°­·ÂÇÑ Á¢±Ù ±ÇÇÑÅëÁ¦ (Powerful Access Control)

ÀüÀÚ¼­¸í ÀÎÁõ±â¹Ý »ç¿ëÀÚ ½Å¿øÈ®ÀÎ
  • X.509 v3 ±¹Á¦Ç¥ÁØ Áؼö
  • ±¹³»/¿Ü °øÀÎÀÎÁõ¼­ ¿¬µ¿ Áö¿ø
       - ±ÝÀ¶°áÁ¦¿ø µî ±¹³» 6°³ °øÀÎÀÎÁõ±â°ü
          ÀÎÁõ¼­ ¿¬µ¿ °¡´É

    TCSEC B1 µî±Þ ¼öÁØÀÇ º¸¾È¼º Á¦°ø
  • ¹Ì±¹ ±¹¹æ¼ºÀÇ ¾ÈÀüÇÑ ÄÄÇ»ÅͽýºÅÛ Æò°¡ ±âÁØÀÎ
        TCSEC(Trusted Computer System Evaluation
        Criteria)ÀÇ B1±Þ¿¡ ÇØ´çÇÏ´Â º¸¾È ±â´É(°­·ÂÇÑ
        Á¢±Ù±ÇÇÑ ÅëÁ¦, ´ÙÁßµî±Þº¸¾È, °­Á¦Àû Á¢±ÙÁ¦¾î
        µî) ¹× º¸Áõ ¿ä±¸»çÇ× ¼öÁØÀ» ¸¸Á·

    ¿ªÇÒ±â¹ÝÀÇ Á¢±ÙÅëÁ¦ (Role Based Access Control)
  • ¸ðµç ½Ã½ºÅÛ ±¸¼º¿ä¼Ò¿¡ ´ëÇØ º¸¾È¼öÁذú
        ¾÷¹« ¿µ¿ª¿¡ µû¶ó º¸¾Èµî±Þ ¹× º¸È£¹üÁÖ ºÎ¿©

    ´ÙÁßµî±Þ Á¢±ÙÅëÁ¦ (Multi Level Security)
  • X.509 v3 ÀÎÁõ¼­ Áö¿ø
  • ±¹³»/¿Ü °øÀÎÀÎÁõ¼­ ¿¬µ¿

    ÃÖ¼Ò±ÇÇÑ & ±ÇÇѺи® (Least Privilege & Separation of Duty)
  • ½Ã½ºÅÛ°ü¸®ÀÚ´Â ½Ã½ºÅÛ ¿î¿µ ±ÇÇѸ¸ ¼ÒÀ¯
        (Least Privilege)
  • ½Ã½ºÅÛ°ü¸®ÀÚ ¹× º¸¾È°ü¸®ÀÚÀÇ ¾ö°ÝÇÑ ºÐ¸®
        (Separation of Duty)
  • ¿î¿µÃ¼Á¦¿Í º°µµÀÇ º¸¾È°ü¸®ÀÚ ¹× »ç¿ëÀÚ ÀÎÁõ ±â´É

  • Áö´ÉÇü ħÀÔŽÁö ¹× ¹æÁö (IIDP: Intelligent Intrusion Detection and Prevention)
    Áö´ÉÇü ħÀÔŽÁö (Intelligent intrusion detection)
  • ÇØÅ·¿¡ ÀÌ¿ëµÉ ¼ö ÀÖ´Â Buffer Overflow,
        Format String, Race Condition µî¿¡ ´ëÇÑ ½Ç½Ã°£
        Å½Áö ¹× ½Ç½Ã°£ Â÷´Ü ±â´É
        - ħÀÔŽÁö ¹æ½Ä: Hybrid Scheme (Signature &
           Anomaly Detection)
        - ½Ã½ºÅÛ °ø°Ý ħÀÔŽÁö: BOF(Buffer Overflow),
           Race Condition µî
        - ³×Æ®¿öÅ© °ø°Ý ħÀÔŽÁö: Internet Worm & Virus,
           DOS µî

