๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

* DevSecOps/Security

AWS re:Inforce 2025: ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ์˜ ํ˜„์žฌ์™€ ๋ฏธ๋ž˜ ๐Ÿ›ก๏ธ

๋“ค์–ด๊ฐ€๋ฉฐ ๐Ÿš€

2025๋…„ 6์›” ํ•„๋ผ๋ธํ”ผ์•„์—์„œ ๊ฐœ์ตœ๋œ AWS re:Inforce๋Š” 5,800๋ช…์˜ ๋ณด์•ˆ ์ „๋ฌธ๊ฐ€๋“ค์ด ๋ชจ์—ฌ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ์˜ ์ตœ์‹  ํŠธ๋ Œ๋“œ์™€ ๊ธฐ์ˆ ์„ ๊ณต์œ ํ•˜๋Š” ์žฅ์ด์—ˆ์Šต๋‹ˆ๋‹ค. ํŠนํžˆ ํ•œ๊ตญ ์ฐธ๊ฐ€์ž๊ฐ€ ์ „๋…„ ๋Œ€๋น„ 2๋ฐฐ ์ฆ๊ฐ€ํ•˜๋ฉฐ ๊ตญ๋‚ด ๊ธฐ์—…๋“ค์˜ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ์— ๋Œ€ํ•œ ๊ด€์‹ฌ์ด ๋†’์•„์ง€๊ณ  ์žˆ์Œ์„ ๋ณด์—ฌ์ฃผ์—ˆ์Šต๋‹ˆ๋‹ค ๐Ÿ“ˆ.

์ด๋ฒˆ ํฌ์ŠคํŠธ์—์„œ๋Š” ์ฝ˜ํผ๋Ÿฐ์Šค์˜ ์ฃผ์š” ์—…๋ฐ์ดํŠธ์™€ ํ•จ๊ป˜ ๋‹ค์–‘ํ•œ ๊ด€์ ์—์„œ์˜ ๋ณด์•ˆ ์ธ์‚ฌ์ดํŠธ๋ฅผ ๊ณต์œ ํ•ฉ๋‹ˆ๋‹ค:

  • AWS์˜ ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์„œ๋น„์Šค ๋ฐ ๊ธฐ๋Šฅ ์—…๋ฐ์ดํŠธ
  • ๊ฐœ์ธ ์—ฐ๊ตฌ ์ฐจ์›์˜ ๋ชจ์˜ํ•ดํ‚น ์‹œ๋‚˜๋ฆฌ์˜ค์™€ ๊ตํ›ˆ
  • ์‹ค์ œ ๊ธฐ์—…๋“ค์˜ ๋ณด์•ˆ ๊ตฌ์ถ• ์‚ฌ๋ก€ (๋‹น๊ทผ๋งˆ์ผ“, WAF ํ™œ์šฉ ์‚ฌ๋ก€)
  • ๋น„์šฉ ํšจ์œจ์ ์ธ ๋ณด์•ˆ ๋„๊ตฌ ์„ ํƒ ๊ฐ€์ด๋“œ

Part 1: AWS ๋ณด์•ˆ ์ธํ”„๋ผ์˜ ์ง„ํ™” ๐Ÿ”’

๋ธ”๋ž™ํฟ(Black Pot)๊ณผ ๋งค๋“œํŒŸ(Mad Pot): AWS์˜ ๋‚ด๋ถ€ ๋ณด์•ˆ ๋„๊ตฌ ์ตœ์ดˆ ๊ณต๊ฐœ

AWS๊ฐ€ ์ด๋ฒˆ ์ฝ˜ํผ๋Ÿฐ์Šค์—์„œ ์ฒ˜์Œ ๊ณต๊ฐœํ•œ ๋‚ด๋ถ€ ๋ณด์•ˆ ์‹œ์Šคํ…œ์€ ๋†€๋ผ์šด ๊ทœ๋ชจ์™€ ํšจ์œจ์„ฑ์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค:

๋ธ”๋ž™ํฟ (Black Pot) ๐Ÿ’ช

  • ์‹œ๊ฐ„๋‹น 13์กฐ ๊ฐœ์˜ ๋กœ๊ทธ ์ฒ˜๋ฆฌ
  • 3๋ถ„๋งˆ๋‹ค IP ์ฐจ๋‹จ ๋ฆฌ์ŠคํŠธ ์—…๋ฐ์ดํŠธ
  • ๋งค ์—…๋ฐ์ดํŠธ์‹œ 12.5%์˜ IP๊ฐ€ ์ƒˆ๋กญ๊ฒŒ ์ถ”๊ฐ€/๋ณ€๊ฒฝ

๋งค๋“œํŒŸ (Mad Pot) ๐Ÿฏ

  • ์˜๋„์ ์œผ๋กœ ์ทจ์•ฝํ•ด ๋ณด์ด๋Š” ํ—ˆ๋‹ˆํŒŸ ์‹œ์Šคํ…œ
  • ๊ณต๊ฒฉ์ž ํ–‰๋™ ํŒจํ„ด ์‹ค์‹œ๊ฐ„ ์ˆ˜์ง‘
  • ์ˆ˜์ง‘๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ธ”๋ž™ํฟ์— ์ฆ‰์‹œ ๋ฐ˜์˜

๐Ÿ“Š ํ•ต์‹ฌ ํ†ต๊ณ„: ์™ธ๋ถ€ ํฌํŠธ๊ฐ€ ์—ด๋ฆฌ๋ฉด ํ‰๊ท  3๋ถ„ ์ด๋‚ด ๊ณต๊ฒฉ ์‹œ๋„ ๋ฐœ์ƒ

