• Mindscape ๐Ÿ”ฅ
    • Playlist ๐ŸŽง
  • Algorithm

    • 1018๋ฒˆ: ์ฒด์ŠคํŒ ๋‹ค์‹œ ์น ํ•˜๊ธฐ
    • 1966๋ฒˆ: ํ”„๋ฆฐํ„ฐ ํ
    • Python ์‹œ๊ฐ„ ์ดˆ๊ณผ ๋ฐฉ์ง€๋ฅผ ์œ„ํ•œ ํŒ
    • C++ std::vector ์‚ฌ์šฉ๋ฒ• ์ •๋ฆฌ
    • Vim ์‚ฌ์šฉ ๋งค๋‰ด์–ผ
  • Ubuntu

    • ๋ฆฌ๋ˆ…์Šค ์šฐ๋ถ„ํˆฌ GRUB ํฐํŠธ ๋ณ€๊ฒฝ
    • ์šฐ๋ถ„ํˆฌ ์ด๋ฏธ์ง€ ๋น„๋””์˜ค ์ธ๋„ค์ผ(๋ฏธ๋ฆฌ๋ณด๊ธฐ) ์•ˆ ๋ณด์ž„ ๋ฌธ์ œ ํ•ด๊ฒฐ
    • Wine ํ™˜๊ฒฝ์—์„œ ์นด์นด์˜คํ†ก ์‹คํ–‰ ์‹œ explorer.exe ๋œจ์ง€ ์•Š๊ฒŒ ํ•˜๋Š” ๋ฒ•
    • ์šฐ๋ถ„ํˆฌ Wine ์นด์นด์˜คํ†ก ์‚ฌ์ง„ ์ด๋ฏธ์ง€ ์Šคํฌ๋ฆฐ์ƒท ๋ถ™์—ฌ๋„ฃ๊ธฐ
    • Wine ์นด์นด์˜คํ†ก ์ด๋ชจ์ง€ ๊นจ์ง ๋ฌธ์ œ ํ•ด๊ฒฐ
    • Ubuntu ์œˆ๋„์šฐ ์• ๋‹ˆ๋ฉ”์ด์…˜ ๋„๊ธฐ
  • Wellness

    • ์ฐจ์ „์žํ”ผ (Psyllium Husk)
    • ์—‘์ŠคํŠธ๋ผ ๋ฒ„์ง„ ์˜ฌ๋ฆฌ๋ธŒ์œ  (Extra Virgin Olive Oil)
    • ์ž๊ฐ€๋น„๊ฐ•์„ธ์ฒ™ (Nasal Irrigation)
    • QCY HT08 (MeloBuds Pro Plus)
    • ์ฝ˜์„œํƒ€ (Concerta)
    • ์ธ๋ฐ๋†€ (Inderal)
    • ์„คํŠธ๋ž„๋ฆฐ (Sertraline)
    • ๋ฉœ๋ผํ† ๋‹Œ (Melatonin)
    • ์น˜๊ฒฝ๋ถ€ ๋งˆ๋ชจ์ฆ
    • ๋ฐ”๋ฒจ ์Šค์ฟผํŠธ (Barbell Squat)
  • Humanities

    • Nordvik, Russia
    • North Sentinel Island
    • ๋กฑ๊ณ ๋กฑ๊ณ (Rongorongo)
    • ๋ฐ”๋กœํฌ ์Œ์•… (Baroque Music)
  • Design

    • ๊ตฌ๊ธ€์˜ ์•„์ด์ฝ˜ ๋Œ€๊ฐœํŽธ โ€” 6๋…„ ๋งŒ์˜ ์‹ค์ˆ˜ ์ธ์ •
    • ์ œ๋Ÿด๋“œ ์  ํƒ€ โ€” ๋Ÿญ์…”๋ฆฌ ์Šคํฌ์ธ  ์›Œ์น˜์˜ ์ฐฝ์‹œ์ž
    • ๋ฐ”์šฐํ•˜์šฐ์Šค โ€” ํ˜„๋Œ€ ๋””์ž์ธ์˜ ์›์ 
  • Brands

    • NOMOS Glashรผtte
    • Frรฉdรฉrique Constant
    • KZ (Knowledge Zenith)
    • ์—์ŠคํŠธ๋ผ (AESTURA)
    • JINHAO (้‡‘่ฑช)
    • Herman Miller
    • ๋ฐ์Šค์ปค (DESKER)
    • ๋ฌด์‹ ์‚ฌ ์Šคํƒ ๋‹ค๋“œ (Musinsa Standard)
  • Finance

    • ํ˜„๋Œ€์นด๋“œ ZERO โ€” Edition2 vs Edition3 ๋น„๊ต
    • ์‹ ํ•œ์นด๋“œ ์ฒ˜์Œ
    • S&P 500 ETF ํˆฌ์ž ๊ฐ€์ด๋“œ
    • ํŒŒํ‚นํ†ต์žฅ vs CMA ํ†ต์žฅ
    • ๋ฒ„ํฌ์…” ํ•ด์„œ์›จ์ด (Berkshire Hathaway)
    • ๋น„ํŠธ์ฝ”์ธ(Bitcoin)
  • Products

    • ์˜ค๋””์˜ค ์ธํ„ฐํŽ˜์ด์Šค (Audio Interface)
    • ์ฟ ๋ฃจํ† ๊ฐ€ (KURUTOGA)
    • CX31993 DAC ๋™๊ธ€
    • ํด๋ Œ์ง• ๋ฐ€ํฌ (Cleansing Milk)
    • ํ”ผ์ ฏ ํ† ์ด (Fidget Toy)
    • ThinkPad
  • Programming Languages

    • 8.0. Statement Level Control Structures
    • 8. Subprogram
    • 9. Implementing Subprogram
    • 10.1. Abstract Data Types and Encapsulation Constructs
    • 10.2. Support for Object Oriented Programming
    • 11. Concurrency
    • 12. FPL (1)
    • 13. FPL (2)
    • 14. Exception Handling and Event Handling
    • Final Exam

2024 Midterm Exam

์ž‘์„ฑ 2026. 6. 12.ยท์ˆ˜์ • 2026. 6. 12.

์ด 15 ๋ฌธํ•ญ, 100์  ๋งŒ์ 
2024.10.16.

  1. [8์ ] Define the following terms.

