DOI QR코드

DOI QR Code

A Study on the Activation of Sharing Cyber-Threat Information among Businesses

기업의 사이버위협정보 공유 활성화에 관한 연구

  • 최석언 ((재)한국보건의료정보원 보건의료표준화부) ;
  • 이종섭 ((주)AIBIZ) ;
  • 탁근선 ((주)아이전스) ;
  • 최주원 ((주)아이전스)
  • Received : 2022.11.16
  • Accepted : 2023.01.26
  • Published : 2023.04.30

Abstract

The domestic threat information sharing system to deal with various security threats in the rapidly changing cyber environment needs to be improved. In this study, to solve these problems and promote the activation of threat information sharing, we derive a research model based on the value-based containment model (VAM) for vital factors in information sharing. After conducting a Ricardian 5-point survey on a total of 204 individuals, the statistical results of the first 151 individuals were analyzed using SPSS and AMOS, and the statistical results of the second 204 individuals were analyzed using R-Studio. As a result, perceivability was found to have a significant impact as a core factor in the activation of cyber threat information sharing (β=0.405, p<0.01), and the hindrance factor was analyzed as innovation resistance (β=-0.152, p<0.01). Microscopically, the obtained results can be applied to factor analysis for activating information sharing of cyber threats by companies in the future, and macroscopically, they can contribute to the foundational development of a national cyber threat response system.

급변하는 사이버 환경에서 다양한 유형으로 발생하는 보안위협에 상응하기 위한 국내 위협정보 공유체계는 미흡한 상황이다. 본 연구에서는 이러한 문제를 해결하고 위협정보 공유 활성화를 제고시키고자, 정보 공유 시 핵심 요인을 가치기반수용모델(VAM) 기반으로 연구모델을 도출하고 정보보호 관련 종사자들 총 204명 대상으로 리커드 5점 척도 설문조사를 수행한 후 1차 151명의 통계결과를 SPSS와 AMOS를 활용하여 분석을 수행하고 2차 204명의 통계결과를 R-Studio를 통해 추가 검증하였다. 이를 통하여 사이버위협정보 공유 활성화 핵심요인으로 지각된 용이성이 유의미한 영향을 미치고 있으며(β=0.405, p<0.01), 저해요인은 혁신 저항으로 분석되었다(β=-0.152, p<0.01). 도출된 연구 결과는 미시적으로 향후 기업의 사어버 위협정보 공유의 활성화를 위한 요인 분석 시 활용과 거시적으로 국가 사이버위협 대응체계의 기반 조성에 기여할 수 있겠다.

