Skip to content · ⁨본문 바로가기⁩

Securing Networks · ⁨네트워크 보안⁩

AP Cybersecurity · ⁨AP 사이버보안⁩ · Topic 3 · ⁨주제 3⁩

Video lesson for this topic · ⁨이 주제용 영상 수업⁩ Open the video page · ⁨영상 페이지 열기⁩
9:26

네트워크 보안

당신은 은행에 메시지를 보냅니다. 도착합니다. 답변이 돌아옵니다. 모든 것이 정상처럼 보입니다. 하지만 누군가가 당신 사이에 조용히 앉아 있는 중이며, 모든 메시지를 읽고 있습니다…

English narration · English + 中文 subtitles burned in · ⁨영어 내레이션 · 영어 + 중국어 자막 burned-in⁩

3.1

Network Vulnerabilities and Attacks · ⁨네트워크 취약점 및 공격⁩

Syllabus
English

Learning Objective 3.1.A: Identify common network attacks.

  • 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
  • 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
  • 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
  • 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.

Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.

  • 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
  • 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
  • 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
  • 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
  • 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
  • 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
  • 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.

Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.

  • 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
  • 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
  • 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
  • 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
    • Illustrative examples for 3.1.C.4:
      • An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
  • 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
    • Illustrative examples for 3.1.C.5:
      • An organization’s external firewall is not configured to block external ICMP traffic.
  • 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
    • Illustrative examples for 3.1.C.6:
      • An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
한국어

학습 목표 3.1.A: 일반적인 네트워크 공격을 식별하십시오.

  • 3.1.A.1 주소 해결 프로토콜(ARP)은 네트워크의 기본 게이트웨이에서 인터넷 프로토콜(IP) 주소를 미디어 액세스 제어(MAC) 주소와 짝짓기하는 표를 생성하는 데 사용됩니다. ARP 포이징 공격은 적대자가 기본 게이트웨이에 위조된 ARP 패킷을 전송하여 표를 수정함으로써 타의 IP 주소를 적대자의 MAC 주소와 연결하고, 타겟으로 향해야 할 트래픽을 적대자 장치가 reception하게 만드는 것입니다. MAC 주위를 위장하는 것을 MAC 스포핑(MAC spoofing)이라고 합니다. 이는 온패스(on-path) 공격(또는 맨-인-더-미들(man-in-the-middle) 공격)의 예입니다. 이 공격은 적대자가 두 당사자 사이의 데이터 스트림을 중계하여 양쪽의 데이터를 캡처하고, 전송 전에数据进行 복제하거나 변조하는 경우를 말합니다. 두 당사자는 서로 직접 통신한다고 생각하지만, 실제로는 각자가 자신의 메시지를 비밀리에 도청하는 적대자와 소통하고 있습니다.
  • 3.1.A.2 MAC 플러딩(MAC flooding) 공격은 적대자가 타겟 스위치에 서로 다른 MAC 주소를 가진 수많은 이더넷 프레임을 전송하는 경우입니다. 이로 인해 스위치가 브로드캐스트 모드로 전환되고, 적대자는 네트워크상의 모든 프레임(브로드캐스트되기 때문에)을 수집할 수 있게 되며, 이는 민감한 정보에 접근할 수 있음을 의미할 수 있습니다. 이는 이브dropping(또는 스니핑, sniffing)의 예입니다. 이攻击은 적대자가 전송 중인 데이터를 캡처하고 기록 및 복제할 수 있는 경우를 말합니다.
  • 3.1.A.3 DNS 포이징(DNS poisoning) 공격은 적대자가 권위 있는 네임 서버(NS)인 척하여 DNS 서버에 가짜 DNS 레코드를 심어 브라우저 트래픽을 자격증 도난을 목적으로 하는 악성 웹사이트로 리디렉션시키는 경우입니다. 이는 크레덴셜 하버스팅(credential harvesting)의 예입니다. 이는 적대자가 실제와 유사한 가짜 로그인 사이트를 설치하여 무고한 사용자들이 실제 자격증을 입력하게 하고, 이를 capture하여 사용하는 경우를 말합니다.
  • 3.1.A.4 스머프(Smurf) 공격은 인터넷 제어 메시지 프로토콜(ICMP) 요청을 사용하여 네트워크를 과부하 상태로 만들려는 시도를 합니다. 이는 서비스 부재(DoS) 공격의 일종으로,AUTHORIZED 사용자에게 시스템이나 자원을 사용 불가능하게 만듭니다. 스머프 공격 중 적대자는 피해자 주소가 포함된 수많은 ICMP 요청을 네트워크의 브로드캐스트 주소로 전송합니다. 네트워크 게이트웨이는 이러한 요청을 네트워크상의 모든 장치로 전송합니다. 네트워크상의 각 장치는 피해자 주소로 응답하며, 정당한 메시지를 차단할 수 있는 트래픽 폭을 생성합니다. 여러 장치가 동일한 타겟을 동시에 공격할 때는 분산 서비스 부재(DDoS) 공격이라고 합니다.

학습 목표 3.1.B: 적대자가 네트워크 취약점을如何利用하여 네트워크 통신을 도난, 방해 또는 파괴할 수 있는지 설명하십시오.

  • 3.1.B.1 적대자는 네트워크를 DoS로 과부하状态로 만들거나 내부 네트워크 구조를 매핑하거나 정당한 장치를 스포핑하기 위해 악성 트래픽을 네트워크에 보낼 수 있습니다. 방화벽이 없거나 부적절하게 구성된 방화벽이 있는 네트워크는 이러한 유형의 공격에 취약합니다.
  • 3.1.B.2 장치를 해킹한 적대자는 종종 로컬 영역 네트워크(LAN)상의 다른 장치도 해킹하기 위해 해당 액세스를 활용하려 시도합니다.
  • 3.1.B.3 적대자가 데이터 포트에 물리적으로 연결하면 포트 보안이 활성화되지 않는 한 스위치 포트를 통해 LAN에 접근할 수 있습니다. 이는 적대자가 DoS 공격을 발동하거나 MAC 플러딩 또는 MAC 스포핑 공격을 수행할 수 있게 합니다.
  • 3.1.B.4 물리적 보안 구역 외부에 서 있는 적대자는 물리적 구역 외부로 브로드캐스팅되는 무선 액세스 포인트의 신호와 Beacon 프레임을 capturing할 수 있습니다. 이를 통해 무선 네트워크에 대한 정보를 gather하고 이에 대한 이브dropping 및 암호화 공격을 시도할 수 있습니다.
  • 3.1.B.5 적대자는 네트워크 내부에서 공격을 발동하기 위해 네트워크에 join하려는 시도를 할 수 있습니다. 장치와 사용자를 인증하지 않는 네트워크는 적대자가 join하기 쉽게 만듭니다.
  • 3.1.B.6 개방된 네트워크 포트가 있다면, 적대자는 해당 포트에 무선 액세스 포인트를 연결하여 로거(Rogue) 액세스 포인트를 생성할 수 있다. 이 로거 액세스 포인트를 통해 내부 네트워크에 무선으로 접근할 수 있으며(물리적 공간 외부에서도 가능), 이는 방화벽을 우회하여 LAN에 직접 접근하게 한다.
  • 3.1.B.7 적대자는 무선 암호화를 해킹하거나, 네트워크상의 데이터를 도청, 도난 또는 유출시키는 시도를 할 수 있다.

