정보보안학 용어 전체 목록
디지털 자산과 정보를 보호하기 위한 기술과 관리 체계를 다루는 분야입니다. 네트워크 보안, 시스템 및 운영체제 보안, 웹 애플리케이션 보안 같은 분야별 대응과 침해사고 대응 및 포렌식까지 포함합니다. 보안 전문가, IT 시스템 관리자, 정보보호 담당자가 필요로 하는 용어들입니다.
총 323개 용어 · 다른 분야 보기
IoT 및 임베디드 보안 (21개)
- 글리칭공격 (Glitching Attack)
- 물리적복제방지함수(PUF) (Physical Unclonable Function)
- 보안 펌웨어 업데이트 메커니즘 (Secure Firmware Update Mechanism)
- 보안요소(SE) (Secure Element)
- 부채널 공격 (Side-Channel Attack)
- 사물인터넷 보안 (Internet of Things Security)
- 산업제어시스템 보안 (Industrial Control System Security)
- 신뢰플랫폼모듈(TPM) (Trusted Platform Module)
- 오류주입 공격 (Fault Injection Attack)
- 운영기술(OT) 보안 (Operational Technology Security)
- 임베디드 시스템 보안 (Embedded System Security)
- 임베디드 신뢰루트 (Embedded Root of Trust)
- 전력분석 부채널 공격 (Power Analysis Side-Channel Attack)
- 펌웨어 리버스엔지니어링 (Firmware Reverse Engineering)
- 펌웨어 변조 탐지 (Firmware Tampering Detection)
- 펌웨어 보안 (Firmware Security)
- IoT 기기 핑거프린팅 (IoT Device Fingerprinting)
- JTAG 디버그포트 악용 (JTAG Debug Port Exploitation)
- JTAG 디버깅보안 (JTAG Debugging Security)
- PLC 보안 (Programmable Logic Controller Security)
- SCADA 보안 (SCADA Security)
PKI 및 키 관리 (17개)
- 공개키 기반구조(PKI) (Public Key Infrastructure)
- 디지털 인증서 (Digital Certificate)
- 상호인증 (Cross-Certification)
- 샤미르 비밀분산 (Shamir's Secret Sharing)
- 시크릿관리 (Secrets Management)
- 완전순방향비밀성 (Perfect Forward Secrecy)
- 인증기관 (Certificate Authority)
- 인증서 투명성 (Certificate Transparency)
- 인증서 폐지목록 (Certificate Revocation List (CRL))
- 키 관리 (Key Management)
- 키 래핑 (Key Wrapping)
- 키 순환 정책 (Key Rotation Policy)
- 키 에스크로 (Key Escrow)
- 키 유도함수 (Key Derivation Function)
- 하드웨어 보안모듈 (Hardware Security Module)
- HKDF 키유도함수 (HMAC-based Key Derivation Function (HKDF))
- OCSP 스테이플링 (OCSP Stapling)
네트워크 보안 (18개)
- 가상사설망 (Virtual Private Network)
- 네트워크 분할 (Network Segmentation)
- 마이크로 세그멘테이션 (Micro-Segmentation)
- 볼류메트릭 DDoS 공격 (Volumetric DDoS Attack)
- 분산서비스거부공격 (Distributed Denial-of-Service Attack)
- 서비스거부공격 (Denial-of-Service Attack)
- 소프트웨어정의네트워크 보안 (Software-Defined Network Security)
- 심층 패킷 검사 (Deep Packet Inspection (DPI))
- 중간자공격 (Man-in-the-Middle Attack)
- 침입방지시스템 (Intrusion Prevention System)
- 침입탐지/방지시스템 (Intrusion Detection/Prevention System (IDS/IPS))
- 침입탐지시스템 (Intrusion Detection System)
- 패킷캡처분석 (Packet Capture Analysis)
- ARP 스푸핑 (ARP Spoofing)
- BGP 하이재킹 (BGP Hijacking)
- DNS 스푸핑 (DNS Spoofing)
- DNS 터널링 (DNS Tunneling)
- SYN 플러드 공격 (SYN Flood Attack)
무선 및 프로토콜 보안 (17개)
- 도메인네임시스템 보안확장(DNSSEC) (Domain Name System Security Extensions)
