SlideShare a Scribd company logo
Copyright@ 2018 All reserved by KrDAG
์˜คํ”ˆ์Šคํƒ ๋ณด์•ˆ
โ€ข ๋ณด์•ˆ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ๋ฐฉ์•ˆ
โ€ข 3rd party ๊ฐ€์ƒ๋ฐฉํ™”๋ฒฝ ๋ฐ๋ชจ
KRDAG STUDY
Seo & Ryu โ€“ Infra Engineer
Copyright@ 2018 All reserved by KrDAG
๋ณธ ๋ฐœํ‘œ์˜ ๋ชจ๋“  ๋‚ด์šฉ์€ ์ง€๊ทนํžˆ
๊ฐœ์ธ์ ์ธ ์˜๊ฒฌ์ž„์„ ๋ฏธ๋ฆฌ ๋ฐํž™๋‹ˆ๋‹ค
Copyright@ 2018 All reserved by KrDAG
0. ๊ฐœ์š”
์™œ ๋ณด์•ˆ์— ๋Œ€ํ•œ ๊ณ ๋ ค๋ฅผ ํ•˜๊ฒŒ ๋˜์—ˆ๋Š”์ง€
Copyright@ 2018 All reserved by KrDAG
#1. HORIZON BRUTEFORCE ATTACK
๋กœ๊ทธ์ธ ์‹œ๋„ ์‹œ ์ ˆ์ฐจ ๋ฐ ๋ถˆ์ ‘์ ์ธ ๋กœ๊ทธ์ธ ์‹œ๋„
Admin / 123456 ์ž…๋ ฅ
Web Proxy Intercept
Admin / โ€œ$$โ€ ์ž…๋ ฅ
ํŠน์ •ํ•œ ๊ฐ’์„ โ€œ$$โ€์— ๋ณ€๊ฒฝ
์ž…๋ ฅํ•˜์—ฌ ๋กœ๊ทธ์ธ ์‹œ๋„
Response Code ํ™•์ธ
์‹คํŒจ ์‹œ /์„ฑ๊ณต ์‹œ
์™ธ๋ถ€์‚ฌ์šฉ์ž
๋กœ๊ทธ์ธ ์‹คํŒจ ์‹œ
๋กœ๊ทธ์ธ ์„ฑ๊ณต ์‹œ Keystone
(์ธ์ฆ์ฒ˜๋ฆฌ)
OpenStack Controller
200OK : Close
302 Found
Sessionid=๋ฐœ๊ธ‰
Horizon dashboard url
redirect
http://sola99.tistory.com/414
Copyright@ 2018 All reserved by KrDAG
#1. ๋Œ€์‘๋ฐฉ์•ˆ
์ ํ•ฉํ•œ ๋ฐฉ์•ˆ ์ค‘ ์„ ํƒ
โœ“ Horizon ์„œ๋น„์Šค๋ฅผ Disable
โœ“ ์ง€์ •๋œ hosts๋งŒ Horizon ์ ‘์† ๊ฐ€๋Šฅ ํ•˜๊ฒŒ ์„ค์ •
/etc/openstack-dashboard/local_settings ํŒŒ์ผ์— ALLOWED_HOSTS = ['*', ] ์— ์ง€์ •
โœ“ ์™ธ๋ถ€ ํ˜น์€ ๋‚ด๋ถ€๋ผ๋„ ๋ฐฉํ™”๋ฒฝ ํ˜น์€ IPtables ๋ฅผ ํ†ตํ•œ ์ ‘๊ทผ ์ฐจ๋‹จ์„ ์„ค์ •ํ•˜๊ณ  ์šด์˜์ž๋งŒ ํ—ˆ์šฉํ•จ
โœ“ Mod_security ์„ค์น˜ ํ›„ ๋กœ๊ทธ์ธ ์ •์ฑ… ์ ์šฉ ๋ฐ Alert ๋กœ๊ทธ ๋ชจ๋‹ˆํ„ฐ๋ง
์˜ˆ) ํŠน์ • IP๊ฐ€ 10๋ฒˆ ๋กœ๊ทธ์ธ ์‹œ๋„ ์‹คํŒจ ์‹œ 10๋ถ„๊ฐ„ ์ ‘์† ์ฐจ๋‹จ
https://docs.mirantis.com/mcp/latest/mcp-security-best-practices/use-cases/brute-force-prevention.html
http://sola99.tistory.com/414
Copyright@ 2018 All reserved by KrDAG
#2. SECURITY CONSIDERATION
๋‹ค์–‘ํ•œ ๊ณ„๊ธฐ
โœ“ Message Queue DDoS ๊ณต๊ฒฉ ์‚ฌ๋ก€ : ์™ธ๋ถ€์— MQ Port๊ฐ€ ์—ด๋ ค ์žˆ์–ด์„œ DDoS ๊ณต๊ฒฉ ์‹œ๋„ ๋ฐ ๋งˆ๋น„
โœ“ ๊ฐœ์ธ ์ •๋ณด ๋ฐ ์ฃผ์š” ์ •๋ณด ์œ ์ถœ ์‚ฌ๋ก€ : Facebook ๋“ฑ
โœ“ ์˜คํ”ˆ์Šคํƒ ๊ธฐ๋ฐ˜ ์„œ๋น„์Šค๋ฅผ ์‹ค์ œ ์šด์˜ ํ™˜๊ฒฝ ์ „ํ™˜ ์ „ ๋ณด์•ˆ ๊ณ ๋ ค ํ•„์š”
โ–ช ์˜คํ”ˆ์Šคํƒ ํ”Œ๋žซํผ์— ๋ณด์•ˆ ๊ฐ€์ด๋“œ ๋ถ€์žฌ : ์ทจ์•ฝ์  ๋ฐ ๋Œ€์‘๋ฐฉ์•ˆ ๋ฐ ์ ๊ฒ€์ฒดํฌ๋ฆฌ์ŠคํŠธ
โ–ช ๋ณด์•ˆ ๋ถ€์„œ/ํŒ€์› ๋“ค์˜ ํด๋ผ์šฐ๋“œ์— ๋Œ€ํ•œ ํ•™์Šต ๋ฐ ์ธ์‹ ๋ณ€ํ™”
โœ“ โ€œ์ธํ„ฐ๋„ท โ€“ ๋‚ด๋ถ€๋ง(๋‹จ๊ณ„๋ณ„๋ณด์•ˆ) โ€“ ์˜คํ”ˆ์Šคํƒโ€œ : ์ „์ฒด ๊ตฌ์„ฑ์—์„œ์˜ ์ž๋™ํ™”(์ตœ์†Œํ•œ์˜ ์ˆ˜๋™ ์ ˆ์ฐจ)๊ฐ€ ํ•„์š”
โœ“ ๊ตญ๊ฐ€๋ณ„ ๋ฒ•์ ์ธ ๊ทœ์ œ ๋ฐ ๊ฑฐ๋ฒ„๋„Œ์Šค ์ค€์ˆ˜ : EU GDRP ๋ฐ โ€œํด๋ผ์šฐ๋“œ์ปดํ“จํŒ… ์ •๋ณด๋ณดํ˜ธ ๊ณ ์‹œโ€ ๋“ฑ
Copyright@ 2018 All reserved by KrDAG
1. ๋ณด์•ˆ๊ฐ•ํ™” ๋ฐฉ์•ˆ
๋ณด์•ˆ ๊ฐ€์ด๋“œ & ๊ณ ๋ ค์‚ฌํ•ญ
Copyright@ 2018 All reserved by KrDAG
#1. OPENSTACK SECURITY GUIDE(OSG)
์˜คํ”ˆ์Šคํƒ ๋ณด์•ˆ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ๊ถŒ์žฅ ์‚ฌํ•ญ ๋ฐ ์ง€์นจ ๋ฐ ์•„ํ‚คํ…์ฒ˜๋ฅผ ์ œ๊ณต
https://docs.openstack.org/security-guide/ http://sola99.tistory.com/415
Copyright@ 2018 All reserved by KrDAG
#1. OSG ์ผ๋ถ€ ๋ฐœ์ทŒ -1-
๋ณด์•ˆ ์ •๋ณด ์ „๋‹ฌ์„ ์œ„ํ•œ ๋ฉ”์ผ๋ง ์„œ๋น„์Šค
https://docs.openstack.org/ansible-hardening/latest/ https://wiki.openstack.org/wiki/Security_Notes
๋ณด์•ˆ ๋…ธํŠธ ๋ฐ ๋ณด์•ˆ ๊ฐ€์ด๋“œ (็พ 82๊ฐœ)
OS ๋ณด์•ˆ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ์ž๋™ํ™”(Ansible)
http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-announce
Copyright@ 2018 All reserved by KrDAG
#1. OSG ์ผ๋ถ€ ๋ฐœ์ทŒ -2-
http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-announce https://wiki.openstack.org/wiki/Security_Notes
Horizon Dashboard Checklist Check-Dashboard-02
Check-Dashboard-01: Is user/group of config files set to root/horizon?
Check-Dashboard-02: Are strict permissions set for horizon configuration files?
Check-Dashboard-03: Is DISALLOW_IFRAME_EMBED parameter set to True?
Check-Dashboard-04: Is CSRF_COOKIE_SECURE parameter set to True?
Check-Dashboard-05: Is SESSION_COOKIE_SECURE parameter set to True?
Check-Dashboard-06: Is SESSION_COOKIE_HTTPONLY parameter set to True?
Check-Dashboard-07: Is PASSWORD_AUTOCOMPLETE set to False?
Check-Dashboard-08: Is DISABLE_PASSWORD_REVEAL set to True?
Check-Dashboard-09: Is ENFORCE_PASSWORD_CHECK set to True?
Check-Dashboard-10: Is PASSWORD_VALIDATOR configured?
Check-Dashboard-11: Is SECURE_PROXY_SSL_HEADER configured?