학습 목표 3.1.C: 네트워크 취약성으로부터의 위험을 평가하고 문서화한다.

  • 3.1.C.1 네트워크의 취약성은 적대자에게 전송 중인数据进行 도청 및 변조하거나, DoS 공격을发起하거나, 네트워크 내에서 이동(navigating)하여 더 민감하거나 중요한 시스템에 접근하는 것을 허용할 수 있다. 네트워크 취약성은 기밀성, 무결성, 가용성에 대한 위험을 구성할 수 있다.
  • 3.1.C.2 네트워크, 장치, 애플리케이션에서 알려진 취약점을 검사할 수 있는 자동화 취약점 스캐너가 있다. 이러한 스캐너는 일반적으로 탐지된 취약점, 그 심각도, 그리고 완화 방안을 포함하는 보고서를 생성한다.
  • 3.1.C.3 네트워크 취약성을 성공적으로 악용하는 것은 종종 고도의 기술적 능력과 지식을 요구한다. 이는 악용 가능성에 영향을 미칠 수 있다.
  • 3.1.C.4 네트워크 취약성에 대한 높은 위험은 적대자가 네트워크 트래픽을 포획하거나, 네트워크 상의 합법적인 장치를 위장(spoofing)하거나, DoS 공격을发起하여 쉽게 중대한 영향을 미치게 할 수 있게 한다.
    • 3.1.C.4에 대한 예시:
      • 한 조직은 무선 네트워크를 통해 접근 가능한 단일 분할되지 않은 내부 네트워크를 가지고 있으며, 해당 네트워크에는 자체 개발 웹 애플리케이션을 실행하는 서버가 있다.
  • 3.1.C.5 네트워크 취약성에 대한 متوسط 위험은 적대자에게 네트워크 상의 시스템이나 장치에 대한 정보를 얻을 수 있게 하는 취약점을 포함할 수 있다.
    • 3.1.C.5의 예시:
      • 한 조직의 외부 방화벽이 외부 ICMP 트래픽을 차단하도록 설정되어 있지 않다.
  • 3.1.C.6 네트워크 취약성에 대한 낮은 위험은 악용하기 어려우며 조직에 미칠 부정적 영향이 극미미한 취약점을 포함한다.
    • 3.1.C.6에 대한 예시:
      • 한 조직의 무선 액세스 포인트가 네트워크 서비스 세트 식별자(SSID)와 무선 암호화 프로토콜을 포함 beacon frame를 방송한다.

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English
A man-in-the-middle attack
DDoS: a botnet floods a server

A network connects devices so they can share data - and every connection is a possible way in. You must know the classic network attacks and the tricks behind them.

  • ARP poisoning 地址解析投毒 - the address resolution protocol (ARP) 地址解析协议 pairs IP addresses with hardware MAC addresses 物理地址. An adversary sends fake ARP messages so traffic meant for the target flows to the adversary instead. This is an on-path attack 中间人攻击 (also called man-in-the-middle): the adversary secretly sits between two parties, reading and even altering their messages.
  • MAC flooding 物理地址泛洪 - flooding a switch 交换机 with fake MAC addresses forces it into broadcast mode, so the adversary can capture all traffic. This is a form of eavesdropping 窃听.
  • DNS poisoning 域名投毒 - planting a fake record on a domain name system (DNS) 域名系统 server redirects users to a malicious site to steal credentials (credential harvesting 凭据收集).
  • Smurf attack - flooding a network with ICMP requests aimed at the broadcast address, so every device replies to the victim. It is a denial of service (DoS) 拒绝服务 attack; when many machines attack at once it becomes a distributed denial of service (DDoS) 分布式拒绝服务.

Adversaries exploit weak networks to flood, map, or spoof devices. A physical data port with no port security lets an attacker plug in; an open port lets them install a rogue access point 非法接入点 that bypasses the firewall entirely. We rate network risk by impact and by how much skill the exploit needs.

To find weaknesses before an adversary does, organisations run an automated vulnerability scanner 自动漏洞扫描器: a tool that checks networks, devices, and applications against a database of known vulnerabilities, then produces a report listing each one found, how severe it is, and a recommended mitigation 缓解措施. Fixing the highest-severity items first is a core part of managing network risk.

한국어
중간자 공격
DDoS: 봇넷이 서버를 폭주시키는 모습

네트워크(Network) 는 기기가 데이터를 공유할 수 있게 연결하는 것이지, 모든 연결은 잠재적인 침투 경로입니다.的经典적인 네트워크 공격과 그에 숨겨진 수법을 이해해야 합니다.

  • ARP 포이즌링(ARP poisoning) - 주소 해결 프로토콜(Address Resolution Protocol, ARP) 은 IP 주소를 하드웨어 MAC 주소와 매핑합니다. 적대자가 위조 ARP 메시지를 보내면, 표적으로 향해야 할 트래픽이 적대자로 우회됩니다. 이는 온패스 공격(On-path attack, 중간자 공격) 입니다. 적대자는 두 당사자 사이에 몰래 위치하여 Defaults의 메시지를 읽거나 심지어 변조할 수 있습니다.
  • MAC 플러딩(MAC flooding) - 스위치(Switch) 에 위조 MAC 주소를 대량 전송하여broadcast 모드에進入하게 만들고, 적대자가 모든 트래픽을 도청할 수 있게 합니다. 이는 도청(Eavesdropping) 의 일종입니다.
  • DNS 포이즌링(DNS poisoning) - 도메인 네임 시스템(Domain Name System, DNS) 서버에 위조 레코드를植入하여 사용자를 악성 사이트로 리다이렉트하고, 자격 증명(자격 증명 채취, Credential harvesting)을 도난합니다.
  • 스머프 공격(Smurf attack) - ICMP 요청을 브로드캐스트 주소로 향하게 하여 네트워크를 폭주시키고, 모든 기기가 피해자에게 응답하도록 만듭니다. 이는 서비스 거부 공격(Denial of service, DoS) 이며, 다수의 기계가 동시에 공격할 경우 분산 서비스 거부 공격(Distributed denial of service, DDoS) 가 됩니다.