- 무선네트워크 보안 (Wireless Network Security)
- 보안소켓계층(SSL) (Secure Sockets Layer)
- 불법 액세스포인트 (Rogue Access Point)
- 블루투스 보안 (Bluetooth Security)
- 블루투스 저전력 보안 (Bluetooth Low Energy Security)
- 전송계층보안(TLS) (Transport Layer Security)
- 지그비 프로토콜 보안 (Zigbee Protocol Security)
- 키 재설치 공격(KRACK) (Key Reinstallation Attack (KRACK))
- CAN버스 보안 (Controller Area Network Security)
- DNS 보안 확장 (DNSSEC)
- GPS 스푸핑 (GPS Spoofing)
- IMSI 캐처 (IMSI Catcher)
- IP 보안 프로토콜(IPsec) (IPsec)
- Modbus 프로토콜 보안 (Modbus Protocol Security)
- NFC 릴레이 공격 (NFC Relay Attack)
- WPA3 동시인증(SAE) (WPA3 Simultaneous Authentication of Equals (SAE))
보안 거버넌스 및 위험관리 (21개)
- 데이터유출방지 (Data Loss Prevention)
- 보안 성과지표 (Security Metrics and KPIs)
- 보안 성숙도 모델 (Security Maturity Model)
- 보안인식교육 (Security Awareness Training)
- 보안정책 (Security Policy)
- 보안통제 기준선 (Security Control Baseline)
- 보이스피싱(비싱) (Vishing)
- 비즈니스이메일침해(BEC) (Business Email Compromise)
- 사회공학 (Social Engineering)
- 스미싱 (Smishing)
- 스피어피싱 (Spear Phishing)
- 업무영향분석 (Business Impact Analysis (BIA))
- 웨일링공격 (Whaling Attack)
- 위험 수용도 (Risk Appetite)
- 위협 모델링 (Threat Modeling)
- 제3자 위험관리 (Third-Party Risk Management)
- 테일게이팅 (Tailgating)
- 프리텍스팅 (Pretexting)
- 피싱 (Phishing)
- ISO/IEC 27001 정보보호관리체계 (ISO/IEC 27001 ISMS)
- NIST 사이버보안 프레임워크 (NIST Cybersecurity Framework)
블록체인 보안 (18개)
- 51% 공격 (51% Attack)
- 개인키 커스터디 (Private Key Custody)
- 개인키탈취 (Private Key Theft)
- 다중서명지갑 (Multisignature Wallet)
- 러그풀 (Rug Pull)
- 블록체인 보안 (Blockchain Security)
- 스마트컨트랙트 취약점 (Smart Contract Vulnerability)
- 시빌 공격 (Sybil Attack)
- 오라클조작공격 (Oracle Manipulation Attack)
- 이중지불 공격 (Double-Spending Attack)
- 재진입 공격 (Reentrancy Attack)
- 채굴자추출가치(MEV) (Miner Extractable Value)
- 콜드월렛 (Cold Wallet)
- 크로스체인 브리지 취약점 (Cross-Chain Bridge Vulnerability)
- 프런트러닝공격 (Front-Running Attack)
- 플래시론 공격 (Flash Loan Attack)
- 합의 알고리즘 보안 (Consensus Algorithm Security)
- 핫월렛 (Hot Wallet)
시스템 및 운영체제 보안 (18개)
- 권한상승 (Privilege Escalation)
- 데이터실행방지(DEP) (Data Execution Prevention)
- 모바일기기관리(MDM) (Mobile Device Management)
- 모바일앱 보안 (Mobile Application Security)
- 보안부팅 (Secure Boot)
- 샌드박싱 (Sandboxing)
- 신뢰실행환경 (Trusted Execution Environment)
- 안드로이드 보안모델 (Android Security Model)
- 앱 리패키징공격 (App Repackaging Attack)
- 제어흐름무결성(CFI) (Control-Flow Integrity)
- 주소공간 배치 난수화 (Address Space Layout Randomization)
- 주소공간배치 무작위화 (Address Space Layout Randomization (ASLR))
- 체루트 감옥 (Chroot Jail)
- 커널 권한상승 (Kernel Privilege Escalation)
- 커널익스플로잇 (Kernel Exploit)
