์นดํ…Œ๊ณ ๋ฆฌ ์—†์Œ

[12์›” 3์ผ] Securi-Center ํ†ตํ•ฉ ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜

ljm 2025. 12. 3. 17:42

 

๐Ÿ›ก๏ธ ๋ณด์•ˆ ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง ์†”๋ฃจ์…˜ ์—ญํ•  (๊ธฐ์ˆ ์  ์„ค๋ช…)

 

1. ๋„คํŠธ์›Œํฌ ๊ฒฝ๊ณ„ ๋ฐ ์ ‘๊ทผ ํ†ต์ œ ์†”๋ฃจ์…˜

์†”๋ฃจ์…˜ ์ด๋ฆ„ ์•ฝ์–ด/๋ถ„๋ฅ˜ ํ•ต์‹ฌ ๊ธฐ๋Šฅ ๋ฐ ๋™์ž‘ ๋ฐฉ์‹
pf-Sense ๋ฐฉํ™”๋ฒฝ
(Firewall)
IP ์ฃผ์†Œ์™€ ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์˜ ํ—ˆ์šฉ/์ฐจ๋‹จ ๊ทœ์น™์„ ์„ค์ •ํ•˜๊ณ  ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค. ๋„คํŠธ์›Œํฌ์˜ **๊ฒฝ๊ณ„(Perimeter)**์—์„œ ์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ์˜ ๋ถˆํ•„์š”ํ•œ ์ ‘๊ทผ์„ ํ†ต์ œํ•˜๋Š” ๊ฐ€์žฅ ๊ธฐ๋ณธ์ ์ธ ๋ฐฉ์–ด์„ ์ž…๋‹ˆ๋‹ค.
Snort /
Suricata
์นจ์ž… ํƒ์ง€/๋ฐฉ์ง€ ์‹œ์Šคํ…œ
(IDS/IPS)
๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์˜ **๋‚ด์šฉ๋ฌผ(Payload)**์„ ํฌํ•จํ•˜์—ฌ ์‹ฌ์ธต์ ์œผ๋กœ ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค. ๋ฏธ๋ฆฌ ์ •์˜๋œ **๊ณต๊ฒฉ ์‹œ๊ทธ๋‹ˆ์ฒ˜(Rule)**์™€ ์ผ์น˜ํ•˜๋Š” ํŒจํ„ด์ด ๋ฐœ๊ฒฌ๋˜๋ฉด **ํƒ์ง€(IDS)**ํ•˜๊ฑฐ๋‚˜, ์ธ๋ผ์ธ(Inline) ๋ชจ๋“œ์—์„œ **์ฐจ๋‹จ(IPS)**ํ•ฉ๋‹ˆ๋‹ค. Suricata๋Š” ๋ฉ€ํ‹ฐ ์ฝ”์–ด CPU๋ฅผ ํ™œ์šฉํ•˜์—ฌ Snort๋ณด๋‹ค ๊ณ ์„ฑ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
Mod-
Security
์›น ๋ฐฉํ™”๋ฒฝ
(WAF)
์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ณ„์ธต(Layer 7, HTTP/HTTPS)์˜ ํŠธ๋ž˜ํ”ฝ์„ ์ „๋ฌธ์ ์œผ๋กœ ๋ถ„์„ํ•ฉ๋‹ˆ๋‹ค. SQL Injection, XSS ๋“ฑ ์›น ์ทจ์•ฝ์ ์„ ์•…์šฉํ•œ ๊ณต๊ฒฉ ํŒจํ„ด์„ ํƒ์ง€ํ•˜๊ณ  ์ฐจ๋‹จํ•˜์—ฌ ์›น ์„œ๋ฒ„๋ฅผ ๋ณดํ˜ธํ•ฉ๋‹ˆ๋‹ค. Apache, Nginx ๋“ฑ์˜ ์›น ์„œ๋ฒ„์— ๋ชจ๋“ˆ ํ˜•ํƒœ๋กœ ์„ค์น˜๋˜์–ด ๋™์ž‘ํ•ฉ๋‹ˆ๋‹ค.