์ฃผ์š” ๋ณด์•ˆ ์„œ๋น„์Šค ์—…๋ฐ์ดํŠธ โœจ

Security Hub ์ „๋ฉด ๊ฐœํŽธ

  • ํ”„๋ฆฌ๋ทฐ ๋ฒ„์ „ ๋ฌด๋ฃŒ ์ œ๊ณต (GA ์ „๊นŒ์ง€)
  • ๋‹ค์–‘ํ•œ ์„œ๋น„์Šค ๋ฐ์ดํ„ฐ์˜ ๋งฅ๋ฝ์  ํ†ตํ•ฉ ๋ถ„์„
  • ๊ธฐ์กด ๋ฒ„์ „์€ CSPM(Cloud Security Posture Management)์œผ๋กœ ๋ช…์นญ ๋ณ€๊ฒฝ

Network Security Director ์‹ ๊ทœ ์ถœ์‹œ

  • CloudFront, API Gateway, ALB์˜ ์˜๋„์น˜ ์•Š์€ ์™ธ๋ถ€ ๋…ธ์ถœ ์ž๋™ ํƒ์ง€
  • ์‹œ๊ฐ์  ๋„คํŠธ์›Œํฌ ํ† ํด๋กœ์ง€ ์ œ๊ณต
  • ์›ํด๋ฆญ ๋ณด์•ˆ ์ˆ˜์ • ๊ธฐ๋Šฅ

IAM ๋ฐ ์ ‘๊ทผ ๊ด€๋ฆฌ ๋Œ€ํญ ๊ฐ•ํ™”

  • 2024๋…„ 6์›”๋ถ€ํ„ฐ MFA ์˜๋ฌดํ™”
  • Verify Permissions ๊ฐ€๊ฒฉ 30๋ฐฐ ์ธํ•˜ ($150 → $5/๋ฐฑ๋งŒ ๊ฑด)
  • Access Analyzer ์ƒˆ๋กœ์šด ๊ธฐ๋Šฅ ์ถ”๊ฐ€

 

Part 2: ๊ฐœ์ธ ๋ชจ์˜ํ•ดํ‚น ์—ฐ๊ตฌ ์‚ฌ๋ก€ ๐Ÿ”

โš ๏ธ ์ค‘์š” ๊ณ ์ง€: ๋‹ค์Œ ๋‚ด์šฉ์€ ๊ฒฉ๋ฆฌ๋œ ๊ฐœ์ธ ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์—์„œ ์ง„ํ–‰ํ•œ ๋ณด์•ˆ ์—ฐ๊ตฌ์ž…๋‹ˆ๋‹ค. ์‹ค์ œ ํ”„๋กœ๋•์…˜ ํ™˜๊ฒฝ์ด ์•„๋‹ˆ๋ฉฐ, ์ˆœ์ˆ˜ ๊ต์œก ๋ชฉ์ ์œผ๋กœ๋งŒ ๊ณต์œ ํ•ฉ๋‹ˆ๋‹ค. ์‹ค์ œ ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ๋ฌด๋‹จ ์นจ์ž…์€ ๋ฒ•์  ์ฒ˜๋ฒŒ ๋Œ€์ƒ์ž…๋‹ˆ๋‹ค.

์—ฐ๊ตฌ ๋ฐฐ๊ฒฝ ๋ฐ ๋ชฉ์ 

AWS ํ™˜๊ฒฝ์˜ ์ž ์žฌ์  ์ทจ์•ฝ์ ์„ ์ดํ•ดํ•˜๊ณ  ํšจ๊ณผ์ ์ธ ๋ฐฉ์–ด ์ „๋žต์„ ์ˆ˜๋ฆฝํ•˜๊ธฐ ์œ„ํ•ด, ์™„์ „ํžˆ ๊ฒฉ๋ฆฌ๋œ ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์—์„œ ๋‹ค์–‘ํ•œ ๊ณต๊ฒฉ ์‹œ๋‚˜๋ฆฌ์˜ค๋ฅผ ์žฌํ˜„ํ•˜๊ณ  ๋ถ„์„ํ–ˆ์Šต๋‹ˆ๋‹ค.

์‹œ๋‚˜๋ฆฌ์˜ค 1: ALB + IMDSv1 ์กฐํ•ฉ์˜ ์น˜๋ช…์  ์ทจ์•ฝ์ 

ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ ๊ตฌ์„ฑ:

ํ…Œ์ŠคํŠธ ์ธํ”„๋ผ (์˜๋„์  ์ทจ์•ฝ ์„ค์ •):
  - ALB: Internet-facing 
  - EC2: IMDSv1 ํ™œ์„ฑํ™”
  - ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜: SSRF ์ทจ์•ฝ์  ํฌํ•จ

๋ฐœ๊ฒฌ๋œ ๊ณต๊ฒฉ ๊ฒฝ๋กœ:

1๏ธโƒฃ SSRF ์ทจ์•ฝ์  ์•…์šฉ

# ์ทจ์•ฝํ•œ ํ”„๋ก์‹œ ์—”๋“œํฌ์ธํŠธ ์˜ˆ์‹œ
@app.route("/proxy")
def vulnerable_proxy():
    url = request.args.get("url")  # ์ž…๋ ฅ ๊ฒ€์ฆ ์—†์Œ!
    return urllib.request.urlopen(url).read()

