³×Æ®¿öÅ© ±â¹Ý ħÀÔ Å½Áö ½Ã½ºÅÛÀº È£½ºÆ® ±â¹Ý IDS¿Í´Â ´Ù¸£°Ô ÀÛµ¿ÇÕ´Ï´Ù. ³×Æ®¿öÅ© ±â¹Ý IDSÀº ³×Æ®¿öÅ© ÆÐŶÀ» ¶ó¿ìÅͳª È£½ºÆ® ¼öÁØ¿¡¼ »ìÆìº¸°í ÆÐŶ Á¤º¸¸¦ °Ë»çÇÑ ÈÄ ¸¸ÀÏ ÀǽɵǴ ÆÐŶÀÌ ÀÖ´Ù¸é Æ¯¼ö ·Î±× ÆÄÀÏ¿¡ º¸´Ù ÀÚ¼¼ÇÑ Á¤º¸¿Í ÇÔ²² ±â·ÏÇϵµ·Ï ¼³°èµÇ¾ú½À´Ï´Ù. ÀÌ·¸°Ô ¹ß°ßµÈ ¼ö»óÇÑ ÆÐŶ¿¡ ±â¹ÝÇÏ¿© ³×Æ®¿öÅ© ±â¹Ý IDS´Â ¾Ë·ÁÁø ³×Æ®¿öÅ© °ø°Ý À¯ÇüÀ» ´ãÀº ÀÚü µ¥ÀÌÅͺ£À̽º¸¦ »ìÆìº» ÈÄ °¢ ÆÐŶ¿¡ ½É°¢¼º ¼öÁØÀ» ÇÒ´çÇÕ´Ï´Ù. ¸¸ÀÏ ½É°¢¼º ¼öÁØÀÌ ³ô´Ù¸é º¸¾ÈÆÀ ±¸¼º¿ø¿¡°Ô °æ°í À̸ÞÀÏÀ̳ª ÈÞ´ë¿ë È£Ãâ±â¿¡ ¿¬¶ôÇÏ¿© ¿¹¿ÜÀûÀÎ »óȲÀ» º¸´Ù ±í°Ô Á¶»çÇϵµ·Ï ÇÕ´Ï´Ù.
³×Æ®¿öÅ© ±â¹Ý IDS´Â ÀÎÅÍ³Ý ¹üÀ§°¡ Ä¿Áö°í Æ®·¡ÇÈÀÌ Áõ°¡ÇÏ¸é¼ º¸´Ù ¸¹ÀÌ »ç¿ëµÇ°í ÀÖ½À´Ï´Ù. ´ëÇü ³×Æ®¿öÅ© ÀÛ¾÷À» ½ºÄµÇÏ¿© ¼ö»óÇÑ Àü¼ÛÀ» ¼º°øÀûÀ¸·Î ã¾Æ³»´Â IDS´Â º¸¾È »ê¾÷¿¡¼ ³ôÀÌ Æò°¡µÇ°í ÀÖ½À´Ï´Ù. TCP/IP ÇÁ·ÎÅäÄÝ º»·¡ÀÇ ºñº¸¾È¼º ¶§¹®¿¡ ´ÙÀ½°ú °°Àº ¾ÇÀǼº ³×Æ®¿öÅ© Ȱµ¿°ú °°Àº º¸¾È Ä§ÇØ »ç°í¸¦ ¹æÁöÇϱâ À§ÇÏ¿© ½ºÄ³³Ê, ½º´ÏÆÛ ¹× ±âŸ ³×Æ®¿öÅ© °¨»ç ¹× ŽÁö µµ±¸°¡ °³¹ßµÇ¾î¾ß¸¸ Çß½À´Ï´Ù:
IP ½ºÇªÇÎ(Spoofing)
¼ºñ½º °ÅºÎ °ø°Ý (denial-of-service attacks)
arp cache poisoning
DNS À̸§ º¯Á¶(name corruption)
man-in-the-middle °ø°Ý
´ëºÎºÐÀÇ ³×Æ®¿öÅ© ±â¹Ý IDS¸¦ »ç¿ëÇϱâ À§Çؼ´Â È£½ºÆ® ½Ã½ºÅÛ ³×Æ®¿öÅ© ÀåÄ¡°¡ ³×Æ®¿öÅ©¸¦ Åë°úÇÏ´Â ¸ðµç ÆÐŶÀ» Æ÷ÂøÇϵµ·Ï ¹«Â÷º° (promiscuous) ¸ðµå·Î ¼³Á¤µÇ¾î¾ß ÇÕ´Ï´Ù. ¹«Â÷º° ¸ðµå´Â ´ÙÀ½°ú °°ÀÌ ifconfig ¸í·ÉÀ» »ç¿ëÇÏ¿© ¼³Á¤ °¡´ÉÇÕ´Ï´Ù:
ifconfig eth0 promisc |
¾Æ¹«·± ¿É¼Ç ¾øÀÌ ifconfig ¸í·ÉÀ» ½ÇÇàÇϽøé eth0ÀÌ ÀÌÁ¦ ¹«Â÷º° (PROMISC) ¸ðµå¶ó´Â °ÍÀ» º¸¿©ÁÝ´Ï´Ù.