적대자는 약한 네트워크를 이용해 기기를 폭주, 맵핑 또는 위장합니다. 포트 보안(Port security) 이 없는 물리적 데이터 포트에는 attacker가 연결할 수 있으며, 개방된 포트에서는 방화벽을 완전히 우회하는 로그 액세스 포인트(Rogue access point) 설치를 허용합니다. 우리는 영향도와 exploit에 필요한 기술 수준에 따라 네트워크 위험도를 평가합니다.

공격자가 사전에 약점을 파악하기 전에 조직은 자동 취약점 스캐너를 실행합니다. 이 도구는 네트워크, 장치 및 애플리케이션을 알려진 취약점 데이터베이스와 대조하여 점검한 후, 발견된 각 항목의 심각도와 권장 대응책이 포함된 보고서를 생성합니다. 가장 심급이 높은 항목부터 수정하는 것이 네트워크 리스크 관리의 핵심입니다.

Explore · ⁨탐색하기⁩

Identify the network attack from its evidence · ⁨증거에 따른 네트워크 공격 식별하기⁩

Each network attack leaves a distinct trace: ARP poisoning = one IP with two MACs; MAC flooding = a surge of new MACs; DNS poisoning = misdirected web traffic; smurf/DoS = a flood that blocks legitimate traffic. · ⁨각 네트워크 공격은 고유한 흔적을 남깁니다: ARP 포이즌링(ARP poisoning) = 하나의 IP에 두 개의 MAC; MAC 플로딩(MAC flooding) = 새로운 MAC의 급증; DNS 포이즌링(DNS poisoning) = 오향된 웹 트래픽; 스머프/DoS(smurf/DoS) = 정당한 트래픽을 막는 폭주 attack.⁩

Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
ARP poisoning/ɑːp ˈpɔɪzənɪŋ/ ARP 포이즌닝
address resolution protocol (ARP)/əˈdres ˌrezəˈluːʃn ˈprəʊtəkɒl/ 주소 해결 프로토콜 (ARP)
MAC addresses/mæk əˈdresɪz/ MAC 주소
on-path attack/ɒn pæθ əˈtæk/ 경로 상 공격(on-path attack)
MAC flooding/mæk ˈflʌdɪŋ/ MAC 플러딩
switch/swɪtʃ/ 스위치
eavesdropping/ˈiːvzdrɒpɪŋ/ 도청
DNS poisoning/ˌdiː en ˈes ˈpɔɪzənɪŋ/ DNS 포이닝
domain name system (DNS)/dəˈmeɪn neɪm ˈsɪstəm/ 도메인 이름 시스템 (DNS)
credential harvesting/krɪˈdenʃl ˈhɑːvɪstɪŋ/ 인증 정보 수집
denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ 서비스 거절 (DoS)
distributed denial of service (DDoS)/ˈdɪstrɪbjuːtɪd dɪˈnaɪəl ɒv ˈsɜːvɪs/ 분산 서비스 거절 (DDoS)
rogue access point/rəʊɡ ˈækses pɔɪnt/ 위조 access point(rogue access point)
automated vulnerability scanner/ˈɔːtəmeɪtɪd ˌvʌlnərəˈbɪlɪti ˈskænə/ 자동 취약점 스캐너
mitigation/ˌmɪtɪˈɡeɪʃn/ 완화 조치
split tunneling/splɪt ˈtʌnəlɪŋ/ 스플릿 터널링(split tunneling)
3.2

Protecting Networks: Managerial Controls and Wireless Security · ⁨네트워크 보호: 관리적 통제 및 무선 보안⁩

Syllabus
English

Learning Objective 3.2.A: Identify managerial controls related to network security.

  • 3.2.A.1 A router security policy will set forth a minimum configuration standard for routers on an organization’s network and may include:
    • Banning local user accounts (All router logins must use an approved authentication server.)
    • Disabling unnecessary services (e.g., Telnet)
    • Requiring a firewall (An organization may opt for a firewall device separate from the router.)
  • 3.2.A.2 A switch security policy will set forth a minimum configuration standard for switches on an organization’s network and may include:
    • Banning local user accounts (All switch logins must use an approved authentication server.)
    • Requiring port security to be enabled.
    • Using MAC filtering
  • 3.2.A.3 A virtual private network (VPN) policy will detail the minimum security requirements for employees using a VPN to access an organization’s internal network, and it may include:
    • A list of roles within the organization that are allowed to use a VPN to access the organization’s internal network
    • Authentication requirements for employees using a VPN (e.g., public/private key system or MFA)
    • A prohibition against split tunneling (also called dual tunneling)
  • 3.2.A.4 A wireless security policy will establish the minimum security requirements for wireless networks within an organization and may include:
    • Requiring users to authenticate to the wireless network through an extensible authentication protocol (EAP) connected to an approved authentication server
    • Requiring all wireless traffic to be encrypted using AES encryption with a minimum key length
    • Disabling beacon frames on wireless access points

Learning Objective 3.2.B: Configure wireless network security features.

  • 3.2.B.1 Organizations can disable beacon frame broadcasting on wireless access points (WAPs) to make it harder for adversaries to find their wireless network and learn its basic properties.
  • 3.2.B.2 Organizations can control the broadcast direction and signal strength of a WAP so the signal does not extend beyond the physical space the access point is meant to cover.
  • 3.2.B.3 Organizations should enable strong wireless encryption protocols to ensure wireless frames are not readable by adversaries who might intercept them.
    • WEP, WPS, and the original WPA wireless encryption protocols have known vulnerabilities and are insecure.
    • WPA3 is currently the strongest wireless encryption algorithm.
  • 3.2.B.4 Organizations can enable MAC filtering to prevent unauthorized devices from accessing the network, and they can require users to authenticate when joining a network.
한국어

학습 목표 3.2.A: 네트워크 보안과 관련된 관리 통제를 식별한다.