 

AI (Amazon Q Developer ๋ฐ Claude, Cursor)๋ฅผ ํ™œ์šฉํ•œ ๊ณต๊ฒฉ ์‹œ๋‚˜๋ฆฌ์˜ค ์ž‘์„ฑ ๋ฐ ๊ณต๊ฒฉ ์‹œ์ž‘

2๏ธโƒฃ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ์„œ๋น„์Šค ์ ‘๊ทผ

# ๊ณต๊ฒฉ ์‹œ๋ฎฌ๋ ˆ์ด์…˜
curl "http://test-alb/proxy?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/"

3๏ธโƒฃ ๊ถŒํ•œ ํƒˆ์ทจ ๋ฐ ์•…์šฉ ๊ฐ€๋Šฅ์„ฑ

  • IAM ์—ญํ•  ํฌ๋ฆฌ๋ด์…œ ํš๋“
  • ๋ฐฑ๋„์–ด ์‚ฌ์šฉ์ž ์ƒ์„ฑ ๊ฐ€๋Šฅ
  • ๋ฆฌ์†Œ์Šค ๋ฌด๋‹จ ์ƒ์„ฑ/์‚ญ์ œ ๊ฐ€๋Šฅ

ํ•ต์‹ฌ ๋ฐฉ์–ด ์ „๋žต:

# ๐Ÿ›ก๏ธ ์ฆ‰์‹œ ์ ์šฉ ํ•„์ˆ˜: IMDSv2 ๊ฐ•์ œ ์„ค์ •
aws ec2 modify-instance-metadata-options \
    --instance-id <instance-id> \
    --http-tokens required \
    --http-endpoint enabled \
    --http-put-response-hop-limit 1

์•„ํ‚คํ…์ฒ˜ ๊ฐœ์„  ๋ฐฉ์•ˆ:

ํ˜„์žฌ (์ทจ์•ฝ):
  Internet → ALB(Internet-facing) → EC2(IMDSv1)

๋ชฉํ‘œ (์•ˆ์ „):
  Internet → CloudFront → ALB(Internal) → EC2(IMDSv2)
  
์ถ”๊ฐ€ ๋ณด์•ˆ์ธต:
  - WAF at CloudFront
  - PrivateLink for internal communication  
  - Session Manager (SSH ์ œ๊ฑฐ)

 

์‹œ๋‚˜๋ฆฌ์˜ค 2: ๋žœ์„ฌ์›จ์–ด ๋ฐ ํฌ๋ฆฝํ† ๋งˆ์ด๋‹ ์‹œ๋ฎฌ๋ ˆ์ด์…˜

ํ…Œ์ŠคํŠธํ•œ ๊ณต๊ฒฉ ํŒจํ„ด๋“ค:

๐Ÿ”ด ๋žœ์„ฌ์›จ์–ด ํ–‰๋™ ํŒจํ„ด

  • ๋Œ€๋Ÿ‰ ํŒŒ์ผ ์•”ํ˜ธํ™” ์‹œ๋ฎฌ๋ ˆ์ด์…˜
  • ๋ฐฑ์—… ์‚ญ์ œ ์‹œ๋„
  • ์Šค๋ƒ…์ƒท ํŒŒ๊ดด ์‹œ๋„

โ›๏ธ ํฌ๋ฆฝํ† ๋งˆ์ด๋‹ ๊ณต๊ฒฉ

  • ๊ณ ์„ฑ๋Šฅ GPU ์ธ์Šคํ„ด์Šค ์ƒ์„ฑ ์‹œ๋„
  • ์˜์‹ฌ์Šค๋Ÿฌ์šด ๋„๋ฉ”์ธ ํ†ต์‹ 
  • CPU ๋ฆฌ์†Œ์Šค ๊ณผ๋‹ค ์‚ฌ์šฉ

GuardDuty ํƒ์ง€ ๊ฒฐ๊ณผ:

ํƒ์ง€์œจ:
  - ๋น„ํŠธ์ฝ”์ธ ๋งˆ์ด๋‹: 100%
  - ๋น„์ •์ƒ API ํ˜ธ์ถœ: 95%
  - ๋ฐ์ดํ„ฐ ์œ ์ถœ ์‹œ๋„: 90%
  
์ฃผ์š” ํƒ์ง€ ํŒจํ„ด:
  - CryptoCurrency:EC2/BitcoinTool.B!DNS
  - UnauthorizedAccess:EC2/SSHBruteForce
  - Impact:EC2/MaliciousDomainRequest

 

์‹œ๋‚˜๋ฆฌ์˜ค 3: ์™ธ๋ถ€ ๋…ธ์ถœ ๋ฆฌ์†Œ์Šค ํƒ์ง€

Access Analyzer ํ™œ์šฉ ๊ฒฐ๊ณผ:

{
  "findings": [
    {
      "type": "S3 Bucket Public Access",
      "severity": "HIGH",
      "recommendation": "Enable Block Public Access"
    },
    {
      "type": "IAM Role External Sharing",
      "severity": "MEDIUM",
      "recommendation": "Review trust relationship"
    }
  ]
}

 

์—ฐ๊ตฌ ๊ฒฐ๊ณผ ๋ฐ ๊ตํ›ˆ

ํ•ต์‹ฌ ๋ฐœ๊ฒฌ์‚ฌํ•ญ:
  1. IMDSv1 + Internet-facing ALB = Critical Risk
  2. ๊ธฐ๋ณธ ๋ณด์•ˆ ์„ค์ •์˜ ์ค‘์š”์„ฑ
  3. Amazon Linux 2023์˜ ์šฐ์ˆ˜ํ•œ ๊ธฐ๋ณธ ๋ณด์•ˆ
  