Horizon Dashboard HTTPS
์•ˆ์ „ํ•œ HTTPS ๋กœ ๋Œ€์‰ฌ๋ณด๋“œ ์ ‘๊ทผํ•˜๊ฒŒ ์„ค์ •ํ•˜๋ผ
โ‡’ local_settings.py ํŒŒ์ผ์— "USE_SSL = True" ์„ค์ •
# ์ทจ์•ฝ์ ํ•ญ๋ชฉ: ๊ตฌ์„ฑํŒŒ์ผ ๊ถŒํ•œ ๊ด€๋ฆฌ
# ์ทจ์•ฝ์ ๊ฐœ์š”: ๊ตฌ์„ฑํŒŒ์ผ์€ ๋™์ž‘์— ํ•„์š”ํ•œ ์ •๋ณด๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์–ด ๊ถŒํ•œ์—†๋Š”
์‚ฌ์šฉ์ž๊ฐ€ ํ•ด๋‹น ํŒŒ์ผ ์ ‘๊ทผํ•˜์—ฌ ์ˆ˜์ • ์‹œ ์„œ๋น„์Šค ์ด์šฉ์— ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Œ
# ๋ณด์•ˆ๋Œ€์ฑ…
- ํŒ๋‹จ๊ธฐ์ค€
- ์–‘ํ˜ธ : ๊ตฌ์„ฑํŒŒ์ผ ๊ถŒํ•œ์ด 640์ดํ•˜์ธ ๊ฒฝ์šฐ
- ์ทจ์•ฝ : ๊ถŒํ•œ์ด 640์ดํ•˜๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ
- ์กฐ์น˜๋ฐฉ๋ฒ• : ๊ตฌ์„ฑํŒŒ์ผ์˜ ๊ถŒํ•œ์„ 640์ดํ•˜๋กœ ์„ค์ •
- ์กฐ์น˜ ์‹œ ์˜ํ–ฅ : ์˜ํ–ฅ๋„ ์—†์Œ
# ์กฐ์น˜ ์ „/ํ›„ ์„ค์ • ๊ฐ’ ํ™•์ธ : ์ ๊ฒ€ ํŒŒ์ผ ์œ„์น˜ ๋ฐ ์ ๊ฒ€ ๋ฐฉ๋ฒ•
stat -L -c "%a" /usr/share/openstack-dashboard/openstack_dashboard/local/local_settings.py
640
# ๋ณด์•ˆ์„ค์ •๋ฐฉ๋ฒ•
chmod 640 /usr/share/openstack-dashboard/openstack_dashboard/local/local_settings.py
Copyright@ 2018 All reserved by KrDAG
#2. MIRANTIS SECURITY GUIDE
๋งค๋…„ ์˜คํ”ˆ์Šคํƒ ๋ณด์•ˆ ๊ฐ€์ด๋“œ ์ž‘์„ฑ/๊ณต์œ  ์˜ˆ)Design Secure Cloud Architecture
https://docs.mirantis.com/mcp/latest/mcp-security-best-practices/common/preface.html
โœ“ ์ทจ์•ฝ์  ์ •์˜
โœ“ ๋Œ€์‘ ๋ณด์•ˆ ๊ธฐ์ˆ  ์ •์˜
โœ“ ์˜คํ”ˆ์Šคํƒ Project ๋ณ„ ๋ณด์•ˆ ๊ฐ•ํ™” ๋ฐฉ์•ˆ
โœ“ K8s ์™€ Docker ํ™˜๊ฒฝ์„ ์œ„ํ•œ ๋ณด์•ˆ ๋ฐฉ์•ˆ
โœ“ ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜
โœ“ ๋ณด์•ˆ ์†”๋ฃจ์…˜
โœ“ Use cases
Copyright@ 2018 All reserved by KrDAG
#3. CLOUD SECURITY DESIGN IDEA
๋ฌผ๋ฆฌ ๋ณด์•ˆ ์žฅ๋น„(๊ณตํ†ต ์ •์ฑ…)๊ณผ ๊ฐ€์ƒVM/SW ๋ณด์•ˆ ์žฅ๋น„์˜ Hybrid ๊ตฌ์„ฑ
โœ“ Firewall rules attached to virtual NICs
โœ“ Everything else is "outsideโ€œ
โœ“ ๋Œ€์šฉ๋Ÿ‰ ๋ฌผ๋ฆฌ ๋ณด์•ˆ ์žฅ๋น„ + ํŠน์ • App ์ฐจ๋‹จ์„ ์œ„ํ•œ SWํ˜•ํƒœ์˜ ๋ณด์•ˆSW
โœ“ Physical(๊ณตํ†ต ์ •์ฑ…) ๊ณผ Virtual(Per-App, FW/LB self-Service)
Appliance ํ˜ผํ•ฉ ๋ฐฐ์น˜
๋ณด์•ˆ ์ „์šฉ ์žฅ๋น„
VM ์—์„œ ๋ณด์•ˆ์ •์ฑ… ๋™์ž‘
Physical + Virtual ๋ณด์•ˆ ์ •์ฑ… ๋™์ž‘
https://www.openstack.org/assets/presentation-media/OS-Security-Talk-rs.pdf
http://sola99.tistory.com/382
Copyright@ 2018 All reserved by KrDAG
#3. CLOUD SECURITY DESIGN IDEA
ํ”Œ๋žซํผ(์˜ˆ. ์˜คํ”ˆ์Šคํƒ)๊ณผ ์—ฐ๋™, Scale-out ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์„œ๋น„์Šค ์ œ๊ณต
โœ“ ํ”Œ๋žซํผ๊ณผ ์—ฐ๋™ : ์˜คํ”ˆ์Šคํƒ security Group, VMware vShield
Edge/NSX FW, Palo Alto Panorama ๋“ฑ
โœ“ L3/L4 ๊ธฐ๋ณธ ์ •์ฑ…์€ ๋ฏธ๋ฆฌ ์ง€์ •, L3~L7 filter rule ์€ ํ”Œ๋žซํผ์ด ์ˆ˜์ง‘ํ•œ
์ •๋ณด๋กœ ์ž๋™์œผ๋กœ ์ ์šฉ
โœ“ ๋ณด์•ˆ ์žฅ๋น„์˜ ์„ฑ๋Šฅ์„ ๋ชจ๋‹ˆํ„ฐ๋ง ํ•˜์—ฌ ์ž„๊ณ„์น˜๊ฐ€ ๋„˜์œผ๋ฉด ์ž๋™์œผ๋กœ ๋ณด์•ˆ
์žฅ๋น„ ์ฆ๊ฐ€
โœ“ Scale-out IPS with OpenFlow Controller
https://www.openstack.org/assets/presentation-media/OS-Security-Talk-rs.pdf
Copyright@ 2018 All reserved by KrDAG
#4. ์˜คํ”ˆ์Šคํƒ ํ™˜๊ฒฝ์—์„œ์˜ ๋ณด์•ˆ ๊ตฌ์„ฑ ๊ณ ๋ ค์‚ฌํ•ญ
VM๊ฐ„ ์ง์ ‘ ํ†ต์‹ ์— ๋Œ€ํ•œ ํ†ต์ œ์™€ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„ ํ™•๋Œ€์— ๋”ฐ๋ฅธ ํ†ต์ œ ํ•„์š”
VM๊ฐ„ ์ง์ ‘ ํ†ต์‹ 
๋ฐฉํ™”๋ฒฝ
Web VM
๊ฐ€์ƒ์Šค์œ„
์น˜
DMZ์Šค์œ„์น˜
Was VM
๊ฐ€์ƒ์Šค์œ„
์น˜
๋‚ด๋ถ€์Šค์œ„์น˜
๊ฐ€์ƒํ™” ๋‚ด๋ถ€๋ง
VM ๊ฐ„
์ง์ ‘ ํ†ต์‹ 
๋ ˆ๊ฑฐ์‹œ ๋ณด์•ˆ
๋ฐฉํ™”๋ฒฝ
Web VM
๊ฐ€์ƒ์Šค์œ„
์น˜
Was VM
๊ฐ€์ƒ์Šค์œ„
์น˜
๋‚ด๋ถ€์Šค์œ„์น˜
๊ฐ€์ƒํ™” ๋‚ด๋ถ€๋ง
DMZ์Šค์œ„์น˜
๋ฌผ๋ฆฌ๋ฐฉํ™”๋ฒฝ ๊ฒฝ์œ 
(๋„คํŠธ์›Œํฌ ๊ฒฉ๋ฆฌ)
๋ ˆ๊ฑฐ์‹œ ๋ณด์•ˆ
ํ•ด๊ฒฐ๋ฐฉ์•ˆ
๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„ ํ™•๋Œ€
๋ฐฉํ™”๋ฒฝ
vLB
๊ฐ€์ƒ์Šค์œ„
์น˜
Was VM
๊ฐ€์ƒ์Šค์œ„
์น˜
๋‚ด๋ถ€์Šค์œ„์น˜
๊ฐ€์ƒํ™” ๋‚ด๋ถ€๋ง
DMZ์Šค์œ„์น˜
๋ฌผ๋ฆฌ๋ฐฉํ™”๋ฒฝ ๊ฒฝ์œ 
(๋„คํŠธ์›Œํฌ ๊ฒฉ๋ฆฌ)
๋ ˆ๊ฑฐ์‹œ ๋ณด์•ˆ
DB VM
๊ฐ€์ƒ๋ผ์šฐ
ํ„ฐ
WebVM1
WebVM2
WebVM3
๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„ ํ™•๋Œ€๋กœ ๋ฌผ
๋ฆฌ ๋ฐฉํ™”๋ฒฝ ๊ฒฝ์œ  ์‹œ โ€˜์ง€์—ฐ
(delay)โ€™ ๋ฐœ์ƒ ๋ฐ ๋‚ด๋ถ€ ๊ตฌ๊ฐ„ ํ†ต
์ œ์˜ ์–ด๋ ค์›€ ๋ฐœ์ƒ
-> VM/SW๊ธฐ๋ฐ˜ ๋ณด์•ˆ๋ฐฉํ™”๋ฒฝ
ํ•„์š” -> (ํด๋ผ์šฐ๋“œ ํ‘œ์ค€ ๋ณด์•ˆ
์†”๋ฃจ์…˜ ์„ ์ •)
VM/SW๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์†”๋ฃจ์…˜ ๋ฐฐ์น˜
๋ฐฉํ™”๋ฒฝ
vLB
๊ฐ€์ƒ์Šค์œ„
์น˜
Was VM
๊ฐ€์ƒ์Šค์œ„
์น˜
๋‚ด๋ถ€์Šค์œ„์น˜
๊ฐ€์ƒํ™” ๋‚ด๋ถ€๋ง
DMZ์Šค์œ„์น˜
๋ฌผ๋ฆฌ๋ฐฉํ™”๋ฒฝ ๊ฒฝ์œ 
(๋„คํŠธ์›Œํฌ ๊ฒฉ๋ฆฌ)
๋ ˆ๊ฑฐ์‹œ ๋ณด์•ˆ
DB VM
๊ฐ€์ƒ๋ฐฉํ™”
๋ฒฝ
WebVM
๊ฐ€์ƒ ์›น๋ฐฉ
ํ™”๋ฒฝ
VM๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์ œํ’ˆ(vFW,
vWAF, vIDS, vIPS)์ด๋‚˜ SW
๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์†”๋ฃจ์…˜(host based
FW/WAF/IDS/IPS SW) ๋ฐฐ์น˜
๋กœ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„์— ๋ณด์•ˆ
๊ธฐ๋Šฅ ์ œ๊ณต ์ตœ์ ํ™”
DB์•”ํ˜ธํ™”
AWS ๊ตฌ์„ฑ ์˜ˆ์‹œ
์œ„ 3Tier Web ๊ตฌ์„ฑ ์—ญ์‹œ vLB
โ€“ Web โ€“ vLB โ€“ WAS โ€“ vDB
๋ฐฐ์น˜๋กœ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„์—์„œ
๊ตฌ์„ฑ๋จ
Copyright@ 2018 All reserved by KrDAG
#4. ์˜คํ”ˆ์Šคํƒ ํ™˜๊ฒฝ์—์„œ์˜ ๋ณด์•ˆ ๊ตฌ์„ฑ ๊ณ ๋ ค์‚ฌํ•ญ
Auto-Scaling ์— ๋Œ€ํ•œ ๋Œ€์‘ ๋ฐฉ์•ˆ ํ•„์š”, VM์ฆ๊ฐ€ ์‹œ ์ž๋™ ๋ฐœ๊ฒฌ ๋“ฑ๋ก/์šด์˜ ํ•„์š”
์ด์Šˆ ๋ฐœ์ƒ
Web VM1 Web VM2
Web VM2
๊ด€๋ฆฌ์„œ๋ฒ„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ณด์•ˆ๊ด€์ œ
10.1.1.1 10.1.1.2
๋“ฑ๋ก IP
10.1.1.1
ํ•ด๊ฒฐ ๋ฐฉ์•ˆ
Web VM1 Web VM2
Web VM2
๊ด€๋ฆฌ์„œ๋ฒ„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ณด์•ˆ๊ด€์ œ
10.1.1.1 10.1.1.2
๋“ฑ๋ก IP
10.1.1.1
10.1.1.2
์„œ๋น„์Šค VM AutoScaling
์„œ๋น„์ŠคVM์˜ AutoScaling ๊ธฐ๋Šฅ์œผ๋กœ VM ์ƒ์„ฑ๊ณผ
์‚ญ์ œ๊ฐ€ ๋นˆ๋ฒˆํ•˜๊ฒŒ ๋ฐœ์ƒํ•จ
๊ณ ๋ ค์‚ฌํ•ญ : ์šด์˜/๊ด€๋ฆฌ ์‹œ์Šคํ…œ์ด ์‹ ๊ทœ ์ƒ์„ฑ ์‹œ ์ž
๋™์œผ๋กœ ๋“ฑ๋ก/์‚ญ์ œ ํ•˜์—ฌ ๊ด€๋ฆฌ๊ฐ€ ๊ฐ€๋Šฅํ•œ์ง€ ๊ฒ€ํ† ,
๊ฐ์‚ฌ/๋กœ๊ทธ ๊ธฐ๋ก ํ™•์ธ ์‹œ ๋ถ€ํ•˜ ๊ฐ์†Œ๋กœ ์‚ญ์ œ๋˜์—ˆ
์„๋•Œ์— ๊ณผ๊ฑฐ ๊ธฐ๋ก ํ™•์ธ ๋ฐฉ์•ˆ ํ•„์š”
์ถฉ๋ถ„ํ•œ ํ…Œ์ŠคํŠธ๊ฐ€ ํ•„์š”ํ•˜๊ณ  Mix_Max ๊ฐฏ์ˆ˜์˜
VM ์ˆ˜๋Ÿ‰์— ๋Œ€ํ•œ ๊ฒ€ํ†  ํ›„ ๊ฒฐ์ • ํ•„์š”
Web VM1
Web VM2
Web VM3
...
