|
|
| |
|
|
|
 |
| |
|
 |

| °·ÂÇÑ Á¢±Ù ±ÇÇÑÅëÁ¦ (Powerful Access Control)
|
 |
ÀüÀÚ¼¸í ÀÎÁõ±â¹Ý »ç¿ëÀÚ ½Å¿øÈ®ÀÎ
X.509 v3 ±¹Á¦Ç¥ÁØ Áؼö
±¹³»/¿Ü °øÀÎÀÎÁõ¼ ¿¬µ¿ Áö¿ø
- ±ÝÀ¶°áÁ¦¿ø µî ±¹³» 6°³ °øÀÎÀÎÁõ±â°ü
ÀÎÁõ¼ ¿¬µ¿ °¡´É
TCSEC B1 µî±Þ ¼öÁØÀÇ º¸¾È¼º Á¦°ø
¹Ì±¹ ±¹¹æ¼ºÀÇ ¾ÈÀüÇÑ ÄÄÇ»ÅͽýºÅÛ Æò°¡ ±âÁØÀÎ
TCSEC(Trusted Computer System Evaluation
Criteria)ÀÇ B1±Þ¿¡ ÇØ´çÇÏ´Â º¸¾È ±â´É(°·ÂÇÑ
Á¢±Ù±ÇÇÑ ÅëÁ¦, ´ÙÁßµî±Þº¸¾È, °Á¦Àû Á¢±ÙÁ¦¾î
µî) ¹× º¸Áõ ¿ä±¸»çÇ× ¼öÁØÀ» ¸¸Á·
¿ªÇÒ±â¹ÝÀÇ Á¢±ÙÅëÁ¦ (Role Based Access Control)
¸ðµç ½Ã½ºÅÛ ±¸¼º¿ä¼Ò¿¡ ´ëÇØ º¸¾È¼öÁذú
¾÷¹« ¿µ¿ª¿¡ µû¶ó º¸¾Èµî±Þ ¹× º¸È£¹üÁÖ ºÎ¿©
´ÙÁßµî±Þ Á¢±ÙÅëÁ¦ (Multi Level Security)
X.509 v3 ÀÎÁõ¼ Áö¿ø
±¹³»/¿Ü °øÀÎÀÎÁõ¼ ¿¬µ¿
ÃÖ¼Ò±ÇÇÑ & ±ÇÇѺи® (Least Privilege & Separation of Duty)
½Ã½ºÅÛ°ü¸®ÀÚ´Â ½Ã½ºÅÛ ¿î¿µ ±ÇÇѸ¸ ¼ÒÀ¯
(Least Privilege)
½Ã½ºÅÛ°ü¸®ÀÚ ¹× º¸¾È°ü¸®ÀÚÀÇ ¾ö°ÝÇÑ ºÐ¸®
(Separation of Duty)
¿î¿µÃ¼Á¦¿Í º°µµÀÇ º¸¾È°ü¸®ÀÚ ¹× »ç¿ëÀÚ ÀÎÁõ ±â´É
|
| Áö´ÉÇü ħÀÔŽÁö ¹× ¹æÁö (IIDP: Intelligent Intrusion Detection and Prevention) |
 |
Áö´ÉÇü ħÀÔŽÁö (Intelligent intrusion detection)
ÇØÅ·¿¡ ÀÌ¿ëµÉ ¼ö ÀÖ´Â Buffer Overflow,
Format String, Race Condition µî¿¡ ´ëÇÑ ½Ç½Ã°£ ŽÁö ¹× ½Ç½Ã°£ Â÷´Ü ±â´É
- ħÀÔŽÁö ¹æ½Ä: Hybrid Scheme (Signature &
Anomaly Detection)
- ½Ã½ºÅÛ °ø°Ý ħÀÔŽÁö: BOF(Buffer Overflow),
Race Condition µî
- ³×Æ®¿öÅ© °ø°Ý ħÀÔŽÁö: Internet Worm & Virus, DOS µî
´Éµ¿Çü ħÀÔ¹æÁö (Dynamic intrusion prevention)
´Éµ¿Àû ħÀÔÂ÷´Ü (Dynamic intrusion blocking)
- ½Ã½ºÅÛ °ü¸®ÀÚ ¹× »ç¿ëÀÚº° Á¢±Ù(login,suµî)
Á¦ÇÑ ±â´É
- ħÀÔ½ÅÈ£ ¹ß»ý°ú µ¿½Ã¿¡, ħÀÔ°ü·Ã ÇÁ·Î¼¼½º ¹× ·Î±ä-¼¼¼ÇÀÇ °Á¦ Á¾·á
Áö´ÉÀû ħÀÔ¹æ¾î (Intelligent intrusion defense)
- ¿î¿µÃ¼Á¦ Ä¿³Î ¼öÁØ¿¡¼ IP, Port, ¼ºñ½ºº° ¼¹ö ¹æÈº®(Server F/W) ±â´É
- ħÀÔÀÚ °ü·Ã Á¤º¸¸¦ Server F/W¿¡ Àü¼Û
- Server F/WÀº ħÀÔÀÚ °ü·Ã Á¤º¸¸¦ ºí·¢¸®½ºÆ®¿¡ ÀÚµ¿ µî·ÏÇÏ¿© ÇâÈÄ Ä§ÀÔÀ» ¿øÃµ Â÷´Ü
|
| ´Ù¾çÇÏ°í Æí¸®ÇÑ ½Ã½ºÅÛ ¼³Á¤ °¡À̵å (Diverse convenient guides to system configuration) |
 |
º¸¾ÈÁ¤Ã¥ ½Ã¹Ä·¹ÀÌ¼Ç (Security Policy Simulation Mode)
º¸¾ÈÁ¤Ã¥ ¼³Á¤ÀÇ ÀûÇÕ¼ºÀ» »çÀü¿¡ ½Ã¹Ä·¹À̼Ç
¼º´ÉÁ¶Á¤ (Performance Tuning Mode)
¿î¿µ ¼¹öÀÇ º¸¾È°ú ¼º´ÉÀ» °í·ÁÇÑ ÃÖÀû¼º´É À¯Áö
Á¢±Ù±ÇÇÑ ¸ñ·Ï ÆíÁý±â (ACL Editor)
Ãʺ¸°ü¸®ÀÚ°¡ ÀÌÇØÇϱ⠽¬¿î º¸¾ÈÁ¤Ã¥ ±âº»Á¦°ø
Àü¹®°ü¸®ÀÚ¸¦ À§ÇÑ »ó¼¼ º¸¾ÈÁ¤Ã¥ ¼³Á¤ÀÇ ÅÛÇø´
ÀÚµ¿ º¸¾È¼³Á¤ (Automatic security policy configuration)
½Ã½ºÅÛ ÁÖ¿ä ÆÄÀÏ¿¡ ´ëÇÑ ÀÚµ¿ º¸¾È ¼³Á¤
ÅëÇÕ ·Î±× °ü¸® Åø 'Audit Center' Á¦°ø
´Ù¾çÇÑ OS±â¹Ý 'Secuve TOS¢ç ·Î±×'ÀÇ Áß¾Ó¼¹ö ÅëÇÕ°ü¸® ¹× ºÐ¼® Report Á¦°ø
½Ç½Ã°£ ¾Ë¶÷
º¸¾ÈÁ¤Ã¥ À§¹Ý »çÇ׿¡ ´ëÇÑ ½Ç½Ã°£ ·Î±ë ¹× °ü¸®ÀÚ Å뺸(¸ÞÀÏ, SMS, ÆË¾÷ µî) ±â´É
|
|
|
| |
|
|
|
 |
|