Cisco ๋ฌด์„  ์นจ์ž… ๋ฐฉ์ง€ ์‹œ์Šคํ…œ (WIPS) ๋กœ๊ทธ ์ˆ˜์ง‘

๋‹ค์Œ์—์„œ ์ง€์›:

์ด ๋ฌธ์„œ์—์„œ๋Š” Bindplane์„ ์‚ฌ์šฉํ•˜์—ฌ Cisco ๋ฌด์„  ์นจ์ž… ๋ฐฉ์ง€ ์‹œ์Šคํ…œ (WIPS) ๋กœ๊ทธ๋ฅผ Google Security Operations์— ์ˆ˜์ง‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. ํŒŒ์„œ๋Š” syslog ๋ฉ”์‹œ์ง€์—์„œ ํ‚ค-๊ฐ’ ์Œ์„ ์ถ”์ถœํ•œ ๋‹ค์Œ ์ด๋Ÿฌํ•œ ๊ฐ’์„ ํ†ตํ•ฉ ๋ฐ์ดํ„ฐ ๋ชจ๋ธ (UDM) ํ•„๋“œ์— ๋งคํ•‘ํ•ฉ๋‹ˆ๋‹ค. ์ฃผ ๊ตฌ์„ฑ์›, ํƒ€๊ฒŸ, ์‚ฌ์šฉ์ž ์ •๋ณด์˜ ์กด์žฌ ์—ฌ๋ถ€์— ๋”ฐ๋ผ ์ ์ ˆํ•œ event_type๋ฅผ ๊ฒฐ์ •ํ•˜๊ณ  eventType ๋ฐ ๊ธฐํƒ€ ํ•„๋“œ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๋ณด์•ˆ ์ด๋ฒคํŠธ๋ฅผ ๋ถ„๋ฅ˜ํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

๋‹ค์Œ ๊ธฐ๋ณธ ์š”๊ฑด์ด ์ถฉ์กฑ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

  • Google SecOps ์ธ์Šคํ„ด์Šค
  • Windows 2016 ์ด์ƒ ๋˜๋Š” systemd๊ฐ€ ์„ค์น˜๋œ Linux ํ˜ธ์ŠคํŠธ
  • ํ”„๋ก์‹œ ๋’ค์—์„œ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ ๋ฐฉํ™”๋ฒฝ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ๋Š”์ง€ ํ™•์ธ
  • Cisco ์•ก์„ธ์Šค ํฌ์ธํŠธ (AP) / ๋ฌด์„  LAN ์ปจํŠธ๋กค๋Ÿฌ (WLC)์— ๋Œ€ํ•œ ๊ถŒํ•œ ์žˆ๋Š” ์•ก์„ธ์Šค

Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ์ˆ˜์ง‘ ์—์ด์ „ํŠธ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.
    • BindPlane์ด ์„ค์น˜๋  ์‹œ์Šคํ…œ์— ํŒŒ์ผ์„ ์•ˆ์ „ํ•˜๊ฒŒ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ๊ณ ๊ฐ ID ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ํ”„๋กœํ•„๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์กฐ์ง ์„ธ๋ถ€์ •๋ณด ์„น์…˜์—์„œ ๊ณ ๊ฐ ID๋ฅผ ๋ณต์‚ฌํ•˜์—ฌ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ ์„ค์น˜

๋‹ค์Œ ์•ˆ๋‚ด์— ๋”ฐ๋ผ Windows ๋˜๋Š” Linux ์šด์˜์ฒด์ œ์— Bindplane ์—์ด์ „ํŠธ๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

Windows ์„ค์น˜

  1. ๋ช…๋ น ํ”„๋กฌํ”„ํŠธ ๋˜๋Š” PowerShell์„ ๊ด€๋ฆฌ์ž๋กœ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    

Linux ์„ค์น˜

  1. ๋ฃจํŠธ ๋˜๋Š” sudo ๊ถŒํ•œ์œผ๋กœ ํ„ฐ๋ฏธ๋„์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    

์ถ”๊ฐ€ ์„ค์น˜ ๋ฆฌ์†Œ์Šค

์ถ”๊ฐ€ ์„ค์น˜ ์˜ต์…˜์€ ์„ค์น˜ ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