eth0 Link encap:Ethernet HWaddr 00:00:D0:0D:00:01 inet addr:192.168.1.50 Bcast:192.168.1.255 Mask:255.255.252.0 UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1 RX packets:6222015 errors:0 dropped:0 overruns:138 frame:0 TX packets:5370458 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:100 RX bytes:2505498554 (2389.4 Mb) TX bytes:1521375170 (1450.8 Mb) Interrupt:9 Base address:0xec80 lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:21621 errors:0 dropped:0 overruns:0 frame:0 TX packets:21621 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:1070918 (1.0 Mb) TX bytes:1070918 (1.0 Mb) |
Red Hat Enterprise Linux¿¡ Æ÷ÇÔµÈ tcpdump¿Í °°Àº µµ±¸¸¦ »ç¿ëÇÏ¿© ³×Æ®¿öÅ©¸¦ Åë°úÇÏ´Â ´ë·®ÀÇ Æ®·¡ÇÈÀ» º¼ ¼ö ÀÖ½À´Ï´Ù:
tcpdump: listening on eth0 02:05:53.702142 pinky.example.com.ha-cluster > \ heavenly.example.com.860: udp 92 (DF) 02:05:53.702294 heavenly.example.com.860 > \ pinky.example.com.ha-cluster: udp 32 (DF) 02:05:53.702360 pinky.example.com.55828 > dns1.example.com.domain: \ PTR? 192.35.168.192.in-addr.arpa. (45) (DF) 02:05:53.702706 ns1.example.com.domain > pinky.example.com.55828: \ 6077 NXDomain* 0/1/0 (103) (DF) 02:05:53.886395 shadowman.example.com.netbios-ns > \ 172.16.59.255.netbios-ns: NBT UDP PACKET(137): QUERY; BROADCAST 02:05:54.103355 802.1d config c000.00:05:74:8c:a1:2b.8043 root \ 0001.00:d0:01:23:a5:2b pathcost 3004 age 1 max 20 hello 2 fdelay 15 02:05:54.636436 konsole.example.com.netbios-ns > 172.16.59.255.netbios-ns:\ NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST 02:05:56.323715 pinky.example.com.1013 > heavenly.example.com.860:\ udp 56 (DF) 02:05:56.323882 heavenly.example.com.860 > pinky.example.com.1013:\ udp 28 (DF) |
¿ì¸®ÀÇ ÄÄÇ»ÅÍÀÎ pinky.example.comÀ¸·Î ÇâÇÏÁö ¾Ê´Â ÆÐŶµéÀº tcpdump¿¡ ÀÇÇØ ½ºÄµµÇ¾î ±â·ÏµÇ´Â °ÍÀ» º¸½Ç ¼ö ÀÖ½À´Ï´Ù.
