MITRE ATT&CK 기반 SOAR 플레이북 설계 프레임워크
A SOAR Playbook Design Framework Based on MITRE ATT&CK
- 주제(키워드) SOAR , MITRE ATT&CK
- 주제(DDC) 005.8
- 발행기관 아주대학교 정보통신대학원
- 지도교수 손태식
- 발행년도 2026
- 학위수여년월 2026. 8
- 학위명 석사
- 학과 및 전공 정보통신대학원 사이버보안
- 실제URI http://www.dcollection.net/handler/ajou/000000036427
- 본문언어 한국어
- 저작권 아주대학교 논문은 저작권에 의해 보호받습니다.
초록/요약
Modern cyberattacks unfold as multi-stage processes that combine multiple tactics and techniques, including phishing, user execution, script-based execution, command-and-control communication, internal reconnaissance, lateral movement, and data exfiltration. Security operations centers must analyze large volumes of events generated by heterogeneous security systems while simultaneously managing alert fatigue, response delays, variations in analysis quality, and operational risks caused by responses to false positives. However, SOAR playbooks based on a single alert or an individual indicator of compromise are effective for automating repetitive tasks, but they have limitations in comprehensively reflecting relationships among attack stages, asset criticality, and the business impact of response actions. This study proposes a framework for modeling threat scenarios based on the tactics and techniques of MITRE ATT&CK and converting them into SOAR playbook design elements. The proposed framework consists of ATT&CK-based scenario modeling, log artifact derivation, context enrichment, correlation-based decision making, response action classification, Human-in-the-Loop approval, and ticket update and termination-condition definition. Through these components, the framework establishes traceability among attack techniques, detection evidence, analysis conditions, response actions, approval points, and termination conditions, and presents a design procedure that is not dependent on a specific SOAR product. The applicability of the framework was examined through an email-based initial access scenario and a command-and-control communication and internal reconnaissance scenario. The ATT&CK mappings were performed based on MITRE ATT&CK Enterprise v19.1. The two scenarios include techniques such as Phishing, User Execution, Command and Scripting Interpreter, Masquerading, Application Layer Protocol, Network Service Discovery, Exploitation of Remote Services, and Exfiltration Over C2 Channel. The evaluation was limited to examining the internal consistency of the design artifacts rather than validating operational performance. Scenario-scope coverage and HITL policy coverage were interpreted as checklist indicators for confirming whether essential design requirements were satisfied. The automation ratio, reusability ratio, and number of traceability links were used as auxiliary indicators to explain the design structure. In addition, defect-injection and boundary non-defect variation reviews based on the six types of traceability links were conducted to examine whether missing essential connections could be identified and whether acceptable implementation differences were not over-detected. In comparison with single-event-based playbooks, functionally reusable basic procedures were recognized in the baseline, while the proposed framework showed a structure in which common atomic actions were reused based on traceability links. The results of this study should be interpreted not as direct evidence of operational effectiveness, but as indicators of design self-consistency, internal defect-identification capability, and traceability under the same evaluation criteria.