Syslog๋ฅผ ์ˆ˜์ง‘ํ•˜์—ฌ Google SecOps๋กœ ์ „์†กํ•˜๋„๋ก Bindplane ์—์ด์ „ํŠธ ๊ตฌ์„ฑ

  1. ๊ตฌ์„ฑ ํŒŒ์ผ์— ์•ก์„ธ์Šคํ•ฉ๋‹ˆ๋‹ค.
    • config.yaml ํŒŒ์ผ์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ Linux์—์„œ๋Š” /etc/bindplane-agent/ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๊ณ  Windows์—์„œ๋Š” ์„ค์น˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ์Šต๋‹ˆ๋‹ค.
    • ํ…์ŠคํŠธ ํŽธ์ง‘๊ธฐ (์˜ˆ: nano, vi, ๋ฉ”๋ชจ์žฅ)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ๊ณผ ๊ฐ™์ด config.yaml ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

    receivers:
        udplog:
            # Replace the port and IP address as required
            listen_address: "0.0.0.0:514"
    
    exporters:
        chronicle/chronicle_w_labels:
            compression: gzip
            # Adjust the path to the credentials file you downloaded in Step 1
            creds_file_path: '/path/to/ingestion-authentication-file.json'
            # Replace with your actual customer ID from Step 2
            customer_id: <customer_id>
            endpoint: malachiteingestion-pa.googleapis.com
            # Add optional ingestion labels for better organization
            log_type: 'CISCO_WIPS'
            raw_log_field: body
            ingestion_labels:
    
    service:
        pipelines:
            logs/source0__chronicle_w_labels-0:
                receivers:
                    - udplog
                exporters:
                    - chronicle/chronicle_w_labels
    
    • ์ธํ”„๋ผ์— ํ•„์š”ํ•œ ๋Œ€๋กœ ํฌํŠธ์™€ IP ์ฃผ์†Œ๋ฅผ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • <customer_id>๋ฅผ ์‹ค์ œ ๊ณ ๊ฐ ID๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ ์„น์…˜์—์„œ ์ธ์ฆ ํŒŒ์ผ์ด ์ €์žฅ๋œ ๊ฒฝ๋กœ๋กœ /path/to/ingestion-authentication-file.json๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์—ฌ ๋ณ€๊ฒฝ์‚ฌํ•ญ ์ ์šฉ

  • Linux์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo systemctl restart bindplane-agent
    
  • Windows์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ์„œ๋น„์Šค ์ฝ˜์†”์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

    net stop BindPlaneAgent && net start BindPlaneAgent
    

Cisco Catalyst์—์„œ ์ ์‘ํ˜• ๋ฌด์„  ์นจ์ž… ๋ฐฉ์ง€ ์‹œ์Šคํ…œ (aWIPS) ๊ตฌ์„ฑ

  1. SSH๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Cisco Catalyst์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. AP ํ”„๋กœํ•„์—์„œ aWIPS๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•˜๋ ค๋ฉด ์ „์—ญ ๊ตฌ์„ฑ์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

    configure terminal
    ap profile <profile-name>
    awips
    
  3. syslog ์ œํ•œ ๊ฐ„๊ฒฉ์„ 60์ดˆ๋กœ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

    awips-syslog throttle period 60
    

Cisco AP ํ”„๋กœํ•„์„ ์‚ฌ์šฉํ•˜์—ฌ Syslog ๊ตฌ์„ฑ

  1. AP-join ํ”„๋กœํ•„ (CLI๋ฅผ ํ†ตํ•ด):

    configure terminal
    ap profile <profile-name>
      syslog host <Bindplane_IP_address>
      syslog level informational
      syslog facility local0
    end
    

Cisco WLC์—์„œ Syslog ๊ตฌ์„ฑ (GUI)

  1. WLC ์›น UI์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. ๊ด€๋ฆฌ > ๋กœ๊ทธ > ๊ตฌ์„ฑ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. Syslog Server IP Address(Syslog ์„œ๋ฒ„ IP ์ฃผ์†Œ) ํ•„๋“œ์— Bindplane ์—์ด์ „ํŠธ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
  4. ์ถ”๊ฐ€๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  5. ๋‹ค์Œ ๊ตฌ์„ฑ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
    • Syslog Severity(Syslog ์‹ฌ๊ฐ๋„): Informational(์ •๋ณด)์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • Syslog Facility(Syslog ๊ธฐ๋Šฅ): Local Use 0(๋กœ์ปฌ ์‚ฌ์šฉ 0)์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  6. ์ ์šฉ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  7. Save Configuration(๊ตฌ์„ฑ ์ €์žฅ)์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