์ฆ‰์‹œ ์กฐ์น˜ ์‚ฌํ•ญ:
  โœ… IMDSv2 ์ „ํ™˜ (์ตœ์šฐ์„ )
  โœ… ์ •๊ธฐ์  Access Analyzer ์Šค์บ”
  โœ… ์ตœ์†Œ ๊ถŒํ•œ ์›์น™ ์ ์šฉ
  โณ ALB Internal ์ „ํ™˜ (์žฅ๊ธฐ ๊ณผ์ œ)

Part 3: ์‹ค์ œ ๊ธฐ์—… ๋ณด์•ˆ ๊ตฌ์ถ• ์‚ฌ๋ก€ ๐Ÿข

๋‹น๊ทผ๋งˆ์ผ“: AI ์‹œ๋Œ€์˜ ์‹ค์šฉ์  ๋ณด์•ˆ ์ „๋žต ๐Ÿฅ•

๋‹น๊ทผ๋งˆ์ผ“์€ AI ๋„๊ตฌ๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ํ™œ์šฉํ•˜๋ฉด์„œ๋„ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๋Š” ๊ท ํ˜•์žกํžŒ ์ ‘๊ทผ๋ฒ•์„ ๊ตฌํ˜„ํ–ˆ์Šต๋‹ˆ๋‹ค.

AI ์•ˆ์ „ ์‚ฌ์šฉ 3๋‹จ๊ณ„ ํ”„๋ ˆ์ž„์›Œํฌ:

1๏ธโƒฃ ๋„คํŠธ์›Œํฌ ๋ ˆ๋ฒจ ๋ณดํ˜ธ

DLP ํŒจํ„ด ์˜ˆ์‹œ:
  AWS_ACCESS_KEY: AKIA[0-9A-Z]{16}
  AWS_SECRET: [0-9a-zA-Z/+=]{40}
  PII_DATA: ์ฃผ๋ฏผ๋“ฑ๋ก๋ฒˆํ˜ธ|์‹ ์šฉ์นด๋“œ๋ฒˆํ˜ธ

2๏ธโƒฃ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ ˆ๋ฒจ ์ œ์–ด

  • ํ”„๋ผ์ด๋ฒ„์‹œ ๋ชจ๋“œ ๊ฐ•์ œ ์„ค์ •
  • ๋ฐ์ดํ„ฐ ํ•™์Šต ๊ฑฐ๋ถ€ ์˜ต์…˜ ํ™œ์„ฑํ™”
  • ํ”„๋กฌํ”„ํŠธ ๋กœ๊น… ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง

3๏ธโƒฃ ๋””๋ฐ”์ด์Šค ๋ ˆ๋ฒจ ๊ด€๋ฆฌ

  • MDM์„ ํ†ตํ•œ ๋‹จ๋ง๊ธฐ ์ •์ฑ… ์ ์šฉ
  • ๋น„์ค€์ˆ˜ ๋””๋ฐ”์ด์Šค ์ ‘๊ทผ ์ฐจ๋‹จ

AI ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์ž๋™ํ™”:

  • Bedrock: ๋ณด์•ˆ ์ด๋ฒคํŠธ 1์ฐจ ๋ถ„์„
  • SageMaker: ์ •ํƒ/์˜คํƒ 95% ์ •ํ™•๋„ ํŒ๋‹จ
  • Slack ํ†ตํ•ฉ: ์‹ค์‹œ๊ฐ„ ์•Œ๋ฆผ ๋ฐ ๋Œ€์‘

์‹ค์ „ ํ›ˆ๋ จ ํ”„๋กœ๊ทธ๋žจ:

๋ชจ์˜ ์‹œ๋‚˜๋ฆฌ์˜ค:
  - ์•”ํ˜ธํ™”ํ ๋งˆ์ด๋‹ ํƒ์ง€
  - ๋ฐ์ดํ„ฐ ์œ ์ถœ ์‹œ๋„
  - ๊ถŒํ•œ ์—์Šค์ปฌ๋ ˆ์ด์…˜
  
์ฐธ์—ฌ ์œ ๋„:
  - ๊ฒŒ์ž„ํ™”๋œ ๋ณด์•ˆ ํ€ด์ฆˆ
  - ์„ฑ๊ณผ ๊ธฐ๋ฐ˜ ์ธ์„ผํ‹ฐ๋ธŒ
  - Amazon Q ํ™œ์šฉ ๊ต์œก

์‹ค์ œ ๊ธฐ์—…์˜ WAF ํ™œ์šฉ ์„ฑ๊ณผ ๐Ÿ›ก๏ธ

๋งŽ์€ ๊ธฐ์—…๋“ค์ด AWS WAF๋ฅผ ํ†ตํ•ด ํšจ๊ณผ์ ์œผ๋กœ DDoS์™€ ๋ด‡ ๊ณต๊ฒฉ์„ ๋ฐฉ์–ดํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

 

์ผ์ผ ํ‰๊ท  ๋ฐฉ์–ด:
  - ์•…์„ฑ ๋ด‡ ์ฐจ๋‹จ: 2.3M ์š”์ฒญ
  - DDoS ๊ณต๊ฒฉ ๋ฐฉ์–ด: 37๊ฑด (์„ฑ๊ณต๋ฅ  100%)
  - False Positive: 0.02% (๋งค์šฐ ๋‚ฎ์Œ)