vLB
๋ณด์•ˆ VM/SW AutoScaling
์„œ๋น„์ŠคVM์˜ AutoScaling์— ๋”ฐ๋ผ โ€˜๋ณด์•ˆ
VM/SWโ€™ ๋„ Active-Backup ๊ตฌ์„ฑ์ด์™ธ์—
AutoScaling ๊ตฌ์„ฑ๋„ ์š”๊ตฌ๋จ.
๊ณ ๋ ค์‚ฌํ•ญ : ๋ผ์ด์„ ์Šค ํ™œ์„ฑํ™”, ๋ณด์•ˆ์ •์ฑ…์— ๋Œ€
ํ•œ ์ž๋™ ์ ์šฉ ๋ฐ ๋™๊ธฐํ™”, ์ƒ/ํ•˜๋‹จ ํ†ต์‹  ์ง€์ 
์— ๋Œ€ํ•œ ์œ ์—ฐ์„ฑ ์ œ๊ณต(vLB ๋ฐฐ์น˜ or SDN ์ค‘ ํƒ
์ผ), ์ž๋™ ๋ฐฐํฌ ๊ตฌ์„ฑ(ํ‘œ์ค€ ๋ณด์•ˆ ๋ฐฐํฌ ํ…œํ”Œ๋ฆฟ)
์†”๋ฃจ์…˜์ด ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์— ์ ํ•ฉํ•œ์ง€ ๊ฒ€ํ†  ๋ฐ
ํ‘œ์ค€ ์†”๋ฃจ์…˜ ์„ ์ •
Web VM1
Web VM2
Web VM3
...
vWAF1
vWAF2
vWAF3
...
vLB
vLB
SDN
Copyright@ 2018 All reserved by KrDAG
#5. COLLABORATION
๊ฐœ๋ฐœ์ž + ์ธํ”„๋ผ ์—”์ง€๋‹ˆ์–ด + ๋ณด์•ˆ ์—”์ง€๋‹ˆ์–ด์˜ ํ˜‘์—…
Source By: Threatstack.com
Copyright@ 2018 All reserved by KrDAG
๋ถ™์ž„. ๊ธˆ์œต๊ถŒ ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค ์ด์šฉ๊ฐ€์ด๋“œ
โ€˜์ „์ž๊ธˆ์œต๊ฐ๋…๊ทœ์ •โ€™์˜ ์•ˆ์ •์„ฑ ํ™•๋ณด ์˜๋ฌด, โ€˜๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ๋ฒ•โ€™์˜ ์•ˆ์ •์„ฑ ํ™•๋ณด ์กฐ์น˜, โ€˜์ •๋ณดํ†ต์‹ ๋ง๋ฒ•๏ผ‡์˜ ์ •๋ณด๋ณดํ˜ธ ์กฐ์น˜,
โ€˜์‹ ์šฉ์ •๋ณด์—…๊ฐ๋…๊ทœ์ •โ€™์˜ ๊ธฐ์ˆ ์ /๋ฌผ๋ฆฌ์ /๊ด€๋ฆฌ์  ๋ณด์•ˆ ๋Œ€์ฒต ๋“ฑ ๊ด€๋ จ ๋ฒ•๊ทœ๋ฅผ ์ค€์ˆ˜ํ•ด์•ผํ•จ
๊ฐ€. ํด๋ผ์šฐ๋“œ๋ง์— ์™ธ๋ถ€๋ง(=์ผ๋ฐ˜ ์ด์šฉ์ž ์ ‘์†)์€
ํ†ต์‹ ๋ง ๋ถ„๋ฆฌ/๊ฒฉ๋ฆฌ
๋‚˜. ํด๋ผ์šฐ๋“œ๋ง์— ๋‚ด๋ถ€๋ง(=๊ธˆ์šฉํšŒ์‚ฌ ๋‚ด๋ถ€๋ง ์—ฐ๋™
๋ฐ ๊ด€๋ฆฌ์ž ์ ‘์†)์€ ํ†ต์‹ ๋ง ๋ถ„๋ฆฌ/๊ฒฉ๋ฆฌ
๋‹ค. ๋‚ด๋ถ€๋ง์—ฐ๋™ ๋ฐ ๊ด€๋ฆฌ์ž ์ ‘์† ์‹œ โ€˜๋ง๋ถ„๋ฆฌ ๋Œ€์ฒด
์ˆ˜์น™โ€˜ โ€˜์ „์šฉํšŒ์„  ํ˜น์€ ๋™๋“ฑ ์ˆ˜์ค€์˜ ๊ฐ€์ƒ ํšŒ์„ โ€™ ์ค€์ˆ˜
๋ผ. ์—…๋ฌด์šฉ๋‹จ๋ง๊ธฐ ๋ฐ ๋‚ด๋ถ€๋ง์—์„œ ํด๋ผ์šฐ๋“œ ์™ธ๋ถ€๋ง
์ ‘์† ์‹œ โ€˜๋ง๋ถ„๋ฆฌ ๋Œ€์ฒด ์ˆ˜์น™โ€™ ์ค€์ˆ˜
๋งˆ. ์—…๋ฌด์šฉ๋‹จ๋ง๊ธฐ ๋ฐ ๋‚ด๋ถ€๋ง์—์„œ ํด๋ผ์šฐ๋“œ ์™ธ๋ถ€๋ง
์ ‘์† ์‹œ โ€˜์•”ํ˜ธํ™”๋œ ํ†ต์‹ ์ฑ„๋„โ€™์„ ์‚ฌ์šฉ
๊ธˆ์œตํšŒ์‚ฌ ๋‚ด๋ถ€ ์‹œ์Šคํ…œ๊ณผ์˜ ์—ฐ๊ณ„
Copyright@ 2018 All reserved by KrDAG
๋ถ™์ž„. ํด๋ผ์šฐ๋“œ์ปดํ“จํŒ… ์ •๋ณด๋ณดํ˜ธ ๊ณ ์‹œ
๋ฏธ๋ž˜์ฐฝ์กฐ๊ณผํ•™๋ถ€์—์„œ ๊ณต๊ณต๋ถ€๋ฌธ ํด๋ผ์šฐ๋“œ ๋„์ž…์˜ ์ œ๋„์  ๊ธฐ๋ฐ˜ ๊ตฌ์ถ•์„ ์œ„ํ•ด 2016.4.4 ๊ณ ์‹œํ•จ
๊ธฐ์ˆ ์ /๊ด€๋ฆฌ์ /๋ฌผ๋ฆฌ์  ๋ณดํ˜ธ์กฐ์น˜ ๊ธฐ์ค€์„ ์ œ์‹œํ•˜๊ณ  ํด๋ผ์šฐ๋“œ ํ’ˆ์งˆ์„ฑ๋Šฅ ์šฐ๋ ค ํ•ด์†Œ์— ์—ญํ• ์„ ํ•  ์ „๋ง์ž„
์ œ3์กฐ (๊ด€๋ฆฌ์  ๋ณดํ˜ธ์กฐ์น˜)
ํด๋ผ์šฐ๋“œ์ปดํ“จํŒ…์„œ๋น„์Šค ์ œ๊ณต์ž๋Š” ํด๋ผ์šฐ๋“œ์„œ๋น„์Šค์˜ ์•ˆ์ •์„ฑ ๋ฐ ์‹ ๋ขฐ์„ฑ
ํ™•๋ณด๋ฅผ ์œ„ํ•˜์—ฌ ๋‹ค์Œ ๊ฐ ํ˜ธ์˜ ์‚ฌํ•ญ์„ ํฌํ•จํ•œ ๊ด€๋ฆฌ์  ๋ณดํ˜ธ์กฐ์น˜๋ฅผ
์ทจํ•˜์—ฌ์•ผ ํ•œ๋‹ค.
1. ์ •๋ณด๋ณดํ˜ธ ์ •์ฑ… ์ˆ˜๋ฆฝ/์ดํ–‰ ๋ฐ ์ •๋ณด๋ณดํ˜ธ ์กฐ์ง ๊ตฌ์„ฑ/์šด์˜์— ๊ด€ํ•œ ์‚ฌํ•ญ
2. ๋‚ด/์™ธ๋ถ€ ์ธ๋ ฅ๊ด€๋ฆฌ ๋ฐ ์ •๋ณด๋ณดํ˜ธ ๊ต์œก์— ๊ด€ํ•œ ์‚ฌํ•ญ
3. ์ž์‚ฐ ์‹๋ณ„, ๋ณ€๊ฒฝ๊ด€๋ฆฌ ๋ฐ ์œ„ํ—˜๊ด€๋ฆฌ์— ๊ด€ํ•œ ์‚ฌํ•ญ
์ œ5์กฐ (๊ธฐ์ˆ ์  ๋ณดํ˜ธ์กฐ์น˜)
ํด๋ผ์šฐ๋“œ์ปดํ“จํŒ…์„œ๋น„์Šค ์ œ๊ณต์ž๋Š” ํด๋ผ์šฐ๋“œ์ปดํ“จํŒ…์„œ๋น„์Šค์˜ ์•ˆ์ •์„ฑ ๋ฐ
์‹ ๋ขฐ์„ฑ ํ™•๋ณด๋ฅผ ์œ„ํ•˜์—ฌ ๋‹ค์Œ ๊ฐ ํ˜ธ์˜ ์‚ฌํ•ญ์„ ํฌํ•จํ•œ ๊ธฐ์ˆ ์  ๋ณดํ˜ธ์กฐ์น˜๋ฅผ
์ทจํ•˜์—ฌ์•ผ ํ•œ๋‹ค.
