Multi-Perspective Security Risk Assessment for APT Attacks Using Scenarios, Security Requirements, and Evidence
- 주제(키워드) Adaptive Security Requirements , Advanced Persistent Threats , Cyber-Physical-Social Systems , Multi-Perspective Security Risk Assessment , Risk-aware Problem Domain Ontology
- 주제(DDC) 006.31
- 발행기관 아주대학교 일반대학원
- 지도교수 Seok-Won Lee
- 발행년도 2026
- 학위수여년월 2026. 8
- 학위명 박사
- 학과 및 전공 일반대학원 인공지능학과
- 실제URI http://www.dcollection.net/handler/ajou/000000036587
- 본문언어 영어
- 저작권 아주대학교 논문은 저작권에 의해 보호받습니다.
초록/요약
In today’s rapidly evolving digital landscape, organizations confront increasingly sophisticated cyber threats with profound political, economic, and social implications. Among them, Advanced Persistent Threats (APTs) are particularly critical due to their persistence, strategic intent, and multi-stage lifecycles that compromise diverse assets while evading detection. Meanwhile, the emergence of cyber-physical-social systems (CPSS) has created complex environments in which cyber, physical, and social domains are tightly interlinked. Traditional approaches—such as attack trees, attack patterns, cyber kill-chain models, and conventional risk assessment methods—remain limited, as they emphasize technology-level analysis and isolated countermeasures but fail to adequately capture multi-layered dependencies and adaptive APT behavior. To address these limitations, this study proposes a unified security risk assessment framework for CPSS environments, specifically designed for security consultants and domain experts. The framework integrates four key components: (1) a top- down approach utilizing knowledge-based APT attack scenario generation and TTP-driven threat modeling; (2) construction of a Mission-Critical Target System (MCTS) comprising vertically and horizontally interconnected layers with extended criticality evaluation; (3) adaptive security requirements engineering to support continuous identification, specification, and refinement of actionable defense measures; and (4) evidence-based risk assessment that incorporates technical, organizational, and social interdependencies to enable iterative, layered defense planning. Ontology-supported knowledge representation is employed to structure threats, assets, and security requirements and to improve traceability and auditability, while risk likelihoods are updated through evidence-driven evaluation rather than automated semantic inference. Validated through theoretical analysis and controlled empirical case studies involving security professionals, the framework effectively captures the dynamic and multidimensional characteristics of APT behavior in CPSS contexts and demonstrates statistically significant improvements in comprehensiveness (S1), precision (S2), adaptiveness (S3), practicality (S4), and applicability (S5) compared with traditional assessment approaches. Keywords: Adaptive Security Requirements, Advanced Persistent Threats, Cyber- Physical-Social Systems, Multi-Perspective Security Risk Assessment, Risk-aware Problem Domain Ontology
more초록/요약
