๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿ’ป Computer Science/๋„คํŠธ์›Œํฌ

[๋„คํŠธ์›Œํฌ] IPS, WAF, FW๋ž€?

by Jay Din 2023. 11. 8.
728x90
๋ฐ˜์‘ํ˜•

์ดํ•ด๋ฅผ ๋•๊ธฐ ์œ„ํ•œ ์‚ฌ์ „์ง€์‹

OSI 7๊ณ„์ธต์ด๋ž€?

https://jay-din.tistory.com/25

 

OSI 7๊ณ„์ธต๊ณผ TCP/IP 4๊ณ„์ธต ์ด๋ž€?

OSI 7๊ณ„์ธต๊ณผ TCP/IP 4๊ณ„์ธต OSI 7๊ณ„์ธต์€ ๋„คํŠธ์›Œํฌ ํ†ต์‹ ์„ ํ‘œ์ค€ํ™”ํ•œ ๋ชจ๋ธ๋กœ, ํ†ต์‹  ์‹œ์Šคํ…œ์„ 7๋‹จ๊ณ„๋กœ ๋‚˜๋ˆ„์–ด ์„ค๋ช…ํ•œ ๊ฒƒ์ด๋‹ค. ํ•˜์ง€๋งŒ OSI ๋ชจ๋ธ์ด ์‹ค๋ฌด์ ์œผ๋กœ ์ด์šฉํ•˜๊ธฐ์— ๋ณต์žกํ•œ ํƒ“์— ์‹ค์ œ ์ธํ„ฐ๋„ท์—์„œ๋Š” ์ด

jay-din.tistory.com

 

WAF์˜ ์ดํ•ด

์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐฉํ™”๋ฒฝ(WAF; Web Application Firewall)์€ ์›น์˜ ๋น„์ •์ƒ ํŠธ๋ž˜ํ”ฝ์„ ํƒ์ง€ํ•˜๊ณ  ์ฐจ๋‹จํ•˜๊ธฐ ์œ„ํ•œ ๋ฐฉํ™”๋ฒฝ์ž…๋‹ˆ๋‹ค.

WAF๋Š” ์›น ํ•ดํ‚น ๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ์›น ์„œ๋น„์Šค๋ฅผ ์ „๋ฌธ์ ์œผ๋กœ ๋ณดํ˜ธํ•˜๊ธฐ ์œ„ํ•ด ํƒ„์ƒํ•œ ์ •๋ณด ๋ณดํ˜ธ ์‹œ์Šคํ…œ์ด๋ผ๊ณ  ์ดํ•ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

์นจ์ž… ํƒ์ง€, ์ฐจ๋‹จ ์‹œ์Šคํ…œ(IDS/IPS)๊ณผ๋„ ์—ญํ• ์ด ๋‹ค๋ฆ…๋‹ˆ๋‹ค.

FW, WAF, IDS/IPS์˜ ์—ญํ• ์„ ์ •ํ™•ํžˆ ๊ตฌ๋ถ„ํ•˜๊ณ  ์ ์ ˆํ•œ ๋ฃฐ์„ ์ˆ˜๋ฆฝํ•˜์—ฌ ์šด์šฉํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค.

๋”ฐ๋ผ์„œ ์ด ์ค‘ ํ•˜๋‚˜์˜ ์†”๋ฃจ์…˜์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋”ฐ๊ณ  ๋‹ค๋ฅธ ๋ณด์•ˆ ์†”๋ฃจ์…˜์ด ํ•„์š” ์—†๋‹ค๋Š” ์ƒ๊ฐ์€ ์ž˜๋ชป๋œ ์ƒ๊ฐ์ž…๋‹ˆ๋‹ค.

์›น ๋ฐฉํ™”๋ฒฝ๊ณผ ๋ฐฉํ™”๋ฒฝ(FW; Firewall) ์ฐจ์ด

์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐฉํ™”๋ฒฝ(WAF; Web Application Firewall)์€ ์ผ๋ฐ˜์ ์œผ๋กœ ์ด์•ผ๊ธฐํ•˜๋Š” ๋ฐฉํ™”๋ฒฝ(FW)๊ณผ ์ฐจ์ด์ ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

๋ฐฉํ™”๋ฒฝ TCP/IP ๋ ˆ๋ฒจ์— ํฌํ•จ๋œ ์ •๋ณด๋“ค์„ ๊ธฐ๋ฐ˜์œผ๋กœ ์ฐจ๋‹จ ๋ฃฐ์„ ์„ค์ •
์›น  ๋ฐฉํ™”๋ฒฝ ์›น ํ”„๋กœํ† ์ฝœ HTTP ์ •๋ณด๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ ์ฐจ๋‹จ ๋ฃฐ์„ ์„ค์ •

 

IPS, WAF, FW์˜ ๊ณตํ†ต์‚ฌํ•ญ

์•…์˜์ ์ธ ์˜๋„๋ฅผ ๊ฐ€์ง€๊ณ  ์ „์‚ฐ์‹œ์Šคํ…œ์„ ๊ณต๊ฒฉํ•˜๋Š” ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ํƒ์ง€ ๋ฐ ์ฐจ๋‹จ

 

์นจ์ž…๋ฐฉ์ง€ ์‹œ์Šคํ…œ(IPS)

์นจ์ž…๋ฐฉ์ง€ ์‹œ์Šคํ…œ(IPS; Instruction Protection System) ์€ ๋„คํŠธ์›Œํฌ Layer3 ~ Layer7 ๊ณ„์ธต์—์„œ IPS๊ฐ€ ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ์ทจ์•ฝ์  ํŒจํ„ด์— ๋Œ€ํ•ด์„œ๋งŒ ํƒ์ง€ ๋ฐ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค.

 

์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐฉํ™”๋ฒฝ(WAF)

์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐฉํ™”๋ฒฝ(WAF; Web Application Firewall) ์€ ๋„คํŠธ์›Œํฌ Layer7(Application Level)๊ณ„์ธต์—์„œ HTTP(80) ํ”„๋กœํ† ์ฝœ์„ ๋ฒ ์ด์Šค๋กœํ•˜๋Š” ์ทจ์•ฝ์  ๊ณต๊ฒฉ๋งŒ ํƒ์ง€ ๋ฐ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค.

 

๋ฐฉํ™”๋ฒฝ(FW)

๋ฐฉํ™”๋ฒฝ(FW; Firewall) ์€ ๋„คํŠธ์›Œํฌ Layer3(Network Level)๊ณ„์ธต์—์„œ IP์™€ Port๋ฅผ ์ œ์–ดํ•จ์œผ๋กœ์จ ์ธ๊ฐ€๋œ ์‚ฌ์šฉ์ž์— ๋Œ€ํ•ด์„œ๋งŒ ์ „์‚ฐ์‹œ์Šคํ…œ์— ์ ‘๊ทผ ํ—ˆ์šฉ Routing Mode์—์„œ NAT(์ฃผ์†Œ ๋ณ€ํ™˜) ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

 

 

 

 

 

 

 


์ฐธ๊ณ 

https://techblog.woowahan.com/2699/

 

728x90
๋ฐ˜์‘ํ˜•