A Study on an Attack-Stage-Based Integrated Response Framework for Security Vulnerability Management in Defense Companies
Abstract
Defense companies possess critical technologies directly linked to national security and remain persistent targets of state-sponsored hacking groups. Recent attacks combine application vulnerabilities, compromised accounts, externally exposed assets, and software supply chains. Consequently, conventional vulnerability management centered on periodic assessments and individual vulnerabilities cannot effectively address actual attack paths. This study analyzes domestic and international threat trends and major cyber incidents and integrates the Cyber Kill Chain and MITRE ATT&CK to construct a six-stage attack structure. The structure is then reorganized from a defender’s perspective to propose an integrated response framework comprising five areas: reconnaissance and external exposure identification, initial access prevention, privilege escalation and lateral movement prevention, critical asset protection, and continuous assessment and improvement. In addition, a four-stage implementation approach —foundation building, operational expansion, integrated operation, and active defense—is presented to enable gradual adoption according to each organization’s resources, capabilities, and operational conditions.