    • contingency planning: ์˜ˆ๊ธฐ์น˜ ์•Š์€ ์‚ฌ๊ณ , ์žฌ๋‚œ, ๋ณด์•ˆ ์นจํ•ด ์‚ฌ๊ณ ๊ฐ€ ๋ฐœ์ƒํ–ˆ์„ ๋•Œ, ์กฐ์ง์ด ์‹ ์†ํ•˜๊ฒŒ ๋Œ€์‘ํ•˜๊ณ  ๋น„์ฆˆ๋‹ˆ์Šค ์—ฐ์†์„ฑ์„ ์œ ์ง€ํ•˜๋ฉฐ ํ”ผํ•ด๋ฅผ ์ตœ์†Œํ™”ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์ „์— ์ˆ˜๋ฆฝํ•˜๋Š” ์ ˆ์ฐจ์™€ ์ „๋žต์˜ ์ง‘ํ•ฉ
    • computationally secure: ์–ด๋–ค ์•”ํ˜ธ ์‹œ์Šคํ…œ์„ ๊นจ๋Š” ๋ฐ ํ•„์š”ํ•œ ๊ณ„์‚ฐ ์ž์›์ด ํ˜„์žฌ์™€ ์˜ˆ์ธก ๊ฐ€๋Šฅํ•œ ๋ฏธ๋ž˜์˜ ๊ธฐ์ˆ  ์ˆ˜์ค€์œผ๋กœ๋„ ํ˜„์‹ค์ ์œผ๋กœ ๋ถˆ๊ฐ€๋Šฅํ•  ์ •๋„๋กœ ๋ง‰๋Œ€ํ•œ ๊ฒฝ์šฐ
    • false positive: ์ •์ƒ์  ํ–‰์œ„๋‚˜ ํŒŒ์ผ์ž„์—๋„ ๋ถˆ๊ตฌํ•˜๊ณ , ๋ณด์•ˆ ์‹œ์Šคํ…œ์ด ์ด๋ฅผ ์•…์˜์  ์œ„ํ˜‘์ด๋‚˜ ๊ณต๊ฒฉ์œผ๋กœ ์ž˜๋ชป ํƒ์ง€ํ•˜๋Š” ์˜ค๋ฅ˜
    • risk: ํŠน์ • ์œ„ํ˜‘์ด ์ž์‚ฐ์˜ ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์—ฌ ํ•ด๋‹น ์ž์‚ฐ์— ์†์‹ค์ด๋‚˜ ์†ํ•ด๋ฅผ ์ž…ํž ๊ฐ€๋Šฅ์„ฑ
  2. [6์ ] ์ปดํ“จํ„ฐ ๋ณด์•ˆ์˜ ๋ชฉํ‘œ(Security Goals)๋Š” Confidentiality(๊ธฐ๋ฐ€์„ฑ), Integrity(๋ฌด๊ฒฐ์„ฑ), Availablity(๊ฐ€์šฉ์„ฑ)์„ ๋ณด์กดํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ฐ ์šฉ์–ด๋ฅผ ์ •์˜ํ•˜๊ณ , ๊ฐ ๋ชฉํ‘œ์— ๋Œ€ํ•œ ๊ณต๊ฒฉ์˜ ์˜ˆ๋ฅผ ์ œ์‹œํ•˜์‹œ์˜ค. The security goals of computer security are to preserve confidentiality, integrity and availability. Define each term and give some examples of attacks on these terms. (a) Confidentiality: ์ธ๊ฐ€๋œ(authorized) ์‚ฌ์šฉ์ž๋งŒ์ด ์ •๋ณด์— ์ ‘๊ทผํ•˜๊ณ  ๊ทธ ๋‚ด์šฉ์„ ์•Œ ์ˆ˜ ์žˆ๋„๋ก ๋ณด์žฅํ•˜๋Š” ๊ฒƒ. - ๊ณต๊ฒฉ ์˜ˆ: ๋ฐ์ดํ„ฐ ๋„์ฒญ(Eavesdropping), ์Šค๋‹ˆํ•‘(Sniffing), ๋ฐ์ดํ„ฐ ์œ ์ถœ(Data breach), ์–ด๊นจ๋„ˆ๋จธ๋กœ ํ›”์ณ๋ณด๊ธฐ(Shoulder surfing). (b) Integrity: ์ •๋ณด๊ฐ€ ์ธ๊ฐ€๋˜์ง€ ์•Š์€ ์‚ฌ์šฉ์ž์— ์˜ํ•ด ์ž„์˜๋กœ ์ƒ์„ฑ, ์ˆ˜์ •, ์‚ญ์ œ๋˜์ง€ ์•Š์•˜์Œ์„ ๋ณด์žฅํ•˜๋Š” ๊ฒƒ. ๋ฐ์ดํ„ฐ์˜ ์ •ํ™•์„ฑ๊ณผ ์™„์ „์„ฑ์„ ์œ ์ง€ํ•จ. - ๊ณต๊ฒฉ ์˜ˆ: ๋ฐ์ดํ„ฐ ๋ณ€์กฐ(Data modification), ๋ฐ”์ด๋Ÿฌ์Šค(Virus) ๊ฐ์—ผ์„ ํ†ตํ•œ ํŒŒ์ผ ์ˆ˜์ •, Man-in-the-Middle (MITM) ๊ณต๊ฒฉ ์ค‘ ๋ฐ์ดํ„ฐ ์กฐ์ž‘. (c) Availability: ์ธ๊ฐ€๋œ ์‚ฌ์šฉ์ž๊ฐ€ ์ •๋ณด๋‚˜ ์‹œ์Šคํ…œ ์ž์›์„ ํ•„์š”๋กœ ํ•  ๋•Œ ์‹œ๊ฐ„์ ์œผ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ๋ณด์žฅํ•˜๋Š” ๊ฒƒ. - ๊ณต๊ฒฉ ์˜ˆ: ์„œ๋น„์Šค ๊ฑฐ๋ถ€(DoS, Denial of Service) ๊ณต๊ฒฉ, ๋ถ„์‚ฐ ์„œ๋น„์Šค ๊ฑฐ๋ถ€(DDoS, Distributed DoS) ๊ณต๊ฒฉ, ๋žœ์„ฌ์›จ์–ด(Ransomware)๋ฅผ ํ†ตํ•œ ํŒŒ์ผ ์ ‘๊ทผ ์ฐจ๋‹จ.

  3. [5์ ] SBOM์— ๋Œ€ํ•˜์—ฌ ์„ค๋ช…ํ•˜๊ณ , SBOM์ด SW ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•˜์˜€์„ ๋•Œ, ์–ด๋–ป๊ฒŒ ํšจ๊ณผ์ ์œผ๋กœ ์‚ฌ์šฉ๋  ์ˆ˜ ์žˆ๋Š”์ง€ ์„ค๋ช…ํ•˜์‹œ์˜ค. Explain about SBOM, and explain how SBOM can be used when SW security vulnerabilities are found.

