|
 |
ºÐ»ê ¼ºñ½º°ÅºÎ °ø°Ý(Distribute Denial of Service attack(DDoS))Àº ¿©·¯ ´ëÀÇ ÄÄÇ»Å͸¦ ÀÏÁ¦È÷ µ¿ÀÛÇÏ°Ô ÇÏ¿© ƯÁ¤ »çÀÌÆ®¸¦ °ø°ÝÇÏ´Â ¹æ½ÄÀÔ´Ï´Ù.
ƯÁ¤ »çÀÌÆ®¸¦ °ø°ÝÇϱâ À§ÇØ ÇØÄ¿°¡ ¼ºñ½º °ø°ÝÀ» À§ÇÑ µµ±¸µéÀ» ¿©·¯ ÄÄÇ»ÅÍ¿¡ ½É¾î³õ°í ¸ñÇ¥»çÀÌÆ®ÀÇ ÄÄÇ»ÅÍ ½Ã½ºÅÛÀÌ Ã³¸®ÇÒ ¼ö ¾ø´Â ¾öû³ ºÐ·®ÀÇ ÆÐŶÀ» µ¿½Ã¿¡ ¹ü¶÷½ÃŰ¸é ³×Æ®¿öÅ©ÀÇ ¼º´É ÀúÇϳª ½Ã½ºÅÛ ¸¶ºñ¸¦ °¡Á®¿É´Ï´Ù. ½Ã½ºÅÛ °úºÎÈ·Î Á¤»ó°í°´µéÀÌ Á¢¼ÓÀ» ÇÒ ¼ö ¾ø´Â »óŰ¡ µÇ´Â °Í. ÇÑ ÀüȹøÈ£¿¡ ÁýÁßÀûÀ¸·Î ÀüȰ¡ °É·Á¿À¸é ÀϽà ºÒÅëµÇ´Â Çö»ó°ú °°½À´Ï´Ù.
ÀÌ¿ëÀÚÀÇ Á¤»óÁ¢¼ÓÀÌ ºÒ°¡´ÉÇØ Áö´Â °ÍÀº ¹°·Ð ½ÉÇϸé ÁÖÄÄÇ»ÅÍ ±â´É¿¡ Ä¡¸íŸ¸¦ ÀÔÈ÷°Ô µË´Ï´Ù.
|
 |
 |
| DDoS °ø°ÝÀº 2¹øÂ°·Î °¡Àå ½É°¢ÇÑ À§ÇùÀÓ |
? InformationWeek U.S. Security Survey
|
| DDoS °ø°ÝÀº º¸¾È ´ã´ç ÀÓ¿øÀÌ °¡Àå ½É°¢ÇÏ°Ô °í·ÁÇÏ´Â Ä§ÇØ»ç°íÀÓ |
? CSO Magazine Security Sensor III & IV Rsearch
|
¼ºñ½º Á¦°øÀÚÀÇ ÃÖ´ë ¿ì¼±¼øÀ§´Â DDoS ¹æÁöÀ̸ç, DDoS °ø°ÝÀº ¸ðµç ¼ºñ½º Á¦°øÀÚ°¡ ÇØ°áÇϰíÀÚ ÇÏ´Â ¹®Á¦ Áß
ÃÖ´ë °ü°ÇÀÓ |
- attribution
|
|
 |
 |
 |
| Specification |
IG200 |
IG2000 |
| ½Ã°¢È, ACLs, ´ë¿ªÆø ÅëÁ¦ |
½Ã°¢È, ACLs, ´ë¿ªÆø ÅëÁ¦ |
½Ã°¢È, ACLs, ´ë¿ªÆø ÅëÁ¦ |
| Æ®·¡ÇÈ ¹× À̺¥Æ® ºÐ¼® |
Áö¿ø |
Áö¿ø |
| Á¤ÂûÇàÀ§ ¹× ÀÌ»ó ¹æÁö |
Áö¿ø |
Áö¿ø |
| Throughput |
200 Mbps
(100 Mbps Full Duplex) |
2000 Mbps
(1000 Mbps Full Duplex) |
| µ¿½Ã ¿¬°á |
1,000,000 |
1,000,000 |
| Áö¿¬½Ã°£ |
50 microseconds ÀÌÇÏ |