1. ๊ฐ€์ƒํ™” ์ธํ”„๋ผ, ๊ฐ€์ƒ ํ™˜๊ฒฝ ๋ณดํ˜ธ์— ๊ด€ํ•œ ์‚ฌํ•ญ
2. ์ ‘๊ทผํ†ต์ œ ๋ฐ ์‚ฌ์šฉ์ž ์‹๋ณ„/์ธ์ฆ์— ๊ด€ํ•œ ์‚ฌํ•ญ
3. ๋„คํŠธ์›Œํฌ ํ†ต์ œ, ์ •๋ณด๋ณดํ˜ธ์‹œ์Šคํ…œ ์šด์˜, ์•”ํ˜ธํ™” ๋“ฑ ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ์—
๊ด€ํ•œ ์‚ฌํ•ญ
4. ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ ๋ฐ ์•”ํ˜ธํ™” ๋“ฑ ์ค‘์š” ์ •๋ณด ๋ณดํ˜ธ์— ๋Œ€ํ•œ ์‚ฌํ•ญ
Copyright@ 2018 All reserved by KrDAG

More Related Content

PDF
Private cloud network architecture (2018)
PDF
Openstack Usecase(2018)
PDF
Network Engineer(2018)
PPTX
์ฐจ์„ธ๋Œ€ ๋ฐ์ดํ„ฐ์„ผํ„ฐ ๋„คํŠธ์›Œํฌ ์ „๋žต
PDF
Cloud datacenter network architecture (2014)
PDF
Cisco sddc solution ์†Œ๊ฐœ
PDF
[White Paper] SDN ๊ธฐ๋ฐ˜ ๊ณต๊ฒฉ ํƒ์ง€์ฐจ๋‹จ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ ์ •๋ณด ๊ตฌ์„ฑ ๋ฐฉ์•ˆ
PDF
Monitoring System Targeting OpenStack, Baremetal, and Network Fabric
Private cloud network architecture (2018)
Openstack Usecase(2018)
Network Engineer(2018)
์ฐจ์„ธ๋Œ€ ๋ฐ์ดํ„ฐ์„ผํ„ฐ ๋„คํŠธ์›Œํฌ ์ „๋žต
Cloud datacenter network architecture (2014)
Cisco sddc solution ์†Œ๊ฐœ
[White Paper] SDN ๊ธฐ๋ฐ˜ ๊ณต๊ฒฉ ํƒ์ง€์ฐจ๋‹จ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ ์ •๋ณด ๊ตฌ์„ฑ ๋ฐฉ์•ˆ
Monitoring System Targeting OpenStack, Baremetal, and Network Fabric

What's hot (20)

PDF
[์˜จ๋ผ์ธ๊ต์œก์‹œ๋ฆฌ์ฆˆ] ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์œ„ํ˜‘ ํƒ์ง€๋Œ€์‘ ๋ฐฉ์•ˆ - ๊น€๋™์šด ๋งค๋‹ˆ์ €
PPSX
SDDC(software defined data center)์—์„œ NFV์˜ ์—ญํ• ๊ณผ ๊ด€๋ฆฌ๋„๊ตฌ (์„ธ๋ฏธ๋‚˜ ๋ฐœํ‘œ ์ž๋ฃŒ)
PDF
[2018] ์˜คํ”ˆ์Šคํƒ 5๋…„ ์šด์˜์˜ ๊ฒฝํ—˜
PDF
Cisco DC ์ „๋žต
PDF
[์˜จ๋ผ์ธ๊ต์œก์‹œ๋ฆฌ์ฆˆ] NKS์—์„œ Cluster & Pods Autoscaling ์ ์šฉ
PDF
[์ด๋™์‹ ์›๊ฒฉ ๋ฐ์ดํ„ฐ์„ผํ„ฐ ์ปจํผ๋Ÿฐ์Šค] SDN๊ธฐ๋ฐ˜ ์ž๋™ํ™” ๊ธฐ์ˆ ์˜ ์ด๋™์‹ ๋ฐ์ดํ„ฐ์„ผํ„ฐ ์ ์šฉ๋ฐฉ์•ˆ-๋‚˜์ž„๋„คํŠธ์›์Šค ๊น€๋™๊ท  ๋งค๋‹ˆ์ €
PDF
[OpenInfra Days Korea 2018] (Track 2) ์˜คํ”ˆ์Šคํƒ ๊ธฐ๋ฐ˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฐ ๋ฉ€ํ‹ฐํด๋ผ์šฐ๋“œ ์—ฐ๋™ ์‚ฌ๋ก€: IXcloud KDX
PDF
150114 OpenStack Korea แ„Œแ…ฅแ†ผแ„€แ…ตแ„‰แ…ฆแ„†แ…ตแ„‚แ…ก session3 - OpenStack ๋„คํŠธ์›Œํฌ์™€ SDN
PDF
[์˜จ๋ผ์ธ๊ต์œก์‹œ๋ฆฌ์ฆˆ] ๋„ค์ด๋ฒ„ํด๋ผ์šฐ๋“œํ”Œ๋žซํผ ์ฃผ์š” ์—…๋ฐ์ดํŠธ - ์œค์ง„๊ทœ ํด๋ผ์šฐ๋“œ ์†”๋ฃจ์…˜ ์•„ํ‚คํ…ํŠธ
PDF
ํ™•์‚ฐ๋˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด ์ •์˜ (SDx) ๊ฐœ๋… ๋ฐ ๋™ํ–ฅ
PDF
(Fios#03) 2. ๋„คํŠธ์›Œํฌ ๊ฐ€์ƒํ™” ํ™˜๊ฒฝ์—์„œ์˜ ์นจํ•ด๋Œ€์‘
PPTX
Cisco network analytics ์†”๋ฃจ์…˜
PDF
[OpenStack Day in Korea 2015] Track 2-4 - Towards Programmable Network (Conce...
PDF
[OpenInfra Days Korea 2018] (Track 2) Microservice Architecture, DevOps ๊ทธ๋ฆฌ๊ณ  5...
PDF
[OpenInfra Days Korea 2018] (Track 3) - SDN/NFV enabled Openstack Platform : ...
PDF
[OpenInfra Days Korea 2018] (Track 2) - OpenStack ๊ธฐ๋ฐ˜์˜ IaaS, PaaS ํ†ตํ•ฉ Orchestra...
PDF
์˜คํ”ˆ์Šคํƒ ๋ฉ€ํ‹ฐ๋…ธ๋“œ ์„ค์น˜ ํ›„๊ธฐ
PDF
[OpenInfra Days Korea 2018] (Track 2) Cloud ํ™˜๊ฒฝ์—์„œ์˜ ๋ณด์•ˆ๊ณผ ๋„คํŠธ์›Œํฌ ์„ฑ๋Šฅ ๋ณด์•ˆ (xFW), DPDK OVS
PPTX
OpenStack Networking
PDF
[9์›” ๋Ÿฐ์น˜ ์„ธ๋ฏธ๋‚˜] ๋„์ปค์™€ ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ๊ธฐ์ˆ ์— ์Šค๋ฉฐ๋“ค๋‹ค
[์˜จ๋ผ์ธ๊ต์œก์‹œ๋ฆฌ์ฆˆ] ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์œ„ํ˜‘ ํƒ์ง€๋Œ€์‘ ๋ฐฉ์•ˆ - ๊น€๋™์šด ๋งค๋‹ˆ์ €
SDDC(software defined data center)์—์„œ NFV์˜ ์—ญํ• ๊ณผ ๊ด€๋ฆฌ๋„๊ตฌ (์„ธ๋ฏธ๋‚˜ ๋ฐœํ‘œ ์ž๋ฃŒ)
[2018] ์˜คํ”ˆ์Šคํƒ 5๋…„ ์šด์˜์˜ ๊ฒฝํ—˜
Cisco DC ์ „๋žต
[์˜จ๋ผ์ธ๊ต์œก์‹œ๋ฆฌ์ฆˆ] NKS์—์„œ Cluster & Pods Autoscaling ์ ์šฉ
[์ด๋™์‹ ์›๊ฒฉ ๋ฐ์ดํ„ฐ์„ผํ„ฐ ์ปจํผ๋Ÿฐ์Šค] SDN๊ธฐ๋ฐ˜ ์ž๋™ํ™” ๊ธฐ์ˆ ์˜ ์ด๋™์‹ ๋ฐ์ดํ„ฐ์„ผํ„ฐ ์ ์šฉ๋ฐฉ์•ˆ-๋‚˜์ž„๋„คํŠธ์›์Šค ๊น€๋™๊ท  ๋งค๋‹ˆ์ €
[OpenInfra Days Korea 2018] (Track 2) ์˜คํ”ˆ์Šคํƒ ๊ธฐ๋ฐ˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฐ ๋ฉ€ํ‹ฐํด๋ผ์šฐ๋“œ ์—ฐ๋™ ์‚ฌ๋ก€: IXcloud KDX
150114 OpenStack Korea แ„Œแ…ฅแ†ผแ„€แ…ตแ„‰แ…ฆแ„†แ…ตแ„‚แ…ก session3 - OpenStack ๋„คํŠธ์›Œํฌ์™€ SDN
[์˜จ๋ผ์ธ๊ต์œก์‹œ๋ฆฌ์ฆˆ] ๋„ค์ด๋ฒ„ํด๋ผ์šฐ๋“œํ”Œ๋žซํผ ์ฃผ์š” ์—…๋ฐ์ดํŠธ - ์œค์ง„๊ทœ ํด๋ผ์šฐ๋“œ ์†”๋ฃจ์…˜ ์•„ํ‚คํ…ํŠธ
ํ™•์‚ฐ๋˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด ์ •์˜ (SDx) ๊ฐœ๋… ๋ฐ ๋™ํ–ฅ
(Fios#03) 2. ๋„คํŠธ์›Œํฌ ๊ฐ€์ƒํ™” ํ™˜๊ฒฝ์—์„œ์˜ ์นจํ•ด๋Œ€์‘
Cisco network analytics ์†”๋ฃจ์…˜
[OpenStack Day in Korea 2015] Track 2-4 - Towards Programmable Network (Conce...
[OpenInfra Days Korea 2018] (Track 2) Microservice Architecture, DevOps ๊ทธ๋ฆฌ๊ณ  5...
[OpenInfra Days Korea 2018] (Track 3) - SDN/NFV enabled Openstack Platform : ...
[OpenInfra Days Korea 2018] (Track 2) - OpenStack ๊ธฐ๋ฐ˜์˜ IaaS, PaaS ํ†ตํ•ฉ Orchestra...
