Endpoint Protector DLP ๋กœ๊ทธ ์ˆ˜์ง‘

๋‹ค์Œ์—์„œ ์ง€์›:

์ด ๋ฌธ์„œ์—์„œ๋Š” Bindplane์„ ์‚ฌ์šฉํ•˜์—ฌ Netwrix Endpoint Protector DLP(๋ฐ์ดํ„ฐ ์†์‹ค ๋ฐฉ์ง€) ๋กœ๊ทธ๋ฅผ Google Security Operations์— ์ˆ˜์ง‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. ํŒŒ์„œ๋Š” grok ํŒจํ„ด์„ ํ™œ์šฉํ•˜์—ฌ ํ•ต์‹ฌ ์ •๋ณด๋ฅผ ์‹๋ณ„ํ•˜์—ฌ syslog ๋ฉ”์‹œ์ง€์—์„œ ํ•„๋“œ๋ฅผ ์ถ”์ถœํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ๋‹ค์Œ ์ถ”์ถœ๋œ ํ•„๋“œ๋ฅผ ํ†ตํ•ฉ ๋ฐ์ดํ„ฐ ๋ชจ๋ธ (UDM)์— ๋งคํ•‘ํ•˜์—ฌ ๋‹ค์–‘ํ•œ ๋ฐ์ดํ„ฐ ์œ ํ˜•์„ ์ฒ˜๋ฆฌํ•˜๊ณ  ๊ณต๊ธ‰์—…์ฒด ๋ฐ ์ œํ’ˆ ์ •๋ณด์™€ ๊ฐ™์€ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋กœ ์ถœ๋ ฅ์„ ๋ณด๊ฐ•ํ•ฉ๋‹ˆ๋‹ค. ํŒŒ์„œ๋Š” ๋ฌธ์ž์—ด ์กฐ์ž‘, ์šด์˜์ฒด์ œ ๋ฐ ๊ธฐํƒ€ ๊ธฐ์ค€์— ๋”ฐ๋ฅธ ํ•„๋“œ์˜ ์กฐ๊ฑด๋ถ€ ๋ณ‘ํ•ฉ ๋“ฑ ์—ฌ๋Ÿฌ ๋ฐ์ดํ„ฐ ๋ณ€ํ™˜๋„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

๋‹ค์Œ ๊ธฐ๋ณธ ์š”๊ฑด์ด ์ถฉ์กฑ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

  • Google SecOps ์ธ์Šคํ„ด์Šค
  • Windows 2016 ์ด์ƒ ๋˜๋Š” systemd๊ฐ€ ์„ค์น˜๋œ Linux ํ˜ธ์ŠคํŠธ
  • ํ”„๋ก์‹œ ๋’ค์—์„œ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ ๋ฐฉํ™”๋ฒฝ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ์Œ
  • Netwrix Endpoint Protector์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ

Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ์ˆ˜์ง‘ ์—์ด์ „ํŠธ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค. Bindplane์ด ์„ค์น˜๋  ์‹œ์Šคํ…œ์— ํŒŒ์ผ์„ ์•ˆ์ „ํ•˜๊ฒŒ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ๊ณ ๊ฐ ID ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ํ”„๋กœํ•„๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์กฐ์ง ์„ธ๋ถ€์ •๋ณด ์„น์…˜์—์„œ ๊ณ ๊ฐ ID๋ฅผ ๋ณต์‚ฌํ•˜์—ฌ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ ์„ค์น˜

๋‹ค์Œ ์•ˆ๋‚ด์— ๋”ฐ๋ผ Windows ๋˜๋Š” Linux ์šด์˜์ฒด์ œ์— Bindplane ์—์ด์ „ํŠธ๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

Windows ์„ค์น˜

  1. ๋ช…๋ น ํ”„๋กฌํ”„ํŠธ ๋˜๋Š” PowerShell์„ ๊ด€๋ฆฌ์ž๋กœ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    