  • 3.2.A.1 라우터 보안 정책은 조직의 네트워크에 있는 라우터에 대한 최소 설정 기준을 수립하며 다음을 포함할 수 있다:
    • 로컬 사용자 계정 사용 금지 (모든 라우터 로그인 시 승인된 인증 서버를 사용해야 함.)
    • 불필요한 서비스 비활성화 (예: Telnet)
    • 방화벽 요구 사항 (조직은 라우터와 분리된 전용 방화벽 장치를 선택할 수 있음.)
  • 3.2.A.2 스위치 보안 정책은 조직의 네트워크에 있는 스위치에 대한 최소 설정 기준을 수립하며 다음을 포함할 수 있다:
    • 로컬 사용자 계정 사용 금지 (모든 스위치 로그인 시 승인된 인증 서버를 사용해야 함.)
    • 포트 보안 활성화 요구 사항.
    • MAC 필터링 사용
  • 3.2.A.3 가상 사설망(VPN) 정책은 VPN을 사용하여 조직 내부 네트워크에 접근하는 직원을 위한 최소 보안 요건을 상세히 설명하며, 다음을 포함할 수 있다:
    • 조직 내부 네트워크에 VPN으로 접근할 수 있는 권한이 부여된 조직 내 역할 목록
    • VPN을 사용하는 직원에 대한 인증 요구 사항 (예: 공개/개인 키 시스템 또는 MFA)
    • 스플릿 터널링(또는 듀얼 터널링) 사용 금지
  • 3.2.A.4 무선 보안 정책은 조직 내 무선 네트워크에 대한 최소 보안 요건을 마련하며 다음을 포함할 수 있다:
    • 승인된 인증 서버와 연결된 확장 인증 프로토콜(EAP)을 통해 사용자가 무선 네트워크에 인증하도록 요구
    • 모든 무선 트래픽이 최소 키 길이를 갖춘 AES 암호화를 사용하여 암호화되도록 요구
    • 무선 액세스 포인트에서ビーコン 프레임 비활성화

학습 목표 3.2.B: 무선 네트워크 보안 기능 구성하기.

  • 3.2.B.1 조직은 무선통신 접속점(WAP)에서ビーコン 프레임 방송을 비활성화하여 적대자가 무선 네트워크를 찾기 어렵게 하고 기본 속성을 파악하는 것을 방지할 수 있다.
  • 3.2.B.2 조직은 WAP의 전송 방향 및 신호 세기를 조절하여 신호가 해당 액세스 포인트가 커버해야 하는 물리적 공간보다 넓게 퍼지지 않도록 할 수 있다.
  • 3.2.B.3 조직은 무선 프레임이 도청자를 통해 읽히지 않도록 강력한 무선 암호화 프로토콜을 활성화해야 합니다.
    • WEP, WPS 및 초기 WPA 무선 암호화 프로토콜에는 알려진 취약점이 있어 보안이 약합니다.
    • WPA3는 현재 가장 강력한 무선 암호화 알고리즘입니다.
  • 3.2.B.4 조직은 MAC 필터링을 활성화하여 무단 장치가 네트워크에 접근하는 것을 방지하고, 네트워크 접속 시 사용자 인증을 요구할 수 있습니다.

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English

Good network security starts with written policies that set a minimum standard: a router security policy and switch security policy ban local accounts and require port security; a VPN policy sets authentication rules and forbids split tunneling 分离隧道; and a wireless security policy requires strong encryption and authenticated access.

For wireless networks specifically, organisations disable beacon frames so the network is harder to find, control signal strength so it does not leak outside the building, enable strong encryption - WPA3 Wi-Fi 保护接入第三代 is the current strongest, while old WEP and the original WPA are broken - and use MAC filtering to allow only known devices.

한국어

좋은 네트워크 보안은 작성된 정책으로 시작되어 최소 기준을 설정합니다. 라우터 보안 정책과 스위치 보안 정책은 로컬 계정을 금지하고 포트 보안을 요구하며, VPN 정책은 인증 규칙을 설정하고 스플릿 터널링을 금지합니다. 또한 무선 보안 정책은 강력한 암호화와 인증된 접근을 요구합니다.

무선 네트워크의 경우, 조직은 네트워크가 찾기 어렵도록 비콘 프레임을 비활성화하고, 신호가 건물 외부로 새어 나오지 않도록 신호 세기를 조절하며, 강력한 암호화를 활성화합니다. 현재 가장 강력한 WPA3 Wi-Fi를 사용하되, 구식인 WEP과 초기 WPA는 이미 무효화되었습니다. 또한 MAC 필터링을 사용하여 알려진 장치만 허용합니다.

Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
WPA3/ˌdʌbljuː piː eɪ ˈθriː/ WPA3
Network segmentation/ˈnetwɜːk ˌseɡmənˈteɪʃn/ 네트워크 세그멘테이션
subnets/ˈsʌbnets/ 서브넷(subnets)
screened subnet/skriːnd ˈsʌbnet/ 스크리닝 서브넷(screened subnet)
3.3

Protecting Networks: Segmentation · ⁨네트워크 보호: 분할(Segmentation)⁩

Syllabus
English

Learning Objective 3.3.A: Identify techniques for segmenting a network.

  • 3.3.A.1 Firewall zones and rules can be used to create a screened subnet (also known as a demilitarized zone, or DMZ)—a network segment that sits between public, external networks like the internet and internal, private networks. A screened subnet is typically a lower security zone than the internal, private networks, and it typically holds an organization’s publicly facing resources, separating them from the internal network.
  • 3.3.A.2 Subnetting can be used to create different subnets based on IP addressing. If a device is compromised by an adversary, subnets can contain a security breach to reduce the number of exposed devices.
  • 3.3.A.3 Switches can be used to create VLANs, which logically separate devices physically connected to central switches.

Learning Objective 3.3.B: Explain why network segmentation can increase network security.

  • 3.3.B.1 Network segmentation refers to the process of dividing a network into smaller, isolated segments or subnetworks (subnets).
  • 3.3.B.2 Dividing a network into smaller subnets isolates network traffic, which can prevent attacks on one subnet from impacting devices on other subnets.
  • 3.3.B.3 Network segmentation can allow for different security policies and controls to be applied to different segments of the network, allowing for higher security zones and lower security zones.
  • 3.3.B.4 Port security on a switch can prevent MAC flooding by limiting the number of addresses assignable to any single switch port.
한국어

학습 목표 3.3.A: 네트워크를 세그먼트로 구분하는 기법을 식별합니다.

  • 3.3.A.1 방화벽 영역 및 규칙을 사용하여 screened subnet(비무장지대 또는 DMZ라고도 함)을 생성할 수 있습니다. 이는 인터넷과 같은 공공 외부 네트워크와 내부 비공개 네트워크 사이에 위치하는 네트워크 세그먼트입니다. screened subnet은 일반적으로 내부 비공개 네트워크보다 보안 수준이 낮으며, 조직의 대중-facing 리소스를 보유하여 이를 내부 네트워크와 분리합니다.
  • 3.3.A.2 서브넷팅은 IP 주소에 따라 서로 다른 서브넷을 생성하는 데 사용될 수 있습니다. 장치가 적대자로부터 침해되면 서브넷은 노출된 장치 수를 줄이기 위해 보안 침해를 국한시킬 수 있습니다.
  • 3.3.A.3 스위치는 물리적으로 중앙 스위치에 연결된 장치를 논리적으로 분리하는 VLAN을 생성하는 데 사용될 수 있습니다.