2. ๋กœ๊ทธ ์ˆ˜์ง‘, ์ฒ˜๋ฆฌ ๋ฐ ์ €์žฅ ์†”๋ฃจ์…˜

์†”๋ฃจ์…˜ ์ด๋ฆ„ ๋ถ„๋ฅ˜ ํ•ต์‹ฌ ๊ธฐ๋Šฅ ๋ฐ ๋™์ž‘ ๋ฐฉ์‹
syslog ํ”„๋กœํ† ์ฝœ ๋‹ค์–‘ํ•œ ์šด์˜์ฒด์ œ(OS)์™€ ๋„คํŠธ์›Œํฌ ์žฅ๋น„๊ฐ€ ์ด๋ฒคํŠธ ๋กœ๊ทธ๋ฅผ ์ค‘์•™ ์„œ๋ฒ„๋กœ ์ „์†กํ•  ๋•Œ ์‚ฌ์šฉํ•˜๋Š” ํ‘œ์ค€ ํ†ต์‹  ๊ทœ์•ฝ์ž…๋‹ˆ๋‹ค.
Filebeat ๋กœ๊ทธ ์ˆ˜์ง‘๊ธฐ (Shipper) ์ง€์ •๋œ ๋กœ๊ทธ ํŒŒ์ผ(์˜ˆ: Suricata์˜ eve.json, Apache์˜ access.log)์˜ ๋‚ด์šฉ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ, ์‹ค์‹œ๊ฐ„์œผ๋กœ ์ค‘์•™ ์„œ๋ฒ„(Elasticsearch ๋˜๋Š” Logstash)๋กœ ๋ฐ์ดํ„ฐ ์†์‹ค ์—†์ด ์ „์†กํ•˜๋Š” ์—์ด์ „ํŠธ์ž…๋‹ˆ๋‹ค.
Logstash ๋กœ๊ทธ ์ฒ˜๋ฆฌ ์—”์ง„ (Processor) Filebeat๋กœ๋ถ€ํ„ฐ ๋ฐ›์€ ์›๋ณธ ๋กœ๊ทธ ๋ฐ์ดํ„ฐ๋ฅผ ๋ถ„์„ํ•˜๊ธฐ ์‰ฝ๋„๋ก **๊ฐ€๊ณตํ•˜๊ณ  ์ •์ œ(Parse)**ํ•˜๋Š” ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค. ๋ณต์žกํ•œ ํ•„ํ„ฐ๋ง ๋ฐ ๋ฐ์ดํ„ฐ ํ˜•์‹ ๋ณ€ํ™˜(์˜ˆ: ํ…์ŠคํŠธ๋ฅผ JSON ํ•„๋“œ๋กœ ๋ถ„ํ• )์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.
Elastic
search
๋ถ„์‚ฐ ๊ฒ€์ƒ‰ ์—”์ง„ (DB) Logstash/Filebeat๊ฐ€ ๋ณด๋‚ธ ๋Œ€๊ทœ๋ชจ์˜ ๋กœ๊ทธ ๋ฐ์ดํ„ฐ๋ฅผ ๋ถ„์‚ฐ ์ €์žฅํ•˜๊ณ , ๋งค์šฐ ๋น ๋ฅด๊ฒŒ ๊ฒ€์ƒ‰ํ•˜๊ณ  ์ง‘๊ณ„ํ•  ์ˆ˜ ์žˆ๋„๋ก **์ƒ‰์ธ(Indexing)**ํ•ฉ๋‹ˆ๋‹ค. ELK ์Šคํƒ์˜ ํ•ต์‹ฌ ์ €์žฅ์†Œ์ž…๋‹ˆ๋‹ค.
Kibana ์‹œ๊ฐํ™” ๋„๊ตฌ (Visualization) Elasticsearch์— ์ €์žฅ๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๊ฐ€์ ธ์™€ ๊ทธ๋ž˜ํ”„, ์ฐจํŠธ, ๋Œ€์‹œ๋ณด๋“œ ํ˜•ํƒœ๋กœ ๋ณ€ํ™˜ํ•˜์—ฌ ๋ณด์—ฌ์ฃผ๋Š” **์‚ฌ์šฉ์ž ์ธํ„ฐํŽ˜์ด์Šค(UI)**์ž…๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ ๋ถ„์„๊ฐ€๋‚˜ ๋ณด์•ˆ ๋‹ด๋‹น์ž๊ฐ€ ํ˜„ํ™ฉ์„ ์ง๊ด€์ ์œผ๋กœ ํŒŒ์•…ํ•˜๋„๋ก ๋•์Šต๋‹ˆ๋‹ค.
Graylog ํ†ตํ•ฉ ๋กœ๊ทธ ๊ด€๋ฆฌ ์‹œ์Šคํ…œ (LMS) ๋กœ๊ทธ ์ˆ˜์ง‘, ์ €์žฅ(Elasticsearch ๋“ฑ ์‚ฌ์šฉ), ๊ฒ€์ƒ‰, ์‹œ๊ฐํ™” ๊ธฐ๋Šฅ์„ ํ•˜๋‚˜์˜ ํ”Œ๋žซํผ์œผ๋กœ ํ†ตํ•ฉํ•˜์—ฌ ์ œ๊ณตํ•˜๋Š” ์†”๋ฃจ์…˜์ž…๋‹ˆ๋‹ค. ELK ์Šคํƒ๊ณผ ์œ ์‚ฌํ•œ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•˜๋ฉฐ ์ƒํ˜ธ ๋Œ€์ฒด์žฌ๋กœ ์‚ฌ์šฉ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

