검색 상세

베이즈 네트워크를 이용한 탈중앙화 암호화폐 지갑의 정량적 위험성 평가

Quantitative Risk Assessment on a Decentralized Cryptocurrency Wallet with a Bayesian Network

초록/요약

2009년 비트코인 블록체인이 처음 생성된 이후 암호화폐 사용자는 꾸준히 증가하고 있다. 하지만 이러한 사용자들의 암호화폐 지갑에 보관된 자산을 노리는 해킹 공격도 증가하고 있다. 따라서 우리는 시중에 나와 있는 암호화폐 지갑들이 안전하게 만들어졌는지를 점검하기 위해 각 지갑에 내재된 위험성을 평가한다. 우리는 위협 모델링을 통해 암호화폐 지갑에 내재된 위협을 식별하고 보안 요구사항을 도출한다. 그리고 도출된 보안 요구사항을 바탕으로 실제 지갑들의 보안성을 분석하고 공격트리와 베이즈 네트워크 등을 활용하여 각 지갑의 위험성을 정량적으로 측정한다. 위험성 평가 결과, 하드웨어 지갑보다 소프트웨어 지갑의 평균적인 위험성이 1.22배 높은 것으로 나타났다. 그리고 하드웨어 지갑 간 비교에서는 secure element를 내장한 Ledger Nano S 지갑보다 범용 MCU를 내장한 Trezor One 지갑의 위험성이 1.11배 높은 것으로 나타났다. 하지만 secure element를 사용하는 것은 암호화폐 지갑의 위험성을 낮추는 데에는 상대적으로 효과가 낮은 것으로 나타났다.

more

초록/요약

Since the creation of the first Bitcoin blockchain in 2009, the number of cryptocurrency users has steadily increased. However, the number of hacking attacks targeting assets stored in these users’ cryptocurrency wallets is also increasing. Therefore, we evaluate the security of the wallets currently on the market to ensure that they are safe. We first conduct threat modeling to identify threats to cryptocurrency wallets and identify the security requirements. Second, based on the derived security requirements, we utilize attack trees and Bayesian network analysis to quantitatively measure the risks inherent in each wallet and compare them. According to the results, the average total risk in software wallets is 1.22 times greater than that in hardware wallets. In the comparison of different hardware wallets, we found that the total risk inherent to the Trezor One wallet, which has a general-purpose MCU, is 1.11 times greater than that of the Ledger Nano S wallet, which has a secure element. However, use of a secure element in a cryptocurrency wallet has been shown to be less effective at reducing risks.

more

목차

국문 요약 1
Abstract 2
1. 서 론 3
1.1 연구 범위 4
2. 배경 지식 5
2.1 암호화폐 지갑 5
2.2 암호화폐 지갑 분류 5
2.3 관련 연구 6
3. 암호화폐 지갑 위험성 평가 방법 8
3.1 위협 모델링 9
3.1.1 데이트 흐름도 (DFD) 작성 10
3.1.2 STRIDE 분석 15
3.1.3 공격트리 작성 27
3.2 위험성 측정 45
3.2.1 공격트리의 베이즈 네트워크 변환 46
3.2.2 위협 노드의 사전 확률 계산 48
3.2.3 하위 목표의 주변 확률 계산 57
3.2.4 공격목표의 위험성 측정 57
3.3 보안 요구사항 체크리스트 58
4. 암호화폐 지갑 위험성 평가 결과 62
4.1 보안 요구사항 체크리스트 점검 결과 62
4.1.1 Ledger Nano S 62
4.1.2 Trezor One 63
4.1.3 Bread 63
4.1.4 Trust Wallet 63
4.1.5 Copay 63
4.1.6 Electrum 66
4.2 위험성 측정 결과 66
4.3 위험성 평가 결과 69
5. 결 론 69
참고문헌 71

more