이로 구성된 3계층 아키텍처를 기반으로 식별 및 인증, 접근통제, SPA 및 암호화 통신, 자체 보호, 보안관리, 감사기록의 6개 보안 영역에 걸쳐 총 13개의 세부 요구사항을 제시하였다. 도출된 요구사항은 NIST SP 800-207의 제로트러스트 7대 원칙을 충족하며, 기존 VPN 및 NAC 제품과의 비교 분석을 통해 SDP만의 차별화된 보안 특성을 입증하였다. 특히 SPA 기반 인프라 은닉화, 세션 단위 동적 접근제어, 지속적 신뢰 재검증 메커니즘은 제로트러스트 원칙 구현의 핵심 요소로 확인되었다. 본 연구는 SDP 제품의 국가 보안적합성 검증을 위한 명확한 기준을 제시함으로써, 중소기업의 인증 부담을 경감하고 국내 제로트러스트 보안 생태계 활성화에 기여할 것으로 기대된다.

more

초록/요약

Development of Security Requirements for Security Certification of Commercial SDP Products Based on Zero Trust Architecture This study develops national-level security requirements for the certification of Software Defined Perimeter (SDP) products based on Zero Trust Architecture (ZTA). Currently, SDP products lack dedicated national security requirements, forcing developers to seek hybrid VPN-NAC certification or individually develop general security requirements — a process requiring 6 to 12 months and imposing significant costs, particularly on small and medium-sized enterprises. This research applied a three-stage methodology: systematic analysis of domestic and international standards, gap analysis against existing VPN and NAC national security requirements, and validation of the developed requirements. Through analysis of NIST SP 800-207, CSA SDP Specification v2.0, the Zero Trust Guideline 2.0, and Korean national security requirement documents, this research develops 13 security requirements across six domains — identification and authentication, access control, SPA-based communication, self-protection, security management, and audit records. The developed requirements satisfy all seven Zero Trust principles of NIST SP 800-207 and the six principles of the Korea Zero Trust Guideline 2.0. Comparative analysis with existing VPN and NAC requirements demonstrates SDP's differentiated security characteristics: SPA-based infrastructure concealment with a default-deny policy, session-based dynamic access control with least privilege, and continuous trust re-verification within five-minute intervals. This research provides clear and standardized certification criteria for SDP products within the national security assurance framework, reducing certification burdens for small and medium-sized enterprises and contributing to the advancement of Korea's Zero Trust security ecosystem.

more

목차

제1장 서 론 1
제2장 관련 연구 4
제1절 제로트러스트 아키텍처 및 SDP 4
제2절 현 국가용 보안요구사항 체계 9
제3장 연구 방법론 16
제1절 문헌 분석 및 현황 조사 16
1. 제로트러스트 및 SDP 관련 표준 분석 16
2. 기존 국가용 보안요구사항 체계 분석 16
3. 선행 연구 분석 21
제2절 요구사항 도출 및 구성 21
1. SDP 아키텍처 분해 및 기능 분류 21
2. 기존 VPN·NAC 요구사항과 SDP 기능 간 갭 분석 22
3. SDP 보안요구사항 도출 체계 구성 22
제3절 검증 및 타당성 확보 23
1. 원칙 충족성 검증 23
2. 정합성 검증 23
제4장 기존 VPN·NAC 요구사항과의 비교분석 25
제1절 VPN 제품 보안요구사항 분석 25
제2절 NAC 제품 보안요구사항 분석 25
제3절 VPN·NAC와 SDP 보안요구사항 비교 26
제5장 국가용 보안요구사항 - SDP 제품 보안요구사항 도출 29
제1절 SDP 제품 보안요구사항 운영환경 정의 29
1. 가정사항 29
2. 제품 개요 30
3. 운용 환경 31
4. 공통보안요구사항의 적용 32
제2절 SDP 제품 보안요구사항 도출 32
1. 식별 및 인증 34
2 접근통제 36
3. SPA 및 암호화 통신 38
4. 자체보호 40
5. 보안관리 40
6. 감사기록 42
제6장 제안요구사항의 타당성 검증 44
제1절 SDP 보안요구사항의 제로트러스트 원칙 충족성 검증 및 평가 44
1. 원칙 충족성 검증 44
2. 제로트러스트 원칙 충족도 종합 평가 47
제2절 정합성 검증 및 평가 48
1. 정합성 검증 48
2. 정합성 종합 평가 49
제7장 결 론 51
제1절 연구 결과 요약 및 시사점 51
제2절 한계점 및 향후 연구 과제 53
참고문헌 55
ABSTRACT 56

more