    ´Éµ¿Çü ħÀÔ¹æÁö (Dynamic intrusion prevention)
  • ´Éµ¿Àû ħÀÔÂ÷´Ü (Dynamic intrusion blocking)
        - ½Ã½ºÅÛ °ü¸®ÀÚ ¹× »ç¿ëÀÚº° Á¢±Ù(login,suµî)
           Á¦ÇÑ ±â´É
        - ħÀÔ½ÅÈ£ ¹ß»ý°ú µ¿½Ã¿¡, ħÀÔ°ü·Ã ÇÁ·Î¼¼½º ¹×
          ·Î±ä-¼¼¼ÇÀÇ °­Á¦ Á¾·á
  • Áö´ÉÀû ħÀÔ¹æ¾î (Intelligent intrusion defense)
        - ¿î¿µÃ¼Á¦ Ä¿³Î ¼öÁØ¿¡¼­ IP, Port, ¼­ºñ½ºº°
          ¼­¹ö ¹æÈ­º®(Server F/W) ±â´É
        - ħÀÔÀÚ °ü·Ã Á¤º¸¸¦ Server F/W¿¡ Àü¼Û
        - Server F/WÀº ħÀÔÀÚ °ü·Ã Á¤º¸¸¦ ºí·¢¸®½ºÆ®¿¡
          ÀÚµ¿ µî·ÏÇÏ¿© ÇâÈÄ Ä§ÀÔÀ» ¿øÃµ Â÷´Ü

  • ´Ù¾çÇÏ°í Æí¸®ÇÑ ½Ã½ºÅÛ ¼³Á¤ °¡À̵å (Diverse convenient guides to system configuration)

    º¸¾ÈÁ¤Ã¥ ½Ã¹Ä·¹ÀÌ¼Ç (Security Policy Simulation Mode)
  • º¸¾ÈÁ¤Ã¥ ¼³Á¤ÀÇ ÀûÇÕ¼ºÀ» »çÀü¿¡ ½Ã¹Ä·¹À̼Ç

    ¼º´ÉÁ¶Á¤ (Performance Tuning Mode)
  • ¿î¿µ ¼­¹öÀÇ º¸¾È°ú ¼º´ÉÀ» °í·ÁÇÑ ÃÖÀû¼º´É À¯Áö

    Á¢±Ù±ÇÇÑ ¸ñ·Ï ÆíÁý±â (ACL Editor)
  • Ãʺ¸°ü¸®ÀÚ°¡ ÀÌÇØÇϱ⠽¬¿î º¸¾ÈÁ¤Ã¥ ±âº»Á¦°ø
  • Àü¹®°ü¸®ÀÚ¸¦ À§ÇÑ »ó¼¼ º¸¾ÈÁ¤Ã¥ ¼³Á¤ÀÇ ÅÛÇø´

    ÀÚµ¿ º¸¾È¼³Á¤ (Automatic security policy configuration)
  • ½Ã½ºÅÛ ÁÖ¿ä ÆÄÀÏ¿¡ ´ëÇÑ ÀÚµ¿ º¸¾È ¼³Á¤

    ÅëÇÕ ·Î±× °ü¸® Åø 'Audit Center' Á¦°ø
  • ´Ù¾çÇÑ OS±â¹Ý 'Secuve TOS¢ç ·Î±×'ÀÇ Áß¾Ó¼­¹ö
        ÅëÇÕ°ü¸® ¹× ºÐ¼® Report Á¦°ø

    ½Ç½Ã°£ ¾Ë¶÷
  • º¸¾ÈÁ¤Ã¥ À§¹Ý »çÇ׿¡ ´ëÇÑ ½Ç½Ã°£ ·Î±ë ¹× °ü¸®ÀÚ
        Å뺸(¸ÞÀÏ, SMS, ÆË¾÷ µî) ±â´É
  •