- iOS 보안모델 (iOS Security Model)
- SELinux 보안정책 (SELinux Security Policy)
- SELinux(보안강화리눅스) (Security-Enhanced Linux)
악성코드 분석 (29개)
- 논리폭탄 (Logic Bomb)
- 다형성 악성코드 (Polymorphic Malware)
- 동적 악성코드 분석 (Dynamic Malware Analysis)
- 랜섬웨어 (Ransomware)
- 랜섬웨어 암호화 방식 (Ransomware Encryption Scheme)
- 루트킷 (Rootkit)
- 루트킷 탐지 (Rootkit Detection)
- 명령제어(C2) 인프라 (Command-and-Control (C2) Infrastructure)
- 명령제어서버 (Command-and-Control Server)
- 백도어 (Backdoor)
- 변형성 악성코드 (Metamorphic Malware)
- 보안 리버스엔지니어링 (Security Reverse Engineering)
- 봇넷 (Botnet)
- 봇넷 아키텍처 (Botnet Architecture)
- 샌드박스 회피 (Sandbox Evasion)
- 샌드박스 회피 기법 (Sandbox Evasion Technique)
- 스파이웨어 (Spyware)
- 악성코드 난독화 (Malware Obfuscation)
- 악성코드 분석 (Malware Analysis)
- 악성코드 패커 (Malware Packer)
- 안티디버깅기법 (Anti-Debugging Technique)
- 와이퍼 악성코드 (Wiper Malware)
- 원격접근트로이목마(RAT) (Remote Access Trojan)
- 정적악성코드분석 (Static Malware Analysis)
- 컴퓨터 웜 (Computer Worm)
- 키로거 (Keylogger)
- 트로이목마 (Trojan Horse)
- 파일리스 악성코드 (Fileless Malware)
- YARA 규칙 (YARA Rule)
암호 알고리즘 (18개)
- 격자 기반 암호 (Lattice-Based Cryptography)
- 고급 암호화 표준(AES) (Advanced Encryption Standard)
- 대칭키 암호 (Symmetric-key Cryptography)
- 블록 암호 (Block Cipher)
- 비대칭키 암호 (Asymmetric-key Cryptography)
- 속성기반암호화 (Attribute-Based Encryption)
- 스트림 암호 (Stream Cipher)
- 안전 다자간 계산 (Secure Multi-Party Computation)
- 양자내성암호 (Post-Quantum Cryptography)
- 임계암호 (Threshold Cryptography)
- 차차20-폴리1305 (ChaCha20-Poly1305)
- 크리스탈스-딜리시움 서명 (CRYSTALS-Dilithium Signature)
- 크리스탈스-카이버 키캡슐화 (CRYSTALS-Kyber Key Encapsulation)
- 패딩 오라클 공격 (Padding Oracle Attack)
- 함수암호화 (Functional Encryption)
- 형태보존암호화 (Format-Preserving Encryption)
- AES-GCM 모드 (AES-GCM (Galois/Counter Mode))
- RSA 암호시스템 (RSA Cryptosystem)
웹 애플리케이션 보안 (20개)
- 객체수준 권한부여 취약점 (Broken Object Level Authorization (BOLA))
- 교차사이트 요청위조 (CSRF)
- 교차출처리소스공유(CORS) (Cross-Origin Resource Sharing)
- 동일출처정책 (Same-Origin Policy)
- 디렉터리순회 (Directory Traversal)
- 블라인드 SQL 인젝션 (Blind SQL Injection)
- 사이트 간 요청 위조 (Cross-Site Request Forgery)
- 서버측요청위조(SSRF) (Server-Side Request Forgery)
- 세션 하이재킹 (Session Hijacking)
- 안전하지않은 역직렬화 (Insecure Deserialization)
- 웹 애플리케이션 방화벽 (Web Application Firewall)
- 입력값 검증 (Input Validation)
- 콘텐츠보안정책(CSP) (Content Security Policy)
- 클릭재킹 (Clickjacking)
- 하위리소스무결성(SRI) (Subresource Integrity)
- API 요청제한 (API Rate Limiting)
- DOM기반 XSS (DOM-based Cross-Site Scripting)
- HTTP 보안헤더 (HTTP Security Headers)
- OWASP 톱10 (OWASP Top 10)
- XML 외부개체(XXE) (XML External Entity)