50 microseconds ÀÌÇÏ |
| °ø°Ý ¿ÏÈ ¹× ´ëÀÀ ½Ã°£ |
2 ÃÊ ÀÌÇÏ |
2 ÃÊ ÀÌÇÏ |
| Redundancy |
´ÜÀÏ Power Supply
´ÜÀÏ ÇÏµå µð½ºÅ© |
Redundant Power Supply
Redundant ÇÏµå µð½ºÅ© |
| »çÀÌÁî |
1-U rack mountable |
2-U rack mountable |
| ¾÷±×·¹À̵å |
2000 Mbps (1000 Mbps Full Duplex) ¹×
8 VIDs ·Î ¾÷±×·¹ÀÌµå °¡´É
(¶óÀ̼±½º Ãß°¡) |
8 VIDs ·Î ¾÷±×·¹ÀÌµå °¡´É
(¶óÀ̼±½º Ãß°¡) |
|
 |
IntruGuardÞäÀÇIG2000Àº DDoS°ø°ÝÀ» Æ÷ÇÔÇÑ ³×Æ®¿öÅ©½ºÄµ,³×Æ®¿öÅ© ºñ Á¤»ó»óŸ¦ ºÐ¼®ÇÏ¿© 2ÃÊ À̳»¿¡ À¯ÇØÆÐŶÀ»
Â÷´ÜÇÏ´Â ³×Æ®¿öÅ© º¸¾ÈÀåºñÀÔ´Ï´Ù. ASICs·Î Á¦Ç°À» Á¦ÀÛÇÏ¿©, IG2000Àº ´ë±Ô¸ðÀÇ °ø°Ý¿¡¼µµ Full-duplex 1Gbps
Æ®·¡ÇÈÀ» Á¦¾îÇÕ´Ï´Ù. |
º»Á¦Ç°Àº ¿¬¼ÓÀûÀ¸·Î Æ®·¡ÇÈ ÆÐÅÏÀ» ÇнÀÇÏ¿©, Åë½ÅÀÇ °èÃþÀÎ Layer2,3,4¿¡¼ 3¹é¸¸ °³ÀÇ À¯Çüº° ÀÓ°è°ª(Thesholds)À»
µ¿ÀûÀ¸·Î ÀÚµ¿ ¼³Á¤ÇÕ´Ï´Ù. ÀÌ´Â °ü¸®ÀÚÀÇ °³ÀÔ¾øÀÌ 2ÃÊ À̳»¿¡ °ø°ÝÀ» ŽÁöÇϰí Â÷´ÜÇϴ Ư¡ÀÌ ÀÖ½À´Ï´Ù. Ÿ»çÁ¦Ç°°ú
´Â ±¸º°µÇ´Â ¿¬¼Ó ÇнÀ´É·Â°ú ´Ù¾çÇÏ°í ¼¶¼¼ÇÑ ÀÓ°è°ªÀ¸·Î ¿ÀŽ ¾øÀÌ Á¤»óÆ®·¡ÇȰú °ø°ÝÆ®·¡ÇÈÀ» ¸íÈ®ÇÏ°Ô ±¸º°ÇÕ´Ï´Ù. |
º»Á¦Ç°ÀÇ ´Ù¾çÇÏ°í ¼¶¼¼ÇÑ ³×Æ®¿öÅ© ½Ã°¢È´Â ³×Æ®¿öÅ© °ø°ÝÀÇ ¿øÀÎÀ» ºÐ¼®ÇÏ¿© Æ®·¡ÇÈ ÆøÁÖ¸¦ Â÷
´ÜÇϸ鼵µ Á¤»óÆ®·¡
ÇÈÀ» Åë°úÇϵµ·Ï ¼³°èµÇ¾î ÀÖ½À´Ï´Ù.
°ø°ÝÁø¿øÁö ¼Ò½ºÃßÀû ±â´ÉÀº °ø°ÝÁø¿øÁöÀÇ IPÁÖ¼Ò¸¦ ¾Ë¾Æ³»¾î ÇØ´ç µµ¸ÞÀÎ °ü¸®ÀÚ
¿¡°Ô ¿¬¶ôÀ» ÃëÇÒ ¼ö ÀÖ½À´Ï´Ù. |
IG2000Àº ¿ú(Worm) ¹× Àº´ÐȰµ¿ÀÇ ÃâÇöÀ» »çÀü¿¡ ¹æÁöÇϱâ À§ÇØ Æ÷Æ®½ºÄµ,³×Æ®¿öÅ©½ºÄµ,´ÙÅ© ¾îµå·¹½º ½ºÄµÀ» Áï½Ã¿¡
Â÷´ÜÇÕ´Ï´Ù.