3. ๋ณด์•ˆ ๋ฐ ์„ฑ๋Šฅ ๋ชจ๋‹ˆํ„ฐ๋ง ํ”Œ๋žซํผ

์†”๋ฃจ์…˜ ์ด๋ฆ„ ๋ถ„๋ฅ˜ ํ•ต์‹ฌ ๊ธฐ๋Šฅ ๋ฐ ๋™์ž‘ ๋ฐฉ์‹
Wazuh ํ†ตํ•ฉ ๋ณด์•ˆ ๊ด€๋ฆฌ
(SIEM/HIDS)
ํ˜ธ์ŠคํŠธ(๊ฐœ๋ณ„ ์„œ๋ฒ„) ๋‚ด๋ถ€์˜ ๋ณด์•ˆ ์ด๋ฒคํŠธ์— ํŠนํ™”๋œ ์†”๋ฃจ์…˜์ž…๋‹ˆ๋‹ค. ์—์ด์ „ํŠธ๊ฐ€ ์„ค์น˜๋œ ์„œ๋ฒ„์˜ OS ๋กœ๊ทธ, ๋ณด์•ˆ ์„ค์ • ์˜ค๋ฅ˜, ํŒŒ์ผ ๋ฌด๊ฒฐ์„ฑ ๋ณ€๊ฒฝ ๋“ฑ์„ ์ˆ˜์ง‘ํ•˜๊ณ , ์ „๋ฌธ์ ์ธ ๋ฃฐ์…‹์„ ์ด์šฉํ•ด ๋ถ„์„ํ•˜์—ฌ ๊ณ ์ˆ˜์ค€์˜ ๋ณด์•ˆ ๊ฒฝ๊ณ ๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.
Zabbix ํ†ตํ•ฉ ์„ฑ๋Šฅ ๋ชจ๋‹ˆํ„ฐ๋ง (APM) ์„œ๋ฒ„, ๋„คํŠธ์›Œํฌ ์žฅ๋น„, ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ **์šด์˜ ์ง€ํ‘œ(Metric)**์ธ CPU ์‚ฌ์šฉ๋ฅ , ๋ฉ”๋ชจ๋ฆฌ, ๋””์Šคํฌ ๊ณต๊ฐ„, ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ ๋“ฑ ์‹œ์Šคํ…œ์˜ ์„ฑ๋Šฅ๊ณผ ๊ฐ€์šฉ์„ฑ์„ ์ค‘์ ์ ์œผ๋กœ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ์žฅ์•  ๋ฐœ์ƒ ์‹œ ์•Œ๋ฆผ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

 

 

 

 

 


 

๐Ÿ›ก๏ธ Securi-Center ํ”„๋กœ์ ํŠธ ์†”๋ฃจ์…˜๋ณ„ ์—ญํ•  ์ •๋ฆฌ

์ด ์‹œ์Šคํ…œ์€ ๊ฒฝ๊ณ„ ๋ฐฉ์–ด, ๋‚ด๋ถ€ ํƒ์ง€ ๋ฐ ์ฐจ๋‹จ, ๊ทธ๋ฆฌ๊ณ  ํ†ตํ•ฉ ๊ด€์ œ์˜ 3๋‹จ๊ณ„ ๋ณด์•ˆ ์ฒด๊ณ„๋ฅผ ๊ตฌ์ถ•ํ•ฉ๋‹ˆ๋‹ค.

