Trend Micro Cloud One ๋กœ๊ทธ ์ˆ˜์ง‘

๋‹ค์Œ์—์„œ ์ง€์›:

๊ฐœ์š”

์ด ํŒŒ์„œ๋Š” Trend Micro Cloud One์˜ syslog ๋ฐ JSON ํ˜•์‹ ๋กœ๊ทธ๋ฅผ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค. LEEF ํ˜•์‹ ๋ฉ”์‹œ์ง€์—์„œ ํ‚ค-๊ฐ’ ์Œ์„ ์ถ”์ถœํ•˜๊ณ , ์‹ฌ๊ฐ๋„ ๊ฐ’์„ ์ •๊ทœํ™”ํ•˜๊ณ , ์ฃผ์ฒด ๋ฐ ํƒ€๊ฒŸ ์—”ํ‹ฐํ‹ฐ (IP, ํ˜ธ์ŠคํŠธ ์ด๋ฆ„, ์‚ฌ์šฉ์ž)๋ฅผ ์‹๋ณ„ํ•˜๊ณ , ๋ฐ์ดํ„ฐ๋ฅผ UDM ์Šคํ‚ค๋งˆ์— ๋งคํ•‘ํ•ฉ๋‹ˆ๋‹ค. LEEF ํ˜•์‹์ด ๊ฐ์ง€๋˜์ง€ ์•Š์œผ๋ฉด ํŒŒ์„œ๋Š” ์ž…๋ ฅ์„ JSON์œผ๋กœ ์ฒ˜๋ฆฌํ•˜๊ณ  ๊ทธ์— ๋”ฐ๋ผ ๊ด€๋ จ ํ•„๋“œ๋ฅผ ์ถ”์ถœํ•˜๋ ค๊ณ  ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

  • Google SecOps ์ธ์Šคํ„ด์Šค๊ฐ€ ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • Trend Micro Cloud One์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • systemd๊ฐ€ ์žˆ๋Š” Windows 2012 SP2 ์ด์ƒ ๋˜๋Š” Linux ํ˜ธ์ŠคํŠธ๊ฐ€ ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • ํ”„๋ก์‹œ ๋’ค์—์„œ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ ๋ฐฉํ™”๋ฒฝ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ์ˆ˜์ง‘ ์—์ด์ „ํŠธ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ๊ณ ๊ฐ ID ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ํ”„๋กœํ•„๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์กฐ์ง ์„ธ๋ถ€์ •๋ณด ์„น์…˜์—์„œ ๊ณ ๊ฐ ID๋ฅผ ๋ณต์‚ฌํ•˜์—ฌ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ ์„ค์น˜

  1. Windows ์„ค์น˜์˜ ๊ฒฝ์šฐ msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  2. Linux ์„ค์น˜์˜ ๊ฒฝ์šฐ sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ถ”๊ฐ€ ์„ค์น˜ ์˜ต์…˜์€ ์ด ์„ค์น˜ ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

Syslog๋ฅผ ์ˆ˜์ง‘ํ•˜์—ฌ Google SecOps๋กœ ์ „์†กํ•˜๋„๋ก Bindplane ์—์ด์ „ํŠธ ๊ตฌ์„ฑ

  1. Bindplane ์—์ด์ „ํŠธ๋กœ ๋จธ์‹ ์— ์•ก์„ธ์Šคํ•ฉ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ๊ณผ ๊ฐ™์ด config.yaml ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

    receivers:
      udplog:
        # Replace the below port <5514> and IP (0.0.0.0) with your specific values
        listen_address: "0.0.0.0:514" 
    
    exporters:
        chronicle/chronicle_w_labels:
            compression: gzip
            # Adjust the creds location below according the placement of the credentials file you downloaded
            creds: '{ json file for creds }'
            # Replace <customer_id> below with your actual ID that you copied
            customer_id: <customer_id>
            endpoint: malachiteingestion-pa.googleapis.com
            # You can apply ingestion labels below as preferred
            ingestion_labels:
            log_type: SYSLOG
            namespace: 
            raw_log_field: body
    service:
        pipelines:
            logs/source0__chronicle_w_labels-0:
                receivers:
                    - udplog
                exporters:
                    - chronicle/chronicle_w_labels
    
  3. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์—ฌ ๋ณ€๊ฒฝ์‚ฌํ•ญ์„ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค. sudo systemctl bindplane restart