ÀÎÅͳÝÅë½Å¿¡¼ Àý´ë Á¸ÀçÇÒ ¼ö ¾ø´Â ÆÐŶÇì´õÀÇ ÀÌ»óÀ̳ª TCPÇÁ·ÎÅäÄÝÀÇ State ÀÌ»óÀ» Â÷´ÜÇÔ À¸·Î½á,
ºÒ·®ÆÐŶÀ» °É·¯ ³»´Â ±â´ÉÀ» Á¦°øÇÕ´Ï´Ù. |
Line-rate °³º°´ÜÀ§ÀÇ ACLs¸¦ Á¦°øÇÔÀ¸·Î½á, IG2000Àº ³×Æ®¿öÅ©¿¡ ºÒÇÊ¿äÇÑ ÇÁ·ÎÅäÄÝ, Æ÷Æ®, ToS, µîÀ» ¿øÃµ Â÷´ÜÇÏ¿©
¶ó¿ìÅ͸¦ º¸È£ÇÏ´Â ±â´ÉÀ» Á¦°øÇÕ´Ï´Ù. |
º» Á¦Ç°Àº ÇϳªÀÇ Àåºñ¿¡¼ 8°³ÀǹöÃò¾ó¸Ó½ÅÀ» Á¦°øÇÔÀ¸·Î½á, º¸È£ÇÒ ³×Æ®¿öÅ©±×·ì ¶Ç´Â È£½ºÆ®¸¦ °³º°°ü¸®ÇÒ ¼ö ÀÖ½À
´Ï´Ù. |
Á÷°üÀûÀÎ ¸®Æ÷ÆÃ ±â´ÉÀº °ü¸®Àڵ鿡°Ô Layer2~4ÀÇ °¢Á¾Æ÷Æ®, ÇÁ·ÎÅäÄÝ, ¿É¼Ç µîÀ» Á¦°øÇÔÀ¸·Î½á,
½±°Ô ³×Æ®¿öÅ©»óȲÀ»
ÆÄ¾ÇÇÒ ¼ö ÀÖ°Ô ÇÕ´Ï´Ù. ¶ÇÇÑ ÃÖ±Ù 5ºÐ Á¤º¸¿¡¼ ¿¬°£Á¤º¸¸¦ ºÐ¼®ÇÒ ¼ö ÀÖ´Â ±â´ÉÀ» Á¦°øÇÕ´Ï´Ù. |
º» Á¦Ç°Àº ¿¬¼ÓÀûÀÎ ¼ºñ½º¸¦ À¯ÁöÇÒ ¼ö ÀÖÀ» »Ó¸¸ ¾Æ´Ï¶ó, ´ë±Ô¸ðÀÇ °ø°Ý Áß¿¡µµ ¶ó¿ìÅÍ, ½ºÀ§Ä¡,
·Îµå¹ë·±¼, ¹æÈº®°ú
ÃÖÁ¾ÀûÀ¸·Î ¼¹öÀÇ °úºÎÇϰ¡ °É¸®Áö ¾Êµµ·Ï º¸È£ÇÕ´Ï´Ù. |
|
 |
| ±â ´É |
Çý ÅÃ |
| ¼¶¼¼ÇÑ ³×Æ®¿öÅ© ½Ã°¢È |
- ºñÁö´Ï½º ¸ñÇ¥¿Í ºÎÇÕÇÏ´Â Á¤Ã¥ °³¹ß |
| À§Çù ¿ÏÈ |
- ÀÚµ¿ÈµÈ DDos ¹æ¾î ¼ºñ½º¸¦ Á¦°ø, BotNet °ø°Ý, ¿ú ÃâÇöÀ» ¹æÁö |
| 1´ëÀÇ Àåºñ·Î 8´ëÀÇ È¿°ú |
- ³×Æ®¿öÅ© ±×·ìº° º¸¾È ¼³Á¤
- ÁÖ¿ä È£½ºÆ® °³º° °ü¸® |
| ´ë¿ªÆø °ü¸® |
- ¼ºñ½º °ø±Þ¾÷ÀÚµéÀÌ ¹Ì¸® Á¤ÀÇµÈ ´ë¿ªÆø¿¡ °¢ °í°´ ¶Ç´Â »ç¿ëÀÚ¸¦ Á¦ÇÑÇϵµ·Ï
Á¤Ã¥µéÀ» À¯Áö |
| Header/State Anomaly ¹æÁö |
- Clean network pipe
-³×Æ®¿öÅ© ¹× ¼ö¹ÝµÇ´Â ÀÎÇÁ¶óÀÇ ÀÌ¿ë °³¼± |
| Stealth Ȱµ¿ ¹æÁö |
- »çÀü Â÷´Ü
- À§Àå °ø°Ý »çÀü ŽÁö ¹× Â÷´Ü
- ¿ú ÃâÇö ¡ÈÄ ¹ß°ß |
|
 |
 |
 |
 |
³×Æ®¿öÅ©½Ã°¢È, ACLs, ´ë¿ªÆøÄÁÆ®·Ñ: |
 |
ARP, RARP, Broadcast, Multicast,, VLAN, Double Encapsulated VLAN, Non-IP, TOS, IP Options, Protocols,
