철도 차량 제어 장치의 사이버보안 취약점 개선을 위 한 IEC 62443 기반 정량적 초기 위험평가 모델 개발에 관한 연구
On the Development of an IEC 62443-Based Quantitative Initial Risk Assessment Model for Improving Cyber Security Vulnerabilities in Rolling Stock Control Systems
- 주제(키워드) Railway , Cyber security , Risk Assessment , Asset Analysis , Security Level
- 주제(DDC) 620
- 발행기관 아주대학교 일반대학원
- 지도교수 이주연
- 발행년도 2026
- 학위수여년월 2026. 8
- 학위명 박사
- 학과 및 전공 일반대학원 시스템공학과
- 실제URI http://www.dcollection.net/handler/ajou/000000036515
- 본문언어 한국어
- 저작권 아주대학교 논문은 저작권에 의해 보호받습니다.
초록/요약
요약 주요 국가 기반 산업인 철도 산업은 국가 경제 성장, 안보 유지, 그리고 기술 혁신에 핵심적인 영향을 미치는 주요 국가 기반 시설로 간주된다. 현대 사회에서 철도 시스템은 인적, 물적 자원의 이동을 담당하는 중요한 교통 인프라로서, 그 안전성 및 신뢰성 있는 운영이 필수적으로 요구된다. 최근 국내외 철도 프로젝트의 다수는 기존 시스템과 정보통신기술 간의 융합이 이루어지면서 시스템의 복잡성이 증가하는 추세를 보인다. 이에 따라, 대부분의 철도 프로젝트에서 사이버 보안 성능 강화의 중요성이 지속적으로 부각되고 있으며, 특히 유럽 및 북미 지역의 철도 산업을 중심으로 추진되는 철도 시스템 프로젝트에서는 사이버 보안 요구사항이 급격히 증대하고 있는 실정이다. 실제로 철도 시스템에 대한 주요 사이버 보안 피해 사례는 빈번하게 발생하고 있으며, 이에 따라 갈수록 복잡성이 심화되는 철도 시스템에 체계적이고 강건한 사이버 보안 대응 방안을 수립하는 것이 필수적인 상황이다. 또한, 최근 유럽은 CRA(Cyber Resilience Act: 사이버 복원력 법)을 제정하여 2024년 12월 공식 발효 후 2027년 12월 전면 시행을 목표로 디지털 제품에 대한 전면적인 OT 보안 규제를 강화하고 있다. 본 논문은 주요 철도 시스템 중에서 차량 제어 장치의 IEC 62443 3-2 기반 사이버보안 초기위험평가를 중심으로 하여 개선된 모델을 제안하였다. 특히 철도 차량 시스템은 움직이는 차량에 복잡한 시스템이 설치되는 관계로 보다 체계적인 위험평가 방법론이 필요하며, 설계 후 보안을 적용하기 위해서는 효율성과 보안성 측면에서 모든 위협에 대응하겠다는 비현실적인 목표보다는 위험한 위협부터 필요한 부분에 적용하는 것이 중요하다. 따라서, 초기위험평가를 수행 시, 필요한 만큼의 보안 자원을 배치하기 위하여 자산 중요도에 따른 효율적인 위험 평가가 수행되어야 한다. 사이버보안 위험 평가란 자산분석, 위협분석, 취약점 분석을 통하여 자산 및 시스템의 위험도 수준을 평가하여 적절한 보안조치를 적용하는 일련의 과정으로 사이버보안 수준 측정을 위한 다양한 지표가 개발되고 있으나 철도 차량 장치에 특화된 정량적 위험평가 방법론이 미흡할 뿐만 아니라, 이과 같은 복잡계에 적합한 단순한 기준과 지표가 없다보니 현실적으로 정성적 분석이 대부분인 실정이다. 또한 초기위험평가시 철도 시스템의 OT 보안 측면에서 자산의 특성이 충분히 고려된 보안 속성이 적용되어, 보다 정량적인 자산 가치가 도출되어야 한다. 이렇게 자산 식별이 명확하게 이뤄져야 발생 가능성과 영향도의 조합으로 구성된 위험도 매트릭스를 통해 신뢰할 수 있는 위험도 값을 산출할 수 있다. 이에 본 논문에서는 기존의 산업용 사이버보안 표준인 IEC 62443 에 따른 위험 평가 방법론 및 TS50701을 기반으로 하여, 개선된 초기 위험 평가 절차를 위해 적합한 자산 평가 및 위험도 도출을 위한 평가 지표를 제시하고 실제 철도 차량 장치에 적용하고자 한다.