Trend Micro Cloud One์—์„œ Syslog ๊ตฌ์„ฑ

  1. ์ •์ฑ… > ์ผ๋ฐ˜ ๊ฐ์ฒด > ๊ธฐํƒ€ > Syslog ๊ตฌ์„ฑ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  2. ์ƒˆ๋กœ ๋งŒ๋“ค๊ธฐ > ์ƒˆ ๊ตฌ์„ฑ > ์ผ๋ฐ˜์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  3. ๋‹ค์Œ ๋งค๊ฐœ๋ณ€์ˆ˜์˜ ๊ฐ’์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.
    • ์ด๋ฆ„: ๊ตฌ์„ฑ์„ ์‹๋ณ„ํ•˜๋Š” ๊ณ ์œ ํ•œ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค (์˜ˆ: Google SecOps BindPlance ์„œ๋ฒ„).
    • ์„œ๋ฒ„ ์ด๋ฆ„: Bindplane ์—์ด์ „ํŠธ์˜ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • ์„œ๋ฒ„ ํฌํŠธ: Bindplane ์—์ด์ „ํŠธ์˜ ํฌํŠธ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค (์˜ˆ: 514).
    • ์ „์†ก: UDP๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • ์ด๋ฒคํŠธ ํ˜•์‹: Syslog๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • ์ด๋ฒคํŠธ์— ์‹œ๊ฐ„๋Œ€ ํฌํ•จ: ์„ ํƒํ•˜์ง€ ์•Š์€ ์ƒํƒœ๋กœ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค.
    • ์‹œ์„ค: ์ด๋ฒคํŠธ๊ฐ€ ์—ฐ๊ฒฐ๋  ํ”„๋กœ์„ธ์Šค ์œ ํ˜•์ž…๋‹ˆ๋‹ค.
    • ์ƒ๋‹ด์‚ฌ๊ฐ€ ๋กœ๊ทธ๋ฅผ ์ „๋‹ฌํ•ด์•ผ ํ•จ: ์‹œ์Šคํ…œ ๋กœ๊ทธ ์„œ๋ฒ„๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

Trend Micro Cloud One์—์„œ ์‹œ์Šคํ…œ ์ด๋ฒคํŠธ ๋‚ด๋ณด๋‚ด๊ธฐ

  1. ๊ด€๋ฆฌ > ์‹œ์Šคํ…œ ์„ค์ • > ์ด๋ฒคํŠธ ์ „๋‹ฌ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  2. ๊ตฌ์„ฑ์„ ์‚ฌ์šฉํ•˜์—ฌ ์›๊ฒฉ ์ปดํ“จํ„ฐ์— ์‹œ์Šคํ…œ ์ด๋ฒคํŠธ ์ „๋‹ฌ (Syslog๋ฅผ ํ†ตํ•ด)์—์„œ ์ด์ „ ๋‹จ๊ณ„์—์„œ ๋งŒ๋“  ๊ตฌ์„ฑ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  3. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

Trend Micro Cloud One์—์„œ ๋ณด์•ˆ ์ด๋ฒคํŠธ ๋‚ด๋ณด๋‚ด๊ธฐ

  1. ์ •์ฑ…์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  2. ์ปดํ“จํ„ฐ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์ •์ฑ…์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  3. ์„ค์ • > ์ด๋ฒคํŠธ ์ „๋‹ฌ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  4. ์ด๋ฒคํŠธ ์ „๋‹ฌ ๋นˆ๋„ (์—์ด์ „ํŠธ/์–ดํ”Œ๋ผ์ด์–ธ์Šค์—์„œ): ์ด๋ฒคํŠธ ์ „์†ก ๊ฐ„๊ฒฉ์„ ์„ ํƒํ•˜๊ณ  ๋ณด์•ˆ ์ด๋ฒคํŠธ๊ฐ€ ์ „๋‹ฌ๋˜๋Š” ๋นˆ๋„๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  5. ์ด๋ฒคํŠธ ์ „๋‹ฌ ๊ตฌ์„ฑ (์—์ด์ „ํŠธ/์–ดํ”Œ๋ผ์ด์–ธ์Šค์—์„œ): ๋ฉ€์›จ์–ด ๋ฐฉ์ง€ Syslog ๊ตฌ์„ฑ์„ ์„ ํƒํ•˜๊ณ  ์ด์ „ ๋‹จ๊ณ„์—์„œ ๋งŒ๋“  ๊ตฌ์„ฑ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  6. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

UDM ๋งคํ•‘ ํ…Œ์ด๋ธ”