Keywords

References

  1. E. Y. Kim, The era of 'cyber pandemic' that resembles COVID-19 is coming.: The Science Times [Internet], https://www.sciencetimes.co.kr/?p=208118.
  2. AtlasVPN, 60 Worrying Cybercrime Statistics & Facts [2022] [Internet], https://atlasvpn.com/blog/cybercrime-statistic.
  3. Y. S. Lee, H. W. Moon, G Y. Park, T. Y. Kim, and J. S. Song, "Trends in cyber threat and response technology according to COVID-19: Focusing on security systems and infringement response services," Korea Institute of Information Security and Cryptology, Vol.31, No.5, pp.5-12, 2021.
  4. National Intelligence Service et al., 2021 National Cybersecurity White Paper [Internet], https://www.kisa.or.kr/20303/form?postSeq=0241&page=1
  5. S. A. Kim, Even if COVID-19 disappears, the cyber pandemic continues : Datanet News [Internet], https://www.datanet.co.kr/news/articleView.html?idxno=15479.
  6. Z. Fathi, A. J. Rafsanjani, and F. Habibi, "Anon-ISAC: Anonymity-preserving cyber threat information sharing platform based on permissioned Blockchain," 2020 28th Iranian Conference on Electrical Engineering (ICEE), Aug. 2020.
  7. D. G. Kim, S. S. Baek, and D. H. Yoo, "Sharing the cyber threat intelligence on cyber crises: The appropriate role of the national intelligence agency," The Society of Digital Policy & Management, Vol.15, No.6, pp.51-59, 2017.
  8. H. J. Lee and H. S. Jo, "Korean cyber threat information sharing technology and development direction," Journal of the Korean Society for Information Protection, Korea Institute of Information Security and Cryptology, Vol.31, No.5, pp.47-54, 2021.
  9. S. N. Khajeddin, A. Madani, H. Gharaee, and F. Abazari, "Towards a functional and trustful web-based information sharing center," 2019 5th International Conference on Web Research (ICWR), pp.252-257, Apr. 2019.
  10. J. S. Lee, "A study on the factors affecting the intention to use mydata service based on open banking," Ph.D. dissertation, Soongsil University, Seoul, 2022.
  11. H. J. Kwoun, "A study on the effect of local government's technology readiness index on cloud computing conversion intention: Focused on the mediating role of VAM and the moderating effect of organizational learning," Ph.D. dissertation, Soongsil University, Seoul, 2022.
  12. Y. J. Joo, "Effect of avatar characteristics and avatar identification on information sharing intention and loyalty in role-playing game (RPG)," MA. dissertation, Konkuk University, Seoul, 2022.
  13. M. Y. Dong, "The Effects of Information sharing by interfirm networks on supply chain resilience and firm's performance," MA. dissertation, Inha University, Incheon, 2022.
  14. S. G. Oh, "Cooperation environment within the supply chain and direct and indirect performance of the company," The Korea Society of Information Technology Applications 2010. Spring Conference Materials Book, pp.235-247, 2010.
  15. S. Barnum, "Standardizing cyber threat intelligence information with the structured threat information expression (stix)," Mitre, pp.7-8, 2012.
  16. D. W. Chadwick et al., "A cloud-edge based data security architecture for sharing and analysing cyber threat information," Future Generation Computer Systems, Vol. 102, No.C, pp.710-722, 2020. https://doi.org/10.1016/j.future.2019.06.026
  17. S. E. Choe, "A study on the facilitation of sharing cyber-threat information among businesses: Empirical analysis according to the value-based adoption model (VAM)," MA. dissertation, Dongguk University, Seoul, 2022.
  18. D. Kahneman and A. Tversky, "Prospect theory: An analysis of decision under risk," The Econometric Society, pp.284-289, 1979.
  19. H. Kim, H. C. Chan, and S. Gupta, "Value-based adoption of mobile internet: An empirical investigation," Decision Support Systems, pp.115-116, 2007.
  20. S. Liu, "A study on factors affecting intention to use sharing economy services based on value-based adoption model: Focus on the moderating effect of psychological ownership," Ph.D. dissertation, Kyunggi University, Suwon, 2022.
  21. S. J. Nam, "The effects of individualism/collectivism and consumption values on the consumption self-regulation," Journal of Korean Consumption Culture Association, Vol.10, No.3, pp.59-86, 2007. https://doi.org/10.17053/jcc.2007.10.3.004
  22. J. W. Choi, "A study on factors affecting acceptance intention to use smart fish farming system based on artificial intelligence," Ph.D. dissertation, Soongsil University, Seoul, 2021.
  23. M. J. Lee, "The association between health teachers' stress, burnout, and self-efficacy: A path analysis approach," Journal of Korea Academia-Industrial Cooperation Society (JKAIS), Vol.21, No.1, pp.317-325, 2020.
  24. Y. T. Jo, "A study of executives' intention on accepting the artificial intelligence collaborative decision-making framework," Ph.D. dissertation, Soongsil University, Seoul, 2022.
  25. G. Y. Gu, "A study on the factor affecting the intention to use the service provided by the rpa system," Ph.D. dissertation, Soongsil University, Seoul, 2022.