1. ๐ŸŒ ๊ฒฝ๊ณ„ ๋ฐฉ์–ด ๋ฐ ์นจ์ž… ์ฐจ๋‹จ (Defense & Prevention)

์ด ์†”๋ฃจ์…˜๋“ค์€ ๊ณต๊ฒฉ ํŠธ๋ž˜ํ”ฝ์ด ์„œ๋ฒ„์— ๋„๋‹ฌํ•˜๊ธฐ ์ „์ด๋‚˜ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์นจํˆฌํ•˜๊ธฐ ์ „์— ์ฐจ๋‹จํ•˜๋Š” ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

์†”๋ฃจ์…˜ ์—ญํ•  ๋ถ„๋ฅ˜ Securi-Center์—์„œ์˜ ๊ตฌ์ฒด์ ์ธ ์—ญํ• 
pfSense ๋„คํŠธ์›Œํฌ ๋ฐฉํ™”๋ฒฝ 1์ฐจ ๋ฐฉ์–ด์„ ์œผ๋กœ์„œ, ๋ณ‘์› ์„œ๋ฒ„๋กœ ๋“ค์–ด์˜ค๋Š” ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ ์ค‘ ํ—ˆ์šฉ๋œ ํฌํŠธ(80, 443 ๋“ฑ) ์™ธ์˜ ํ†ต์‹ ์„ ์ฐจ๋‹จํ•˜๊ณ , ๋Œ€๋Ÿ‰ ์Šค์บ” ์‹œ๋„๋‚˜ DoS ๊ณต๊ฒฉ์„ ๋„คํŠธ์›Œํฌ ๊ณ„์ธต์—์„œ ๊ฑธ๋Ÿฌ๋ƒ…๋‹ˆ๋‹ค.
Suricata ์ฃผ์š” IPS (์ฐจ๋‹จ) ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์„ ์‹ฌ์ธต ๋ถ„์„ํ•˜์—ฌ SQL Injection, Brute Force ๋“ฑ ์•Œ๋ ค์ง„ ๊ณต๊ฒฉ ํŒจํ„ด์„ ๋ฐœ๊ฒฌํ•˜๋ฉด ํ•ด๋‹น ์„ธ์…˜์„ ์ฆ‰์‹œ ์ฐจ๋‹จํ•˜๊ณ , ๋ชจ๋“  ํƒ์ง€ ์ด๋ฒคํŠธ๋ฅผ **eve.json**์— ๊ธฐ๋กํ•ฉ๋‹ˆ๋‹ค.
Snort ๋ณด์กฐ IDS (ํƒ์ง€) Suricata์™€ ๋ณ‘ํ–‰ํ•˜์—ฌ ํŠน์ • ๊ตฌ๊ฐ„์˜ ํŠธ๋ž˜ํ”ฝ์„ ๊ฐ์‹œํ•˜๋ฉฐ, ๊ณต๊ฒฉ ํŒจํ„ด์„ ํƒ์ง€ํ•˜๊ณ  ๋กœ๊ทธ๋ฅผ ๊ธฐ๋กํ•ฉ๋‹ˆ๋‹ค. Suricata์˜ ์„ฑ๋Šฅ ๋ถ€ํ•˜๋ฅผ ๋ถ„์‚ฐ์‹œํ‚ค๊ฑฐ๋‚˜, ๋‹ค๋ฅธ ๋ฃฐ์…‹์„ ์ ์šฉํ•˜์—ฌ ํƒ์ง€ ๋ฒ”์œ„๋ฅผ ํ™•์žฅํ•ฉ๋‹ˆ๋‹ค.
Mod
Security
์›น ๋ฐฉํ™”๋ฒฝ (WAF) Apache ์›น ์„œ๋ฒ„์— ๋ชจ๋“ˆ ํ˜•ํƒœ๋กœ ์„ค์น˜๋˜์–ด, ์ง„๋ฃŒ ์˜ˆ์•ฝ ํŽ˜์ด์ง€ ๋“ฑ์œผ๋กœ ๋“ค์–ด์˜ค๋Š” HTTP ์š”์ฒญ์˜ ํŒŒ๋ผ๋ฏธํ„ฐ์™€ ๋ณธ๋ฌธ์„ ๋ถ„์„ํ•˜์—ฌ **์›น ์ทจ์•ฝ์  ๊ณต๊ฒฉ(SQLi, XSS)**์„ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค.