오늘날 급변하는 디지털 환경에서 기업과 기관들은 정치·경제·사회적으로 막대한 파급력을 지닌 고도화된 사이버 위협에 직면해 있다. 그중에서도 특히 지능형 지속 위협(Advanced Persistent Threats, APT)은 탐지를 우회하여 다양한 자산을 침해할 뿐만 아니라, 뚜렷한 전략적 의도를 가지고 다단계 생명주기에 걸쳐 집요하게 공격을 수행한다는 점에서 매우 치명적이다. 나아가 사이버-물리-사회 시스템(Cyber-Physical-Social Systems, CPSS)의 등장으로 사이버, 물리, 사회적 영역이 긴밀하게 상호 연결된 복잡한 융합 환경이 조성되면서 위협의 양상은 더욱 복잡해지고 있다. 그러나 공격 트리(Attack Tree), 공격 패턴(Attack Pattern), 사이버 킬체인(Cyber Kill Chain) 모델 및 전통적인 위험 평가 등 기존의 접근 방식은 기술적 관점의 분석과 개별적 대응에 집중되어 있고, 자산 간의 다층적 종속성과 APT 공격의 동적이고 적응적(Adaptive) 특성을 제대로 반영하지 못하는 한계가 있다. 이러한 한계를 극복하기 위해, 본 연구는 보안 컨설턴트 및 도메인 전문가가 실무에서 직접 활용할 수 있도록 설계된 통합 보안 위험 평가 프레임워크를 제안한다. 제안하는 프레임워크는 다음 네 가지 핵심 구성요소로 구성된다. 첫째, 지식 기반 APT 공격 시나리오 생성 및 TTP 기반 위협 모델링을 활용한 하향식(Top-down) 접근 방식을 적용한다. 둘째, 수직·수평적으로 상호 연결된 계층 구조와 확장된 중요도 평가 방식을 반영하여 미션 크리티컬 타겟 시스템(Mission-Critical Target System, MCTS)을 구축한다. 셋째, 실효성 있는 방어 조치를 지속적으로 식별, 명세 및 고도화할 수 있도록 지원하는 적응형 보안 요구공학(Adaptive Security Requirements Engineering)을 도입한다. 넷째, 기술·조직·사회적 상호의존성을 종합적으로 고려하여 반복적이고 다층적인 방어 계획 수립을 지원하는 증거 기반 위험 평가(Evidence-based Risk Evaluation)를 수행한다. 이 과정에서 위협(Threats), 자산(Assets), 보안 요구사항(Security Requirements)을 체계적으로 구조화하고 평가의 추적성(Traceability)과 감사 가능성(Auditability)을 높이기 위해 온톨로지(Ontology) 기반의 지식 표현 기법을 활용하였다. 또한 기계적인 자동화 추론에 의존하기보다 실제 구현 증거(Evidence)를 바탕으로 공격 성공 가능성을 갱신하는 현실적인 접근법을 채택하였다. 본 연구는 이론적 분석과 더불어 현업 보안 전문가들을 대상으로 한 통제된 실증 사례 연구를 통해 프레임워크의 타당성을 검증하였다. 그 결과, 제안하는 프레임워크가 CPSS 환경에서 발생하는 APT 공격의 다차원적 특성을 효과적으로 반영하며, 전통적인 평가 방식에 비해 포괄성(S1), 정밀성(S2), 적응성(S3), 실용성(S4) 및 적용성(S5) 측면에서 모두 통계적으로 유의미하게 향상되었음을 입증하였다. 주제어: 적응형 보안 요구사항, 지능형 지속 위협, 사이버-물리-사회 시스템, 다관점 보안 위험 평가, 위험 인지 문제 도메인 온톨로지
more목차
I. Introduction 1
II. Background 5
A. Advanced Persistent Threat 5
B. Cyber-Physical-Social Systems 6
C. Limitations of Traditional Security Risk Assessment 7
D. Need for Multi-perspective Security Understanding 9
III. Related Work 12
A. Technology-Centric Detection 15
B. Attack Modeling and Frameworks 16
C. Quantitative and Mathematical Models 18
D. Dynamic/Proactive Risk Assessment Methodologies 19
E. Multidimensional Approaches 20
F. Summary and Positioning 21
IV. Proposed Security Risk Assessment Framework 24
A. APT Attack Scenario Model 27
B. Mission-Critical Target System 31
1. Mission-Critical Target System Model 31
2. Building Mission-Critical Target System 33
3. Evaluating Criticality of Protected Assets 36
C. Risk-aware Problem Domain Ontology (RaPDO) 41
1. Ontology construction and knowledge integration 42
2. Representative ontology elements for traceability 44
3. Ontology components and role in the framework 44
D. Adaptive Security Requirements Engineering (ASRE) 48
1. Adaptive Security Requirements 48
2. Security Requirements Engineering for Evolving APT Attacks 49
E. Integrated Security Risk Assessment Process (ISRAP) 51
1. Analyzing Risk Factors Through TTP-Based Threat Modeling 52
2. Eliciting Adaptive Security Requirements 54
3. Constructing And Evaluating Evidence 55
4. Assessing and Analyzing Security Risks 59
V. Application of the Proposed Framework 63
A. Case Scenario 1: Smart Traffic Signal Disruption Attack (SmartTrans) 64
1. SmartTrans Description 64
2. Application of the Traditional Method 65
3. Application of the Proposed Method 76
B. Case Scenario 2: Smart Grid Power Outage Attack (SmartGrid) 103
1. SmartGrid Description 103
2. Application of the Traditional Method 104
3. Application of the Proposed Method 115
C. Comprehensive Risk Response and Disaster Recovery Guidelines 138
VI. Theoretical Study 140
VII. Empirical Study 146
A. Experimental Design 146
B. Measured Variables and Research Questions 148
C. Results and Discussion 153
VIII. Threats to Validity 155
A. Conceptual and Theoretical Validity 155
B. Ontological and Implementation Validity 156
C. Empirical and Statistical Validity 156
IX. Conclusion 158
References. 161
Appendix A. Pre-Questionnaire for Participants 175
Appendix B. Overview for Empirical Study 180
Appendix C. Questionnaire for Empirical Study 184
국문초록 208