์˜คํ”ˆ์Šคํƒ ๋ฉ€ํ‹ฐ๋…ธ๋“œ ์„ค์น˜ ํ›„๊ธฐ
[OpenInfra Days Korea 2018] (Track 2) Cloud ํ™˜๊ฒฝ์—์„œ์˜ ๋ณด์•ˆ๊ณผ ๋„คํŠธ์›Œํฌ ์„ฑ๋Šฅ ๋ณด์•ˆ (xFW), DPDK OVS
OpenStack Networking
[9์›” ๋Ÿฐ์น˜ ์„ธ๋ฏธ๋‚˜] ๋„์ปค์™€ ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ๊ธฐ์ˆ ์— ์Šค๋ฉฐ๋“ค๋‹ค
Ad

Similar to Openstack security(2018) (20)

PDF
cloud security trend and case
ย 
PDF
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์œ„ํ˜‘ ๋™ํ–ฅ๊ณผ ํ†ตํ•ฉ ๋ณด์•ˆ ์ „๋žต - ๊น€์ค€ํ˜ธ ๊ณผ์žฅ, SECUI :: AWS Summit Seoul 2019
PDF
Cloud security suk kim
ย 
PDF
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์œ„ํ˜‘์— ๊ฐ€์žฅ ํ˜„๋ช…ํ•œ ๋Œ€์ฒ˜ โ€˜์•ˆ๋žฉ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์„œ๋น„::๊น€์ค€ํ˜ธ::AWS Summit Seoul 2018
PDF
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์œ„ํ˜‘์— ๊ฐ€์žฅ ํ˜„๋ช…ํ•œ ๋Œ€์ฒ˜ โ€˜์•ˆ๋žฉ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์„œ๋น„::๊น€์ค€ํ˜ธ::AWS Summit Seoul 2018
PDF
[DataUs]ํด๋ผ์šฐ๋“œ ์ž…๋ฌธ์ž๋ฅผ ์œ„ํ•œ ๋ณด์•ˆ ๊ฐ€์ด๋“œ
ย 
PDF
๋ฉ€ํ‹ฐ ํด๋ผ์šฐ๋“œ ์‹œ๋Œ€์˜ ์ •๋ณด๋ณดํ˜ธ ๊ด€๋ฆฌ์ฒด๊ณ„
PDF
Secure Virtual Private Cloud(VPC)๋ฅผ ํ™œ์šฉํ•œ ๋ณด์•ˆ์„ฑ ๊ฐ•ํ™”์™€ ๋น„์šฉ์ ˆ๊ฐ - ์•ˆ๊ฒฝ์ง„ ๋ถ€์žฅ, ํฌํ‹ฐ๋„ท ์ฝ”๋ฆฌ์•„ :: AWS ...
PDF
Cloud sec 2015 megazone slideshare 20150910
PDF
cloud security-suk kim-2022-10-14-Busan.pdf
ย 
PDF
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์ด์Šˆ ๋ฐ ์›๊ฒฉ ๊ด€์ œ ๊ธฐ๋ฐ˜ ๋Œ€์‘ ๋ฐฉ์•ˆ - AWS Summit Seoul 2017
PDF
VPC๋ฅผ ์œ„ํ•œ Hybrid ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ :: ๊น€๋ฏผ์„ :: AWS Summit Seoul 2016
PDF
ใ€Žแ„‹แ…ฉแ„‘แ…ณแ†ซแ„‰แ…ณแ„แ…ขแ†จ แ„‹แ…ตแ†ซ แ„‹แ…ขแ†จแ„‰แ…งแ†ซใ€ - แ„†แ…กแ†บแ„‡แ…ฉแ„€แ…ต
PDF
แ„’แ…กแ„‰แ…ตแ„แ…ฉแ„‘แ…ณแ„‹แ…ช แ„’แ…กแ†ทแ„แ…ฆแ„’แ…กแ„‚แ…ณแ†ซ แ„‹แ…กแ†ฏแ„…แ…ตแ„‡แ…กแ„‡แ…ก แ„แ…ณแ†ฏแ„…แ…กแ„‹แ…ฎแ„ƒแ…ณ DevSecOps แ„ˆแ…ฉแ„€แ…ขแ„€แ…ต E01 SecOps
PDF
AWS ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ๋ฐ ๊ทœ์ • ์ค€์ˆ˜ ์†Œ๊ฐœ (๋ฐ•์ฒ ์ˆ˜) - AWS ์›จ๋น„๋‚˜ ์‹œ๋ฆฌ์ฆˆ
PDF
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ์˜ ์Šˆํผ ํžˆ์–ด๋กœ๊ฐ€ ๋˜๊ธฐ ์œ„ํ•œ 3๊ฐ€์ง€ ๋น„๋ฐ€ :: TrendMicro ์–‘ํฌ์„  :: AWS Summit Seoul 2016
PDF
[๊ธˆ์œต ๊ณ ๊ฐ์„ ์œ„ํ•œ Resiliency in the Cloud] Open Discussion
PDF
[OpenInfra Days Korea 2018] (Track 1) ์ปค๋ฎค๋‹ˆํ‹ฐ ์˜คํ”ˆ์Šคํƒ ํŒจํ‚ค์ง• ๋„์ž… ์ „๋žต ๋ฐ ๊ตฌํ˜„์‚ฌ๋ก€ ๋ฐœํ‘œ
PDF
ํด๋ผ์šฐ๋“œ ์ปดํ“จํŒ… ๊ธฐ๋ณธ ์‚ฌํ•ญ (Fundamentals)
PDF
OpenStack ์ธ์Šคํ„ด์Šค ๊ฐ„๋žต ์‚ฌ์šฉ์ž_๋งค๋‰ด์–ผ(liberty)_v1
cloud security trend and case
ย 
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์œ„ํ˜‘ ๋™ํ–ฅ๊ณผ ํ†ตํ•ฉ ๋ณด์•ˆ ์ „๋žต - ๊น€์ค€ํ˜ธ ๊ณผ์žฅ, SECUI :: AWS Summit Seoul 2019
Cloud security suk kim
ย 
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์œ„ํ˜‘์— ๊ฐ€์žฅ ํ˜„๋ช…ํ•œ ๋Œ€์ฒ˜ โ€˜์•ˆ๋žฉ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์„œ๋น„::๊น€์ค€ํ˜ธ::AWS Summit Seoul 2018
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์œ„ํ˜‘์— ๊ฐ€์žฅ ํ˜„๋ช…ํ•œ ๋Œ€์ฒ˜ โ€˜์•ˆ๋žฉ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์„œ๋น„::๊น€์ค€ํ˜ธ::AWS Summit Seoul 2018
[DataUs]ํด๋ผ์šฐ๋“œ ์ž…๋ฌธ์ž๋ฅผ ์œ„ํ•œ ๋ณด์•ˆ ๊ฐ€์ด๋“œ
ย 
๋ฉ€ํ‹ฐ ํด๋ผ์šฐ๋“œ ์‹œ๋Œ€์˜ ์ •๋ณด๋ณดํ˜ธ ๊ด€๋ฆฌ์ฒด๊ณ„
Secure Virtual Private Cloud(VPC)๋ฅผ ํ™œ์šฉํ•œ ๋ณด์•ˆ์„ฑ ๊ฐ•ํ™”์™€ ๋น„์šฉ์ ˆ๊ฐ - ์•ˆ๊ฒฝ์ง„ ๋ถ€์žฅ, ํฌํ‹ฐ๋„ท ์ฝ”๋ฆฌ์•„ :: AWS ...
Cloud sec 2015 megazone slideshare 20150910
cloud security-suk kim-2022-10-14-Busan.pdf
ย 
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์ด์Šˆ ๋ฐ ์›๊ฒฉ ๊ด€์ œ ๊ธฐ๋ฐ˜ ๋Œ€์‘ ๋ฐฉ์•ˆ - AWS Summit Seoul 2017
VPC๋ฅผ ์œ„ํ•œ Hybrid ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ :: ๊น€๋ฏผ์„ :: AWS Summit Seoul 2016
ใ€Žแ„‹แ…ฉแ„‘แ…ณแ†ซแ„‰แ…ณแ„แ…ขแ†จ แ„‹แ…ตแ†ซ แ„‹แ…ขแ†จแ„‰แ…งแ†ซใ€ - แ„†แ…กแ†บแ„‡แ…ฉแ„€แ…ต
แ„’แ…กแ„‰แ…ตแ„แ…ฉแ„‘แ…ณแ„‹แ…ช แ„’แ…กแ†ทแ„แ…ฆแ„’แ…กแ„‚แ…ณแ†ซ แ„‹แ…กแ†ฏแ„…แ…ตแ„‡แ…กแ„‡แ…ก แ„แ…ณแ†ฏแ„…แ…กแ„‹แ…ฎแ„ƒแ…ณ DevSecOps แ„ˆแ…ฉแ„€แ…ขแ„€แ…ต E01 SecOps
AWS ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ๋ฐ ๊ทœ์ • ์ค€์ˆ˜ ์†Œ๊ฐœ (๋ฐ•์ฒ ์ˆ˜) - AWS ์›จ๋น„๋‚˜ ์‹œ๋ฆฌ์ฆˆ
ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ์˜ ์Šˆํผ ํžˆ์–ด๋กœ๊ฐ€ ๋˜๊ธฐ ์œ„ํ•œ 3๊ฐ€์ง€ ๋น„๋ฐ€ :: TrendMicro ์–‘ํฌ์„  :: AWS Summit Seoul 2016
[๊ธˆ์œต ๊ณ ๊ฐ์„ ์œ„ํ•œ Resiliency in the Cloud] Open Discussion
[OpenInfra Days Korea 2018] (Track 1) ์ปค๋ฎค๋‹ˆํ‹ฐ ์˜คํ”ˆ์Šคํƒ ํŒจํ‚ค์ง• ๋„์ž… ์ „๋žต ๋ฐ ๊ตฌํ˜„์‚ฌ๋ก€ ๋ฐœํ‘œ
ํด๋ผ์šฐ๋“œ ์ปดํ“จํŒ… ๊ธฐ๋ณธ ์‚ฌํ•ญ (Fundamentals)
OpenStack ์ธ์Šคํ„ด์Šค ๊ฐ„๋žต ์‚ฌ์šฉ์ž_๋งค๋‰ด์–ผ(liberty)_v1