  26. B. Muthen and D. Kaplan, "A comparison of some methodologies for the factor analysis of non-normal Likert variables," British Journal of Mathematical and Statistical Psychology, Vol.38, No.2, pp.87-94, 1985. https://doi.org/10.1111/j.2044-8317.1985.tb00818.x
  27. E. G. Carmines and J. P. McIver, "Analyzing models with unobserved variables: Analysis of covariance structures," Social Measurement : Current Issues, 1981.
  28. M. W. Browne and R. Cudeck, "Alternative ways of assessing model fit," Sociological Methods & Research, Vol.21, No.2, pp.230-258, 1992. https://doi.org/10.1177/0049124192021002005
  29. J. F. Hair, R. E. Anderson, and R. Tatham, "Multivariate data analysis with readings, 2nd and 4th Ed," New York, NY: Macmillan, 1998.
  30. K.G. Joreskog and D. Sorbom, "LISREL VI: Analysis of linear structural relationships by the method of maximum likelihood," Chicago : National Educational Resources, 1984.
  31. S. A. Mulaik, L. R. James, J. Van Alstine, N. Bennet, S. Lind, and C. D. Stilwell, "Evaluation of goodness-of-fit indices for structural equation models," Psychological Bulletin, Vol.105, No.3, pp.430-445, 1989. https://doi.org/10.1037/0033-2909.105.3.430
  32. P. M. Bentler and D. G. Bonett, "Significance tests and goodness of fit in the analysis of covariance structures," Psychological Bulletin, Vol.88, No.3, pp.588-606, 1980.  https://doi.org/10.1037/0033-2909.88.3.588
  33. P. M. Bentler, "Comparative fit indexes in structural models," Psychological Bulletin, Vol.107, No.2, pp.238-246, 1990. https://doi.org/10.1037/0033-2909.107.2.238
  34. L. R. James, S. A. Mulaik, and J. M. Brett, "Causal analysis: Assumptions, models, and data," Beverly Hills (Calif.): Sage. 1983.
  35. E. S. Lee, "Development of a job crafting scale for hospital nurses," Ph.D. dissertation, Chosun University, Gwangju, 2018.
  36. H. K. Kwoun, "The mediation effect of college Major and Job match on the relationship between Graduates satisfaction with university education and job satisfaction," MA. dissertation, Yeungnam University, Gyeongsan, 2021.
  37. J. C. Nunnally and I. H. Bernstein, "Psychometric theory," 3rd edition, New York : McGraw-Hill, 1994.
  38. R. P. Bagozzi and Y. Yi, "On the evaluation of structural equation models," Journal of the Academy of Marketing Science, Vol.16, No.1, pp.74-94,
  39. C. H. Yoon and S. H. Kim, "A tutorial on PLS structural equating modeling using R: (Centering on) Exemplified research model and data," Information Systems Review, Vol.16, No.3, pp.89-112, 2014. https://doi.org/10.14329/isr.2014.16.3.089
  40. D. Gefen and D. Straub, "A practical guide to factorial validity using PLS-Graph: Tutorial and annotated example," Communications of the Association for Information Systems, Vol.16, No.1, pp.91-109, 2005. https://doi.org/10.17705/1CAIS.01605
  41. J. F. Hair, G. T. M. Hult, C. M. Ringle, and M. Sarstedt, "A primer on partial least squares structural equation modeling (PLS-SEM), Thousand Oaks: Sage Publications," 2014.
  42. F. Francy, "The aviation information sharing and analysis center (A-ISAC)," ICNS 2015 - Innovation in Operations, Implementation Benefits and Integration of the CNS Infrastructure, Conference Proceedings, 2015.
  43. T. Wallis and R. Leszczyna, "EE-ISAC-Practical cyber-security solution for the energy sector," Energies, Vol.15, No.6, pp.2170, 2022.
  44. C. Z. Liu, Y. A. Au, and H. Zafar, "Rethinking FS-ISAC: An IT security information sharing network model for the financial services sector," Communications of the Association for Information Systems, Vol.34, No.1, pp.15-36, 2014. https://doi.org/10.17705/1CAIS.03402
  45. I. M. Sholihah, H. Setiawan, and O. G. Nabila, "Design and development of information sharing and analysis center (ISAC) as an information sharing platform," 2021 Sixth International Conference on Informatics and Computing (ICIC), 2021.
  46. C. P. Lamberton and R. L. Rose. "When is ours better than mine? A framework for understanding and altering participation in commercial sharing systems," Journal of Marketing, Vol.76, No.4, pp.109-125, 2012. https://doi.org/10.1509/jm.10.0368
  47. G. Y. Jo, "Study on the structural relationship between characteristic factors of shared accommodation platform and co-creation value and reuse intention by applying Value-based Adoption Model: Focusing on Airbnb," Ph.D. dissertation, Kyunghee University, Seoul, 2020.
  48. I. S. Koo, "The effect of shared leadership on organizational commitment and change-oriented organizational citizenship behavior: The mediating effect of positive psychological capital and the moderating effect of LMX," Ph.D. dissertation, Hanyang University, Seoul, 2020.
  49. K. Y. Koo, "A study on the factor affecting the intention to use the service provided by the RPA system," Ph.D. dissertation, Soongsil University, Seoul, 2022,
  50. V. A. Zeithaml, "Consumer perceptions of price, quality, and value: a means-end model and synthesis of evidence," Journal of Marketing, Vol.52, No.3, pp.2-22, 1988.  https://doi.org/10.1177/002224298805200302