Linux ์„ค์น˜

  1. ๋ฃจํŠธ ๋˜๋Š” sudo ๊ถŒํ•œ์œผ๋กœ ํ„ฐ๋ฏธ๋„์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    

์ถ”๊ฐ€ ์„ค์น˜ ๋ฆฌ์†Œ์Šค

์ถ”๊ฐ€ ์„ค์น˜ ์˜ต์…˜์€ ์„ค์น˜ ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

Syslog๋ฅผ ์ˆ˜์ง‘ํ•˜์—ฌ Google SecOps๋กœ ์ „์†กํ•˜๋„๋ก Bindplane ์—์ด์ „ํŠธ ๊ตฌ์„ฑ

  1. ๊ตฌ์„ฑ ํŒŒ์ผ์— ์•ก์„ธ์Šคํ•ฉ๋‹ˆ๋‹ค.
    • config.yaml ํŒŒ์ผ์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ Linux์—์„œ๋Š” /etc/bindplane-agent/ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๊ณ  Windows์—์„œ๋Š” ์„ค์น˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ์Šต๋‹ˆ๋‹ค.
    • ํ…์ŠคํŠธ ํŽธ์ง‘๊ธฐ (์˜ˆ: nano, vi, ๋ฉ”๋ชจ์žฅ)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ๊ณผ ๊ฐ™์ด config.yaml ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

    receivers:
        udplog:
            # Replace the port and IP address as required
            listen_address: "0.0.0.0:514"
    
    exporters:
        chronicle/chronicle_w_labels:
            compression: gzip
            # Adjust the path to the credentials file you downloaded in Step 1
            creds_file_path: '/path/to/ingestion-authentication-file.json'
            # Replace with your actual customer ID from Step 2
            customer_id: <customer_id>
            endpoint: malachiteingestion-pa.googleapis.com
            # Add optional ingestion labels for better organization
            ingestion_labels:
                log_type: 'ENDPOINT_PROTECTOR_DLP'
                raw_log_field: body
    
    service:
        pipelines:
            logs/source0__chronicle_w_labels-0:
                receivers:
                    - udplog
                exporters:
                    - chronicle/chronicle_w_labels
    
    • ์ธํ”„๋ผ์— ํ•„์š”ํ•œ ๋Œ€๋กœ ํฌํŠธ์™€ IP ์ฃผ์†Œ๋ฅผ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • <customer_id>๋ฅผ ์‹ค์ œ ๊ณ ๊ฐ ID๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ ์„น์…˜์—์„œ ์ธ์ฆ ํŒŒ์ผ์ด ์ €์žฅ๋œ ๊ฒฝ๋กœ๋กœ /path/to/ingestion-authentication-file.json๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์—ฌ ๋ณ€๊ฒฝ์‚ฌํ•ญ ์ ์šฉ

  • Linux์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo systemctl restart bindplane-agent
    
  • Windows์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ์„œ๋น„์Šค ์ฝ˜์†”์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