  • ์†Œํ”„ํŠธ์›จ์–ด ์ œํ’ˆ์„ ๊ตฌ์„ฑํ•˜๋Š” ๋ชจ๋“  ๊ตฌ์„ฑ ์š”์†Œ(components), ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ(libraries), ๋ชจ๋“ˆ, ๊ทธ๋ฆฌ๊ณ  ์ด๋“ค์˜ ์ข…์†์„ฑ(dependencies)์— ๋Œ€ํ•œ ์ƒ์„ธํ•œ ๋ชฉ๋ก.
  • ๋ณธ๋ž˜ ์ œ์กฐ์—…์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์ž์žฌ ๋ช…์„ธ์„œ(BOM) ๊ฐœ๋…์„ ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง(Supply Chain)์— ์ ์šฉํ•œ ๊ฒƒ์œผ๋กœ, ๊ฐ ๊ตฌ์„ฑ ์š”์†Œ์˜ ๋ฒ„์ „ ์ •๋ณด, ๋ผ์ด์„ ์Šค, ์ œ๊ณต์ž ๋“ฑ์„ ํฌํ•จํ•จ.
  • SW ๋ณด์•ˆ ์ทจ์•ฝ์  ๋ฐœ์ƒ ์‹œ ํ™œ์šฉ ๋ฐฉ์•ˆ:
    • ์‹ ์†ํ•œ ์ทจ์•ฝ์  ์‹๋ณ„: ํŠน์ • ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ(e.g., Log4j, OpenSSL)์—์„œ ์‹ฌ๊ฐํ•œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ์„ ๋•Œ, ์กฐ์ง์€ ์œ ์ง€๋ณด์ˆ˜ ์ค‘์ธ ๋ชจ๋“  ์†Œํ”„ํŠธ์›จ์–ด์˜ ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ์ผ์ผ์ด ๊ฒ€ํ† ํ•  ํ•„์š” ์—†์ด, ๋ณด์œ ํ•œ SBOM ๋ชฉ๋ก์„ ์ฆ‰์‹œ ์กฐํšŒํ•จ.
    • ์˜ํ–ฅ๋„ ๋ถ„์„: SBOM ์กฐํšŒ๋ฅผ ํ†ตํ•ด ํ•ด๋‹น ์ทจ์•ฝ์ ์„ ๊ฐ€์ง„ ๊ตฌ์„ฑ ์š”์†Œ๊ฐ€ ์ž์‚ฌ์˜ ์–ด๋–ค ์†Œํ”„ํŠธ์›จ์–ด ์ œํ’ˆ์˜ ์–ด๋А ๋ฒ„์ „์— ์‚ฌ์šฉ๋˜์—ˆ๋Š”์ง€ ์ •ํ™•ํ•˜๊ณ  ๋น ๋ฅด๊ฒŒ ํŒŒ์•…ํ•  ์ˆ˜ ์žˆ์Œ.
    • ํšจ์œจ์ ์ธ ๋Œ€์‘: ์˜ํ–ฅ๋ฐ›๋Š” ์‹œ์Šคํ…œ์„ ์‹ ์†ํ•˜๊ฒŒ ์‹๋ณ„ํ•˜์—ฌ ์šฐ์„ ์ ์œผ๋กœ ๋ณด์•ˆ ํŒจ์น˜(patch)๋ฅผ ์ ์šฉํ•˜๊ฑฐ๋‚˜ ์™„ํ™” ์กฐ์น˜(mitigation)๋ฅผ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์–ด, ์ „์ฒด์ ์ธ ๋Œ€์‘ ์‹œ๊ฐ„(MTTR, Mean Time To Respond)์„ ํš๊ธฐ์ ์œผ๋กœ ๋‹จ์ถ•์‹œํ‚ด.
  1. [7์ ] Feistel cipher structure๋ฅผ ๊ทธ๋ฆฌ๊ณ , ์ด ๊ตฌ์กฐ์˜ ๊ตฌ์„ฑ ์š”์†Œ ๋ฐ ์žฅ์ ์„ ์„ค๋ช…ํ•˜์‹œ์˜ค. Draw the Feistel cipher structure, and explain the elements of the structure and the advantage of the structure.

  2. [8์ ] Symmetric Encryption ๋ฐฉ๋ฒ•๊ณผ Asymmetric Encryption ๋ฐฉ๋ฒ•์„ ๋น„๊ตํ•˜์—ฌ ์„ค๋ช…ํ•˜๊ณ , ๊ฐ ๋ฐฉ๋ฒ•์˜ ์žฅ๋‹จ์ ์„ ์„ค๋ช…ํ•˜๊ณ , ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์˜ˆ๋ฅผ ๋‚˜์—ดํ•˜์‹œ์˜ค. Explain both symmetric encryption and asymmetric encryption, and explain pros and cons of each method, and give examples of algorithms.

SymmetricAsymmetric
explanation
advantages
disadvantages
Algorithm
Examples
  1. [8์ ] Block cipher๋ฅผ ์ด์šฉํ•œ mode-of-operation์— ๋Œ€ํ•˜์—ฌ ๋‹ค์Œ ๋ฌผ์Œ์— ๋‹ตํ•˜์‹œ์˜ค. (a) Explain the Output feedback(OFB) mode and the Cipher feedback(CFB) mode with drawings. (explain both encryption and decryption processes.)

    (b) Explain pros and cons of the OFB mode. OFB ๋ชจ๋“œ์˜ ์žฅ๋‹จ์ ์„ ์„ค๋ช…ํ•˜์‹œ์˜ค.

  2. [8์ ] RSA cryptosystem์— ๋Œ€ํ•˜์—ฌ ๋‹ค์Œ ๋ฌผ์Œ์— ๋‹ตํ•˜์‹œ์˜ค. (a) Explain how to generate public key and private key.

    (b) Encrypt a message M with the public key.

  3. [4์ ] User authentication methods can be categorized into four approaches. Explain four categories and give examples for each category.

  4. [8์ ] Password salt์— ๋Œ€ํ•˜์—ฌ ๋‹ค์Œ ๋ฌผ์Œ์— ๋‹ตํ•˜์‹œ์˜ค. (a) Explain how to apply the password salt.

    (b) Explain why password salt can make the password file more secure.