2. ๐Ÿ“Š ๋ฐ์ดํ„ฐ ์ˆ˜์ง‘ ๋ฐ ์ฒ˜๋ฆฌ (Data Pipeline)

์ด ์†”๋ฃจ์…˜๋“ค์€ ๋ฐฉ์–ด ์‹œ์Šคํ…œ์ด ์ƒ์„ฑํ•œ ๋กœ๊ทธ์™€ ์‹œ์Šคํ…œ ์ด๋ฒคํŠธ๋ฅผ ๋ถ„์„ ๊ฐ€๋Šฅํ•œ ํ˜•ํƒœ๋กœ ๊ฐ€๊ณตํ•˜์—ฌ ์ค‘์•™ ์ €์žฅ์†Œ๋กœ ์ „๋‹ฌํ•˜๋Š” ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค.

์†”๋ฃจ์…˜ ์—ญํ•  ๋ถ„๋ฅ˜ Securi-Center์—์„œ์˜ ๊ตฌ์ฒด์ ์ธ ์—ญํ• 
Filebeat ๋กœ๊ทธ ์ˆ˜์ง‘/์ „๋‹ฌ ์—์ด์ „ํŠธ ์›น ์„œ๋ฒ„์—์„œ ์ƒ์„ฑ๋œ Apache ์—๋Ÿฌ ๋กœ๊ทธ(PHP Fatal Error ํฌํ•จ), Suricata์˜ eve.json, ModSecurity์˜ ๊ฐ์‚ฌ ๋กœ๊ทธ(Audit Log) ๋“ฑ์„ ์ฝ์–ด ์†์‹ค ์—†์ด ๋‹ค์Œ ๋‹จ๊ณ„(Logstash ๋˜๋Š” Wazuh)๋กœ ์ „์†กํ•ฉ๋‹ˆ๋‹ค.
Logstash ๋กœ๊ทธ ์ฒ˜๋ฆฌ/์ •์ œ ์—”์ง„ Filebeat๋กœ๋ถ€ํ„ฐ ๋ฐ›์€ ์›๋ณธ ๋กœ๊ทธ ๋ฐ์ดํ„ฐ๋ฅผ ๊ตฌ์กฐํ™”ํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ์›น ๋กœ๊ทธ ํ…์ŠคํŠธ ๋ผ์ธ์„ IP, ํƒ€์ž„์Šคํƒฌํ”„, ์‚ฌ์šฉ์ž ID, URL ๋“ฑ ๊ฐœ๋ณ„ ํ•„๋“œ๋กœ **๋ถ„๋ฆฌ(Parsing)**ํ•˜์—ฌ Elasticsearch๊ฐ€ ํšจ์œจ์ ์œผ๋กœ ๊ฒ€์ƒ‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ๋ฐ์ดํ„ฐ ํ˜•์‹์„ ํ†ต์ผํ•ฉ๋‹ˆ๋‹ค.

3. ๐Ÿ›ก๏ธ ๋ณด์•ˆ ๋ถ„์„ ๋ฐ ํ†ตํ•ฉ ๊ด€์ œ (SIEM & Monitoring)

์ด ์†”๋ฃจ์…˜๋“ค์€ ๊ฐ€๊ณต๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ถ„์„ํ•˜๊ณ , IT ์šด์˜ ์ƒํƒœ์™€ ๋ณด์•ˆ ์œ„ํ˜‘์„ ์‹œ๊ฐํ™”ํ•˜์—ฌ ๋ณด์•ˆํŒ€์˜ ์‹ ์†ํ•œ ๋Œ€์‘์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