    net stop BindPlaneAgent && net start BindPlaneAgent
    

Netwrix Endpoint Protector์—์„œ Syslog ๊ตฌ์„ฑ

  1. Endpoint Protector ์›น UI์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. ์–ดํ”Œ๋ผ์ด์–ธ์Šค > SIEM ํ†ตํ•ฉ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ƒˆ ํ•ญ๋ชฉ ์ถ”๊ฐ€๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  4. ๋‹ค์Œ ๊ตฌ์„ฑ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
    • SIEM ์ƒํƒœ: ์Šค์œ„์น˜๋ฅผ ์ „ํ™˜ํ•˜์—ฌ SIEM ์„œ๋ฒ„๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
    • ๋กœ๊น… ์‚ฌ์šฉ ์ค‘์ง€: ์Šค์œ„์น˜๋ฅผ ์ „ํ™˜ํ•˜์—ฌ ๋กœ๊น…์„ ์‚ฌ์šฉ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
    • ์„œ๋ฒ„ ์ด๋ฆ„: ๊ณ ์œ ํ•˜๊ณ  ์˜๋ฏธ ์žˆ๋Š” ์„œ๋ฒ„ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • ์„œ๋ฒ„ ์„ค๋ช…: ์ด ํ†ตํ•ฉ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
    • ์„œ๋ฒ„ IP ๋˜๋Š” DNS: Bindplane ์—์ด์ „ํŠธ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • Server Protocol(์„œ๋ฒ„ ํ”„๋กœํ† ์ฝœ): UDP๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • ์„œ๋ฒ„ ํฌํŠธ: Bindplane ์—์ด์ „ํŠธ ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค (์˜ˆ: UDP์˜ ๊ฒฝ์šฐ 514).
    • ํ—ค๋” ์ œ์™ธ: ์Šค์œ„์น˜๋ฅผ ์ „ํ™˜ํ•˜์—ฌ ๋กœ๊ทธ ํ—ค๋”๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
    • ๋กœ๊ทธ ์œ ํ˜•: SIEM์œผ๋กœ ์ „์†กํ•  ์ˆ˜ ์žˆ๋Š” ๋กœ๊ทธ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  5. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

UDM ๋งคํ•‘ ํ…Œ์ด๋ธ”