학습 목표 3.3.B: 네트워크 분리가 네트워크 보안을 향상시키는 이유를 설명하십시오.

  • 3.3.B.1 네트워크 분리는 네트워크를 더 작고 격리된 세그먼트나 하부 네트워크(서브넷)로 나누는 과정을 의미합니다.
  • 3.3.B.2 네트워크를 작은 서브넷으로 나누면 네트워크 트래픽이 격리되어 한 서브넷에 대한 공격이 다른 서브넷의 장치에 영향을 미치지 않도록 할 수 있습니다.
  • 3.3.B.3 네트워크 분리는 네트워크의 다른 세그먼트에 서로 다른 보안 정책 및 통제가 적용되도록 하여 높은 보안 구역과 낮은 보안 구역을 만들 수 있게 합니다.
  • 3.3.B.4 스위치의 포트 보안은 단일 포트에 할당할 수 있는 주소 수를 제한함으로써 MAC 플러딩을 방지할 수 있습니다.

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English

Network segmentation 网络分段 divides one network into smaller, isolated pieces (subnets 子网). If one subnet is breached, the damage is contained and cannot spread.

A key pattern is the screened subnet 屏蔽子网 (also called a DMZ 隔离区). It sits between the public internet and the private internal network, holding an organisation's public-facing servers in a lower-security zone - separated from the sensitive internal systems.

Segments can also be built with subnetting (by IP address) or VLANs 虚拟局域网 (logically separating devices on the same switch). Each segment can then get its own security policy - higher-security and lower-security zones.

한국어

네트워크 분할은 하나의 네트워크를 더 작고 격리된 조각(서브넷)으로 나눕니다. 한 서브넷이 침범당하면 피해가 통제되어 확산되지 않습니다.

핵심 패턴 중 하나는 스크린드 서브넷(또는 DMZ)입니다. 이는 공개 인터넷과 사설 내부 네트워크 사이에 위치하여, 조직의 대중-facing 서버를较低的 보안 구역에 보관합니다. 민감한 내부 시스템과는 분리됩니다.

스크린드 서브넷(DMZ)은 두 개의 방화벽 사이에 공공 서버를 배치하여 사설 네트워크로부터 격리함
스크린드 서브넷(DMZ)은 두 개의 방화벽 사이에 공공 서버를 배치하여 사설 네트워크로부터 격리함

세그먼트는 IP 주소를 통한 서브네팅이나 **VLAN(동일 스위치 위의设备进行 논리적 분리)**을 통해 구축할 수 있습니다. 각 세그먼트는 자체 보안 정책을 가질 수 있으며, 높은 보안 구역과 낮은 보안 구역을 구성합니다.

서버 랙: 네트워크 분할로 시스템을 격리하여 한 번의 침투가 모든 것을 열게 하지 않음
서버 랙: 네트워크 분할은 시스템을 격리하여 하나의 침범이 모든 것을 열지 않게 함
Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
DMZ/ˌdiː em ˈzed/ DMZ
VLANs/ˈviːlænz/ VLANs
3.4

Protecting Networks: Firewalls · ⁨네트워크 보호: 방화벽⁩

Syllabus
Learning ObjectiveEssential Knowledge

3.4.A
Identify types of network-based firewalls.

  • 3.4.A.1 A firewall is used to allow or deny network traffic in or out of a network. The firewall itself is software that can be hosted on a standalone device or integrated into another network device, such as a router.
  • 3.4.A.2 A stateless firewall filters traffic based on information in packet headers, such as IP addresses, ports, and protocols.
  • 3.4.A.3 A stateful firewall (also known as dynamic packet filtering) tracks the state of network connections passing through the firewall and can filter according to connection-related rules in addition to the filtering done by a stateless firewall. This allows for more control over content allowed in and out of a network.
  • 3.4.A.4 A next-generation firewall (NGFW) has both the capabilities of typical stateless and stateful firewalls and additional advanced features, such as intrusion prevention, deep packet inspection, and filtering by application type.

3.4.B
Explain how a firewall uses an access control list to allow or deny traffic entering or leaving a network.

  • 3.4.B.1 Network administrators create a set of rules, called an access control list (ACL), that a firewall uses to permit or deny inbound and outbound network traffic.
  • 3.4.B.2 ACL rules are checked in order and the first rule that matches the criteria will be executed for the specified data.
  • 3.4.B.3 A typical ACL will specify the direction of traffic (inbound or outbound), the criterion to filter by (IP addresses, logical port, service, or application), and the action to take (permit or deny).

3.4.C
Determine the effective placement of firewalls in a network.

  • 3.4.C.1 Each segment of a network should have a firewall to control the flow of data in and out of that segment.
  • 3.4.C.2 Network segments may have different security needs based on the data and services within them. The level of security for each firewall can be set independently.
  • 3.4.C.3 Each point of data ingress and egress between the internal network and the public internet should have a firewall.

3.4.D
Configure a firewall to manage the flow of network traffic.

  • 3.4.D.1 The requirements for a firewall will specify what type of traffic from which sources or to which destinations should be allowed or denied.
  • 3.4.D.2 Specific rules for a firewall can allow or deny inbound or outbound traffic based on source or destination port or IP address, service, protocol, or application.
    • Illustrative examples for 3.4.D.2:
      • Allow inbound TCP port 22 from ALL; (this rule will allow all inbound TCP traffic with destination port 22, which is the designated port for the SSH protocol)
      • Deny inbound TCP port 80 from 192.168.1.0/24; (this rule will deny inbound TCP traffic with destination port 80 from IP addresses in the 192.168.1.0-192.168.1.255 range)
  • 3.4.D.3 Rules are implemented in order, and changing the order of a set of rules can change which traffic is allowed or denied. Consideration must be given to the precedence of filtering priorities when establishing the order of rules.
    • Illustrative examples for 3.4.D.3:
      • This set of rules would allow SSH traffic and deny other inbound TCP traffic
      • Rule 1: ALLOW inbound TCP port 22 from ALL;
      • Rule 2: DENY inbound TCP ALL from ALL;
      • Reversing the order of those rules would deny all inbound TCP traffic including SSH traffic.

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English
How a firewall decides

A firewall 防火墙 allows or denies traffic entering or leaving a network. There are several kinds:

  • Stateless 无状态 - filters on packet headers alone (IP, port, protocol).
  • Stateful 有状态 - also tracks the state of each connection for finer control.
  • Next-generation (NGFW) - adds advanced features like intrusion prevention and deep packet inspection.

A firewall follows an access control list (ACL) 访问控制列表 - an ordered set of rules. Rules are checked in order, and the first match wins, so the order of rules changes which traffic gets through. Each rule specifies a direction, a thing to filter by (IP, port, service), and an action (permit or deny).