  5. [6์ ] Proactive password checking์— ๋Œ€ํ•˜์—ฌ ์„ค๋ช…ํ•˜๊ณ , proactive password checking์—์„œ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•๋“ค์„ ์„ค๋ช…ํ•˜์‹œ์˜ค.

Proactive password checking์€ ์‚ฌ์šฉ์ž๊ฐ€ ์•”ํ˜ธ๋ฅผ ์„ค์ •ยท๋ณ€๊ฒฝํ•  ๋•Œ ์‹œ์Šคํ…œ์ด ์ฆ‰์‹œ ๊ทธ ์•”ํ˜ธ์˜ ์•ฝ์ ์„ ๊ฒ€์‚ฌํ•˜์—ฌ ์ทจ์•ฝํ•œ ์•”ํ˜ธ์˜ ์‚ฌ์šฉ์„ ์ฐจ๋‹จํ•˜๊ฑฐ๋‚˜ ๊ฐœ์„ ์„ ์š”๊ตฌํ•˜๋Š” ์ ‘๊ทผ ๋ฐฉ์‹์ž…๋‹ˆ๋‹ค. ์ฃผ๋œ ๋ชฉ์ ์€ ์‚ฌ์šฉ์ž๊ฐ€ ์•ฝํ•œ ์•”ํ˜ธ๋ฅผ ์“ฐ๋Š” ๊ฒƒ์„ ์‚ฌ์ „์— ๋ง‰์•„ ์ดํ›„ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ๊ณ„์ • ํƒˆ์ทจ ์œ„ํ—˜์„ ์ค„์ด๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์‚ฌ์šฉ๋˜๋Š” ๋ฐฉ๋ฒ•๋“ค(์˜ˆ):

โ€ข	๊ธธ์ดยท๊ตฌ์„ฑ ๊ทœ์น™ ๊ฒ€์‚ฌ: ์ตœ์†Œ ๊ธธ์ด, ๋Œ€๋ฌธ์ž/์†Œ๋ฌธ์ž/์ˆซ์ž/ํŠน์ˆ˜๋ฌธ์ž ํฌํ•จ ์—ฌ๋ถ€ ๋“ฑ ๊ธฐ๋ณธ ๊ทœ์น™ ์ ์šฉ.
โ€ข	๋ธ”๋ž™๋ฆฌ์ŠคํŠธ(๊ธˆ์ง€ ์•”ํ˜ธ) ๊ฒ€์‚ฌ: ์ž์ฃผ ์“ฐ์ด๋Š” ์•”ํ˜ธ ๋ชฉ๋ก(์˜ˆ: 123456, password ๋“ฑ)์ด๋‚˜ ์ด์ „์— ์œ ์ถœ๋œ ์•”ํ˜ธ ๋ชฉ๋ก๊ณผ ๋น„๊ตํ•ด ์ฐจ๋‹จ.
โ€ข	ํ˜•ํƒœ ๊ธฐ๋ฐ˜ ๊ฒ€์‚ฌ: ์—ฐ์†๋œ ๋ฌธ์ž/์ˆซ์ž, ํ‚ค๋ณด๋“œ ํŒจํ„ด, ์‚ฌ์šฉ์ž ๊ด€๋ จ ์ •๋ณด(์ด๋ฆ„, ์ด๋ฉ”์ผ ๋“ฑ) ํฌํ•จ ์—ฌ๋ถ€ ๊ฒ€์‚ฌ.
โ€ข	์ถ”์ธก ์ €ํ•ญ์„ฑ ํ‰๊ฐ€(๋น„๋ฐ€๋ฒˆํ˜ธ ๊ฐ•๋„ ์ถ”์ •): ํŒจ์Šค์›Œ๋“œ์— ๋Œ€ํ•œ ์ถ”์ธก ์‹œ๋„(๋ฌด์ฐจ๋ณ„ยท์‚ฌ์ „ ๊ณต๊ฒฉ)๋ฅผ ๋ชจ์‚ฌํ•ด ์ถ”์ธก ๋‚œ์ด๋„๋ฅผ ์ ์ˆ˜ํ™”(์˜ˆ: ํŒจ์Šค์›Œ๋“œ ์—”ํŠธ๋กœํ”ผ ์ถ”์ •).
โ€ข	์ •์ฑ… ํ”ผ๋“œ๋ฐฑ ์ œ๊ณต: ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•  ๋•Œ ์‹ค์‹œ๊ฐ„์œผ๋กœ ์•ฝํ•œ ๋ถ€๋ถ„์„ ์•Œ๋ ค์ฃผ๊ณ  ๊ฐœ์„  ๋ฐฉ์•ˆ์„ ์ œ์‹œ.
โ€ข	์•”ํ˜ธ ์žฌ์‚ฌ์šฉ ํƒ์ง€(๊ฐ€๋Šฅํ•˜๋ฉด): ๋™์ผ ๊ณ„์ • ๋˜๋Š” ๊ฐ™์€ ๋„๋ฉ”์ธ ๋‚ด ์ด์ „ ์•”ํ˜ธ ์žฌ์‚ฌ์šฉ ๊ธˆ์ง€.
  1. [5์ ] The access control matrix can be used to implement Discretionary Access Control (DAC) method. Explain problems of the access control matrix and explain how role-based access control (RBAC) can alleviate these problems. ์ ‘๊ทผ ์ œ์–ด ๋งคํŠธ๋ฆญ์Šค ๋ฌธ์ œ์ :

    โ€ข ํ™•์žฅ์„ฑ ๋ฌธ์ œ: ์ฃผ์ฒด(์‚ฌ์šฉ์ž)์™€ ๊ฐ์ฒด(๋ฆฌ์†Œ์Šค)๊ฐ€ ๋งŽ์•„์ง€๋ฉด ํ–‰๋ ฌ ํฌ๊ธฐ๊ฐ€ ๋งค์šฐ ์ปค์ ธ ๊ด€๋ฆฌยท์ €์žฅ ๋น„์šฉ์ด ์ปค์ง. โ€ข ๊ด€๋ฆฌ ๋ณต์žก์„ฑ: ๊ฐœ๋ณ„ ์‚ฌ์šฉ์ž๋ณ„ ๊ถŒํ•œ์„ ์ผ์ผ์ด ์ˆ˜์ •ยท๊ฒ€ํ† ํ•ด์•ผ ํ•˜๋ฏ€๋กœ ๋Œ€๊ทœ๋ชจ ํ™˜๊ฒฝ์—์„œ ๋น„ํšจ์œจ์ ์ž„. โ€ข ์ผ๊ด€์„ฑ ์œ ์ง€ ์–ด๋ ค์›€: ๋™์ผํ•œ ์—ญํ• ์„ ๊ฐ€์ง„ ์‚ฌ์šฉ์ž๋“ค ๊ฐ„ ๊ถŒํ•œ ์ผ๊ด€์„ฑ ์œ ์ง€๊ฐ€ ์–ด๋ ค์›€. โ€ข ๊ถŒํ•œ ๊ณผ๋‹ค ๋ถ„์‚ฐ ๊ฐ€๋Šฅ์„ฑ: ๊ถŒํ•œ ์œ„์ž„์ด ์ž์œ ๋กœ์šด DAC์˜ ํŠน์„ฑ ๋•Œ๋ฌธ์— ๊ถŒํ•œ์ด ๋ถˆํ•„์š”ํ•˜๊ฒŒ ํ™•์‚ฐ๋  ์ˆ˜ ์žˆ์Œ.