Ad

Openstack security(2018)

  • 1. Copyright@ 2018 All reserved by KrDAG ์˜คํ”ˆ์Šคํƒ ๋ณด์•ˆ โ€ข ๋ณด์•ˆ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ๋ฐฉ์•ˆ โ€ข 3rd party ๊ฐ€์ƒ๋ฐฉํ™”๋ฒฝ ๋ฐ๋ชจ KRDAG STUDY Seo & Ryu โ€“ Infra Engineer
  • 2. Copyright@ 2018 All reserved by KrDAG ๋ณธ ๋ฐœํ‘œ์˜ ๋ชจ๋“  ๋‚ด์šฉ์€ ์ง€๊ทนํžˆ ๊ฐœ์ธ์ ์ธ ์˜๊ฒฌ์ž„์„ ๋ฏธ๋ฆฌ ๋ฐํž™๋‹ˆ๋‹ค
  • 3. Copyright@ 2018 All reserved by KrDAG 0. ๊ฐœ์š” ์™œ ๋ณด์•ˆ์— ๋Œ€ํ•œ ๊ณ ๋ ค๋ฅผ ํ•˜๊ฒŒ ๋˜์—ˆ๋Š”์ง€
  • 4. Copyright@ 2018 All reserved by KrDAG #1. HORIZON BRUTEFORCE ATTACK ๋กœ๊ทธ์ธ ์‹œ๋„ ์‹œ ์ ˆ์ฐจ ๋ฐ ๋ถˆ์ ‘์ ์ธ ๋กœ๊ทธ์ธ ์‹œ๋„ Admin / 123456 ์ž…๋ ฅ Web Proxy Intercept Admin / โ€œ$$โ€ ์ž…๋ ฅ ํŠน์ •ํ•œ ๊ฐ’์„ โ€œ$$โ€์— ๋ณ€๊ฒฝ ์ž…๋ ฅํ•˜์—ฌ ๋กœ๊ทธ์ธ ์‹œ๋„ Response Code ํ™•์ธ ์‹คํŒจ ์‹œ /์„ฑ๊ณต ์‹œ ์™ธ๋ถ€์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธ ์‹คํŒจ ์‹œ ๋กœ๊ทธ์ธ ์„ฑ๊ณต ์‹œ Keystone (์ธ์ฆ์ฒ˜๋ฆฌ) OpenStack Controller 200OK : Close 302 Found Sessionid=๋ฐœ๊ธ‰ Horizon dashboard url redirect http://sola99.tistory.com/414
  • 5. Copyright@ 2018 All reserved by KrDAG #1. ๋Œ€์‘๋ฐฉ์•ˆ ์ ํ•ฉํ•œ ๋ฐฉ์•ˆ ์ค‘ ์„ ํƒ โœ“ Horizon ์„œ๋น„์Šค๋ฅผ Disable โœ“ ์ง€์ •๋œ hosts๋งŒ Horizon ์ ‘์† ๊ฐ€๋Šฅ ํ•˜๊ฒŒ ์„ค์ • /etc/openstack-dashboard/local_settings ํŒŒ์ผ์— ALLOWED_HOSTS = ['*', ] ์— ์ง€์ • โœ“ ์™ธ๋ถ€ ํ˜น์€ ๋‚ด๋ถ€๋ผ๋„ ๋ฐฉํ™”๋ฒฝ ํ˜น์€ IPtables ๋ฅผ ํ†ตํ•œ ์ ‘๊ทผ ์ฐจ๋‹จ์„ ์„ค์ •ํ•˜๊ณ  ์šด์˜์ž๋งŒ ํ—ˆ์šฉํ•จ โœ“ Mod_security ์„ค์น˜ ํ›„ ๋กœ๊ทธ์ธ ์ •์ฑ… ์ ์šฉ ๋ฐ Alert ๋กœ๊ทธ ๋ชจ๋‹ˆํ„ฐ๋ง ์˜ˆ) ํŠน์ • IP๊ฐ€ 10๋ฒˆ ๋กœ๊ทธ์ธ ์‹œ๋„ ์‹คํŒจ ์‹œ 10๋ถ„๊ฐ„ ์ ‘์† ์ฐจ๋‹จ https://docs.mirantis.com/mcp/latest/mcp-security-best-practices/use-cases/brute-force-prevention.html http://sola99.tistory.com/414
  • 6. Copyright@ 2018 All reserved by KrDAG #2. SECURITY CONSIDERATION ๋‹ค์–‘ํ•œ ๊ณ„๊ธฐ โœ“ Message Queue DDoS ๊ณต๊ฒฉ ์‚ฌ๋ก€ : ์™ธ๋ถ€์— MQ Port๊ฐ€ ์—ด๋ ค ์žˆ์–ด์„œ DDoS ๊ณต๊ฒฉ ์‹œ๋„ ๋ฐ ๋งˆ๋น„ โœ“ ๊ฐœ์ธ ์ •๋ณด ๋ฐ ์ฃผ์š” ์ •๋ณด ์œ ์ถœ ์‚ฌ๋ก€ : Facebook ๋“ฑ โœ“ ์˜คํ”ˆ์Šคํƒ ๊ธฐ๋ฐ˜ ์„œ๋น„์Šค๋ฅผ ์‹ค์ œ ์šด์˜ ํ™˜๊ฒฝ ์ „ํ™˜ ์ „ ๋ณด์•ˆ ๊ณ ๋ ค ํ•„์š” โ–ช ์˜คํ”ˆ์Šคํƒ ํ”Œ๋žซํผ์— ๋ณด์•ˆ ๊ฐ€์ด๋“œ ๋ถ€์žฌ : ์ทจ์•ฝ์  ๋ฐ ๋Œ€์‘๋ฐฉ์•ˆ ๋ฐ ์ ๊ฒ€์ฒดํฌ๋ฆฌ์ŠคํŠธ โ–ช ๋ณด์•ˆ ๋ถ€์„œ/ํŒ€์› ๋“ค์˜ ํด๋ผ์šฐ๋“œ์— ๋Œ€ํ•œ ํ•™์Šต ๋ฐ ์ธ์‹ ๋ณ€ํ™” โœ“ โ€œ์ธํ„ฐ๋„ท โ€“ ๋‚ด๋ถ€๋ง(๋‹จ๊ณ„๋ณ„๋ณด์•ˆ) โ€“ ์˜คํ”ˆ์Šคํƒโ€œ : ์ „์ฒด ๊ตฌ์„ฑ์—์„œ์˜ ์ž๋™ํ™”(์ตœ์†Œํ•œ์˜ ์ˆ˜๋™ ์ ˆ์ฐจ)๊ฐ€ ํ•„์š” โœ“ ๊ตญ๊ฐ€๋ณ„ ๋ฒ•์ ์ธ ๊ทœ์ œ ๋ฐ ๊ฑฐ๋ฒ„๋„Œ์Šค ์ค€์ˆ˜ : EU GDRP ๋ฐ โ€œํด๋ผ์šฐ๋“œ์ปดํ“จํŒ… ์ •๋ณด๋ณดํ˜ธ ๊ณ ์‹œโ€ ๋“ฑ
  • 7. Copyright@ 2018 All reserved by KrDAG 1. ๋ณด์•ˆ๊ฐ•ํ™” ๋ฐฉ์•ˆ ๋ณด์•ˆ ๊ฐ€์ด๋“œ & ๊ณ ๋ ค์‚ฌํ•ญ
  • 8. Copyright@ 2018 All reserved by KrDAG #1. OPENSTACK SECURITY GUIDE(OSG) ์˜คํ”ˆ์Šคํƒ ๋ณด์•ˆ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ๊ถŒ์žฅ ์‚ฌํ•ญ ๋ฐ ์ง€์นจ ๋ฐ ์•„ํ‚คํ…์ฒ˜๋ฅผ ์ œ๊ณต https://docs.openstack.org/security-guide/ http://sola99.tistory.com/415
  • 9. Copyright@ 2018 All reserved by KrDAG #1. OSG ์ผ๋ถ€ ๋ฐœ์ทŒ -1- ๋ณด์•ˆ ์ •๋ณด ์ „๋‹ฌ์„ ์œ„ํ•œ ๋ฉ”์ผ๋ง ์„œ๋น„์Šค https://docs.openstack.org/ansible-hardening/latest/ https://wiki.openstack.org/wiki/Security_Notes ๋ณด์•ˆ ๋…ธํŠธ ๋ฐ ๋ณด์•ˆ ๊ฐ€์ด๋“œ (็พ 82๊ฐœ) OS ๋ณด์•ˆ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ์ž๋™ํ™”(Ansible) http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-announce
  • 10. Copyright@ 2018 All reserved by KrDAG #1. OSG ์ผ๋ถ€ ๋ฐœ์ทŒ -2- http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-announce https://wiki.openstack.org/wiki/Security_Notes Horizon Dashboard Checklist Check-Dashboard-02 Check-Dashboard-01: Is user/group of config files set to root/horizon? Check-Dashboard-02: Are strict permissions set for horizon configuration files? Check-Dashboard-03: Is DISALLOW_IFRAME_EMBED parameter set to True? Check-Dashboard-04: Is CSRF_COOKIE_SECURE parameter set to True? Check-Dashboard-05: Is SESSION_COOKIE_SECURE parameter set to True? Check-Dashboard-06: Is SESSION_COOKIE_HTTPONLY parameter set to True? Check-Dashboard-07: Is PASSWORD_AUTOCOMPLETE set to False? Check-Dashboard-08: Is DISABLE_PASSWORD_REVEAL set to True? Check-Dashboard-09: Is ENFORCE_PASSWORD_CHECK set to True? Check-Dashboard-10: Is PASSWORD_VALIDATOR configured? Check-Dashboard-11: Is SECURE_PROXY_SSL_HEADER configured? Horizon Dashboard HTTPS ์•ˆ์ „ํ•œ HTTPS ๋กœ ๋Œ€์‰ฌ๋ณด๋“œ ์ ‘๊ทผํ•˜๊ฒŒ ์„ค์ •ํ•˜๋ผ โ‡’ local_settings.py ํŒŒ์ผ์— "USE_SSL = True" ์„ค์ • # ์ทจ์•ฝ์ ํ•ญ๋ชฉ: ๊ตฌ์„ฑํŒŒ์ผ ๊ถŒํ•œ ๊ด€๋ฆฌ # ์ทจ์•ฝ์ ๊ฐœ์š”: ๊ตฌ์„ฑํŒŒ์ผ์€ ๋™์ž‘์— ํ•„์š”ํ•œ ์ •๋ณด๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์–ด ๊ถŒํ•œ์—†๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ํ•ด๋‹น ํŒŒ์ผ ์ ‘๊ทผํ•˜์—ฌ ์ˆ˜์ • ์‹œ ์„œ๋น„์Šค ์ด์šฉ์— ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Œ # ๋ณด์•ˆ๋Œ€์ฑ… - ํŒ๋‹จ๊ธฐ์ค€ - ์–‘ํ˜ธ : ๊ตฌ์„ฑํŒŒ์ผ ๊ถŒํ•œ์ด 640์ดํ•˜์ธ ๊ฒฝ์šฐ - ์ทจ์•ฝ : ๊ถŒํ•œ์ด 640์ดํ•˜๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ - ์กฐ์น˜๋ฐฉ๋ฒ• : ๊ตฌ์„ฑํŒŒ์ผ์˜ ๊ถŒํ•œ์„ 640์ดํ•˜๋กœ ์„ค์ • - ์กฐ์น˜ ์‹œ ์˜ํ–ฅ : ์˜ํ–ฅ๋„ ์—†์Œ # ์กฐ์น˜ ์ „/ํ›„ ์„ค์ • ๊ฐ’ ํ™•์ธ : ์ ๊ฒ€ ํŒŒ์ผ ์œ„์น˜ ๋ฐ ์ ๊ฒ€ ๋ฐฉ๋ฒ• stat -L -c "%a" /usr/share/openstack-dashboard/openstack_dashboard/local/local_settings.py 640 # ๋ณด์•ˆ์„ค์ •๋ฐฉ๋ฒ• chmod 640 /usr/share/openstack-dashboard/openstack_dashboard/local/local_settings.py
  • 11. Copyright@ 2018 All reserved by KrDAG #2. MIRANTIS SECURITY GUIDE ๋งค๋…„ ์˜คํ”ˆ์Šคํƒ ๋ณด์•ˆ ๊ฐ€์ด๋“œ ์ž‘์„ฑ/๊ณต์œ  ์˜ˆ)Design Secure Cloud Architecture https://docs.mirantis.com/mcp/latest/mcp-security-best-practices/common/preface.html โœ“ ์ทจ์•ฝ์  ์ •์˜ โœ“ ๋Œ€์‘ ๋ณด์•ˆ ๊ธฐ์ˆ  ์ •์˜ โœ“ ์˜คํ”ˆ์Šคํƒ Project ๋ณ„ ๋ณด์•ˆ ๊ฐ•ํ™” ๋ฐฉ์•ˆ โœ“ K8s ์™€ Docker ํ™˜๊ฒฝ์„ ์œ„ํ•œ ๋ณด์•ˆ ๋ฐฉ์•ˆ โœ“ ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ โœ“ ๋ณด์•ˆ ์†”๋ฃจ์…˜ โœ“ Use cases
  • 12. Copyright@ 2018 All reserved by KrDAG #3. CLOUD SECURITY DESIGN IDEA ๋ฌผ๋ฆฌ ๋ณด์•ˆ ์žฅ๋น„(๊ณตํ†ต ์ •์ฑ…)๊ณผ ๊ฐ€์ƒVM/SW ๋ณด์•ˆ ์žฅ๋น„์˜ Hybrid ๊ตฌ์„ฑ โœ“ Firewall rules attached to virtual NICs โœ“ Everything else is "outsideโ€œ โœ“ ๋Œ€์šฉ๋Ÿ‰ ๋ฌผ๋ฆฌ ๋ณด์•ˆ ์žฅ๋น„ + ํŠน์ • App ์ฐจ๋‹จ์„ ์œ„ํ•œ SWํ˜•ํƒœ์˜ ๋ณด์•ˆSW โœ“ Physical(๊ณตํ†ต ์ •์ฑ…) ๊ณผ Virtual(Per-App, FW/LB self-Service) Appliance ํ˜ผํ•ฉ ๋ฐฐ์น˜ ๋ณด์•ˆ ์ „์šฉ ์žฅ๋น„ VM ์—์„œ ๋ณด์•ˆ์ •์ฑ… ๋™์ž‘ Physical + Virtual ๋ณด์•ˆ ์ •์ฑ… ๋™์ž‘ https://www.openstack.org/assets/presentation-media/OS-Security-Talk-rs.pdf http://sola99.tistory.com/382
  • 13. Copyright@ 2018 All reserved by KrDAG #3. CLOUD SECURITY DESIGN IDEA ํ”Œ๋žซํผ(์˜ˆ. ์˜คํ”ˆ์Šคํƒ)๊ณผ ์—ฐ๋™, Scale-out ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์„œ๋น„์Šค ์ œ๊ณต โœ“ ํ”Œ๋žซํผ๊ณผ ์—ฐ๋™ : ์˜คํ”ˆ์Šคํƒ security Group, VMware vShield Edge/NSX FW, Palo Alto Panorama ๋“ฑ โœ“ L3/L4 ๊ธฐ๋ณธ ์ •์ฑ…์€ ๋ฏธ๋ฆฌ ์ง€์ •, L3~L7 filter rule ์€ ํ”Œ๋žซํผ์ด ์ˆ˜์ง‘ํ•œ ์ •๋ณด๋กœ ์ž๋™์œผ๋กœ ์ ์šฉ โœ“ ๋ณด์•ˆ ์žฅ๋น„์˜ ์„ฑ๋Šฅ์„ ๋ชจ๋‹ˆํ„ฐ๋ง ํ•˜์—ฌ ์ž„๊ณ„์น˜๊ฐ€ ๋„˜์œผ๋ฉด ์ž๋™์œผ๋กœ ๋ณด์•ˆ ์žฅ๋น„ ์ฆ๊ฐ€ โœ“ Scale-out IPS with OpenFlow Controller https://www.openstack.org/assets/presentation-media/OS-Security-Talk-rs.pdf
  • 14. Copyright@ 2018 All reserved by KrDAG #4. ์˜คํ”ˆ์Šคํƒ ํ™˜๊ฒฝ์—์„œ์˜ ๋ณด์•ˆ ๊ตฌ์„ฑ ๊ณ ๋ ค์‚ฌํ•ญ VM๊ฐ„ ์ง์ ‘ ํ†ต์‹ ์— ๋Œ€ํ•œ ํ†ต์ œ์™€ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„ ํ™•๋Œ€์— ๋”ฐ๋ฅธ ํ†ต์ œ ํ•„์š” VM๊ฐ„ ์ง์ ‘ ํ†ต์‹  ๋ฐฉํ™”๋ฒฝ Web VM ๊ฐ€์ƒ์Šค์œ„ ์น˜ DMZ์Šค์œ„์น˜ Was VM ๊ฐ€์ƒ์Šค์œ„ ์น˜ ๋‚ด๋ถ€์Šค์œ„์น˜ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€๋ง VM ๊ฐ„ ์ง์ ‘ ํ†ต์‹  ๋ ˆ๊ฑฐ์‹œ ๋ณด์•ˆ ๋ฐฉํ™”๋ฒฝ Web VM ๊ฐ€์ƒ์Šค์œ„ ์น˜ Was VM ๊ฐ€์ƒ์Šค์œ„ ์น˜ ๋‚ด๋ถ€์Šค์œ„์น˜ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€๋ง DMZ์Šค์œ„์น˜ ๋ฌผ๋ฆฌ๋ฐฉํ™”๋ฒฝ ๊ฒฝ์œ  (๋„คํŠธ์›Œํฌ ๊ฒฉ๋ฆฌ) ๋ ˆ๊ฑฐ์‹œ ๋ณด์•ˆ ํ•ด๊ฒฐ๋ฐฉ์•ˆ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„ ํ™•๋Œ€ ๋ฐฉํ™”๋ฒฝ vLB ๊ฐ€์ƒ์Šค์œ„ ์น˜ Was VM ๊ฐ€์ƒ์Šค์œ„ ์น˜ ๋‚ด๋ถ€์Šค์œ„์น˜ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€๋ง DMZ์Šค์œ„์น˜ ๋ฌผ๋ฆฌ๋ฐฉํ™”๋ฒฝ ๊ฒฝ์œ  (๋„คํŠธ์›Œํฌ ๊ฒฉ๋ฆฌ) ๋ ˆ๊ฑฐ์‹œ ๋ณด์•ˆ DB VM ๊ฐ€์ƒ๋ผ์šฐ ํ„ฐ WebVM1 WebVM2 WebVM3 ๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„ ํ™•๋Œ€๋กœ ๋ฌผ ๋ฆฌ ๋ฐฉํ™”๋ฒฝ ๊ฒฝ์œ  ์‹œ โ€˜์ง€์—ฐ (delay)โ€™ ๋ฐœ์ƒ ๋ฐ ๋‚ด๋ถ€ ๊ตฌ๊ฐ„ ํ†ต ์ œ์˜ ์–ด๋ ค์›€ ๋ฐœ์ƒ -> VM/SW๊ธฐ๋ฐ˜ ๋ณด์•ˆ๋ฐฉํ™”๋ฒฝ ํ•„์š” -> (ํด๋ผ์šฐ๋“œ ํ‘œ์ค€ ๋ณด์•ˆ ์†”๋ฃจ์…˜ ์„ ์ •) VM/SW๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์†”๋ฃจ์…˜ ๋ฐฐ์น˜ ๋ฐฉํ™”๋ฒฝ vLB ๊ฐ€์ƒ์Šค์œ„ ์น˜ Was VM ๊ฐ€์ƒ์Šค์œ„ ์น˜ ๋‚ด๋ถ€์Šค์œ„์น˜ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€๋ง DMZ์Šค์œ„์น˜ ๋ฌผ๋ฆฌ๋ฐฉํ™”๋ฒฝ ๊ฒฝ์œ  (๋„คํŠธ์›Œํฌ ๊ฒฉ๋ฆฌ) ๋ ˆ๊ฑฐ์‹œ ๋ณด์•ˆ DB VM ๊ฐ€์ƒ๋ฐฉํ™” ๋ฒฝ WebVM ๊ฐ€์ƒ ์›น๋ฐฉ ํ™”๋ฒฝ VM๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์ œํ’ˆ(vFW, vWAF, vIDS, vIPS)์ด๋‚˜ SW ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์†”๋ฃจ์…˜(host based FW/WAF/IDS/IPS SW) ๋ฐฐ์น˜ ๋กœ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„์— ๋ณด์•ˆ ๊ธฐ๋Šฅ ์ œ๊ณต ์ตœ์ ํ™” DB์•”ํ˜ธํ™” AWS ๊ตฌ์„ฑ ์˜ˆ์‹œ ์œ„ 3Tier Web ๊ตฌ์„ฑ ์—ญ์‹œ vLB โ€“ Web โ€“ vLB โ€“ WAS โ€“ vDB ๋ฐฐ์น˜๋กœ ๊ฐ€์ƒํ™” ๋‚ด๋ถ€ ๊ตฌ๊ฐ„์—์„œ ๊ตฌ์„ฑ๋จ
