DOI QR코드

DOI QR Code

VPN의 보안성 평가를 위한 CC와 ISO 관련 표준의 융합

Convergence of Related Standard of CC and ISO for Security Evaluation of VPN

  • 이하용 (서울벤처대학원대학교 융합산업학과) ;
  • 양효식 (삼일회계법인 IT Risk & Security)
  • Lee, Ha-Young (Dept. of Fusion Industry, Seoul Venture University) ;
  • Yang, Hyo-Sik (Samil PricewaterhouseCoopers IT Risk & Security)
  • 투고 : 2016.04.04
  • 심사 : 2016.05.20
  • 발행 : 2016.05.28

초록

VPN은 인터넷망을 이용하므로 데이터를 암호화하는 보안기술이 뒷받침되어야 하며 보안성에 대한 확신을 줄 수 있도록 표준에 기반을 둔 평가 기술이 뒷받침되어야 한다. 그러므로 연관된 표준을 기반으로 VPN의 보안성을 평가할 수 있는 방법을 체계화할 필요가 있다. 따라서 본 연구에서는 정보보호시스템의 인증을 위한 평가기준인 CC(Common Criteria)와 소프트웨어 품질평가 표준인 ISO의 보안성(기밀성, 무결성, 부인방지, 책임성, 인증성) 평가 부분을 접목하여 이를 통합한 보안성 평가 모델을 구축하고자 하였다. 이를 위해 VPN의 기반 기술과 보안성에 관한 품질 요구사항을 분석하여 두 국제표준의 품질특성과의 연관성을 고려한 평가모델을 개발하였다. 이를 통해 VPN의 보안성 품질수준을 평가하는 융합 모델을 구축할 수 있을 것으로 사료되며, 향후 VPN에 대한 평가사례의 축적을 통해 평가모델의 적합성과 타당성을 제고할 필요가 있다.

Because VPN(Virtual Private Network) uses internet network, the security technique should support it and evaluation technique based on standard should support it. Therefore the method should be organized that can evaluate the security of VPN based on the related standard. In this study, we intended to construct the security evaluation model through combining CC(Common Criteria) which is a evaluation standard and a part of security(Confidentiality, Integrity, Non-repudiation, Accountability, Authenticity) evaluation of ISO which is the standard of software quality evaluation. For this, we analyzed the quality requirements about intra-technology and security of VPN and constructed the evaluation model related to the quality characteristics of two international standard. Through this, we are able to construct a convergence model for security evaluation of VPN. Through accumulating the evaluation practices for VPN in the future, the suitability and validity of the evaluation model must be improved.

키워드

참고문헌

  1. Bong-Hyun Kim, Dong-Uk Cho, "Trend and Prospect of Network Security Technology", The Journal of Korean Institute of Communications and Information Sciences(J-KICS)NIPA), Vol. 31, No. 4, 2014.
  2. Jong-Hoon Han, Jung-Woo Lee, Sung-Han Park, "A Dynamic Key Lifetime Change Algorithm for Performance Improvement of Virtual Private Networks", Journal of the Institute of Electronics Engineers of Korea, Vol. 42, No. 10, p. 31, 2005. 10.
  3. Kang-Soo Lee, Young-Soo Kim et al.,, "Virtual Private Network Protection Profile V2.0", Korea Information Security Agency & Hannam University, 2008. 4.
  4. Ha-Yong Lee, Jung-Gyu Kim, "Efficiency Evaluation Convergence Model of Virtual Private Network based on CC and ISO Standard", Journal of Digital Convergence, Vol.13, No.5, pp. 169-176, 2015. 5. https://doi.org/10.14400/JDC.2015.13.5.169
  5. Myung-Seong Yim, "Development of Measures of Information Security Policy Effectiveness To Maximize the Convergence Security", Journal of the Korea Convergence Society, Vol. 5, No. 4, pp. 27-32, 2014. https://doi.org/10.15207/JKCS.2014.5.4.027
  6. Kyung-Muk Kim, Hae-Sool Yang, "VPN(Virtual Private Network) SW's examination example analysis", Journal of academia-industrial technology, Vol.11, No.8, 2010.
  7. Ha-Yong Lee, Jung_Gyu Kim, "Quality Evaluation Model about Efficiency for Fingerprint Recognition System", Journal of digital Convergence, Vol. 12, No. 6, 2014.
  8. Ha-Yong Lee, Jung-Gyu Kim, "Quality Evaluation Model for Security of DRM Software", The Journal of Policy & Management, Vol. 11, No. 5, 2013. 5.
  9. Sang-Won Kang, In-Oh Jeon, Hae-Sool Yang, "Usability Quality Evaluation Plan of DRM Softwares", Proceedings of The Korea Academia-Industrial Cooperation Society, 2010. 11.
  10. Sang-Won Kang, Hae-Sool Yang, "Quality Evaluation of Criterion Construction for Open Source Software", The Journal of digital policy & management, Vol. 11, No. 2, pp. 323-330, 2013.
  11. ISO/IEC 25020, "Software product Quality Requirements and Evaluation(SQuaRE) -- Measurement reference model and guide", 2007.
  12. ISO/IEC 25030, "Soiftware product Quality Requirements and Evaluation(SQuaRE) -- Quality requirements", 2007.
  13. ISO/IEC 25040, "Systems and software engineering - Systems and software Quality Requirements and Evaluation(SQuaRE) -- Evaluation process", 2011.
  14. ISO/IEC 25041, "Systems and software engineering -- Systems and software Quality Requirements and Evaluation(SQuaRE) -- Evaluation guide for developers, acquirers and independent evaluators", 2012.
  15. yong-won kim, "A study on Convergent & Adaptive Quality Analysis using DQnA model", Journal of the Korea Convergence Society, Vol. 5, No. 4, pp. 21-25, 2014. https://doi.org/10.15207/JKCS.2014.5.4.021