RBAC๊ฐ€ ์™„ํ™”ํ•˜๋Š” ๋ฐฉ๋ฒ•: โ€ข ์—ญํ•  ์ค‘์‹ฌ ์ถ”์ƒํ™”: ์‚ฌ์šฉ์ž์—๊ฒŒ ์ง์ ‘ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜์ง€ ์•Š๊ณ  ์—ญํ• (role)์— ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•œ ๋’ค ์‚ฌ์šฉ์ž๋ฅผ ์—ญํ• ์— ํ• ๋‹นํ•˜์—ฌ ๊ด€๋ฆฌ ๋‹จ์œ„๋ฅผ ์ถ•์†Œ. โ€ข ๊ด€๋ฆฌ ๋‹จ์ˆœํ™”: ์—ญํ•  ๋‹จ์œ„๋กœ ๊ถŒํ•œ์„ ๊ด€๋ฆฌํ•˜๋ฏ€๋กœ ๋Œ€๊ทœ๋ชจ ์‚ฌ์šฉ์ž ์ง‘ํ•ฉ์—์„œ๋„ ๋ณ€๊ฒฝ์ด ์‰ฝ๊ณ  ์ผ๊ด€์„ฑ ์œ ์ง€๊ฐ€ ์‰ฌ์›€. โ€ข ์ตœ์†Œ ๊ถŒํ•œ ์›์น™ ์ ์šฉ ์šฉ์ด: ์—ญํ•  ์„ค๊ณ„๋ฅผ ํ†ตํ•ด ํ•„์š”ํ•œ ๊ถŒํ•œ๋งŒ ๋ฌถ์–ด ์ œ๊ณตํ•จ์œผ๋กœ์จ ๊ณผ๋‹ค ๊ถŒํ•œ์„ ์ค„์ž„. โ€ข ๊ฐ์‚ฌยท์ •์ฑ… ์ ์šฉ ์šฉ์ด: ์—ญํ•  ๊ธฐ๋ฐ˜์œผ๋กœ ๊ฐ์‚ฌ ๋กœ๊ทธยท์ •์ฑ…์„ ์ ์šฉํ•˜๊ธฐ ์‰ฌ์›Œ ๊ฑฐ๋ฒ„๋„Œ์Šค ํ–ฅ์ƒ.

12.	[8์ ] Answer the following questions.

(a) What is the SQL injection attack? SQL ์ธ์ ์…˜ ๊ณต๊ฒฉ์€ ์ž…๋ ฅ๊ฐ’(์˜ˆ: ์›น ํผ, URL ํŒŒ๋ผ๋ฏธํ„ฐ ๋“ฑ)์— ๊ณต๊ฒฉ์ž๊ฐ€ ์กฐ์ž‘ํ•œ SQL ์ฝ”๋“œ๋ฅผ ์‚ฝ์ž…ํ•˜์—ฌ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ์˜๋„์น˜ ์•Š์€ SQL ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๊ฒŒ ๋งŒ๋“œ๋Š” ๊ณต๊ฒฉ์ž…๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ์ธ์ฆ ์šฐํšŒ, ๋ฐ์ดํ„ฐ ๋…ธ์ถœยท๋ณ€์กฐ, ์‹ฌ์ง€์–ด ์„œ๋ฒ„ ์‚ฌ์ด๋“œ ๋ช…๋ น ์‹คํ–‰๊นŒ์ง€ ๊ฐ€๋Šฅํ•ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

(b) Explain how to defend against the SQL injection attack. ๋ฐฉ์–ด ๋ฐฉ๋ฒ•๋“ค(๋Œ€ํ‘œ์ ): โ€ข ํŒŒ๋ผ๋ฏธํ„ฐํ™”๋œ ์ฟผ๋ฆฌ(Prepared Statements) ์‚ฌ์šฉ: ์ž…๋ ฅ๊ฐ’๊ณผ ์ฟผ๋ฆฌ ๊ตฌ์กฐ๋ฅผ ๋ถ„๋ฆฌํ•˜์—ฌ ์ž…๋ ฅ์ด SQL ๊ตฌ๋ฌธ์œผ๋กœ ํ•ด์„๋˜์ง€ ์•Š๊ฒŒ ํ•จ. โ€ข ORM ๋˜๋Š” ์•ˆ์ „ํ•œ DB ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์‚ฌ์šฉ: ORM์ด ์ž๋™์œผ๋กœ ํŒŒ๋ผ๋ฏธํ„ฐ ๋ฐ”์ธ๋”ฉ์„ ์ œ๊ณตํ•จ. โ€ข ์ž…๋ ฅ ๊ฒ€์ฆยท์ •๊ทœํ™”(์„œ๋ฒ„ ์ธก): ํ—ˆ์šฉ๋œ ํ˜•์‹(๋ฌธ์ž์—ด ๊ธธ์ด, ์ •๊ทœ์‹ ๋“ฑ)๋งŒ ํ†ต๊ณผ์‹œํ‚ค๊ณ  ์ด์ƒ ๊ฐ’์€ ๊ฑฐ๋ถ€. โ€ข ์ตœ์†Œ ๊ถŒํ•œ์˜ DB ๊ณ„์ • ์‚ฌ์šฉ: ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ํ•„์š”ํ•œ ๊ถŒํ•œ๋งŒ ๊ฐ€์ง„ DB ๊ณ„์ •์œผ๋กœ ์ ‘์†ํ•ด ํ”ผํ•ด ๋ฒ”์œ„ ์ถ•์†Œ. โ€ข ์ถœ๋ ฅ ์ด์Šค์ผ€์ดํ”„/์ธ์ฝ”๋”ฉ: ์ฟผ๋ฆฌ๊ฐ€ ์•„๋‹Œ ์ฝ˜ํ…์ŠคํŠธ(์˜ˆ: HTML)์— ์ถœ๋ ฅํ•  ๋•Œ ์ ์ ˆํžˆ ์ด์Šค์ผ€์ดํ”„. โ€ข ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐฉํ™”๋ฒฝ(WAF): ์•Œ๋ ค์ง„ ๊ณต๊ฒฉ ํŒจํ„ด ์ฐจ๋‹จ์„ ๋ณด์กฐ. โ€ข ์ •๊ธฐ์  ์ฝ”๋“œ ๋ฆฌ๋ทฐ ๋ฐ ์นจํˆฌ ํ…Œ์ŠคํŠธ: ์ทจ์•ฝํ•œ ์ฟผ๋ฆฌ ํŒจํ„ด์„ ์ฐพ์•„ ์ˆ˜์ •.