more초록/요약
현대의 사이버 공격은 피싱, 사용자 실행, 스크립트 실행, 명령제어 통신, 내부 정찰, 횡적 이동, 정보 유출 등 여러 전술과 기법이 결합된 다단계 흐름으로 전개된다. 보안관제센터는 이기종 보안 장비에서 발생하는 대량의 이벤트를 분석하면서 경보 피로, 대응 지연, 분석 품질 편차, 오탐 대응에 따른 운영 리스크를 동시에 관리해야 한다. 그러나 단일 경보 또는 개별 침해지표 중심의 SOAR 플레이북은 반복 업무 자동화에는 효과적이지만, 공격 단계 간 연관성, 자산 중요도, 대응 조치의 업무 영향을 종합적으로 반영하는 데 한계가 있다. 본 연구는 MITRE ATT&CK의 전술·기법 체계를 기반으로 위협 시나리오를 모델링하고, 이를 SOAR 플레이북 설계 요소로 변환하기 위한 프레임워크를 제안한다. 제안 프레임워크는 ATT&CK 기반 시나리오 모델링, 로그 아티팩트 도출, 컨텍스트 보강, 상관분석 기반 의사결정, 대응 액션 분류, Human-in-the-Loop 승인, 티켓 갱신 및 종료 조건 정의로 구성된다. 이를 통해 공격기법, 탐지 근거, 분석 조건, 대응 조치, 승인 지점, 종료 조건 사이의 추적성을 확보하고, 특정 SOAR 제품에 종속되지 않는 설계 절차를 제시한다. 프레임워크의 적용 가능성은 이메일 기반 초기 접근 시나리오와 명령제어 통신 및 내부 정찰 시나리오를 통해 검토하였다. ATT&CK 매핑은 MITRE ATT&CK Enterprise v19.1을 기준으로 수행하였으며, 두 시나리오는 Phishing, User Execution, Command and Scripting Interpreter, Masquerading, Application Layer Protocol, Network Service Discovery, Exploitation of Remote Services, Exfiltration Over C2 Channel 등의 기법을 포함한다. 평가는 운영 성능 검증이 아니라 설계 산출물의 내부 정합성 검토로 한정하였다. 시나리오 범위 충족률과 HITL 정책 충족률은 필수 설계요건의 충족 여부를 확인하는 체크 지표로 해석하였고, 자동화 비율, 재사용 비율, 추적 링크 수는 설계 구조를 설명하는 보조 지표로 사용하였다. 또한 추적 링크 6유형에 기반한 결함 주입 및 경계적 비결함 변형 검토를 통해 필수 연결 누락 식별 가능성과 과검출 여부를 확인하였다. 단일 이벤트 중심 플레이북과의 비교에서는 비교군에도 기능상 재사용 가능한 기본 절차를 인정하였으며, 제안 프레임워크는 공통 아토믹 액션을 추적 링크 기반으로 재사용하는 구조를 보였다. 본 연구의 결과는 운영 효과의 직접 증거가 아니라, 동일 기준에 따른 설계 산출물의 자기 일관성, 내부 결함 식별 가능성, 추적성을 보여주는 지표로 해석된다.
more목차
제 1장 서론 1
제 1절 연구 배경 및 필요성 1
제 2절 연구 목적 및 연구 문제 3
제 3절 연구 범위 및 방법 4
제 4절 연구의 차별성 및 기여 6
제 5절 논문 구성 8
제 2장 이론적 배경 및 관련 연구 9
제 1절 MITRE ATT&CK 프레임워크 9
제 2절 위협 모델링 비교 프레임워크 10
제 3절 SOAR와 보안관제 자동화 12
제 4절 대응 측 분류체계와 위협 시나리오 모델링 13
제 5절 SOAR 플레이북 설계와 Human-in-the-Loop 14
제 6절 관련 연구 동향 및 한계 16
제 3장 MITRE ATT&CK 기반 SOAR 플레이북 설계 프레임워크 17
제 1절 설계 프레임워크 개요 17
제 2절 ATT&CK 기반 위협 시나리오 모델링 절차 18
제 3절 로그 아티팩트 및 컨텍스트 보강 정보 도출 20
제 4절 상관분석 기반 의사결정 구조 22
제 5절 대응 액션 분류 및 Human-in-the-Loop 승인 기준 23
제 6절 플레이북 설계 산출물 및 평가 기준 25
제 4장 제안 프레임워크의 사례 적용 및 평가 27
제 1절 사례 적용 환경 및 평가 방법 27
제 2절 이메일 기반 초기 접근 시나리오 적용 28
제 3절 명령제어 통신 및 내부 정찰 행위 시나리오 적용 30
제 4절 설계 프레임워크와 SOAR 구성요소 간 매핑 32
제 5절 설계 산출물의 내부 정합성 검토 34
제 6절 단일 이벤트 중심 플레이북과의 산출물 단위 비교 36
제 7절 논의 및 개선 방향 38
제 5장 결론 40
제 1절 연구 결과 요약 및 RQ별 답변 40
제 2절 연구의 의의 41
제 3절 한계 42
제 4절 향후 연구 방향 43
참고문헌 47
부록 51
Abstract 59