인공지능 보안 (14개)
- 데이터오염공격 (Data Poisoning Attack)
- 멤버십추론공격 (Membership Inference Attack)
- 모델 오염공격 (Model Poisoning Attack)
- 모델역전공격 (Model Inversion Attack)
- 모델추출공격 (Model Extraction Attack)
- 백도어 트리거 공격 (Backdoor Trigger Attack)
- 연합학습 보안 (Federated Learning Security)
- 연합학습 프라이버시 (Federated Learning Privacy)
- 인공지능 기반 침입탐지 (AI-based Intrusion Detection)
- 적대적 예제 공격 (Adversarial Example Attack)
- 적대적공격 (Adversarial Attack)
- 적대적학습 (Adversarial Training)
- 프롬프트인젝션공격 (Prompt Injection Attack)
- AI 백도어공격 (AI Backdoor Attack)
인증 및 접근제어 (17개)
- 강제적 접근통제 (Mandatory Access Control (MAC))
- 권한계정 관리 (Privileged Access Management (PAM))
- 다중요소 인증 (Multi-Factor Authentication)
- 생체인증 (Biometric Authentication)
- 생체인증 스푸핑 (Biometric Authentication Spoofing)
- 속성기반 접근통제 (Attribute-Based Access Control (ABAC))
- 신원접근관리(IAM) (Identity and Access Management)
- 역할기반 접근제어 (Role-Based Access Control)
- 인증 프로토콜 (Authentication Protocol)
- 접근제어목록 (Access Control List)
- 제로트러스트 아키텍처 (Zero Trust Architecture)
- 크리덴셜 스터핑 공격 (Credential Stuffing Attack)
- 통합인증(SSO) (Single Sign-On)
- FIDO2 웹인증 (FIDO2 WebAuthn)
- IAM 설정오류 (IAM Misconfiguration)
- JWT 토큰 위조 (JWT Token Forgery)
- OAuth 2.0 인가코드 흐름 (OAuth 2.0 Authorization Code Flow)
취약점 분석 및 침투테스트 (30개)
- 개념증명 익스플로잇 (Proof-of-Concept Exploit)
- 검사시점-사용시점 취약점(TOCTOU) (Time-of-Check to Time-of-Use)
- 공통취약점등급시스템 (Common Vulnerability Scoring System (CVSS))
- 공통취약점및노출(CVE) (Common Vulnerabilities and Exposures)
- 공통취약점점수시스템(CVSS) (Common Vulnerability Scoring System)
- 기호실행 (Symbolic Execution)
- 동적애플리케이션보안테스트(DAST) (Dynamic Application Security Testing)
- 레드팀 훈련 (Red Team Exercise)
- 리턴지향프로그래밍(ROP) (Return-Oriented Programming)
- 메모리 손상 (Memory Corruption)
- 모의침투테스트 (Penetration Testing)
- 버퍼 오버플로우 공격 (Buffer Overflow Exploitation)
- 보안 설정 오류 (Security Misconfiguration)
- 셸코드 (Shellcode)
- 소프트웨어구성분석(SCA) (Software Composition Analysis)
- 스택오버플로우 공격 (Stack Overflow Attack)
- 원격코드실행(RCE) (Remote Code Execution)
- 익스플로잇 개발 (Exploit Development)
- 익스플로잇 완화기법 우회 (Exploit Mitigation Bypass)
- 익스플로잇키트 (Exploit Kit)
- 정수오버플로우 취약점 (Integer Overflow Vulnerability)
- 정적애플리케이션보안테스트(SAST) (Static Application Security Testing)
- 제로데이 취약점 (Zero-Day Vulnerability)
- 제로데이 취약점 공격 (Zero-Day Exploit)
- 침투테스트 방법론 (Penetration Testing Methodology)
- 퍼징 (Fuzzing)
- 포맷스트링취약점 (Format String Vulnerability)
- 해제후사용(UAF) (Use-After-Free)
- 힙오버플로우 (Heap Overflow)
- TOCTOU 경쟁조건 (Time-of-Check to Time-of-Use (TOCTOU) Race Condition)