JA4 ํ•‘๊ฑฐํ”„๋ฆฐํŠธ ํ˜์‹ :

  • TLS ํ•ธ๋“œ์…ฐ์ดํฌ ๊ธฐ๋ฐ˜ 36์ž๋ฆฌ ๊ณ ์œ  ํ•ด์‹œ
  • IP/User-Agent ๋ณ€๊ฒฝ์œผ๋กœ ์šฐํšŒ ๋ถˆ๊ฐ€
  • ์•Œ๋ ค์ง„ ๋ด‡ ํŒจํ„ด ์ฆ‰์‹œ ์‹๋ณ„

์ƒˆ๋กœ์šด WAF ์ฝ˜์†” ์žฅ์ :

  • ์„ค์ • ์‹œ๊ฐ„ 80% ๋‹จ์ถ•
  • Protection Pack์œผ๋กœ ์ฆ‰์‹œ ์ ์šฉ
  • ๋‹จ์ผ ํŽ˜์ด์ง€ ์„ค์ • ์™„๋ฃŒ

Part 4: Datadog SIEM๊ณผ Cloud Security ๋ชจ๋‹ˆํ„ฐ๋ง ์ „๋žต ๐Ÿ”

Datadog Cloud SIEM ํ™œ์šฉ ์‚ฌ๋ก€

์‹ค์‹œ๊ฐ„ ์œ„ํ˜‘ ํƒ์ง€ ๋ฐ ๋Œ€์‘:

Datadog SIEM ํ•ต์‹ฌ ๊ธฐ๋Šฅ:
  Log Management:
    - ์ดˆ๋‹น ์ˆ˜๋ฐฑ๋งŒ ๋กœ๊ทธ ์ฒ˜๋ฆฌ
    - 15๊ฐœ์›” ๋กœ๊ทธ ๋ณด๊ด€ (์ปดํ”Œ๋ผ์ด์–ธ์Šค)
    - Hot/Warm/Cold ํ‹ฐ์–ด๋ง์œผ๋กœ ๋น„์šฉ ์ตœ์ ํ™”
  
  Detection Rules:
    - 400+ ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ ํƒ์ง€ ๊ทœ์น™
    - MITRE ATT&CK ํ”„๋ ˆ์ž„์›Œํฌ ๋งคํ•‘
    - ์ปค์Šคํ…€ ๊ทœ์น™ ์ƒ์„ฑ ์ง€์›
  
  Investigation:
    - Security Signal ์ž๋™ ์ƒ์„ฑ
    - ๊ด€๋ จ ๋กœ๊ทธ ์ž๋™ ๊ทธ๋ฃนํ•‘
    - ํƒ€์ž„๋ผ์ธ ๊ธฐ๋ฐ˜ ํฌ๋ Œ์‹

์‹ค์ œ ํ™œ์šฉ ์‹œ๋‚˜๋ฆฌ์˜ค:

1๏ธโƒฃ ์ด์ƒ ์ ‘๊ทผ ํŒจํ„ด ํƒ์ง€

# Datadog ํƒ์ง€ ๊ทœ์น™ ์˜ˆ์‹œ
rule = {
    "name": "Unusual IAM Access Pattern",
    "query": """
        source:aws.cloudtrail 
        @evt.name:(AssumeRole OR GetSessionToken)
        | group by @usr.name
        | where count > 50
    """,
    "threshold": 50,
    "timeWindow": "5m",
    "severity": "HIGH"
}

2๏ธโƒฃ ์ž๋™ํ™”๋œ ์ธ์‹œ๋˜ํŠธ ๋Œ€์‘

์›Œํฌํ”Œ๋กœ์šฐ:
  1. ์ด์ƒ ํƒ์ง€ → Security Signal ์ƒ์„ฑ
  2. Slack/PagerDuty ์•Œ๋ฆผ
  3. ์ž๋™ ๊ฒฉ๋ฆฌ ์Šคํฌ๋ฆฝํŠธ ์‹คํ–‰
  4. ํฌ๋ Œ์‹ ๋ฐ์ดํ„ฐ ์ˆ˜์ง‘
  5. ์ธ์‹œ๋˜ํŠธ ํ‹ฐ์ผ“ ์ƒ์„ฑ

Datadog Cloud Security Monitoring

ํ†ตํ•ฉ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ๊ฐ€์‹œ์„ฑ:

Cloud Security Management:
  CSPM (Cloud Security Posture Management):
    - 800+ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ทœ์น™
    - CIS, PCI-DSS, HIPAA ๋ฒค์น˜๋งˆํฌ
    - ์ž๋™ ์ˆ˜์ • ์ œ์•ˆ
    
  CWP (Cloud Workload Protection):
    - ๋Ÿฐํƒ€์ž„ ๋ณด์•ˆ ๋ชจ๋‹ˆํ„ฐ๋ง
    - ์ปจํ…Œ์ด๋„ˆ/์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ๋ณด์•ˆ
    - ํŒŒ์ผ ๋ฌด๊ฒฐ์„ฑ ๋ชจ๋‹ˆํ„ฐ๋ง
    
  CSM Threats:
    - ์‹ค์‹œ๊ฐ„ ์œ„ํ˜‘ ํƒ์ง€
    - ํ–‰๋™ ๊ธฐ๋ฐ˜ ๋ถ„์„
    - ๋„คํŠธ์›Œํฌ ์ด์ƒ ํƒ์ง€