Worked example. A firewall has Rule 3: DENY TCP 443 from 192.168.*, and lower down Rule 7: ALLOW TCP 443 from ALL. A user at 192.168.45.37 cannot reach port 443 - even though Rule 7 would allow them - because Rule 3 matches first, and the first match wins. The fix is to move the ALLOW rule above the DENY. This is why rule order, not just rule content, decides what traffic gets through.

Firewalls belong at every point where data crosses between zones - at each network segment and at every gateway to the public internet.

한국어
방화벽이 어떻게 결정하는지

방화벽은 네트워크로 유입되거나 유출되는 트래픽을 허용하거나 거부합니다. 여러 종류가 있습니다:

  • Stateless(무상태) - 패킷 헤더(IP, 포트, 프로토콜)만으로 필터링합니다.
  • Stateful(유상태) - 각 연결의 상태도 추적하여 더 정밀한 제어를 제공합니다.
  • 次世代 (NGFW) - 침입 방지 및 깊은 패킷 검사 등 고급 기능을 추가합니다.

방화벽은 **접근 제어 목록(ACL)**을 따릅니다. 이는 순서가 지정된 규칙의 집합입니다. 규칙은 순서에 따라 확인되며, 첫 번째 일치하는 규칙이 승리하므로 규칙의 순서는 어떤 트래픽이 통과할지를 결정합니다. 각 규칙은 방향, 필터링 대상(IP, 포트, 서비스), 그리고 조치(허용 또는 거부)를 명시합니다.

방화벽은 ACL을 위에서부터 아래까지 확인하며, 첫 번째 일치 규칙이 결정됨
방화벽은 ACL을 상단에서 하단까지 확인하며, 첫 번째 일치하는 규칙이 결정함

해설 예제. 방화벽에 규칙 3: DENY TCP 443 from 192.168.*가 있고, 그 아래에 규칙 7: ALLOW TCP 443 from ALL가 있습니다. 사용자는 192.168.45.37에서 포트 443에 도달할 수 없습니다. 규칙 7는 허용할 수 있지만, 규칙 3가 먼저 일치하기 때문입니다. 여기서는 첫 번째 일치 규칙이 승리합니다. 해결 방법은 ALLOW 규칙을 DENY 규칙 위로 이동시키는 것입니다. 이것이 규칙의 내용뿐만 아니라 규칙의 순서 또한 트래픽 통과 여부를 결정하는 이유입니다.

방화벽은 데이터가 구역 간을 오가는 모든 지점에 위치해야 합니다. 각 네트워크 세그먼트와 공개 인터넷으로 가는 모든 게이트웨이마다 필요합니다.

여러 이더넷 케이블이 연결된 랙 장착형 네트워크 스위치
실제 네트워크 하드웨어: 방화벽은 이러한 케이블이 외부 세계와 만나는 곳에 설치된 장치(또는 소프트웨어)입니다
Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
firewall/ˈfaɪəwɔːl/ 방화벽
Stateless/ˈsteɪtləs/ 무상태
Stateful/ˈsteɪtfl/ 유상태
access control list (ACL)/ˈækses kənˈtrəʊl lɪst/ 접근 제어 목록 (ACL)
log files/lɒɡ faɪlz/ 로그 파일
network intrusion detection system (NIDS)/ˈnetwɜːk ɪnˈtruːʒn dɪˈtekʃn ˈsɪstəm/ 네트워크 침입 탐지 시스템 (NIDS)
network intrusion prevention system (NIPS)/ˈnetwɜːk ɪnˈtruːʒn prɪˈvenʃn ˈsɪstəm/ 네트워크 침입 방지 시스템 (NIPS)
security information and event management (SIEM)/sɪˈkjʊərɪti ˌɪnfəˈmeɪʃn ænd ɪˈvent ˈmænɪdʒmənt/ 보안 정보 및 이벤트 관리 (SIEM)
Signature-based/ˈsɪɡnɪtʃə beɪst/ 서명 기반
Anomaly-based/əˈnɒməli beɪst/ 이상 징후 기반
baseline/ˈbeɪslaɪn/ 베이스라인 (baseline)
network-based indicators of compromise/ˈnetwɜːk beɪst ˈɪndɪkeɪtəz ɒv ˈkɒmprəmaɪz/ 네트워크 기반 침해 지표
probabilistic/ˌprɒbəbɪˈlɪstɪk/ 확률적
3.5

Detecting Network Attacks · ⁨네트워크 공격 탐지⁩

Syllabus
English

Learning Objective 3.5.A: Identify types of automated security tools used to detect network attacks.

  • 3.5.A.1 Automated detection tools analyze data collected from an organization’s network and devices, such as switches and routers, servers, firewalls, and user computers. These data are often collected in a log file.
  • 3.5.A.2 A network intrusion detection system (NIDS) is an automated tool that analyzes data to determine if malicious activity is taking place on a network. When an attack is detected, it generates an alert.
  • 3.5.A.3 A network intrusion prevention system (NIPS) is an automated tool that, like an IDS, analyzes data to determine if malicious activity is taking place on a network. A NIPS can also mitigate or halt an attack by closing ports, blocking specific IP or MAC addresses, or rejecting specific protocols.
  • 3.5.A.4 A security information and event management (SIEM) system collects and analyzes data from multiple sources (including firewalls, NIDS/NIPS, device logs, and application logs) to detect patterns that may indicate a cyberattack and raises an alert if a potential attack is detected. Security analysts investigate the alert to determine whether it represents a true threat and follow standard operating procedures to resolve or escalate the alert.

Learning Objective 3.5.B: Explain how organizations can leverage artificial intelligence (AI) to enhance threat detection and response.

  • 3.5.B.1 Computers log every action that users take. Firewalls, IDS, IPS, and other network sensors log all the traffic passing through various points in a network. A medium-sized organization’s network is logging millions (or even tens of millions) of data points per day. Even a large team of humans is incapable of analyzing so much data.
  • 3.5.B.2 Threat detection teams are creating AI algorithms to analyze large amounts of data and classify the data patterns as malicious or normal.
  • 3.5.B.3 AI models for threat detection are based on probabilistic calculations; they report a percentage to indicate the likelihood that something is malicious.
  • 3.5.B.4 Organizations determine their own thresholds for what percentage of likelihood of a threat results in an alert. If the threshold is set too high, real attacks may go undetected; if the threshold is too low, the security team will be overwhelmed with false alerts.

Learning Objective 3.5.C: Determine a network detection method.