Fragment, Source, Destination, TCP Ports, UDP Ports, ICMPTypes/Codes, TCP Options, SYN, connection establishment rate |
|
 |
Æ®·¡ÇÈ ¹× À̺¥Æ® ºÐ¼® |
 |
½Ã, ÀÏ, ÁÖ, ¿ù,¿¬ ´ÜÀ§ Æ®·¡ÇÈÀ» À§ÇÑ ±×·¡ÇÁ ¹× ¸®Æ÷Æ®
Top attacks, top attackers, top sources, top connections, top destinations, top scanners, top attacked services |
|
 |
Á¤ÂûÇàÀ§ ¹× ºñÁ¤»óÇàÀ§(Anomaly) ¹æÁö |
 |
Network Scan; Dark Address Scan, Port Scan
IP header checksum, Land attack, Loopback, address spoofing, Non-IPV4/V6, TCP, UDP, ICMP Header
checksum, Illegal TCP flag combination, Illegal TCP state transitions, TCP Sequence Number Violations, Foreign
TCP Packets |
|
 |
¼º´É¸ÞÆ®¸¯½º |
 |
Throughput : 2 Gbps(1 Gbps Full Duplex)
µ¿½Ã¿¬°á: 1,000,000
Latency(Áö¿¬½Ã°£): 50 microsecond ÀÌÇÏ
°ø°Ý¿ÏÈ´ëÀÀ½Ã°£: 2ÃÊÀÌÇÏ |
|
 |
ÀåÄ¡°ü¸® |
 |
SSLÀÇÀ¥ÀÎÅÍÆäÀ̽º
SNMP: 1, V2c, V3 Traps
À̸ÞÀÏ Å뺸 |
|
 |
ȯ°æ |
 |
¿î¿µ¿Âµµ: 0¡ÆC~ 40 ¡ÆC(32 ¡ÆF ~ 104 ¡ÆF)
½Àµµ: 5% -95% (non-condensing) |
|
 |
ÀϹݻçÇ× |
 |
Network Interface:10/100/1000 Base-T µ¥ÀÌÅÍÆ÷Æ®2 , 10/100/1000 Base-T Æ÷·»½ÄÆ÷Æ®2 ,10/100 Base-T °ü¸®Æ÷Æ®
Power: 100 VAC ~220 VAC, 250 Watts
Failover Áö¿ø: ¿ÜºÎ ¹×³»Àç
Å©±â: Rack mountable 2-U chassis, 3.40¡± (86.60 mm) H, 15.98¡±(431.40 mm) W,17.41¡± (442.38 mm) D
¹«°Ô: ÃÖ´ë33 lbs(15 kg) |
|
 |
 |
|
 |
| |
| |
|
 |
´ã´çÀÚ : ±è¹Î¼ö ºÎÀå |
|
¿¬¶ôó : 011-413-9246 |
e-mail : minsookim@nis.co.kr |
´ëÇ¥ÀüÈ : 02-890-7261 |
ÆÑ½º : 02-890-7260 |
|
 |
|
|
 |
|
 |
|
|