๋กœ๊ทธ ํ•„๋“œ UDM ๋งคํ•‘ ๋…ผ๋ฆฌ
Client Computer principal.asset.asset_id Client Computer ๊ฐ’์€ 'Client Computer: '๋ฅผ ์•ž์— ์ถ”๊ฐ€ํ•œ ํ›„ principal.asset.asset_id์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Client User principal.user.userid Client User ๊ฐ’์ด principal.user.userid์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Content Policy security_result.rule_name Content Policy ๊ฐ’์ด security_result.rule_name์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Content Policy Type security_result.rule_id Content Policy Type ๊ฐ’์ด security_result.rule_id์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Destination metadata.ingestion_labels.value Destination ๊ฐ’์€ key์ด 'Destination'์ธ ingestion_labels ๊ฐ์ฒด์˜ value ํ•„๋“œ์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Destination Type metadata.ingestion_labels.value Destination Type ๊ฐ’์€ key์ด '๋Œ€์ƒ ์œ ํ˜•'์ธ ingestion_labels ๊ฐ์ฒด์˜ value ํ•„๋“œ์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Device PID metadata.ingestion_labels.value Device PID ๊ฐ’์€ key์ด '๊ธฐ๊ธฐ PID'์ธ ingestion_labels ๊ฐ์ฒด์˜ value ํ•„๋“œ์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Device Serial metadata.ingestion_labels.value Device Serial ๊ฐ’์€ key์ด '๊ธฐ๊ธฐ ์ผ๋ จ๋ฒˆํ˜ธ'์ธ ingestion_labels ๊ฐ์ฒด์˜ value ํ•„๋“œ์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค. Device Serial๊ฐ€ ๋น„์–ด ์žˆ์ง€ ์•Š์€ ๊ฒฝ์šฐ์—๋งŒ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค.
Device VID metadata.ingestion_labels.value Device VID ๊ฐ’์€ key์ด '๊ธฐ๊ธฐ VID'์ธ ingestion_labels ๊ฐ์ฒด์˜ value ํ•„๋“œ์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
File Name target.file.full_path File Name ๊ฐ’์ด target.file.full_path์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
File Size target.file.size File Size ๊ฐ’์ด target.file.size์— ํ• ๋‹น๋˜๊ณ  ๋ถ€ํ˜ธ ์—†๋Š” ์ •์ˆ˜๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
IP Address principal.ip IP Address ๊ฐ’์ด principal.ip์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Item Details metadata.ingestion_labels.value Item Details ๊ฐ’์€ key์ด '์ƒํ’ˆ ์„ธ๋ถ€์ •๋ณด'์ธ ingestion_labels ๊ฐ์ฒด์˜ value ํ•„๋“œ์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Log ID metadata.product_log_id Log ID ๊ฐ’์ด metadata.product_log_id์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
MAC Address principal.mac ๋ชจ๋“  ํ•˜์ดํ”ˆ์„ ์ฝœ๋ก ์œผ๋กœ ๋ฐ”๊พผ ํ›„ MAC Address ๊ฐ’์ด principal.mac์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Matched Item metadata.ingestion_labels.value Matched Item ๊ฐ’์€ key์ด '์ผ์น˜ํ•˜๋Š” ํ•ญ๋ชฉ'์ธ ingestion_labels ๊ฐ์ฒด์˜ value ํ•„๋“œ์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
Message security_result.summary Message ๊ฐ’์ด security_result.summary์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
OS principal.platform OS ๊ฐ’์€ principal.platform ๊ฐ’์„ ๊ฒฐ์ •ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. OS์— 'Windows'๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์œผ๋ฉด principal.platform์ด 'WINDOWS'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. OS์— 'Mac'์ด ํฌํ•จ๋œ ๊ฒฝ์šฐ principal.platform์ด 'MAC'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. OS์— 'Lin'์ด ํฌํ•จ๋œ ๊ฒฝ์šฐ principal.platform์ด 'LINUX'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
Serial Number principal.asset.hardware.serial_number Serial Number ๊ฐ’์ด principal.asset.hardware.serial_number์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค. grok์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉ”์‹œ์ง€ ํ•„๋“œ์—์„œ ์ถ”์ถœํ•˜๊ณ  intermediary.hostname์— ํ• ๋‹นํ–ˆ์Šต๋‹ˆ๋‹ค. grok์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉ”์‹œ์ง€ ํ•„๋“œ์—์„œ ์ถ”์ถœํ•˜๊ณ  metadata.description์— ํ• ๋‹นํ–ˆ์Šต๋‹ˆ๋‹ค. syslog ๋ฉ”์‹œ์ง€์˜ ํƒ€์ž„์Šคํƒฌํ”„๊ฐ€ ํŒŒ์‹ฑ๋˜์–ด metadata.event_timestamp์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค. 'SCAN_UNCATEGORIZED' ๊ฐ’์ด metadata.event_type์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค. 'ENDPOINT_PROTECTOR_DLP' ๊ฐ’์ด metadata.log_type์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค. 'ENDPOINT_PROTECTOR_DLP' ๊ฐ’์ด metadata.product_name์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค. 'ENDPOINT_PROTECTOR_DLP' ๊ฐ’์ด metadata.vendor_name์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค. grok์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉ”์‹œ์ง€ ํ•„๋“œ์—์„œ ์ถ”์ถœํ•˜๊ณ  principal.hostname์— ํ• ๋‹นํ–ˆ์Šต๋‹ˆ๋‹ค. grok์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉ”์‹œ์ง€ ํ•„๋“œ์—์„œ ์ถ”์ถœํ•˜๊ณ  principal.ip์— ํ• ๋‹นํ–ˆ์Šต๋‹ˆ๋‹ค. syslog ๋ฉ”์‹œ์ง€์˜ ํƒ€์ž„์Šคํƒฌํ”„๊ฐ€ ํŒŒ์‹ฑ๋˜์–ด ์ตœ์ƒ์œ„ timestamp ํ•„๋“œ์— ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.

๋„์›€์ด ๋” ํ•„์š”ํ•˜์‹ ๊ฐ€์š”? ์ปค๋ฎค๋‹ˆํ‹ฐ ํšŒ์› ๋ฐ Google SecOps ์ „๋ฌธ๊ฐ€๋กœ๋ถ€ํ„ฐ ๋‹ต๋ณ€์„ ๋ฐ›์œผ์„ธ์š”.