  • 3.5.C.1 Volume of network traffic is a criterion for determining a detection method. Signature-based detection is more efficient for networks with high traffic volume. Signature-based detection compares detection data to a database of known indicators of compromise (IoCs), called signatures. Signature databases must be updated with IoCs for the latest attacks. Signature-based detection runs more quickly than anomaly-based detection.
  • 3.5.C.2 Consistency of network traffic patterns is a criterion for determining a detection method. Anomaly-based detection is most effective on networks with consistent traffic patterns. Anomaly-based detection compares detection data to a baseline of recorded activity. Baselines must be recorded on uncompromised systems to establish expected data types and volumes. Anomaly-based detection triggers an alert or action when data types or volumes outside of a specified tolerance range are recorded. Anomaly-based detection relies on consistent patterns in network traffic to detect anomalous traffic patterns.
  • 3.5.C.3 Degree of sensitivity or criticality of a network is a criterion for determining a detection method. Networks with more sensitive or critical data or services will likely consider a hybrid approach. Hybrid detection combines signature-based and anomaly-based detection. Hybrid detection is more expensive than using either signature- or anomaly-based detection alone, and hybrid-detection models generate more alerts.
  • 3.5.C.4 Likelihood of novel attacks on a network is a criterion for determining a detection method. Signature-based detection cannot detect a new attack. When an organization suspects that adversaries are likely to attempt a new attack on a network, anomaly-based detection is the preferred method when the cost of hybrid detection is prohibitively high.

Learning Objective 3.5.D: Evaluate the impact of a network detection method.

  • 3.5.D.1 Speed of detection is a factor in evaluating the impact of a network detection method. Faster detection enables faster response. Signature-based detection methods are faster than anomaly-based detection methods, especially on networks with high traffic volume.
  • 3.5.D.2 Cost is a factor in evaluating the impact of a network detection method. Detection tools and ongoing costs need to be within a budget. Anomaly-based detection systems require more expensive hardware to operate than signature based. Hybrid detection is the most expensive option because it combines both anomaly- and signature-based methods.
  • 3.5.D.3 False positive rate is a factor in evaluating the impact of a network detection method. Signature-based detection has almost no false positives. Anomaly-based or hybrid detection will have higher false positive rates. Impacts of high false positive rates include:
    • Time and resources are put toward investigating alerts for nonmalicious activity.
    • Alert fatigue is a condition that occurs when responders get accustomed to false positives and take alerts less seriously because they assume alerts are false positives before investigating them.
  • 3.5.D.4 False negative rate is a factor in evaluating the impact of a network detection method. A false negative occurs when an adversary can bypass a detection system. Signature-based detection systems are easier to bypass than anomaly-based or hybrid systems. False negatives can result in adversaries causing loss, harm, disruption, or destruction to data and systems.

Learning Objective 3.5.E: Apply detection techniques to identify indicators of network attacks by analyzing log files.

  • 3.5.E.1 Evil-twin attacks can be detected by regularly scanning for service set identifiers (SSIDs) that look suspicious or similar to local legitimate SSIDs. Signal triangulation can be used to locate and disable an access point broadcasting an evil-twin network.
  • 3.5.E.2 Jamming attacks can be detected by recognizing that no wireless devices in a specific physical space are able to connect to a wireless network and by scanning for electromagnetic (EM) noise in the wireless range.
  • 3.5.E.3 ARP poisoning attacks can be detected by monitoring network traffic for unusual ARP messages (particularly duplicate MAC address ARP packets) and checking the ARP table on the default gateway.
  • 3.5.E.4 MAC flooding attacks can be detected by monitoring network traffic for an unexpected surge of Ethernet frames with different MAC addresses and checking the MAC address table on a switch.
  • 3.5.E.5 DNS poisoning attacks are difficult to detect. However, if an organization’s website experiences an abrupt and otherwise inexplicable drop in traffic, DNS records should be examined as a potential cause.
  • 3.5.E.6 Smurf attacks can be detected by watching network traffic for a sudden increase in ICMP requests sent to the network’s broadcast address.
  • 3.5.E.7 Network-based IoCs are discovered when analyzing network traffic, often in the form of packet capture files. Indicators can be found in source and destination IP addresses, ports, and protocols. These can include:
    • Connections to known malicious IP addresses
    • Unauthorized network scans
    • Unusual spikes or slow downs in network traffic
    • Mismatched port-application traffic
한국어

학습 목표 3.5.A: 네트워크 공격을 탐지하는 데 사용되는 자동화된 보안 도구 유형을 식별하십시오.

  • 3.5.A.1 자동화 탐지 도구는組織의 네트워크 및 장치(스위치 및 라우터, 서버, 방화벽, 사용자 컴퓨터 등)에서 수집된 데이터를 분석합니다. 이러한 데이터는 주로 로그 파일에 수집됩니다.
  • 3.5.A.2 네트워크 침입 탐지 시스템(NIDS)은 데이터를 분석하여 네트워크에서 악의적 활동이 발생하는지 판단하는 자동화 도구입니다. 공격이 감지되면 경보를 발생시킵니다.
  • 3.5.A.3 네트워크侵入 방지 시스템(NIPS)은 IDS와 마찬가지로 데이터를 분석하여 네트워크 내에서 악의적 활동이 발생하고 있는지 판단하는 자동화 도구입니다. NIPS는 포트 폐쇄, 특정 IP 또는 MAC 주소 차단, 특정 프로토콜 거부 등을 통해 공격을 완화하거나 중단할 수도 있습니다.
  • 3.5.A.4 보안 정보 및 이벤트 관리(SIEM) 시스템은 방화벽, NIDS/NIPS, 장치 로그, 애리케이션 로그 등 다양한 소스로부터 데이터를 수집하고 분석하여 사이버 공격을 나타낼 수 있는 패턴을 탐지합니다. 잠재적 공격이 감지되면 경보를 발신하며, 보안 전문가는 해당 경보가 실제 위협인지 확인하기 위해 조사하고 표준 운영 절차에 따라 경보를 해결하거나 상향 보고합니다.

학습 목표 3.5.B: 조직이 인공지능(AI)을 활용하여 위협 탐지 및 대응을 향상시키는 방법을 설명하십시오.

