선박용 Security Information Event Management (SIEM) 개발을 위한 보안 정책 모델에 관한 연구Research on Security Detection Policy Model in the SIEM for Ship
- Other Titles
- Research on Security Detection Policy Model in the SIEM for Ship
- Authors
- 손금준; 안종우; 이창식; 강남선; 김성록
- Issue Date
- 8월-2024
- Publisher
- 대한조선학회
- Keywords
- SIEM(Security Information Event Management; 보안 정보 및 이벤트 관리); Security(보안); Policy(정책); Traffic(트래픽); Event log(이벤트 로그)
- Citation
- 대한조선학회 논문집, v.61, no.4, pp 278 - 288
- Pages
- 11
- Journal Title
- 대한조선학회 논문집
- Volume
- 61
- Number
- 4
- Start Page
- 278
- End Page
- 288
- URI
- https://www.kriso.re.kr/sciwatch/handle/2021.sw.kriso/10684
- DOI
- 10.3744/SNAK.2024.61.4.278
- ISSN
- 1225-1143
2287-7355
- Abstract
- According to International Association of Classification Societies (IACS) Unified Requirement (UR) E26, ships contracted for construction after July 1, 2024 should be designed, constructed, commissioned and operated taking into account of cyber security. In particular, ship network monitoring tools should be installed in accordance with requirement 4.3.1 in IACS UR E26. In this paper, we propose a Security Information and Event Management (SIEM) security policy model for ships as an effective threat detection method by analyzing the cyber security regulations and ship network status in the maritime domain. For this purpose, we derived the items managed in the SIEM from the maritime cyber security regulations such as those of International Maritime Organization (IMO) and IACS, and defined 14 detection policies considering the status of the ship network. We also presents the detection policy for non-expert crews to understand it, and occurrence conditions depending on the ship's network environment to minimize indiscriminate alarms. We expect that the results of this study will help improve the efficiency of ship SIEM to be installed in the future.
- Files in This Item
- There are no files associated with this item.
- Appears in
Collections - ETC > 1. Journal Articles
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.