Untitled Document

   FIREWALL/IPS/VPN
  

 
   
   (ÁÖ)¼¾Å¸ºñÀü RAPTUS¢çIPS ħÀÔ¹æÁö½Ã½ºÅÛ
  ±Û¾´ÀÌ : SIC)Á¤³²Áø     ³¯Â¥ : 07-03-06 17:34     Á¶È¸ : 4596    

 
 
 
·¦ÅÍ Ä§ÀÔ¹æÁö½Ã½ºÅÛ(RAPTUS ¢ç Intrusion Prevention System)Àº ³×Æ®¿öÅ© »óÀÇ ¿ú,¾Ç¼ºÄÚµå,ÇØÅ· µî¿¡ ´ëÇÑ À¯ÇØÆ®·¡ÇÈÀ» Â÷´ÜÇÏ°í, ¿î¿µÃ¼Á¦ ¹× ¾ÖÇø®ÄÉÀ̼ÇÀÇ Ãë¾àÁ¡À» »çÀü¿¡ º¸¿ÏÇϸç ƯÈ÷ ºñÁ¤»óÀûÀÎ(Anomaly) Æ®·¡ÇÈÀ̳ª ¾Ë·ÁÁöÁö ¾ÊÀº °ø°Ý±îÁö ´Éµ¿ÀûÀ¸·Î Â÷´ÜÇÒ ¼ö ÀÖµµ·Ï ¼³°èµÈ ¡°½º½º·Î ŽÁöÇÏ°í ½º½º·Î ÅëÁ¦¡±ÇÏ´Â Â÷¼¼´ë ÅëÇÕº¸¾È ½Ã½ºÅÛÀÔ´Ï´Ù. ¶ÇÇÑ, ¹æÈ­º®À» Åë°úÇÑ Çã¿ë Æ®·¡ÇÈÀÇ °ø°Ý½Ãµµ ¹× À¯ÇØ Æ®·¡ÇÈÀÇ À¯ÀÔ, ³»ºÎ·Î ºÎÅÍ ¹ß»ýÇÑ °¢Á¾ À¯ÇØ Æ®·¡ÇÈÀÇ È®»êÀ» Ä¿³Î±â¹Ý Çϵå¿þ¾î ·ÎÁ÷¿¡¼­ ½Ç½Ã°£ ó¸® ÇÔÀ¸·Î½á °í¼ÓÀÇ ¾²·çDzÀ» À¯ÁöÇϸç, ¾îÇø®ÄÉÀÌ¼Ç °èÃþÀÇ ÄÜÅÙÃ÷ ¹× ÇÁ·ÎÅäÄÝ DPI(Deep Packet Inspection)°¨½Ã´Â ºÎÀûÀýÇÑ Æ®·¡ÇÈÀÇ ÀÏ°ü¼º ÀÖ´Â Â÷´Ü°ú ÇÔ²² ´ë¿ªÆøÀ» ÀûÀýÈ÷ Á¶Á¤ÇÒ ¼ö ÀÖ´Â ¸ÖƼ¹æ¾î ±â´ÉÀ» ¼öÇàÇÕ´Ï´Ù.

 
±¸¼º ȯ°æ ¹× ½Ã½ºÅÛ Á¤º¸
  -. ³×Æ®¿÷ ±â¹Ý Çϵå¿þ¾î ÀÏüÇüÀ¸·Î ÀζóÀÎ ¹æ½Ä ¿î¿µ
       

  -. ¸ÖƼ ±â°¡ºñÆ® ȯ°æÀ» À§ÇÑ ³×Æ®¿öÅ© ÇÁ·Î¼¼¼­(NP) ±â¹Ý ÇÁ·Î¼¼½º ·Îµå¹ß¶õ½Ì

  - ¼ÒÇÁÆ®¿þ¾îÀû °áÇÔ, Àü¿ø ÀÌ»ó(Çϵå¿þ¾î °áÇÔ)½Ã LAN Bypass ±â´ÉÀ¸·Î ³×Æ®¿öÅ© ½Å·Ú¼º À¯Áö
 