13.	[6์ ] Explain about the inference attack, and explain how to defend the attack. Inference ๊ณต๊ฒฉ์— ๋Œ€ํ•˜์—ฌ ์„ค๋ช…ํ•˜๊ณ , ๋ฐฉ์–ด ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•˜์‹œ์˜ค.

์ •์˜:

โ€ข	Inference ๊ณต๊ฒฉ์€ ๋ณดํ˜ธ๋œ(๋ฏผ๊ฐํ•œ) ์ •๋ณด๋ฅผ ์ง์ ‘์ ์œผ๋กœ ์ œ๊ณตํ•˜์ง€ ์•Š๋Š” ํ†ต๊ณ„ ์งˆ์˜๋‚˜ ์ง‘๊ณ„ ๊ฒฐ๊ณผ๋“ค์„ ์—ฐ์†์ ์œผ๋กœ ์งˆ์˜ํ•˜๊ฑฐ๋‚˜ ๊ต์ฐจ ๋ถ„์„ํ•˜์—ฌ ๋ฏผ๊ฐํ•œ ๊ฐœ์ธ ์ •๋ณด๋‚˜ ๊ฐœ๋ณ„ ๋ ˆ์ฝ”๋“œ๋ฅผ ์ถ”๋ก ํ•ด๋‚ด๋Š” ๊ณต๊ฒฉ์ž…๋‹ˆ๋‹ค. ์˜ˆ: ํ†ต๊ณ„ ๋ฐ์ดํ„ฐ์…‹์— ๋Œ€ํ•ด ์—ฌ๋Ÿฌ ์กฐ๊ฑด์œผ๋กœ ์ง‘๊ณ„๋ฅผ ๋ฐ˜๋ณตํ•˜์—ฌ ํŠน์ • ๊ฐœ์ธ์˜ ์†์„ฑ ์œ ์ถ”.

๋ฐฉ์–ด ๋ฐฉ๋ฒ•๋“ค: โ€ข ์ถœ๋ ฅ ์ œ์–ด(์ฟผ๋ฆฌ ์ œํ•œ): ๋™์ผ ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ๋นˆ๋ฒˆํ•œ ์งˆ์˜๋‚˜ ํŠน์ • ์กฐํ•ฉ ์งˆ์˜๋ฅผ ์ œํ•œ. โ€ข ๊ฒฐ๊ณผ ๋…ธ์ด์ฆˆ ์ถ”๊ฐ€(๋ฌด์ž‘์œ„ํ™”): ์ฐจ๋“ฑ ํ”„๋ผ์ด๋ฒ„์‹œ ๊ฐ™์€ ๊ธฐ๋ฒ•์œผ๋กœ ํ†ต๊ณ„ ๊ฒฐ๊ณผ์— ํ™•๋ฅ ์  ๋…ธ์ด์ฆˆ๋ฅผ ์ถ”๊ฐ€ํ•ด ๊ฐœ๋ณ„ ๊ฐ’ ์ถ”์ •์„ ์–ด๋ ต๊ฒŒ ํ•จ. โ€ข ์ตœ์†Œ ์‘๋‹ต ๋‹จ์œ„(aggregation threshold): ๊ฒฐ๊ณผ์— ํฌํ•จ๋˜๋Š” ๋ ˆ์ฝ”๋“œ ์ˆ˜๊ฐ€ ์ž„๊ณ„๊ฐ’(์˜ˆ: ์ตœ์†Œ 5๋ช…)๋ณด๋‹ค ์ž‘์œผ๋ฉด ์‘๋‹ต์„ ๊ฑฐ๋ถ€ํ•˜๊ฑฐ๋‚˜ ์ผ๋ฐ˜ํ™”. โ€ข ์ฟผ๋ฆฌ ๊ฒ€ํ†  ๋ฐ ๊ฐ์‚ฌ: ๋ฏผ๊ฐํ•œ ์กฐํ•ฉ์˜ ์งˆ์˜๋ฅผ ํƒ์ง€ํ•ด ์ฐจ๋‹จ ๋˜๋Š” ๊ฒ€ํ† . โ€ข ๋ฐ์ดํ„ฐ ๋งˆ์Šคํ‚น/์ต๋ช…ํ™”: ์ง์ ‘ ์‹๋ณ„์ž๋ฅผ ์ œ๊ฑฐํ•˜๊ณ , ํ•„์š” ์‹œ k-์ต๋ช…์„ฑยทl-๋‹ค์–‘์„ฑ ๊ฐ™์€ ์ต๋ช…ํ™” ๊ธฐ๋ฒ• ์ ์šฉ. โ€ข ์ ‘๊ทผ ํ†ต์ œ ๊ฐ•ํ™”: ๋ฏผ๊ฐ ๋ฐ์ดํ„ฐ์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์—„๊ฒฉํžˆ ํ†ต์ œํ•˜๊ณ , ์—ญํ• ๊ธฐ๋ฐ˜ ์ ‘๊ทผ์œผ๋กœ ์ตœ์†Œ ๊ถŒํ•œ๋งŒ ๋ถ€์—ฌ.

14.	[5์ ] Explain the โ€œpackingโ€ technology that can be used to hinder malware analysis, and how a packed malware can be executed. ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„์„ ๋ฐฉํ•ดํ•˜๋Š” ํŒจํ‚น ๊ธฐ์ˆ ์— ๋Œ€ํ•˜์—ฌ ์„ค๋ช…ํ•˜๊ณ , ํŒจํ‚น๋œ ์•…์„ฑ์ฝ”๋“œ๊ฐ€ ์–ด๋–ป๊ฒŒ ์‹คํ–‰๋˜๋Š”์ง€ ์„ค๋ช…ํ•˜์‹œ์˜ค.

