메뉴 건너뛰기
.. 내서재 .. 알림
소속 기관/학교 인증
인증하면 논문, 학술자료 등을  무료로 열람할 수 있어요.
한국대학교, 누리자동차, 시립도서관 등 나의 기관을 확인해보세요
(국내 대학 90% 이상 구독 중)
로그인 회원가입 고객센터 ENG
주제분류

추천
검색

논문 기본 정보

자료유형
학위논문
저자정보

이우진 (고려대학교, 고려대학교 정보보호대학원)

지도교수
김인석
발행연도
2018
저작권
고려대학교 논문은 저작권에 의해 보호받습니다.

이용수0

표지
AI에게 요청하기
추천
검색

이 논문의 연구 히스토리 (2)

초록· 키워드

오류제보하기
최근 모바일뱅킹 인터넷전문은행의 등장과 생체인증을 이용한 간편한 인증 및 결제로 사용자에게 점점 가까이 다가오면서 모바일 뱅킹의 사용이 일상화가 되었다. 하지만, 아직 국내 금융권의 안드로이드 뱅킹 어플리케이션은 실행을 위해서 안티바이러스의 설치를 의무화하고 있어 사용자에게 불편함을 초래하고 있다. 본 논문에서는 금융권에서 안티바이러스를 도입하게 된 정책적인 배경을 알아보고, 실증적인 연구를 통해 도입된 안티바이러스를 우회함으로써 보안 솔루션 연동과정의 문제점을 분석한다. 이러한 결과를통해 보안 위협 가능성 발생 시 무분별한 보안 솔루션 도입의 문제점을 지적한다. 안드로이드 뱅킹 어플리케이션 안티바이러스의 도입 여부에 대하여 미국의 사례를 통한 국내금융권의 기술적·정책적 개선 방안을 제시한다.

목차

1. 서론 ··············································································································· 1
2. 금융권 안티바이러스 적용 현황 ················································ 5
2.1 금융권 안드로이드 안티바이러스 ···································································· 5
2.1.1 국내 금융권 안드로이드 안티바이러스 사용 현황 ································· 5
2.1.2 해외 금융권 안드로이드 안티바이러스 사용 현황 ································· 7
2.1.3 안드로이드 안티바이러스의 주요 기능 ···················································· 8
2.1.4 안드로이드 안티바이러스 사용자 인식 ···················································· 9
2.2 국내 모바일 뱅킹 보안 관련 법규 현황 ························································ 10
2.2.1 스마트폰 금융안전대책 이행실태 체크리스트 ······································ 11
2.2.2 전자금융거래법 시행령 ············································································· 15
2.2.3 전자금융감독규정 ······················································································· 17
2.2.4 전자금융거래법 ··························································································· 18
2.2.5 금융 IT 보안 자율규제 방안 ··································································· 20
3. 배경지식 ································································································· 21
3.1 관련연구 ·········································································································· 21
3.2 안드로이드 운영체제의 특징 ············································································ 22
3.3 안드로이드 분석 과정 및 도구 ········································································ 23
3.4 언어의 분류 ········································································································· 25
3.4.1 Dex 파일 ····································································································· 25
3.4.2 Smali 파일 ·································································································· 25
3.5 국내 금융권 안드로이드 안티바이러스 연동 구조 ······································· 28
4. 안티바이러스 우회 실험 및 결과 ············································································ 29
4.1 정적분석 방법 ····································································································· 32
4.1.1 String id 값 추출 ····················································································· 32
4.1.2 Smali 구조 분석 ························································································ 33
4.1.3 우회 코드 수정 ··························································································· 34
4.2 동적분석 방법 ····································································································· 35
4.2.1 보안 검사 예상 지점 클래스 추출 ························································ 35
4.2.2 해당 클래스 내 메소드 분석 ··································································· 37
4.3 실험결과 ········································································································· 38
5. 개선방안 ···············································································································41
5.1 안티바이러스 도입 시 개선방안 ······································································ 42
5.1.1 리소스 암호화 ··························································································· 42
5.1.2 제어흐름 난독화 강화 ············································································· 44
5.1.3 무결성 검증 지점 확대 ··········································································· 45
5.1.4 평가 체크리스트 항목 점검 ··································································· 46
5.2 안티바이러스 폐지 시 개선방안 ······································································ 47
5.2.1 미국 금융권 모바일 뱅킹 취약점 체크리스트 ···································· 47
5.2.2 뉴욕주 금융기관에 대한 사이버보안규정 ············································ 49
5.2.3 국내 모바일 안티바이러스 도입 현황에 대한 문제점 ······················· 52
5.2.4 국내 모바일 안티바이러스 도입 현황에 대한 개선방안 ··················· 53
6. 결론 ······································································································· 55

최근 본 자료

전체보기

댓글(0)

0