WLC (CLI)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์•ก์„ธ์Šค ํฌ์ธํŠธ์—์„œ Syslog ๊ตฌ์„ฑ

  1. ์ „์—ญ AP syslog ํ˜ธ์ŠคํŠธ:

    config ap syslog host global <Bindplane_IP_address>
    
  2. ํŠน์ • AP syslog ํ˜ธ์ŠคํŠธ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

    config ap syslog host specific <AP-name> <Bindplane_IP_address>
    
  3. AP syslog ์‹ฌ๊ฐ๋„๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

    config ap logging syslog level informational
    
  4. AP ๋ฉ”์‹œ์ง€ ๊ธฐ๋Šฅ์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

    config logging syslog facility local0
    

UDM ๋งคํ•‘ ํ…Œ์ด๋ธ”

๋กœ๊ทธ ํ•„๋“œ UDM ๋งคํ•‘ ๋…ผ๋ฆฌ
applicationCategoryData security_result.summary ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
applicationSpecificAlarmID target.resource.attribute.labels.applicationSpecificAlarmID ๋Œ€์ƒ ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
attackerMacAddr target.mac ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
authEntityId principal.resource.attribute.labels.authEntityId ์ฃผ ๊ตฌ์„ฑ์› ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
category security_result.category_details ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
detectingApCount target.resource.attribute.labels.detectingApCount ๋Œ€์ƒ ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
description metadata.description ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
displayName principal.user.userid ํŒจํ„ด์ด ์ผ์น˜ํ•˜๋Š” ๊ฒฝ์šฐ displayName์—์„œ ์ •๊ทœ ํ‘œํ˜„์‹ host/(?P<user_id>[\\w-]+)์„ ์‚ฌ์šฉํ•˜์—ฌ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
eventType metadata.product_event_type ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
instanceId principal.resource.attribute.labels.instanceId ์ฃผ ๊ตฌ์„ฑ์› ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
instanceUuid metadata.product_log_id ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
instanceVersion principal.resource.attribute.labels.instanceVersion ์ฃผ ๊ตฌ์„ฑ์› ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
macInfo target.resource.attribute.labels.macInfo ๋Œ€์ƒ ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
notificationDeliveryMechanism target.resource.attribute.labels.notificationDeliveryMechanism, network.ip_protocol ๋Œ€์ƒ ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ฐ’์— 'snmp' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)๊ฐ€ ํฌํ•จ๋œ ๊ฒฝ์šฐ network.ip_protocol์ด 'UDP'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
previousSeverity target.resource.attribute.labels.previousSeverity ๋Œ€์ƒ ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค. eventType์ด 'USER_AUTHENTICATION_FAILURE'์ด๊ณ  user_id์ด ๋น„์–ด ์žˆ์ง€ ์•Š์œผ๋ฉด 'AUTHTYPE_UNSPECIFIED'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. ๋กœ๊ทธ์˜ timestamp์—์„œ ๋ณต์‚ฌํ–ˆ์Šต๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ ์กฐ๊ฑด์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํŒŒ์„œ ๋กœ์ง์— ์˜ํ•ด ๊ฒฐ์ •๋ฉ๋‹ˆ๋‹ค. eventType์ด 'USER_AUTHENTICATION_FAILURE'์ด๊ณ  user_id์ด ๋น„์–ด ์žˆ์ง€ ์•Š์€ ๊ฒฝ์šฐ 'USER_LOGIN'์ž…๋‹ˆ๋‹ค.