  • 15. Copyright@ 2018 All reserved by KrDAG #4. ์˜คํ”ˆ์Šคํƒ ํ™˜๊ฒฝ์—์„œ์˜ ๋ณด์•ˆ ๊ตฌ์„ฑ ๊ณ ๋ ค์‚ฌํ•ญ Auto-Scaling ์— ๋Œ€ํ•œ ๋Œ€์‘ ๋ฐฉ์•ˆ ํ•„์š”, VM์ฆ๊ฐ€ ์‹œ ์ž๋™ ๋ฐœ๊ฒฌ ๋“ฑ๋ก/์šด์˜ ํ•„์š” ์ด์Šˆ ๋ฐœ์ƒ Web VM1 Web VM2 Web VM2 ๊ด€๋ฆฌ์„œ๋ฒ„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ณด์•ˆ๊ด€์ œ 10.1.1.1 10.1.1.2 ๋“ฑ๋ก IP 10.1.1.1 ํ•ด๊ฒฐ ๋ฐฉ์•ˆ Web VM1 Web VM2 Web VM2 ๊ด€๋ฆฌ์„œ๋ฒ„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ณด์•ˆ๊ด€์ œ 10.1.1.1 10.1.1.2 ๋“ฑ๋ก IP 10.1.1.1 10.1.1.2 ์„œ๋น„์Šค VM AutoScaling ์„œ๋น„์ŠคVM์˜ AutoScaling ๊ธฐ๋Šฅ์œผ๋กœ VM ์ƒ์„ฑ๊ณผ ์‚ญ์ œ๊ฐ€ ๋นˆ๋ฒˆํ•˜๊ฒŒ ๋ฐœ์ƒํ•จ ๊ณ ๋ ค์‚ฌํ•ญ : ์šด์˜/๊ด€๋ฆฌ ์‹œ์Šคํ…œ์ด ์‹ ๊ทœ ์ƒ์„ฑ ์‹œ ์ž ๋™์œผ๋กœ ๋“ฑ๋ก/์‚ญ์ œ ํ•˜์—ฌ ๊ด€๋ฆฌ๊ฐ€ ๊ฐ€๋Šฅํ•œ์ง€ ๊ฒ€ํ† , ๊ฐ์‚ฌ/๋กœ๊ทธ ๊ธฐ๋ก ํ™•์ธ ์‹œ ๋ถ€ํ•˜ ๊ฐ์†Œ๋กœ ์‚ญ์ œ๋˜์—ˆ ์„๋•Œ์— ๊ณผ๊ฑฐ ๊ธฐ๋ก ํ™•์ธ ๋ฐฉ์•ˆ ํ•„์š” ์ถฉ๋ถ„ํ•œ ํ…Œ์ŠคํŠธ๊ฐ€ ํ•„์š”ํ•˜๊ณ  Mix_Max ๊ฐฏ์ˆ˜์˜ VM ์ˆ˜๋Ÿ‰์— ๋Œ€ํ•œ ๊ฒ€ํ†  ํ›„ ๊ฒฐ์ • ํ•„์š” Web VM1 Web VM2 Web VM3 ... vLB ๋ณด์•ˆ VM/SW AutoScaling ์„œ๋น„์ŠคVM์˜ AutoScaling์— ๋”ฐ๋ผ โ€˜๋ณด์•ˆ VM/SWโ€™ ๋„ Active-Backup ๊ตฌ์„ฑ์ด์™ธ์— AutoScaling ๊ตฌ์„ฑ๋„ ์š”๊ตฌ๋จ. ๊ณ ๋ ค์‚ฌํ•ญ : ๋ผ์ด์„ ์Šค ํ™œ์„ฑํ™”, ๋ณด์•ˆ์ •์ฑ…์— ๋Œ€ ํ•œ ์ž๋™ ์ ์šฉ ๋ฐ ๋™๊ธฐํ™”, ์ƒ/ํ•˜๋‹จ ํ†ต์‹  ์ง€์  ์— ๋Œ€ํ•œ ์œ ์—ฐ์„ฑ ์ œ๊ณต(vLB ๋ฐฐ์น˜ or SDN ์ค‘ ํƒ ์ผ), ์ž๋™ ๋ฐฐํฌ ๊ตฌ์„ฑ(ํ‘œ์ค€ ๋ณด์•ˆ ๋ฐฐํฌ ํ…œํ”Œ๋ฆฟ) ์†”๋ฃจ์…˜์ด ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์— ์ ํ•ฉํ•œ์ง€ ๊ฒ€ํ†  ๋ฐ ํ‘œ์ค€ ์†”๋ฃจ์…˜ ์„ ์ • Web VM1 Web VM2 Web VM3 ... vWAF1 vWAF2 vWAF3 ... vLB vLB SDN
  • 16. Copyright@ 2018 All reserved by KrDAG #5. COLLABORATION ๊ฐœ๋ฐœ์ž + ์ธํ”„๋ผ ์—”์ง€๋‹ˆ์–ด + ๋ณด์•ˆ ์—”์ง€๋‹ˆ์–ด์˜ ํ˜‘์—… Source By: Threatstack.com
  • 17. Copyright@ 2018 All reserved by KrDAG ๋ถ™์ž„. ๊ธˆ์œต๊ถŒ ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค ์ด์šฉ๊ฐ€์ด๋“œ โ€˜์ „์ž๊ธˆ์œต๊ฐ๋…๊ทœ์ •โ€™์˜ ์•ˆ์ •์„ฑ ํ™•๋ณด ์˜๋ฌด, โ€˜๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ๋ฒ•โ€™์˜ ์•ˆ์ •์„ฑ ํ™•๋ณด ์กฐ์น˜, โ€˜์ •๋ณดํ†ต์‹ ๋ง๋ฒ•๏ผ‡์˜ ์ •๋ณด๋ณดํ˜ธ ์กฐ์น˜, โ€˜์‹ ์šฉ์ •๋ณด์—…๊ฐ๋…๊ทœ์ •โ€™์˜ ๊ธฐ์ˆ ์ /๋ฌผ๋ฆฌ์ /๊ด€๋ฆฌ์  ๋ณด์•ˆ ๋Œ€์ฒต ๋“ฑ ๊ด€๋ จ ๋ฒ•๊ทœ๋ฅผ ์ค€์ˆ˜ํ•ด์•ผํ•จ ๊ฐ€. ํด๋ผ์šฐ๋“œ๋ง์— ์™ธ๋ถ€๋ง(=์ผ๋ฐ˜ ์ด์šฉ์ž ์ ‘์†)์€ ํ†ต์‹ ๋ง ๋ถ„๋ฆฌ/๊ฒฉ๋ฆฌ ๋‚˜. ํด๋ผ์šฐ๋“œ๋ง์— ๋‚ด๋ถ€๋ง(=๊ธˆ์šฉํšŒ์‚ฌ ๋‚ด๋ถ€๋ง ์—ฐ๋™ ๋ฐ ๊ด€๋ฆฌ์ž ์ ‘์†)์€ ํ†ต์‹ ๋ง ๋ถ„๋ฆฌ/๊ฒฉ๋ฆฌ ๋‹ค. ๋‚ด๋ถ€๋ง์—ฐ๋™ ๋ฐ ๊ด€๋ฆฌ์ž ์ ‘์† ์‹œ โ€˜๋ง๋ถ„๋ฆฌ ๋Œ€์ฒด ์ˆ˜์น™โ€˜ โ€˜์ „์šฉํšŒ์„  ํ˜น์€ ๋™๋“ฑ ์ˆ˜์ค€์˜ ๊ฐ€์ƒ ํšŒ์„ โ€™ ์ค€์ˆ˜ ๋ผ. ์—…๋ฌด์šฉ๋‹จ๋ง๊ธฐ ๋ฐ ๋‚ด๋ถ€๋ง์—์„œ ํด๋ผ์šฐ๋“œ ์™ธ๋ถ€๋ง ์ ‘์† ์‹œ โ€˜๋ง๋ถ„๋ฆฌ ๋Œ€์ฒด ์ˆ˜์น™โ€™ ์ค€์ˆ˜ ๋งˆ. ์—…๋ฌด์šฉ๋‹จ๋ง๊ธฐ ๋ฐ ๋‚ด๋ถ€๋ง์—์„œ ํด๋ผ์šฐ๋“œ ์™ธ๋ถ€๋ง ์ ‘์† ์‹œ โ€˜์•”ํ˜ธํ™”๋œ ํ†ต์‹ ์ฑ„๋„โ€™์„ ์‚ฌ์šฉ ๊ธˆ์œตํšŒ์‚ฌ ๋‚ด๋ถ€ ์‹œ์Šคํ…œ๊ณผ์˜ ์—ฐ๊ณ„
  • 18. Copyright@ 2018 All reserved by KrDAG ๋ถ™์ž„. ํด๋ผ์šฐ๋“œ์ปดํ“จํŒ… ์ •๋ณด๋ณดํ˜ธ ๊ณ ์‹œ ๋ฏธ๋ž˜์ฐฝ์กฐ๊ณผํ•™๋ถ€์—์„œ ๊ณต๊ณต๋ถ€๋ฌธ ํด๋ผ์šฐ๋“œ ๋„์ž…์˜ ์ œ๋„์  ๊ธฐ๋ฐ˜ ๊ตฌ์ถ•์„ ์œ„ํ•ด 2016.4.4 ๊ณ ์‹œํ•จ ๊ธฐ์ˆ ์ /๊ด€๋ฆฌ์ /๋ฌผ๋ฆฌ์  ๋ณดํ˜ธ์กฐ์น˜ ๊ธฐ์ค€์„ ์ œ์‹œํ•˜๊ณ  ํด๋ผ์šฐ๋“œ ํ’ˆ์งˆ์„ฑ๋Šฅ ์šฐ๋ ค ํ•ด์†Œ์— ์—ญํ• ์„ ํ•  ์ „๋ง์ž„ ์ œ3์กฐ (๊ด€๋ฆฌ์  ๋ณดํ˜ธ์กฐ์น˜) ํด๋ผ์šฐ๋“œ์ปดํ“จํŒ…์„œ๋น„์Šค ์ œ๊ณต์ž๋Š” ํด๋ผ์šฐ๋“œ์„œ๋น„์Šค์˜ ์•ˆ์ •์„ฑ ๋ฐ ์‹ ๋ขฐ์„ฑ ํ™•๋ณด๋ฅผ ์œ„ํ•˜์—ฌ ๋‹ค์Œ ๊ฐ ํ˜ธ์˜ ์‚ฌํ•ญ์„ ํฌํ•จํ•œ ๊ด€๋ฆฌ์  ๋ณดํ˜ธ์กฐ์น˜๋ฅผ ์ทจํ•˜์—ฌ์•ผ ํ•œ๋‹ค. 1. ์ •๋ณด๋ณดํ˜ธ ์ •์ฑ… ์ˆ˜๋ฆฝ/์ดํ–‰ ๋ฐ ์ •๋ณด๋ณดํ˜ธ ์กฐ์ง ๊ตฌ์„ฑ/์šด์˜์— ๊ด€ํ•œ ์‚ฌํ•ญ 2. ๋‚ด/์™ธ๋ถ€ ์ธ๋ ฅ๊ด€๋ฆฌ ๋ฐ ์ •๋ณด๋ณดํ˜ธ ๊ต์œก์— ๊ด€ํ•œ ์‚ฌํ•ญ 3. ์ž์‚ฐ ์‹๋ณ„, ๋ณ€๊ฒฝ๊ด€๋ฆฌ ๋ฐ ์œ„ํ—˜๊ด€๋ฆฌ์— ๊ด€ํ•œ ์‚ฌํ•ญ ์ œ5์กฐ (๊ธฐ์ˆ ์  ๋ณดํ˜ธ์กฐ์น˜) ํด๋ผ์šฐ๋“œ์ปดํ“จํŒ…์„œ๋น„์Šค ์ œ๊ณต์ž๋Š” ํด๋ผ์šฐ๋“œ์ปดํ“จํŒ…์„œ๋น„์Šค์˜ ์•ˆ์ •์„ฑ ๋ฐ ์‹ ๋ขฐ์„ฑ ํ™•๋ณด๋ฅผ ์œ„ํ•˜์—ฌ ๋‹ค์Œ ๊ฐ ํ˜ธ์˜ ์‚ฌํ•ญ์„ ํฌํ•จํ•œ ๊ธฐ์ˆ ์  ๋ณดํ˜ธ์กฐ์น˜๋ฅผ ์ทจํ•˜์—ฌ์•ผ ํ•œ๋‹ค. 1. ๊ฐ€์ƒํ™” ์ธํ”„๋ผ, ๊ฐ€์ƒ ํ™˜๊ฒฝ ๋ณดํ˜ธ์— ๊ด€ํ•œ ์‚ฌํ•ญ 2. ์ ‘๊ทผํ†ต์ œ ๋ฐ ์‚ฌ์šฉ์ž ์‹๋ณ„/์ธ์ฆ์— ๊ด€ํ•œ ์‚ฌํ•ญ 3. ๋„คํŠธ์›Œํฌ ํ†ต์ œ, ์ •๋ณด๋ณดํ˜ธ์‹œ์Šคํ…œ ์šด์˜, ์•”ํ˜ธํ™” ๋“ฑ ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ์— ๊ด€ํ•œ ์‚ฌํ•ญ 4. ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ ๋ฐ ์•”ํ˜ธํ™” ๋“ฑ ์ค‘์š” ์ •๋ณด ๋ณดํ˜ธ์— ๋Œ€ํ•œ ์‚ฌํ•ญ
  • 19. Copyright@ 2018 All reserved by KrDAG