๋กœ๊ทธ ํ•„๋“œ UDM ๋งคํ•‘ ๋…ผ๋ฆฌ
act security_result.action act์ด 'deny' ๋˜๋Š” 'block'์ด๋ฉด(๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ) BLOCK act์ด 'pass' ๋˜๋Š” 'allow' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)์ธ ๊ฒฝ์šฐ ALLOW act์ด 'update' ๋˜๋Š” 'rename'์ธ ๊ฒฝ์šฐ(๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ) ALLOW_WITH_MODIFICATION act์ด 'quarantine' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)์ด๋ฉด QUARANTINE. ๊ทธ ์™ธ์˜ ๊ฒฝ์šฐ UNKNOWN_ACTION๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
act security_result.action_details ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
๊ณ ์–‘์ด security_result.category_details ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
cn1 target.asset_id cn1Label์ด 'ํ˜ธ์ŠคํŠธ ID'์ธ ๊ฒฝ์šฐ 'ํ˜ธ์ŠคํŠธ ID:'๊ฐ€ ์•ž์— ๋ถ™์Šต๋‹ˆ๋‹ค.
๋‚ด๋ฆผ์ฐจ์ˆœ metadata.description ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
dvchost target.asset.hostname ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
dvchost target.hostname ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
log_type metadata.product_name ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
msg security_result.description ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
name security_result.summary ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
์กฐ์ง target.administrative_domain ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
proto additional.fields.key proto ํ•„๋“œ๋ฅผ ์ •์ˆ˜๋กœ ๋ณ€ํ™˜ํ•  ์ˆ˜ ์—†๋Š” ๊ฒฝ์šฐ 'ํ”„๋กœํ† ์ฝœ'๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
proto additional.fields.value.string_value proto ํ•„๋“œ๋ฅผ ์ •์ˆ˜๋กœ ๋ณ€ํ™˜ํ•  ์ˆ˜ ์—†๋Š” ๊ฒฝ์šฐ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
proto network.ip_protocol ํ”„๋กœํ† ์ฝœ ๋ฒˆํ˜ธ๋ฅผ ํ•ด๋‹น ์ด๋ฆ„์œผ๋กœ ๋ณ€ํ™˜ํ•˜๋Š” parse_ip_protocol.include ๋…ผ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค (์˜ˆ: '6'์€ 'TCP'๊ฐ€ ๋ฉ๋‹ˆ๋‹ค.
product_version metadata.product_version ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
sev security_result.severity sev๊ฐ€ '0', '1', '2', '3' ๋˜๋Š” 'low' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)์ธ ๊ฒฝ์šฐ LOW sev์ด '4', '5', '6' ๋˜๋Š” 'medium' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)์ธ ๊ฒฝ์šฐ MEDIUM sev์ด '7', '8' ๋˜๋Š” 'high' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)์ธ ๊ฒฝ์šฐ HIGH sev์ด '9', '10' ๋˜๋Š” 'very high' (๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„ ์•ˆ ํ•จ)์ธ ๊ฒฝ์šฐ CRITICAL
sev security_result.severity_details ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
src principal.asset.hostname ์œ ํšจํ•œ IP ์ฃผ์†Œ๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
src principal.asset.ip ์œ ํšจํ•œ IP ์ฃผ์†Œ์ธ ๊ฒฝ์šฐ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
src principal.hostname ์œ ํšจํ•œ IP ์ฃผ์†Œ๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
src principal.ip ์œ ํšจํ•œ IP ์ฃผ์†Œ์ธ ๊ฒฝ์šฐ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
TrendMicroDsTenant security_result.detection_fields.key 'TrendMicroDsTenant'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
TrendMicroDsTenant security_result.detection_fields.value ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
TrendMicroDsTenantId security_result.detection_fields.key 'TrendMicroDsTenantId'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
TrendMicroDsTenantId security_result.detection_fields.value ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
usrName principal.user.userid ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. has_principal์ด true์ด๊ณ  has_target์ด true์ด๋ฉด NETWORK_CONNECTION์ž…๋‹ˆ๋‹ค. has_principal์ด true์ด๋ฉด STATUS_UPDATE์ž…๋‹ˆ๋‹ค. has_target๊ฐ€ ์ฐธ์ด๊ณ  has_principal๊ฐ€ ๊ฑฐ์ง“์ด๋ฉด USER_UNCATEGORIZED์ž…๋‹ˆ๋‹ค. ๊ทธ ์™ธ์˜ ๊ฒฝ์šฐ GENERIC_EVENT๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. event_type์ด USER_UNCATEGORIZED์ด๋ฉด AUTHTYPE_UNSPECIFIED๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ์ฃผ ๊ตฌ์„ฑ์› IP, ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ ๋˜๋Š” MAC ์ฃผ์†Œ๊ฐ€ ์ถ”์ถœ๋œ ๊ฒฝ์šฐ 'true'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด 'false'๋กœ ์ดˆ๊ธฐํ™”๋ฉ๋‹ˆ๋‹ค. ํƒ€๊ฒŸ IP, ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ ๋˜๋Š” MAC ์ฃผ์†Œ๊ฐ€ ์ถ”์ถœ๋œ ๊ฒฝ์šฐ 'true'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด 'false'๋กœ ์ดˆ๊ธฐํ™”๋ฉ๋‹ˆ๋‹ค. ์ตœ์ƒ์œ„ ์ด๋ฒคํŠธ ํƒ€์ž„์Šคํƒฌํ”„์™€ ๋™์ผํ•ฉ๋‹ˆ๋‹ค. 'Trend Micro'๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

๋„์›€์ด ๋” ํ•„์š”ํ•˜์‹ ๊ฐ€์š”? ์ปค๋ฎค๋‹ˆํ‹ฐ ํšŒ์› ๋ฐ Google SecOps ์ „๋ฌธ๊ฐ€๋กœ๋ถ€ํ„ฐ ๋‹ต๋ณ€์„ ๋ฐ›์œผ์„ธ์š”.