A Study on the Real-time Cyber Attack Intrusion Detection Method

실시간 사이버 공격 침해사고 탐지방법에 관한 연구

  • Choi, Jae-Hyun (Department of Smart Convergency Consulting, Hansung University) ;
  • Lee, Hoo-Jin (Department of Smart Convergency Consulting, Hansung University)
  • 최재현 (한성대학교 스마트융합컨설팅학과) ;
  • 이후진 (한성대학교 스마트융합컨설팅학과)
  • Received : 2018.05.29
  • Accepted : 2018.07.20
  • Published : 2018.07.28


Recently, as the threat of cyber crime increases, the importance of security control to cope with cyber attacks on the information systems in the first place such as real-time detection is increasing. In the name of security control center, cyber terror response center and infringement response center, institutional control personnel are making efforts to prevent cyber attacks. Especially, we are detecting infringement accident by using network security equipment or utilizing control system, but it's not enough to prevent infringement accident by just controlling based on device-driven simple patterns. Therefore, the security control system is continuously being upgraded, and the development and research on the detection method are being actively carried out by the prevention activity against the threat of infringement. In this paper, we have defined the method of detecting infringement of major component module in order to improve the problem of existing infringement detection method. Through the performance tests for each module, we propose measures for effective security control and study effective infringement threat detection method by upgrading the control system using Security Information Event Management (SIEM).


Security Control Center;ESM;SIEM;Correlation Analysis;Cyber Crime