ํŒจํ‚น ๊ธฐ์ˆ  ์„ค๋ช…:

โ€ข	ํŒจํ‚น์€ ์›๋ž˜์˜ ์‹คํ–‰ ํŒŒ์ผ(๋˜๋Š” ์•…์„ฑ์ฝ”๋“œ ๋ณธ์ฒด)์„ ์••์ถ•ยท์•”ํ˜ธํ™”ํ•˜๊ฑฐ๋‚˜ ๋‚œ๋…ํ™”ํ•˜์—ฌ ์ •์  ๋ถ„์„(๋ฐ”์ด๋„ˆ๋ฆฌ ์‹œ๊ทธ๋‹ˆ์ฒ˜, ๋ฌธ์ž์—ด ์ถ”์ถœ ๋“ฑ)์„ ์–ด๋ ต๊ฒŒ ๋งŒ๋“œ๋Š” ๊ธฐ์ˆ ์ž…๋‹ˆ๋‹ค. ํ•ฉ๋ฒ•์  ์†Œํ”„ํŠธ์›จ์–ด๋„ ๋ฆด๋ฆฌ์ฆˆ ํฌ๊ธฐ ์ถ•์†Œ๋ฅผ ์œ„ํ•ด ์“ฐ์ง€๋งŒ, ์•…์„ฑ์ฝ”๋“œ๋Š” ์ด๋ฅผ ์ด์šฉํ•ด ํƒ์ง€ ํšŒํ”ผ์™€ ๋ถ„์„ ์ง€์—ฐ์„ ๋…ธ๋ฆฝ๋‹ˆ๋‹ค.
โ€ข	๋‹ค์–‘ํ•œ ๋ฐฉ์‹: ๋‹จ์ˆœ ์••์ถ•(UPX ๋“ฑ), ์•”ํ˜ธํ™” + ์ž์ฒด ๋ณตํ˜ธํ™” ๋ฃจํ‹ด, ๋‹ค์ค‘ ๋ ˆ์ด์–ด(์žฌํŒจํ‚น), ๋‚œ๋…ํ™”๋œ ๋ณตํ˜ธํ™” ์Šคํ…, ๊ฐ€์ƒํ™” ๊ธฐ๋ฐ˜ ํŒจํ‚น(์ฝ”๋“œ๋ฅผ ๊ฐ€์ƒ ๋ช…๋ น์–ด๋กœ ๋ณ€ํ™˜) ๋“ฑ.

ํŒจํ‚น๋œ ์•…์„ฑ์ฝ”๋“œ ์‹คํ–‰ ๋ฐฉ์‹(์ผ๋ฐ˜ ํ๋ฆ„):

  1. ์‚ฌ์šฉ์ž(๋˜๋Š” ์‹œ์Šคํ…œ)๊ฐ€ ํŒจํ‚น๋œ ์‹คํ–‰ํŒŒ์ผ์„ ๋กœ๋“œ/์‹คํ–‰.
  2. ์‹คํ–‰ ํŒŒ์ผ์˜ ์—”ํŠธ๋ฆฌ ํฌ์ธํŠธ๋Š” ํŒจ์ปค์˜ ์Šคํ… ์ฝ”๋“œ(๋ณตํ˜ธํ™”/์••์ถ• ํ•ด์ œ ์ฝ”๋“œ)๋กœ ์—ฐ๊ฒฐ๋จ.
  3. ์Šคํ…์€ ๋‚ด๋ถ€์— ํฌํ•จ๋œ ์•”ํ˜ธํ™”๋œ/์••์ถ•๋œ ์›๋ณธ ์•…์„ฑ ํŽ˜์ด๋กœ๋“œ๋ฅผ ๋ฉ”๋ชจ๋ฆฌ๋กœ ์ฝ์–ด๋“ค์ž„.
  4. ๋ฉ”๋ชจ๋ฆฌ์—์„œ ๋ณตํ˜ธํ™”ยท์••์ถ• ํ•ด์ œ ์ˆ˜ํ–‰(๋•Œ๋กœ๋Š” ๋‚œ๋…ํ™”๋œ ๋ฃจํ‹ด์œผ๋กœ ์ˆจ๊น€).
  5. ํ•ด์ œ๋œ ์›๋ณธ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰(์ง์ ‘ ์ ํ”„ ๋˜๋Š” ์ƒˆ๋กœ์šด ๋ฉ”๋ชจ๋ฆฌ ์˜์—ญ์— ๋งคํ•‘ ํ›„ ์‹คํ–‰).
  6. ์ดํ›„ ์•…์„ฑ ํ–‰์œ„ ์ˆ˜ํ–‰.

โ€ข ์ด ๊ณผ์ • ๋•Œ๋ฌธ์— ์ •์  ๋ถ„์„ ๋„๊ตฌ๋Š” ์›๋ณธ ์ฝ”๋“œ๋ฅผ ์‰ฝ๊ฒŒ ์‹๋ณ„ํ•˜์ง€ ๋ชปํ•˜๊ณ , ๋™์  ๋ถ„์„ ํ™˜๊ฒฝ(์ƒŒ๋“œ๋ฐ•์Šค)์—์„œ๋„ ๋ณตํ˜ธํ™” ๋ฃจํ‹ด์„ ์ˆจ๊ธฐ๊ฑฐ๋‚˜ ํ™˜๊ฒฝ ๊ฐ์ง€๋ฅผ ํ†ตํ•ด ํ–‰์œ„๋ฅผ ์ง€์—ฐ์‹œํ‚ค๋Š” ๊ธฐ๋ฒ•์„ ๋ณ‘์šฉํ•˜๊ธฐ๋„ ํ•จ.