침해사고 대응 및 포렌식 (22개)
- 데이터카빙 (Data Carving)
- 디스크이미징 (Disk Imaging)
- 디지털포렌식 증거보전연계성 (Chain of Custody in Digital Forensics)
- 로그 분석 (Log Analysis)
- 로그 상관분석 (Log Correlation Analysis)
- 모바일포렌식 (Mobile Forensics)
- 보안정보 이벤트관리(SIEM) (Security Information and Event Management)
- 사이버킬체인 (Cyber Kill Chain)
- 안티포렌식 (Anti-Forensics)
- 위협 인텔리전스 (Threat Intelligence)
- 위협 헌팅 (Threat Hunting)
- 증거보전명령 (Evidence Preservation Order)
- 지능형 지속위협 (Advanced Persistent Threat)
- 침해사고 대응 (Incident Response)
- 침해사고대응 플레이북 (Incident Response Playbook)
- 침해지표 (Indicator of Compromise)
- 타임라인분석 (Timeline Analysis)
- 포렌식 디스크 이미징 (Forensic Disk Imaging)
- 포렌식 타임라인 재구성 (Timeline Reconstruction in Forensics)
- 포렌식준비성 (Forensic Readiness)
- 휘발성메모리분석 (Volatile Memory Analysis)
- MITRE ATT&CK 프레임워크 (MITRE ATT&CK Framework)
클라우드 및 가상화 보안 (18개)
- 가상머신 부채널 공격 (VM Side-Channel Attack)
- 가상머신 이스케이프 (Virtual Machine Escape)
- 공동책임모델 (Shared Responsibility Model)
- 멀티테넌시 격리 (Multi-Tenancy Isolation)
- 서버리스 보안 (Serverless Security)
- 서버리스 함수 보안 (Serverless Function Security)
- 컨테이너 보안 (Container Security)
- 컨테이너 이스케이프 (Container Escape)
- 컨테이너 탈출 취약점 (Container Escape Vulnerability)
- 코드형인프라 보안 (Infrastructure as Code Security)
- 쿠버네티스 보안 (Kubernetes Security)
- 쿠버네티스 RBAC 보안 (Kubernetes RBAC Security)
- 클라우드 보안 (Cloud Security)
- 클라우드 설정오류 (Cloud Misconfiguration)
- 클라우드 워크로드 보호플랫폼 (Cloud Workload Protection Platform (CWPP))
- 클라우드접근보안중개(CASB) (Cloud Access Security Broker)
- 하이퍼바이저 보안 (Hypervisor Security)
- 하이퍼바이저 탈출 공격 (Hypervisor Escape Attack)
프라이버시 및 익명화 (13개)
- 개인정보영향평가(DPIA) (Data Protection Impact Assessment)
- 데이터 비식별화 (Data De-Identification)
- 머신러닝 차분프라이버시 (Differential Privacy in Machine Learning)
- 어니언 라우팅 (Onion Routing)
- 재식별공격 (Re-identification Attack)
- 토르네트워크 (Tor Network)
- 프라이버시 강화기술 (Privacy-Enhancing Technology)
- 프라이버시 보존 레코드 연계 (Privacy-Preserving Record Linkage)
- 프라이버시 보존 합성데이터 생성 (Synthetic Data Generation for Privacy)
- 합성데이터 프라이버시 (Synthetic Data Privacy)
- k-익명성 (k-Anonymity)
- l-다양성 (l-Diversity)
- t-근접성 (t-Closeness)
해시 및 메시지 인증 (10개)
- 길이확장 공격 (Length Extension Attack)
- 레인보우 테이블 공격 (Rainbow Table Attack)
- 메시지 인증 코드 (Message Authentication Code)
- 생일 공격 (Birthday Attack)
- 폴리1305 메시지인증코드 (Poly1305 Message Authentication Code)
- 해시 기반 메시지 인증 코드(HMAC) (HMAC)
- Argon2 비밀번호 해싱 (Argon2 Password Hashing)
- CMAC (Cipher-based Message Authentication Code (CMAC))
- PBKDF2
- SHA-3(케착) (SHA-3 (Keccak))