is_target_present ๋ฐ is_principal_present๊ฐ€ ๋ชจ๋‘ true์ธ ๊ฒฝ์šฐ 'NETWORK_CONNECTION'
is_principal_present์ด true์ธ ๊ฒฝ์šฐ 'STATUS_UPDATE' user_id์ด ๋น„์–ด ์žˆ์ง€ ์•Š์€ ๊ฒฝ์šฐ
'USER_UNCATEGORIZED'
๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด 'GENERIC_EVENT' 'CISCO_WIPS'๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค. '๋ฌด์„  ์นจ์ž… ๋ฐฉ์ง€ ์‹œ์Šคํ…œ (WIPS)'์œผ๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋ฉ๋‹ˆ๋‹ค. 'Cisco'๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋จ notificationDeliveryMechanism์— 'snmp' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)๊ฐ€ ํฌํ•จ๋œ ๊ฒฝ์šฐ 'UDP'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. IP๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ reportingEntityAddress ๋˜๋Š” source์—์„œ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. IP์ธ ๊ฒฝ์šฐ reportingEntityAddress ๋˜๋Š” source์—์„œ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. MAC ์ฃผ์†Œ์ธ ๊ฒฝ์šฐ source์—์„œ ์ •๊ทœ ํ‘œํ˜„์‹์„ ์‚ฌ์šฉํ•˜์—ฌ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค. ์ฃผ ๊ตฌ์„ฑ์› ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ฃผ ๊ตฌ์„ฑ์› ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
reportingEntityAddress principal.ip, principal.hostname IP ์ฃผ์†Œ์ธ ๊ฒฝ์šฐ principal.ip์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด principal.hostname๋กœ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
severity security_result.severity ๋‹ค์Œ ์กฐ๊ฑด์— ๋”ฐ๋ผ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
์ด '0', '1', 'CRITICAL' ๋˜๋Š” 'VERY-HIGH'์ธ ๊ฒฝ์šฐ 'CRITICAL'severity severity์ด '2', '3', '4' ๋˜๋Š” 'HIGH'์ธ ๊ฒฝ์šฐ
์€ 'HIGH'์ž…๋‹ˆ๋‹ค. severity์ด '5' ๋˜๋Š” 'MEDIUM'์ธ ๊ฒฝ์šฐ
์€ 'MEDIUM'์ž…๋‹ˆ๋‹ค. severity์ด '6', '7' ๋˜๋Š” 'LOW'์ธ ๊ฒฝ์šฐ
์€ 'LOW'์ž…๋‹ˆ๋‹ค.
sigAlertDescription security_result.description ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
signatureName target.resource.attribute.labels.signatureName ๋Œ€์ƒ ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
source principal.hostname, principal.ip, principal.mac IP ์ฃผ์†Œ์ธ ๊ฒฝ์šฐ principal.ip์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. MAC ์ฃผ์†Œ์ธ ๊ฒฝ์šฐ principal.mac์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด principal.hostname๋กœ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
srcObjectClassId principal.resource.attribute.labels.srcObjectClassId ์ฃผ ๊ตฌ์„ฑ์› ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
srcObjectId principal.resource.attribute.labels.srcObjectId ์ฃผ ๊ตฌ์„ฑ์› ๋ฆฌ์†Œ์Šค์˜ ๋ผ๋ฒจ๋กœ ๋ณ€ํ™˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
subclassName security_result.rule_name ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. applicationSpecificAlarmID์— 'BlockList' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)๊ฐ€ ํฌํ•จ๋˜๊ฑฐ๋‚˜ eventType์ด 'SIGNATURE_ATTACK', 'MALICIOUS_ROGUE_AP_DETECTED', 'USER_AUTHENTICATION_FAILURE' ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ 'BLOCK'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. eventType์— ๊ธฐ๋ฐ˜ํ•œ ํŒŒ์„œ ๋กœ์ง์— ๋”ฐ๋ผ ๊ฒฐ์ •๋ฉ๋‹ˆ๋‹ค. eventType์ด 'MALICIOUS_ROGUE_AP_DETECTED'์ธ ๊ฒฝ์šฐ
์€ 'NETWORK_MALICIOUS'์ž…๋‹ˆ๋‹ค.
eventType์ด 'SIGNATURE_ATTACK'์ธ ๊ฒฝ์šฐ 'NETWORK_SUSPICIOUS' eventType์ด 'USER_AUTHENTICATION_FAILURE'์ธ ๊ฒฝ์šฐ
'AUTH_VIOLATION'
timestamp metadata.event_timestamp seconds ๋ฐ nanos ํ•„๋“œ๋Š” ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.

๋„์›€์ด ๋” ํ•„์š”ํ•˜์‹ ๊ฐ€์š”? ์ปค๋ฎค๋‹ˆํ‹ฐ ํšŒ์› ๋ฐ Google SecOps ์ „๋ฌธ๊ฐ€๋กœ๋ถ€ํ„ฐ ๋‹ต๋ณ€์„ ๋ฐ›์œผ์„ธ์š”.