๋น„์šฉ ์ตœ์ ํ™” ์ „๋žต:

ํšจ์œจ์  ์‚ฌ์šฉ ๋ฐฉ๋ฒ•:
  ํ•„์ˆ˜ ์œ ์ง€:
    - Cloud SIEM (๋กœ๊ทธ ๋ถ„์„ ํ•ต์‹ฌ)
    - CSM Threats (์‹ค์‹œ๊ฐ„ ์œ„ํ˜‘ ํƒ์ง€)
    
  ์„ ํƒ์  ์‚ฌ์šฉ:
    - CSPM → Prowler + AWS Config
    - CWP → GuardDuty + Inspector
    
  ๋กœ๊ทธ ๊ด€๋ฆฌ ์ตœ์ ํ™”:
    - ํ•„์ˆ˜ ๋กœ๊ทธ๋งŒ ์ธ๋ฑ์‹ฑ
    - ๋‚˜๋จธ์ง€๋Š” Archive๋กœ ์ €์žฅ
    - Rehydration์œผ๋กœ ํ•„์š”์‹œ ๋ณต๊ตฌ
    
์›” ๋น„์šฉ ์˜ˆ์‹œ (100 hosts):
  ์ „์ฒด ๊ธฐ๋Šฅ: $3,000-5,000
  ์ตœ์ ํ™” ํ›„: $1,000-1,500 (70% ์ ˆ๊ฐ)

์‹ค์ „ ๋ชจ๋‹ˆํ„ฐ๋ง ๋Œ€์‹œ๋ณด๋“œ ๊ตฌ์„ฑ:

ํ•ต์‹ฌ ๋Œ€์‹œ๋ณด๋“œ:
  Executive Dashboard:
    - ์ „์ฒด ๋ณด์•ˆ ์ ์ˆ˜
    - ์ฃผ์š” ์œ„ํ˜‘ ํŠธ๋ Œ๋“œ
    - ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ƒํƒœ
    
  SOC Dashboard:
    - ์‹ค์‹œ๊ฐ„ ์•Œ๋ฆผ
    - ์ง„ํ–‰์ค‘์ธ ์ธ์‹œ๋˜ํŠธ
    - ๋Œ€์‘ ๋ฉ”ํŠธ๋ฆญ
    
  Compliance Dashboard:
    - CIS ๋ฒค์น˜๋งˆํฌ ์ ์ˆ˜
    - ๋ฏธ์ค€์ˆ˜ ๋ฆฌ์†Œ์Šค ๋ชฉ๋ก
    - ์ˆ˜์ • ์šฐ์„ ์ˆœ์œ„
    
  Cost Dashboard:
    - ๋ณด์•ˆ ๋„๊ตฌ๋ณ„ ๋น„์šฉ
    - ๋กœ๊ทธ ๋ณผ๋ฅจ ํŠธ๋ Œ๋“œ
    - ์ตœ์ ํ™” ๊ธฐํšŒ

Part 5: AWS + Datadog + ์˜คํ”ˆ์†Œ์Šค ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ์ „๋žต ๐Ÿ’ฐ

ํ†ตํ•ฉ ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ ์„ค๊ณ„

Prowler + AWS Config ํ™œ์šฉ ์ „๋žต:

์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ ๊ฒ€ ์ฒด๊ณ„:
  Prowler:
    ์—ญํ• : ์ •๊ธฐ์ ์ธ ์‹ฌ์ธต ๋ณด์•ˆ ๊ฐ์‚ฌ
    ์‹คํ–‰: ์ผ์ผ/์ฃผ๊ฐ„ ์Šค์ผ€์ค„
    ๋ฒ”์œ„: 
      - CIS Benchmark Level 1&2
      - PCI-DSS, HIPAA, GDPR
      - ์ปค์Šคํ…€ ๋ณด์•ˆ ์ •์ฑ…
    
  AWS Config:
    ์—ญํ• : ์‹ค์‹œ๊ฐ„ ๊ตฌ์„ฑ ๋ณ€๊ฒฝ ๋ชจ๋‹ˆํ„ฐ๋ง
    ๊ทœ์น™:
      - required-tags (ํƒœ๊น… ์ •์ฑ…)
      - s3-bucket-public-read-prohibited
      - iam-password-policy
      - ec2-imdsv2-check
    ๋Œ€์‘: ์ž๋™ ์ˆ˜์ • ์•ก์…˜
    
  ํ†ตํ•ฉ ๋ฐฉ๋ฒ•:
    - Config ๋ณ€๊ฒฝ ์ด๋ฒคํŠธ → Prowler ์ฆ‰์‹œ ์Šค์บ”
    - Prowler ๊ฒฐ๊ณผ → Config Aggregator๋กœ ์ˆ˜์ง‘
    - ํ†ตํ•ฉ ๋Œ€์‹œ๋ณด๋“œ์—์„œ ์ „์ฒด ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™•์ธ

Security Hub ํ†ตํ•ฉ ์ „๋žต

์ค‘์•™ํ™”๋œ ๋ณด์•ˆ ๊ด€๋ฆฌ:

Security Hub ํ†ตํ•ฉ ๊ตฌ์„ฑ:
  ๋ฐ์ดํ„ฐ ์†Œ์Šค:
    AWS ๋„ค์ดํ‹ฐ๋ธŒ:
      - GuardDuty (์œ„ํ˜‘ ํƒ์ง€)
      - Inspector (์ทจ์•ฝ์  ์Šค์บ”)
      - Access Analyzer (๊ถŒํ•œ ๋ถ„์„)
      - Config (์ปดํ”Œ๋ผ์ด์–ธ์Šค)
      - Macie (๋ฐ์ดํ„ฐ ๋ณดํ˜ธ)
    
    ์„œ๋“œํŒŒํ‹ฐ:
      - Prowler ๊ฒฐ๊ณผ (ASFF ํ˜•์‹)
      - Datadog Security Signals
    
  ํ†ตํ•ฉ ์›Œํฌํ”Œ๋กœ์šฐ:
    1. ๋ชจ๋“  ๋ณด์•ˆ ์ด๋ฒคํŠธ → Security Hub
    2. ์‹ฌ๊ฐ๋„๋ณ„ ์ž๋™ ๋ถ„๋ฅ˜
    3. ์ž๋™ ํ‹ฐ์ผ“ ์ƒ์„ฑ (Critical/High)
    4. Datadog SIEM์œผ๋กœ ์ถ”๊ฐ€ ๋ถ„์„
    5. ๋Œ€์‘ ํ”Œ๋ ˆ์ด๋ถ ์ž๋™ ์‹คํ–‰

๋น„์šฉ ํšจ์œจ์  ๊ตฌ์„ฑ ์˜ˆ์‹œ:

์›”๊ฐ„ ๋น„์šฉ ๋ถ„์„ (100 AWS ๋ฆฌ์†Œ์Šค ๊ธฐ์ค€):
  
  ๊ธฐ๋ณธ ๋ณด์•ˆ ์Šคํƒ:
    Security Hub: $0.001/check (ํ”„๋ฆฌ๋ทฐ ๋ฌด๋ฃŒ)
    GuardDuty: ~$50
    Config: ~$30 (๊ทœ์น™ 20๊ฐœ)
    Prowler: $0 (์˜คํ”ˆ์†Œ์Šค)
    ์†Œ๊ณ„: ~$80
  
  Datadog ์„ ํƒ์  ์ถ”๊ฐ€:
    SIEM Lite: ~$500 (ํ•„์ˆ˜ ๋กœ๊ทธ๋งŒ)
    CSM Threats: ~$300
    ์†Œ๊ณ„: ~$800
  
  ์ด ๋น„์šฉ: ~$880/์›”
  
  vs ์ „์ฒด Datadog ์‚ฌ์šฉ: $3,000+/์›”
  ์ ˆ๊ฐ์•ก: 70% ์ด์ƒ

์‹ค์ „ ๊ตฌํ˜„ ๋กœ๋“œ๋งต

Phase 1 (1๊ฐœ์›”):
  - Security Hub ํ™œ์„ฑํ™”
  - GuardDuty ๊ตฌ์„ฑ
  - Prowler ์ผ์ผ ์Šค์บ” ์„ค์ •
  - AWS Config ํ•ต์‹ฌ ๊ทœ์น™ 20๊ฐœ
  
Phase 2 (2-3๊ฐœ์›”):
  - Datadog SIEM ๋„์ž… (ํ•„์ˆ˜ ๋กœ๊ทธ๋งŒ)
  - Security Hub ์ปค์Šคํ…€ ํ†ตํ•ฉ
  - ์ž๋™ ๋Œ€์‘ ํ”Œ๋ ˆ์ด๋ถ 5๊ฐœ
  
Phase 3 (4-6๊ฐœ์›”):
  - ์ „์ฒด ํ†ตํ•ฉ ๋Œ€์‹œ๋ณด๋“œ
  - AI ๊ธฐ๋ฐ˜ ์ด์ƒ ํƒ์ง€
  - 24/7 ๋ชจ๋‹ˆํ„ฐ๋ง ์ฒด๊ณ„
  
์˜ˆ์ƒ ํšจ๊ณผ:
  - ๋ณด์•ˆ ์‚ฌ๊ณ  ํƒ์ง€ ์‹œ๊ฐ„: 24์‹œ๊ฐ„ → 5๋ถ„
  - False Positive: 50% → 10%
  - ์ˆ˜๋™ ๋Œ€์‘: 80% → 20%

๋ณด์•ˆ ์„ฑ์ˆ™๋„ ๋กœ๋“œ๋งต ๐Ÿ“Š

Level 1: Essential โญ

  • [x] Root ๊ณ„์ • MFA
  • [x] CloudTrail ํ™œ์„ฑํ™”
  • [x] S3 ๋ฒ„ํ‚ท ๋ณดํ˜ธ
  • [x] ๊ธฐ๋ณธ ๋ชจ๋‹ˆํ„ฐ๋ง

Level 2: Standard โญโญ

  • [x] GuardDuty ํ™œ์„ฑํ™”
  • [x] IMDSv2 ์ „์ฒด ์ ์šฉ
  • [ ] Security Hub + Prowler
  • [ ] AWS Config ๊ทœ์น™ ์„ค์ •

Level 3: Advanced โญโญโญ

  • [x] Datadog SIEM ๋ถ€๋ถ„ ๋„์ž…
  • [ ] ์ž๋™ํ™”๋œ ๋Œ€์‘ ์ฒด๊ณ„
  • [ ] ํ†ตํ•ฉ ๋Œ€์‹œ๋ณด๋“œ ๊ตฌ์ถ•
  • [ ] Zero Trust ์‹œ์ž‘