์†”๋ฃจ์…˜ ์—ญํ•  ๋ถ„๋ฅ˜ Securi-Center์—์„œ์˜ ๊ตฌ์ฒด์ ์ธ ์—ญํ• 
Wazuh ๋ณด์•ˆ ๊ด€์ œ ์—”์ง„ ๋กœ๊ทธ ๊ธฐ๋ฐ˜ ๋ถ„์„ ์™ธ์—๋„, ์„œ๋ฒ„ ๋‚ด๋ถ€์˜ ํŒŒ์ผ ๋ฌด๊ฒฐ์„ฑ ๋ณ€๊ฒฝ ํƒ์ง€ ๋ฐ ์‹œ์Šคํ…œ ์„ค์ • ์˜ค๋ฅ˜ ๋“ฑ์„ ๊ฐ์‹œํ•ฉ๋‹ˆ๋‹ค. ํŠนํžˆ, ์—ฐ์†์ ์ธ ๋กœ๊ทธ์ธ ์‹คํŒจ๋‚˜ ๋‹ค๋ฅธ IP์—์„œ์˜ ๋™์ผํ•œ DB ์˜ค๋ฅ˜ ๋ฐ˜๋ณต๊ณผ ๊ฐ™์€ ์ƒ๊ด€๊ด€๊ณ„ ๋ถ„์„์„ ์ˆ˜ํ–‰ํ•˜์—ฌ **๊ณ ์ˆ˜์ค€์˜ ๋ณด์•ˆ ๊ฒฝ๊ณ (Alert)**๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.
Elasticsearch ์ค‘์•™ ๋ฐ์ดํ„ฐ ์ €์žฅ์†Œ Logstash์™€ Wazuh์—์„œ ์ฒ˜๋ฆฌ๋œ ๋ชจ๋“  ๋กœ๊ทธ์™€ ๋ณด์•ˆ ๊ฒฝ๊ณ  ๋ฐ์ดํ„ฐ๋ฅผ ๋Œ€๊ทœ๋ชจ๋กœ ์ €์žฅํ•˜๊ณ  ์ƒ‰์ธํ•ฉ๋‹ˆ๋‹ค. ๋ณด์•ˆ ๋‹ด๋‹น์ž๊ฐ€ ์ˆ˜๋ฐฑ๋งŒ ๊ฑด์˜ ์ด๋ฒคํŠธ๋ฅผ ์ˆ˜ ์ดˆ ๋‚ด์— ๊ฒ€์ƒ‰ํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋ฐ˜์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
Kibana ํ†ตํ•ฉ ์ƒํ™ฉํŒ/์‹œ๊ฐํ™” Elasticsearch์˜ ๋ฐ์ดํ„ฐ๋ฅผ ํ™œ์šฉํ•˜์—ฌ ์‹ค์‹œ๊ฐ„ ๋Œ€์‹œ๋ณด๋“œ๋ฅผ ๊ตฌํ˜„ํ•ฉ๋‹ˆ๋‹ค. Wazuh ๊ฒฝ๊ณ  ๋ฐœ์ƒ๋ฅ , ๊ณต๊ฒฉ ์œ ํ˜•๋ณ„ ๋ถ„ํฌ, ์„œ๋ฒ„ ์„ฑ๋Šฅ ๋“ฑ์˜ ์ง€ํ‘œ๋ฅผ ์‹œ๊ฐํ™”ํ•˜์—ฌ ๋ณด์•ˆํŒ€์˜ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ๋ถ„์„์„ ๋•์Šต๋‹ˆ๋‹ค.
Zabbix ์„ฑ๋Šฅ ๋ฐ ๊ฑด๊ฐ• ๋ชจ๋‹ˆํ„ฐ๋ง ์„œ๋ฒ„์˜ CPU, ๋ฉ”๋ชจ๋ฆฌ, ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ ๋“ฑ ์„ฑ๋Šฅ ์ง€ํ‘œ๋ฅผ ๊ฐ์‹œํ•ฉ๋‹ˆ๋‹ค. ๋ชจ์˜ ํ•ดํ‚น ๊ณต๊ฒฉ ์‹œ ์„œ๋ฒ„์˜ ๋ฆฌ์†Œ์Šค ์‚ฌ์šฉ๋Ÿ‰์ด ๊ธ‰์ฆํ•˜๋Š” ๊ฒฝ์šฐ๋ฅผ ํƒ์ง€ํ•˜์—ฌ, ๋ณด์•ˆ ์ด์Šˆ์™€ ๋ณ„๊ฐœ๋กœ ์šด์˜ ์žฅ์•  ๊ฐ€๋Šฅ์„ฑ์„ ์กฐ๊ธฐ์— ์•Œ๋ฆฝ๋‹ˆ๋‹ค.