自訂 Cookie
禁止且拒絕未經各資訊當事人同意,擅自蒐集本服務提供的使用者個人資訊資料等資料之行為。即使是公開資料,若未經許可使用爬蟲等技術裝置進行蒐集,依個人資訊保護法可能會受到刑事處分,特此告知。
© 2025 Rocketpunch, 주식회사 더블에이스, 김인기, 大韓民國首爾特別市城東區聖水一路10街 12, 12樓 1號, 04793, support@rocketpunch.com, +82 10-2710-7121
統一編號 206-87-09615
更多
自訂 Cookie
禁止且拒絕未經各資訊當事人同意,擅自蒐集本服務提供的使用者個人資訊資料等資料之行為。即使是公開資料,若未經許可使用爬蟲等技術裝置進行蒐集,依個人資訊保護法可能會受到刑事處分,特此告知。
© 2025 Rocketpunch, 주식회사 더블에이스, 김인기, 大韓民國首爾特別市城東區聖水一路10街 12, 12樓 1號, 04793, support@rocketpunch.com, +82 10-2710-7121
統一編號 206-87-09615
更多


조세라
I'm Cyber Security Engineer at Hyundai Motor Group, Hyundai Autoever. My main job duty is Penetration Testing of Automotive(ECU, In-vehicle infotainment System, etc.). And I have experienced many types of penetration testing projects.t(Automotive, Web application, APP, CS, IoT, ICS). Core competences include: Cybersecurity, Penetration Testing, Reverse Engineering, STRIDE(Threat Modeling), Comunications, Project management
職涯
貼文
AI 職涯摘要
조세라님은 8년 차 사이버 보안 엔지니어로서 현대자동차그룹 현대오토에버에서 차량(ECU, 인포테인먼트 시스템 등) 대상 침투 테스트를 리드하고 수행해왔습니다. 자동차, 웹, 앱, IoT, ICS 등 다양한 분야의 침투 테스트 경험과 함께 리버스 엔지니어링, 위협 모델링, 프로젝트 관리 역량을 보유하고 있습니다. 현재는 자동차 사이버 보안 컨설팅 서비스 개발에도 참여하고 있습니다.
經歷
1. Managed all phases of the project as a leader • Interacted with customers and managed project member • Managed detailed work breakdown structures (WBS) • Managed quality of project output 2. Penetration Testing of Automotive(ECU, In-vehicle infotainment System, etc.) • Developed Penetration Testing attack scenario through attack surface analysis. • Drew attack tree based on attack path • Performed reverse engineering ARM, AArch64, PPC(Power PC), Renesas, Infineon TriCore, intel, etc. • Analyzed Encryption(AES, ARIA, etc.) and Dgital signature(RSA) logic vulnerabilities (ARM TrustZone, HSM, etc.) • Analyzed firmware update procedure vulnerabilities(OTA (Over-The-Air), USB, and UDS(Unified Diagnostic Services) Reprogramming • Analyzed USB(Andorid Auto, Car Play, Mirror Link .etc) implementation logic vulnerabilities • Analyzed interface implementation logic vulnerabilities(WiFi, Bluetooth, DAB(Digital audio broadcasting), GPS, etc.) • Analyzed security functions (Secure Boot, Smack, etc.) • Performed hardware reverse engineering using JTAG and UART • Extracted firmware using Flash Memory Dump • Analyzed operating system security • Developed English resultant documentation, including security assessment report, penetration test report, and measures guide 3. Penetration Testing of Web application, APP, CS, IoT • Worked on improvements for security services, including the continuous enhancement of existing methodology material and supporting assets • Communicated technical vulnerabilities and remediation steps to developers and management • Worked with application developers to validate, assess, understand root cause and mitigate vulnerabilities 4. Developed cyber security Consulting service • Analyzed Standard and Regulation(UNCE UNR.155, ISO 21434, SAE j3061, etc.) • Developed Checklist for CSMS(Cyber Security Management System) • Developed Cyber security Attack Scenarios for VTA(Vehicle Type Approval)
更多
• Performed Penetration Testing of IoT, ICS, WEB, Security SW • Developed Penetration Testing attack scenario through attack surface analysis • Performed reverse engineering ARM, MIPS, etc. • Analyzed firmware vulnerabilities • Drew attack tree based on threat modeling • Developed list of classifications of cyber attack technologies • Developed cyber security emergency response and recovery plan • Developed cyber security technology applicability evaluation method
更多
• Performed Penetration Testing of IoT • Developed Penetration Testing attack scenario through attack surface analysis • Performed reverse engineering ARM • Analyzed firmware vulnerabilities
更多
學歷
Threat Analysis of the vehicle remote control service through Threat Modeling The vehicle remote control service has been developed so that the user can control the vehicle even from a long distance. This has created a new security vulnerability accessible from the external network to the vehicle remote control service. The security threat to the vehicle remote control service can cause loss of property as well as loss of life. Therefore, there is a need for research on vehicle security. In this paper, we drew a data flow diagram to understand the security threats of the vehicle remote control service. Based on this, we intend to present possible security threats from vehicle remote control service through STRIDE threat analysis.
更多
活動
最近活動
獲獎 1
證照 1
수상
Win the top prize
Hyundai Autoever · 2020년 11월
CSMS(Cyber Security Management System) and VTA(Vehicle Type Approval) Consulting service in accordance with UNECE/WP.29 vehicle cyber security regulations
자격증
정보처리기사
2015년 1월
語言
원어민
중급 (업무상 의사소통)
초급
초급
이 프로필의 담당자이신가요?
인증을 통해 현재 프로필에 병합하거나 삭제할 수 있습니다. 만약 인증할 수 없는 경우 본인임을 증빙하는 서류 제출 후 프로필 관리 권한을 취득할 수 있습니다.