Level 4: Optimized โญโญโญโญ

  • [ ] AI ๊ธฐ๋ฐ˜ ์œ„ํ˜‘ ๋ถ„์„
  • [ ] ์˜ˆ์ธก์  ๋ณด์•ˆ
  • [ ] ์™„์ „ ์ž๋™ํ™”
  • [ ] Chaos Engineering

๋งบ์Œ๋ง ๐ŸŽฏ

AWS re:Inforce 2025๋Š” ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ์ด ๋‹จ์ˆœํ•œ ๋ฐฉ์–ด๋ฅผ ๋„˜์–ด ์˜ˆ์ธก, ์ž๋™ํ™”, ์ง€๋Šฅํ™”๋กœ ์ง„ํ™”ํ•˜๊ณ  ์žˆ์Œ์„ ๋ณด์—ฌ์ฃผ์—ˆ์Šต๋‹ˆ๋‹ค.

ํ•ต์‹ฌ ๊ตํ›ˆ:

  1. ๊ธฐ๋ณธ์ด ๊ฐ€์žฅ ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค - IMDSv2 ํ•˜๋‚˜๋งŒ ์ œ๋Œ€๋กœ ์„ค์ •ํ•ด๋„ ๋Œ€๋ถ€๋ถ„์˜ ๊ณต๊ฒฉ์„ ๋ง‰์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค
  2. ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ์ ‘๊ทผ์ด ํ˜„์‹ค์ ์ž…๋‹ˆ๋‹ค - AWS ๋„ค์ดํ‹ฐ๋ธŒ + Datadog ํ•ต์‹ฌ ๊ธฐ๋Šฅ + ์˜คํ”ˆ์†Œ์Šค ์กฐํ•ฉ์œผ๋กœ 70% ๋น„์šฉ ์ ˆ๊ฐ
  3. Security Hub๊ฐ€ ๊ฒŒ์ž„ ์ฒด์ธ์ €์ž…๋‹ˆ๋‹ค - ๋ชจ๋“  ๋ณด์•ˆ ๋„๊ตฌ๋ฅผ ํ•˜๋‚˜๋กœ ํ†ตํ•ฉํ•˜์—ฌ ๊ด€๋ฆฌ ํšจ์œจ์„ฑ ๊ทน๋Œ€ํ™”
  4. ์ž๋™ํ™”๋Š” ์„ ํƒ์ด ์•„๋‹Œ ํ•„์ˆ˜์ž…๋‹ˆ๋‹ค - 24์‹œ๊ฐ„ ์ˆ˜๋™ ๋ชจ๋‹ˆํ„ฐ๋ง์€ ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค

ํŠนํžˆ ALB Internet-facing + IMDSv1 ์กฐํ•ฉ์€ ์‹œํ•œํญํƒ„๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค. ๋‹น์žฅ IMDSv2๋ฅผ ์ ์šฉํ•˜๊ณ , ์žฅ๊ธฐ์ ์œผ๋กœ Internal ALB๋กœ ์ „ํ™˜ ๊ณ„ํš์„ ์ˆ˜๋ฆฝํ•˜์„ธ์š”.

๋ณด์•ˆ์€ ๊ธฐ์ˆ , ํ”„๋กœ์„ธ์Šค, ์‚ฌ๋žŒ์˜ ์กฐํ™”์ž…๋‹ˆ๋‹ค. AI ์‹œ๋Œ€์—๋„ ๊ธฐ๋ณธ๊ธฐ์— ์ถฉ์‹คํ•˜๋ฉด์„œ ์ƒˆ๋กœ์šด ๊ธฐ์ˆ ์„ ํ˜„๋ช…ํ•˜๊ฒŒ ํ™œ์šฉํ•˜๋Š” ๊ท ํ˜•์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค ๐Ÿ’ช


โš ๏ธ ๋ฒ•์  ๊ณ ์ง€ ๋ฐ ์ฃผ์˜์‚ฌํ•ญ:

  • ๋ณธ ๋ฌธ์„œ์˜ ๋ชจ์˜ํ•ดํ‚น ์‹œ๋‚˜๋ฆฌ์˜ค๋Š” ๊ฒฉ๋ฆฌ๋œ ๊ฐœ์ธ ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์—์„œ๋งŒ ์ˆ˜ํ–‰๋˜์—ˆ์Šต๋‹ˆ๋‹ค
  • ์‹ค์ œ ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ๋ฌด๋‹จ ์นจ์ž…์€ ํ˜•๋ฒ• ๋ฐ ์ •๋ณดํ†ต์‹ ๋ง๋ฒ• ์œ„๋ฐ˜์œผ๋กœ ์ฒ˜๋ฒŒ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค
  • ๋ชจ๋“  ๋ณด์•ˆ ํ…Œ์ŠคํŠธ๋Š” ๋ฐ˜๋“œ์‹œ ์†Œ์œ ์ž์˜ ๋ช…์‹œ์  ํ—ˆ๊ฐ€๋ฅผ ๋ฐ›์€ ํ›„ ์ง„ํ–‰ํ•˜์„ธ์š”
  • ํ”„๋กœ๋•์…˜ ํ™˜๊ฒฝ ๋ณ€๊ฒฝ ์‹œ ๋ฐ˜๋“œ์‹œ ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์—์„œ ๋จผ์ € ๊ฒ€์ฆํ•˜์„ธ์š”