tcpdumpÀº À¯¿ëÇÑ °¨½Ã µµ±¸ÀÌÁö¸¸ ÁøÁ¤ÇÑ IDS·Î °£ÁÖµÇÁö´Â ¾Ê½À´Ï´Ù. ±× ÀÌÀ¯´Â ÆÐŶÀ» ºÐ¼®ÇÏ¿© ¿¹¿ÜÀûÀÎ Áõ»óÀÌ ÀÖ´Â ÆÐŶÀ» ã¾Æ³»Áö ¸øÇϱ⠶§¹®ÀÔ´Ï´Ù. tcpdumpÀº ´ë½Å ¸ðµç ÆÐŶ Á¤º¸¸¦ ºÐ¼®ÇÏÁö ¾Ê°í ȸéÀ̳ª ·Î±× ÆÄÀÏ¿¡ ÀμâÇÕ´Ï´Ù. ÀûÀýÇÑ IDS´Â ÆÐŶÀ» ºÐ¼®ÇÏ°í ¼ö»óÇÑ ÆÐŶ Àü¼ÛÀ» ã¾Æ³»¾î Çü½ÄÈµÈ ·Î±× ÆÄÀÏ¿¡ ÀúÀåÇØ¾ß ÇÕ´Ï´Ù.
Snort´Â ¼º°øÀûÀ¸·Î ¼ö»óÇÑ ³×Æ®¿öÅ© Ȱµ¿À» ±â·ÏÇϰí ÀáÀçÀû º¸¾È ¹®Á¦°¡ ¹ß»ýÇÏ¿´À»¶§ °ü¸®¿¡°Ô ¾Ë·ÁÁÖµµ·Ï °³¹ßµÈ ±¤¹üÀ§Çϰí Á¤È®ÇÑ IDS ÀÔ´Ï´Ù. Snort´Â Ç¥ÁØ libcap ¶óÀ̺귯¸®¿Í tcpdump¸¦ ÆÐŶ ±â·Ï ¹é¿£µå·Î »ç¿ëÇÕ´Ï´Ù.
SnortÀÇ ÀÌ·¯ÇÑ ±â´É ¿Ü¿¡µµ °¡Àå Æ¯º°ÇÑ ±â´ÉÀº À¯¿¬ÇÑ Ä§ÀÓŽÁö ÆÐÅÏ ÇϺνýºÅÛÀÔ´Ï´Ù. Snort´Â ħÀÔ °ø°Ý ÆÐÅÏ µ¥ÀÌÅͺ£À̽º¿¡ »õ·Î¿î °ø°Ý ÆÐÅÏÀ» Ãß°¡Çϰųª ÀÎÅͳÝÀ» ÅëÇÏ¿© °è¼ÓÀûÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù. »ç¿ëÀÚ´Â »õ·Î¿î ³×Æ®¿öÅ© °ø°Ý¿¡ ´ëÇÑ °ø°Ý ÆÐÅÏÀ» »ý¼ºÇÏ¿© Snort ħÀÔŽÁö ÆÐÅÏ ¸ÞÀϸµ ¸®½ºÆ® (http://www.snort.org/lists.html)·Î Á¦ÃâÇÏ¿© ¸ðµç Snort »ç¿ëÀÚµéÀÌ ÇýÅÃÀ» ÇÔ²² ´©¸± ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ Ä¿¹Â´ÏƼ °øÀ¯ Á¤½Å¿¡ ÈûÀÔ¾î Snort´Â °¡Àå ¾÷µ¥ÀÌÆ®µÇ°í °·ÂÇÑ ³×Æ®¿öÅ© ±â¹Ý IDS Áß Çϳª·Î ÀÚ¸®Àâ°Ô µÇ¾ú½À´Ï´Ù.
![]() | ¾Ë¸² |
---|---|
Snort´Â Red Hat Enterprise Linux¿¡ Æ÷ÇԵǾî ÀÖÁö ¾ÊÀ¸¸ç Áö¿øµÇÁö ¾Ê½À´Ï´Ù. ÀÌ ¹®¼¿¡¼´Â ÀÌ ÀÀ¿ë ÇÁ·Î±×·¥À» »ç¿ëÇϰíÀÚ ÇϽô »ç¿ëÀÚ¸¦ À§ÇÑ Âü°í ÀÚ·á·Î¼ ¾ð±ÞµÇ¾ú½À´Ï´Ù. |
Snort¿¡ ´ëÇÑ º¸´Ù ÀÚ¼¼ÇÑ Á¤º¸´Â °ø½Ä À¥»çÀÌÆ® http://www.snort.org/¸¦ ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù.