AWS Network Firewall ๋กœ๊ทธ ์ˆ˜์ง‘

๋‹ค์Œ์—์„œ ์ง€์›:

์ด ๋ฌธ์„œ์—์„œ๋Š” AWS Network Firewall ๋กœ๊ทธ๋ฅผ Google Security Operations์— ์ˆ˜์ง‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. AWS Network Firewall์€ ์•…์„ฑ ํŠธ๋ž˜ํ”ฝ์œผ๋กœ๋ถ€ํ„ฐ VPC๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๊ด€๋ฆฌํ˜• ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. ๋„คํŠธ์›Œํฌ ๋ฐฉํ™”๋ฒฝ ๋กœ๊ทธ๋ฅผ Google SecOps๋กœ ์ „์†กํ•˜๋ฉด ๋ชจ๋‹ˆํ„ฐ๋ง, ๋ถ„์„, ์œ„ํ˜‘ ๊ฐ์ง€๋ฅผ ๊ฐœ์„ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

๋‹ค์Œ ๊ธฐ๋ณธ ์š”๊ฑด์ด ์ถฉ์กฑ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

  • Google SecOps ์ธ์Šคํ„ด์Šค
  • AWS์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ

AWS ๋„คํŠธ์›Œํฌ ๋ฐฉํ™”๋ฒฝ์˜ ๋กœ๊น…์„ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•

  1. AWS ๊ด€๋ฆฌ ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. Amazon VPC ์ฝ˜์†”์„ ์—ฝ๋‹ˆ๋‹ค.
  3. ํƒ์ƒ‰ ์ฐฝ์—์„œ ๋ฐฉํ™”๋ฒฝ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  4. ์ˆ˜์ •ํ•  ๋ฐฉํ™”๋ฒฝ์˜ ์ด๋ฆ„์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  5. ๋ฐฉํ™”๋ฒฝ ์„ธ๋ถ€์ •๋ณด ํƒญ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  6. ๋กœ๊น… ์„น์…˜์—์„œ ์ˆ˜์ •์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  7. ํ๋ฆ„, ์•Œ๋ฆผ, TLS ๋กœ๊ทธ ์œ ํ˜•์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  8. ์„ ํƒํ•œ ๊ฐ ๋กœ๊ทธ ์œ ํ˜•์— ๋Œ€ํ•ด ๋Œ€์ƒ ์œ ํ˜•์œผ๋กœ S3๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

  9. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

ํ”ผ๋“œ ์„ค์ •

Google SecOps ํ”Œ๋žซํผ์—์„œ ํ”ผ๋“œ๋ฅผ ์„ค์ •ํ•˜๋Š” ๋ฐฉ๋ฒ•์€ ๋‘ ๊ฐ€์ง€์ž…๋‹ˆ๋‹ค.

  • SIEM ์„ค์ • > ํ”ผ๋“œ > ์ƒˆ๋กœ ์ถ”๊ฐ€
  • ์ฝ˜ํ…์ธ  ํ—ˆ๋ธŒ > ์ฝ˜ํ…์ธ  ํŒฉ > ์‹œ์ž‘ํ•˜๊ธฐ

AWS Network Firewall ํ”ผ๋“œ๋ฅผ ์„ค์ •ํ•˜๋Š” ๋ฐฉ๋ฒ•

  1. Amazon Cloud Platform ํŒฉ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  2. AWS Network Firewall ๋กœ๊ทธ ์œ ํ˜•์„ ์ฐพ์Šต๋‹ˆ๋‹ค.
  3. ๋‹ค์Œ ํ•„๋“œ์— ๊ฐ’์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

    • ์†Œ์Šค ์œ ํ˜•: Amazon SQS V2
    • Queue Name: ์ฝ์–ด์˜ฌ SQS ํ ์ด๋ฆ„
    • S3 URI: ๋ฒ„ํ‚ท URI์ž…๋‹ˆ๋‹ค.
      • s3://your-log-bucket-name/
        • your-log-bucket-name์„ ์‹ค์ œ S3 ๋ฒ„ํ‚ท ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • ์†Œ์Šค ์‚ญ์ œ ์˜ต์…˜: ์ˆ˜์ง‘ ํ™˜๊ฒฝ์„ค์ •์— ๋”ฐ๋ผ ์‚ญ์ œ ์˜ต์…˜์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

    • ์ตœ๋Œ€ ํŒŒ์ผ ๊ธฐ๊ฐ„: ์ง€๋‚œ ์ผ์ˆ˜ ๋™์•ˆ ์ˆ˜์ •๋œ ํŒŒ์ผ์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค. ๊ธฐ๋ณธ๊ฐ’์€ 180์ผ์ž…๋‹ˆ๋‹ค.

    • SQS ๋Œ€๊ธฐ์—ด ์•ก์„ธ์Šค ํ‚ค ID: 20์ž๋ฆฌ ์˜์ˆซ์ž ๋ฌธ์ž์—ด์ธ ๊ณ„์ • ์•ก์„ธ์Šค ํ‚ค์ž…๋‹ˆ๋‹ค.

    • SQS ๋Œ€๊ธฐ์—ด ๋ณด์•ˆ ๋น„๋ฐ€ ์•ก์„ธ์Šค ํ‚ค: 40์ž๋กœ ๋œ ์˜์ˆซ์ž ๋ฌธ์ž์—ด์ธ ๊ณ„์ • ์•ก์„ธ์Šค ํ‚ค์ž…๋‹ˆ๋‹ค.

    ๊ณ ๊ธ‰ ์˜ต์…˜

    • ํ”ผ๋“œ ์ด๋ฆ„: ํ”ผ๋“œ๋ฅผ ์‹๋ณ„ํ•˜๋Š” ๋ฏธ๋ฆฌ ์ฑ„์›Œ์ง„ ๊ฐ’์ž…๋‹ˆ๋‹ค.
    • ์• ์…‹ ๋„ค์ž„์ŠคํŽ˜์ด์Šค: ํ”ผ๋“œ์™€ ์—ฐ๊ฒฐ๋œ ๋„ค์ž„์ŠคํŽ˜์ด์Šค์ž…๋‹ˆ๋‹ค.
    • ์ˆ˜์ง‘ ๋ผ๋ฒจ: ์ด ํ”ผ๋“œ์˜ ๋ชจ๋“  ์ด๋ฒคํŠธ์— ์ ์šฉ๋˜๋Š” ๋ผ๋ฒจ์ž…๋‹ˆ๋‹ค.
  4. ํ”ผ๋“œ ๋งŒ๋“ค๊ธฐ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

์ด ์ œํ’ˆ๊ตฐ ๋‚ด์—์„œ ๋‹ค์–‘ํ•œ ๋กœ๊ทธ ์œ ํ˜•์— ๋Œ€ํ•ด ์—ฌ๋Ÿฌ ํ”ผ๋“œ๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๊ด€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ œํ’ˆ๋ณ„ ํ”ผ๋“œ ๊ตฌ์„ฑ์„ ์ฐธ๊ณ ํ•˜์„ธ์š”.

UDM ๋งคํ•‘ ํ…Œ์ด๋ธ”

๋กœ๊ทธ ํ•„๋“œ UDM ๋งคํ•‘ ๋…ผ๋ฆฌ
availability_zone target.resource.attribute.cloud.availability_zone availability_zone ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
event.app_proto network.application_protocol event.app_proto ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๋ฉฐ, ์ง€์ •๋œ ๊ฐ’ (ikev2, tftp, failed, snmp, tls, ftp) ์ค‘ ํ•˜๋‚˜๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ ๋Œ€๋ฌธ์ž๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค. HTTP2๊ฐ€ HTTP๋กœ ๋Œ€์ฒด๋ฉ๋‹ˆ๋‹ค.
event.dest_ip target.ip event.dest_ip ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
event.dest_port target.port event.dest_port ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๋ฉฐ ์ •์ˆ˜๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.event_type additional.fields[event_type_label].key ํ‚ค๋Š” 'event_type'์œผ๋กœ ํ•˜๋“œ ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.
event.event_type additional.fields[event_type_label].value.string_value event.event_type ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
event.flow_id network.session_id event.flow_id ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๊ณ  ๋ฌธ์ž์—ด๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.netflow.age additional.fields[netflow_age_label].key ํ‚ค๋Š” 'netflow_age'๋กœ ํ•˜๋“œ ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.
event.netflow.age additional.fields[netflow_age_label].value.string_value event.netflow.age ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๊ณ  ๋ฌธ์ž์—ด๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.netflow.bytes network.sent_bytes event.netflow.bytes ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๋ฉฐ ๋ถ€ํ˜ธ ์—†๋Š” ์ •์ˆ˜๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.netflow.end additional.fields[netflow_end_label].key ํ‚ค๋Š” 'netflow_end'๋กœ ํ•˜๋“œ ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.
event.netflow.end additional.fields[netflow_end_label].value.string_value event.netflow.end ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
event.netflow.max_ttl additional.fields[netflow_max_ttl_label].key ํ‚ค๋Š” 'netflow_max_ttl'๋กœ ํ•˜๋“œ ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.
event.netflow.max_ttl additional.fields[netflow_max_ttl_label].value.string_value event.netflow.max_ttl ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๊ณ  ๋ฌธ์ž์—ด๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.netflow.min_ttl additional.fields[netflow_min_ttl_label].key ํ‚ค๋Š” 'netflow_min_ttl'๋กœ ํ•˜๋“œ ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.
event.netflow.min_ttl additional.fields[netflow_min_ttl_label].value.string_value event.netflow.min_ttl ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๊ณ  ๋ฌธ์ž์—ด๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.netflow.pkts network.sent_packets event.netflow.pkts ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๋ฉฐ ์ •์ˆ˜๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.netflow.start additional.fields[netflow_start_label].key ํ‚ค๋Š” 'netflow_start'๋กœ ํ•˜๋“œ ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.
event.netflow.start additional.fields[netflow_start_label].value.string_value event.netflow.start ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
event.proto network.ip_protocol event.proto ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. ๊ฐ’์ด 'IPv6-ICMP'์ด๋ฉด 'ICMP'๋กœ ๋Œ€์ฒด๋ฉ๋‹ˆ๋‹ค.
event.src_ip principal.ip event.src_ip ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
event.src_port principal.port event.src_port ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๋ฉฐ ์ •์ˆ˜๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.tcp.syn additional.fields[syn_label].key ํ‚ค๋Š” 'syn'์œผ๋กœ ํ•˜๋“œ ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.
event.tcp.syn additional.fields[syn_label].value.string_value event.tcp.syn ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๊ณ  ๋ฌธ์ž์—ด๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
event.tcp.tcp_flags additional.fields[tcp_flags_label].key ํ‚ค๋Š” 'tcp_flags'๋กœ ํ•˜๋“œ ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.
event.tcp.tcp_flags additional.fields[tcp_flags_label].value.string_value event.tcp.tcp_flags ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
event_timestamp metadata.event_timestamp.seconds event_timestamp ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๋ฉฐ ํƒ€์ž„์Šคํƒฌํ”„๋กœ ํŒŒ์‹ฑ๋ฉ๋‹ˆ๋‹ค.
event_timestamp timestamp.seconds event_timestamp ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋˜๋ฉฐ ํƒ€์ž„์Šคํƒฌํ”„๋กœ ํŒŒ์‹ฑ๋ฉ๋‹ˆ๋‹ค.
firewall_name metadata.product_event_type firewall_name ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. event.src_ip๊ณผ event.dest_ip์ด ๋ชจ๋‘ ์žˆ๋Š” ๊ฒฝ์šฐ 'NETWORK_CONNECTION'์œผ๋กœ ์„ค์ •ํ•˜๊ณ , ๊ทธ๋ ‡์ง€ ์•Š์€ ๊ฒฝ์šฐ 'GENERIC_EVENT'๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. 'AWS Network Firewall'๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค. 'AWS'๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค.

๋„์›€์ด ๋” ํ•„์š”ํ•˜์‹ ๊ฐ€์š”? ์ปค๋ฎค๋‹ˆํ‹ฐ ํšŒ์› ๋ฐ Google SecOps ์ „๋ฌธ๊ฐ€๋กœ๋ถ€ํ„ฐ ๋‹ต๋ณ€์„ ๋ฐ›์œผ์„ธ์š”.