  1. [8์ ] ๋ด‡๋„ท(botnet)์— ๋Œ€ํ•˜์—ฌ ๋‹ค์Œ ๋ฌผ์Œ์— ๋‹ตํ•˜์‹œ์˜ค. (a) Explain four components of botnet, and what are roles of each component? ๋ด‡๋„ท์˜ ๊ตฌ์„ฑ์š”์†Œ(๋Œ€ํ‘œ์  4๊ฐ€์ง€)์™€ ์—ญํ• :

  2. C&C ์„œ๋ฒ„(๋˜๋Š” C2 ์ธํ”„๋ผ): ๊ณต๊ฒฉ์ž(๋ด‡๋งˆ์Šคํ„ฐ)๊ฐ€ ๋ด‡(๊ฐ์—ผ๋œ ํ˜ธ์ŠคํŠธ)๋“ค์—๊ฒŒ ๋ช…๋ น์„ ์ „๋‹ฌํ•˜๊ณ  ์ œ์–ด๋ฅผ ์ˆ˜ํ–‰ํ•˜๋Š” ์ค‘์•™ํ™”๋œ ์„œ๋ฒ„ ๋˜๋Š” ๋ถ„์‚ฐ ์ œ์–ด ์ธํ”„๋ผ(์˜ˆ: P2P). ๋ช…๋ น ๋ฐœ์†ก, ์—…๋ฐ์ดํŠธ ๋ฐฐํฌ, ๋ฐ์ดํ„ฐ ์ˆ˜์ง‘ ์—ญํ• .

  3. ๋ด‡(Agent, ๊ฐ์—ผ๋œ ํ˜ธ์ŠคํŠธ): ์•…์„ฑ์ฝ”๋“œ์— ์˜ํ•ด ์ œ์–ด๋˜๋Š” ์ปดํ“จํ„ฐ/์žฅ๋น„๋กœ์„œ ๋ช…๋ น์„ ์ˆ˜์‹ ํ•ด DDoS, ์ŠคํŒธ ์ „์†ก, ์ •๋ณด ์ˆ˜์ง‘ ๋“ฑ ์•…์„ฑ ํ–‰์œ„๋ฅผ ์ˆ˜ํ–‰.

  4. Command & Control ์ฑ„๋„/ํ”„๋กœํ† ์ฝœ: C&C์™€ ๋ด‡ ๊ฐ„ ํ†ต์‹ ์„ ์œ„ํ•œ ์ฑ„๋„๋กœ HTTP, IRC, P2P, DNS, ์•”ํ˜ธํ™”๋œ ์ฑ„๋„ ๋“ฑ ๋‹ค์–‘ํ•œ ๋ฐฉ์‹์ด ์‚ฌ์šฉ๋จ. ํ†ต์‹ ์„ ํ†ตํ•ด ๋ช…๋ นยท๊ฒฐ๊ณผยท์ƒํƒœ ๋ณด๊ณ ๊ฐ€ ์ด๋ฃจ์–ด์ง.

  5. ๋ฐฐํฌยท๊ฐ์—ผ ๋ฉ”์ปค๋‹ˆ์ฆ˜(์ „ํŒŒ ์ˆ˜๋‹จ): ๋ด‡์„ ํ™•์‚ฐ์‹œํ‚ค๋Š” ์ˆ˜๋‹จ์œผ๋กœ ์ด๋ฉ”์ผ ํ”ผ์‹ฑ, ์ทจ์•ฝ์  ์ต์Šคํ”Œ๋กœ์ž‡, ์•…์„ฑ ๊ด‘๊ณ , ์†Œ์…œ ์—”์ง€๋‹ˆ์–ด๋ง ๋“ฑ์ด ํฌํ•จ๋จ. ์ด๋กœ์จ ์ถ”๊ฐ€ ํ˜ธ์ŠคํŠธ๋ฅผ ๊ฐ์—ผ์‹œ์ผœ ๋ด‡๋„ท ๊ทœ๋ชจ๋ฅผ ํ‚ค์›€.

(b) Among the rally mechanisms, what is the dynamic DNS mechanism? โ€ข Dynamic DNS(Dynamic Domain Name System) ๋ฉ”์ปค๋‹ˆ์ฆ˜์€ ๋ด‡๋„ท์—์„œ C&C์˜ ์œ„์น˜๋ฅผ ์œ ์—ฐํ•˜๊ฒŒ ์œ ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ๊ธฐ๋ฒ• ์ค‘ ํ•˜๋‚˜์ž…๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ์ž์ฃผ ๋ฐ”๋€Œ๋Š” IP ์ฃผ์†Œ(์˜ˆ: ์ž„๋Œ€ํ˜• ์„œ๋ฒ„, DDoS ํšŒํ”ผ, ๋น ๋ฅธ ์ „ํ™˜)๋ฅผ ๊ฐ€์ง„ C&C ์„œ๋ฒ„๋ฅผ ์šด์˜ํ•  ๋•Œ ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ์‚ฌ์šฉํ•˜๊ณ , ํ•ด๋‹น ๋„๋ฉ”์ธ์— ๋Œ€ํ•ด ๋™์ ์œผ๋กœ DNS ๋ ˆ์ฝ”๋“œ๋ฅผ ๊ฐฑ์‹ ํ•ฉ๋‹ˆ๋‹ค. โ€ข ๋ด‡์€ ๊ณ ์ • IP ๋Œ€์‹  ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ์กฐํšŒํ•ด ํ˜„์žฌ ์—ฐ๊ฒฐ ๊ฐ€๋Šฅํ•œ C&C IP๋ฅผ ์–ป์œผ๋ฏ€๋กœ, C&C์˜ ์‹ค์ œ IP๊ฐ€ ๋ฐ”๋€Œ์–ด๋„ ๋„๋ฉ”์ธ๋งŒ ์—…๋ฐ์ดํŠธํ•˜๋ฉด ๋ด‡๊ณผ์˜ ์—ฐ๊ฒฐ์„ ์œ ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. โ€ข ์ด ๋ฐฉ์‹์€ C&C ์€๋‹‰์„ฑ ํ–ฅ์ƒ ๋ฐ ์ถ”์ ยท์ฐจ๋‹จ ํšŒํ”ผ์— ์œ ๋ฆฌํ•˜๋ฉฐ, ๋ฐฉ์–ด์ธก์—์„œ๋Š” ๋„๋ฉ”์ธ ์ž์ฒด๋ฅผ ์ฐจ๋‹จํ•˜๊ฑฐ๋‚˜ DNS ์š”์ฒญ ํŒจํ„ด ๋ถ„์„์œผ๋กœ ํƒ์ง€ยท์ฐจ๋‹จํ•˜๋Š” ๋Œ€์‘์„ ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.

์ตœ๊ทผ ์ˆ˜์ •: 26. 6. 12. ์˜คํ›„ 3:28
Contributors: kmbzn, Claude Sonnet 4.6

BUILT WITH

CloudflareNode.jsGitHubGitVue.jsJavaScriptVSCodenpm

All trademarks and logos are property of their respective owners.
ยฉ 2026 kmbzn ยท MIT License