more초록/요약
Abstract The railway industry is a critical national infrastructure with major impact on economic growth, security, and technological innovation, requiring safe and reliable operation as essential transportation infrastructure. As railway systems increasingly converge with information and communication technologies, system complexity is rising, and cybersecurity requirements are growing rapidly in railway system projects across Europe and North America. In practice, major cybersecurity incidents affecting railway systems have occurred frequently, underscoring the urgency of addressing this issue. In addition, the European Union recently enacted the Cyber Resilience Act (CRA), officially in force since December 2024 with full implementation targeted for December 2027, strengthening comprehensive OT security regulation for digital products. This paper proposes an improved model centered on IEC 62443-3-2-based initial cybersecurity risk assessment for vehicle control devices among major railway systems. Because railway vehicle systems involve complex systems installed on moving vehicles, a more systematic risk assessment methodology is required. In applying security after design, rather than pursuing the unrealistic goal of addressing all threats in terms of both efficiency and security, it is important to prioritize measures starting with the most dangerous threats. Therefore, when conducting initial risk assessment, an efficient risk assessment based on asset criticality must be performed in order to allocate security resources as needed. Cybersecurity risk assessment refers to a series of processes that evaluate the risk level of assets and systems through asset analysis, threat analysis, and vulnerability analysis, and apply appropriate security measures accordingly. While various indicators for measuring cybersecurity levels are being developed, quantitative risk assessment methodologies specialized for railway vehicle devices remain insufficient, and in the absence of simple criteria and indicators suited to such complex systems, qualitative analysis remains predominant in practice. Furthermore, in initial risk assessment, security attributes that sufficiently reflect asset characteristics from the OT security perspective of railway systems must be applied in order to derive more quantitative asset values. Only when asset identification is clearly established in this way can reliable risk values be derived through a risk matrix composed of combinations of likelihood and impact. Accordingly, this paper, based on the risk assessment methodology of IEC 62443 and TS 50701, proposes evaluation indicators suitable for asset assessment and risk derivation for an improved initial risk assessment procedure, and applies them to an actual railway vehicle device.
more목차
제 1 장 연구 배경 및 목표 1
제 1 절 연구 범주 1
제 2 절 연구 배경 4
1. 글로벌 사이버 위협과 철도 시스템의 고도화 4
2. 사이버보안 관련 글로벌 규제 동향 5
3. 국제 표준 기반의 보안 리스크 관리 체계 6
4. 위험평가 방법론의 한계 및 정량화 필요성 11
제 3 절 연구 목표 12
제 2 장 선행 연구 분석 14
제 1 절 주요 선행 연구 분석 14
제 2 절 주요 선행 연구의 한계점 및 본 연구의 차별점 17
1. 리스크 평가 이론의 OT 환경 반영 한계 17
2. 방법론적 복잡성으로 인한 실무 적용의 어려움18
3. 표준의 추상성과 실무 적용의 간극19
제 3 장 연구 방법 20
제 1 절 현재 위험평가 프로세스 20
1. HSE 위험평가 단계 21
2. 초기위험평가 단계 22
3. 상세위험평가 단계 22
4. 초기위험평가 단계의 세부 개념 23
제 2 절 위험평가 프로세스 개선 방안 26
1. STEP 1: 자산 특성 및 중요도 산출 29
2. STEP 2: 위험 매트릭스 정의 및 위험도 평가 31
3. STEP 3: 목표 보안 레벨 정의 38
제 3 절 검증 방법 40
1. 초기 위험평가 지표에 대한 검증 40
2. 철도 차량 제어 장치 사례연구를 통한 검증 42
3. 초기 위험평가 SL-T 결과값에 대한 민감도 및 강건성 분석 56
제 4 장 결론 및 기대효과 64
제 1 절 결론 64
제 2 절 기대효과 65
1. 학술적 기대효과 65
2. 실무적 기대효과 65
3. 경제적 기대효과 66
제 3 절 한계점 및 향후 연구과제 67
1. 본 연구의 한계점 67
2. 향후 연구과제 70
참 고 문 헌 73
부록 81
Abstract 111