ICS Technology
  
- Simple analyzer¿Í Complex analyzer ·Î ±¸¼ºµÈ ´Ù´Ü°è ŽÁø¿£ÁøÀº ¿ÀŽÀ²À»
    ¿¹¹æÇϸç, º¯ Çü °ø°ÝÀ̳ª ¿À¿ë°ø°Ý µîÀÇ ½Ç½Ã°£ Â÷´Ü¹æ¾î
  - ÀλçÀ̵å Ä¿³Î ¾ÆÅ°ÅØó¿¡ µû¸¥ µ¶Ã¢ÀûÀÎ ½Ì±Û ij½Ã ¾ÆÅ°ÅØÃÄ(Session Map and Detection
    Map in kernel) ±¸ÇöÀ¸·Î ¼º´É Çâ»ó°ú ³·Àº Áö¿¬¼Óµµ º¸Áõ
  - ½Ç½Ã°£ ħÀÔ°ø°Ý ŽÁö ÈÄ Áï°¢ÀûÀÎ ÅëÁ¦(Self Detection and Self Control)
  - ±ÔÄ¢±â¹ÝÀÇ Å½Áö ¹× ÅëÁ¦ Á¤Ã¥(Rule-based detection and control policy)
  

ÆÐÅÏ°ü¸® ¹× ¾÷µ¥ÀÌÆ®
  - Á¤ÇüÈ­µÈ ŽÁö±ÔÄ¢(Well-formed RIVA-Signature) À¸·Î ¿ÀŽÀ²(False positive)À» ÃÖ¼ÒÈ­Çϸç
    ÆÐÅÏÀÇ ±¹Á¦ Ç¥ÁØ Áؼö·Î ½Å·Ú¼º È®º¸ ** RIVA : Raptus Incident Vulnerabilities Advisory
  - °ø°ÝÆÐÅÏ ¹× Ãë¾à¼º DB(Vulnerability)¿¡ ´ëÇÑ »ó¼¼ÇÑ ÇÑ±Û µµ¿ò¸» ³»Àå




À¯ÇØ(Anomaly) Æ®·¡ÇÈ Á¦¾î ¹× Á¤±ÔÈ­(Normalization)
  - ´Ù¾çÇÑ °ø°ÝÀ¯Çü (Special°ø°Ý, Á¤º¸¼öÁý°ø°Ý, Ãë¾à¼º°ø°Ý, ÄÁÅÙÃ÷°ø°Ý, ¼­ºñ½º°ÅºÎ°ø°Ý,
    ¹éµµ¾î °ø°Ý,»ç¿ëÀÚ Á¤ÀÇ µî)¿¡ ´ëÇÑ ½Ç½Ã°£ Â÷´Ü¹æ¾î
  - °ø°Ý ¼¼¼Ç¿¡ ´ëÇÑ ¾îÇø®ÄÉÀÌ¼Ç °èÃþ ÆÐŶ¼öÁØ Å½Áö ¹× Â÷´Ü¹æ¾î
  - Á¤»ó ¹× ºñÁ¤»ó Æ®·¡ÇÈ¿¡ ´ëÇÑ zero-Day °ø°Ý¹æ¾î(Traffic and Protocol anomaly Detection)
  - ºñ¾÷¹«(P2P ¹× ¸Þ½Ã¡) Æ®·¡ÇÈ¿¡ ´ëÇÑ ÀûÀýÇÑ °ü¸®
  - ¾Ç¼ºÆ®·¡ÇÈÀ̳ª ºñÀΰ¡ Æ®·¡ÇÈÀ» Àû±ØÀûÀ¸·Î Â÷´ÜÇϸ鼭 Àΰ¡ Æ®·¡ÇÈ º¸È£


¸ð´ÏÅ͸µ ¹× ºÐ¼®
  - ½Ç½Ã°£ ½Ã½ºÅÛ ºÎÇÏ·®, ½Ç½Ã°£ ÅëÁ¦Á¤º¸, ½Ç½Ã°£ ¼¼¼ÇÁ¤º¸ ¸ð´ÏÅ͸µ
  - °ø°ÝÀ¯Çü, °ø°Ý IP, ¼­ºñ½º, Æ÷Æ®µîÀÇ °ø°ÝÇöȲÀ» ½Ç½Ã°£À¸·Î È®ÀÎ, ÀúÀå ¹× °Ë»ö


Åë°è ¹× º¸°í¼­
  - ½ºÄÉÁÙ¸µ ¸®Æ÷ÆÃ, Á¶°Ç°Ë»ö¿¡ ÀÇÇÑ ¸®Æ÷ÆÃ, ±×·ìº° ¸®Æ÷Æà µî ´Ù¾çÇÑ Åë°è º¸°í¼­ Áö¿ø
  - ½Ã°£,ÀÏ°£,ÁÖ°£,¿ù°£, °ø°ÝÀ¯Çü, ¼Ò½ºIP, ¼Ò½ºÆ÷Æ®, °ø°Ý´ë»ó IP, °ø°Ý´ë»óÆ÷Æ®,
    Å½Áö±â°£º° »ó¼¼ ¸®Æ÷Æà °¡´É



½Ã½ºÅÛ °ü¸®
  - IP °ø°ÝÀ̳ª ³»ºÎ ARP(MAC Address)°ø°ÝÀ¸·Î ºÎÅÍ ½Ã½ºÅÛ ÀÚü ¹æ¾î¸¦ À§ÇÑ
    ½ºÅÚ½º(Stealth) º¸È£±â´É
  - À̺¥Æ® ¹ß»ý½Ã ÀÚµ¿ ÅëÁö (¾Ë¶÷,e-mail,´Â, syslog, SNMP) ±â´É
  - SSLÀ» ÀÌ¿ëÇÑ ¾ÈÀüÇÑ ¿ø°Ý Á¦¾î °ü¸®(SSH,HTTPS)
  - ³»ÀåµÈ À¥ºê¶ó¿ìÀú¸¦ ÅëÇÑ ¿ø°Ý Á¦¾î °ü¸®


 
ISP. ¿£ÅÍÇÁ¶óÀÌÁî ½Ã¸®Áî
¸ðµ¨¸í RT6500 RT6000 RT5000
 


 ¼º´É
Max. Throughput 5Gbps 5Gbps 4Gbps
Max. Concurrent Session 3,000,000+ 2,000,000+ 2,000,000
 ÀÎÅÍÆäÀ̽º
Processor 1 NPC,1 APC 1 NPC Dual Xeon 3.6GHz
Network Interface 4 100/1000 + 1 Fiber GE
4 Fiber GE
4 100/1000 + 1 Fiber GE
4 Fiber GE
4 100/1000 GE
6 Fiber GE
Power Supply 460W 1+1 Redundant 460W 1+1 Redundant 500W 1+1 Redundant
(1) NPC : Network Processor Card / (2) APC : Application Processor Card
 
Áß,´ëÇü ½Ã¸®Áî
¸ðµ¨¸í RT5000E RT4500 RT4000
 


 ¼º´É
Max. Throughput 2Gbps 2Gbps 1.2Gbps
Max. Concurrent Session 1,800,000 1,800,000 1,500,000
 ÀÎÅÍÆäÀ̽º
Processor Dual Xeon 3.6GHz Dual Xeon 2.8GHz Dual Xeon 2.4GHz
Network Interface 4 100/1000 GE
4 Fiber GE
2 100/1000 GE
4 Fiber GE
2 100/1000 GE
2 Fiber GE
Power Supply 500W 1+1 Redundant 350W 1+1 Redundant 350W Full range ATX
 
¼ÒÇü½Ã¸®Áî
¸ðµ¨¸í RT2000 RT2000E RT2000S
 


 ¼º´É
Max. Throughput 400Mbps 200Mbps 100Mbps
Max. Concurrent Session 1,400,000 1,200,000 1,200,000
 ÀÎÅÍÆäÀ̽º
Processor Pentium IV 2.8GHz Pentium IV 2.4GHz Pentium C 2.0GHz
Network Interface 2 100/1000 GE
2 10/100 FE
4 10/100 FE 4 10/100 FE
Power Supply 250W Full range ATX 220W Full range ATX 220W Full range ATX