  • 3.5.B.1 컴퓨터는 사용자가 수행하는 모든 행위를 로그로 기록합니다. 방화벽, IDS, IPS 및 기타 네트워크 센서는 네트워크 내 다양한 지점을 통과하는 모든 트래픽을 로그로 기록합니다. 중형 규모의 조직 네트워크는 하루에 수백만 개(혹은 수천만 개)에 달하는 데이터 포인트를 로깅합니다.even 대規模한 인력 팀조차도 이러한 방대한 양의 데이터를 분석하는 것은 불가능합니다.
  • 3.5.B.2 위협 탐지 팀은 방대한 양의 데이터를 분석하고 데이터 패턴이 악의적이거나 정상인지를 분류하기 위해 AI 알고리즘을 개발하고 있습니다.
  • 3.5.B.3 위협 탐지를 위한 AI 모델은 확률 계산에 기반하며, 무언가가 악의적일 가능성을 나타내는 퍼센트 값을 보고합니다.
  • 3.5.B.4 조직은 경보를 발신하기 위한 위험 가능성의 임계값을 자체적으로 설정합니다. 임계값이 너무 높게 설정되면 실제 공격이 탐지되지 않을 수 있으며, 반대로 임계값이 너무 낮으면 보안 팀이虚假경보로 과부하 상태에 빠질 수 있습니다.

학습 목표 3.5.C: 네트워크 탐지 방법을 결정하십시오.

  • 3.5.C.1 네트워크 트래픽의 볼륨은 탐지 방법 선택의 기준이 됩니다. 높은 트래픽 볼륨을 가진 네트워크에서는 서명 기반 탐지가 더 효율적입니다. 서명 기반 탐지는 탐지 데이터를已知한 침범 지표(IoCs)가 저장된 서명 데이터베이스와 비교합니다. 최신 공격에 대한 IoCs로 서명 데이터베이스를 업데이트해야 합니다. 서명 기반 탐지는 비정상 기반 탐지보다 빠르게 실행됩니다.
  • 3.5.C.2 네트워크 트래픽 패턴의 일관성은 탐지 방법 선택의 기준이 됩니다. 트래픽 패턴이 일정한 네트워크에서는 비정상 기반 탐지가 가장 효과적입니다. 비정상 기반 탐지는 탐지 데이터를 기록된 활동의 기준선(baseline)과 비교합니다. 예상되는 데이터 유형과 볼륨을 설정하기 위해서는 침범되지 않은 시스템에서 기준선을 기록해야 합니다. 지정된 허용 범위 외의 데이터 유형이나 볼륨이 기록될 때 비정상 기반 탐지는 경보나 조치를 트리거합니다. 비정상 기반 탐지는 네트워크 트래픽의 일관된 패턴을 이용하여 비정상적인 트래픽 패턴을 탐지하는 데 의존합니다.
  • 3.5.C.3 네트워크의 민감도 또는 중요도는 탐지 방법 선택의 기준이 됩니다. 더 민감하거나 중요한 데이터나 서비스를 보유한 네트워크는 하이브리드 접근 방식을 고려할 가능성이 높습니다. 하이브리드 탐지는 서명 기반 탐지와 비정상 기반 탐지를 결합합니다. 하이브리드 탐지는 서명 기반 또는 비정상 기반 탐지 중 하나만을 사용하는 것보다 비용이 더 많이 들며, 하이브리드 탐지 모델은 더 많은 경보를 생성합니다.
  • 3.5.C.4 네트워크에 대한 새로운类型的攻击的可能性是选择检测方法的标准。签名检测无法检测新的攻击行为。当组织怀疑对手可能尝试对网络发起新型攻击时,如果混合检测的成本过高,则首选异常检测作为替代方案。

학습 목표 3.5.D: 네트워크 탐지 방법의 영향을 평가하십시오.

  • 3.5.D.1 탐지 속도는 네트워크 탐지 방법의 영향을 평가하는 요소입니다. 빠른 탐지는 빠른 대응으로 이어집니다. 특히 높은 트래픽 볼륨을 가진 네트워크에서는 서명 기반 탐지 방법이 비정상 기반 탐지 방법보다 빠릅니다.
  • 3.5.D.2 비용은 네트워크 탐지 방법의 영향을 평가하는 요소입니다. 탐지 도구 및 유지 관리 비용은 예산 내에 있어야 합니다. 비정상 기반 탐지 시스템은 서명 기반 시스템보다 작동에 더 비싼 하드웨어가 필요합니다. 하이브리드 탐지는 비정상 기반 및 서명 기반两种方式를 모두 결합하므로 가장昂贵的选项。
  • 3.5.D.3虚假阳性率是评估网络检测方法影响的因素。签名检测几乎没有虚假阳性。非异常或混合检测会有更高的虚假阳性率。高虚假阳性率的影响包括:
    • 时间和资源被用于调查非恶意活动的警报。
    • 警报疲劳是一种状况,响应人员习惯于虚假阳性,因此在调查前就假设警报为虚假阳性,从而不再认真对待警报。
  • 3.5.D.4 虚假阴性率是评估网络检测方法影响的因素。当攻击者能够绕过检测系统时,就会发生虚假阴性。签名检测系统比非异常或混合系统更容易被绕过。虚假阴性可能导致攻击者对数据和系统造成损失、伤害、中断或破坏。

学习目标 3.5.E: 应用检测技术通过分析日志文件来识别网络攻击的指标。

  • 3.5.E.1 악의적 쌍방(Evil-twin) 공격은 로컬 합법적 SSID와 유사하거나 의심스러운 서비스 세트 식별자(SSID)를 정기적으로 스캔하여 탐지할 수 있다. 신호 삼각 측량法을 사용하여 악의적 쌍방 네트워크를 Broadcasting하는 액세스 포인트를 위치 지정하고 비활성화할 수 있다.
  • 3.5.E.2 자밍(Jamming) 공격은 특정 물리적 공간에 있는 무선 기기가 무선 네트워크에 연결할 수 없음을 인지하고, 무선 범위 내 전자기(EM) 노이즈를 스캔하여 탐지할 수 있다.
  • 3.5.E.3 ARP 포이징(ARP poisoning) 공격은 네트워크 트래픽을 모니터링하여 비정상적인 ARP 메시지(특히 중복 MAC 주소 ARP 패킷)를 확인하고 기본 게이트웨이의 ARP 표를 확인함으로써 탐지할 수 있다.
  • 3.5.E.4 MAC 플러딩(MAC flooding) 공격은 네트워크 트래픽을 모니터링하여 서로 다른 MAC 주소를 가진 이더넷 프레임의 예상치 못한 급증 현상을 확인하고 스위치의 MAC 주소 표를 확인함으로써 탐지할 수 있다.
  • 3.5.E.5 DNS 포이징(DNS poisoning) 공격은 탐지가 어렵다. 그러나 조직의 웹사이트에서 갑작스럽고 설명 불가능한 트래픽 감소가 발생하면 DNS 레코드를 잠재적 원인으로 조사해야 한다.
  • 3.5.E.6 스머프(Smurf) 공격은 네트워크 트래픽을 모니터링하여 네트워크의 브로드캐스트 주소로 보내지는 ICMP 요청의 급격한 증가를 관찰함으로써 탐지할 수 있다.
  • 3.5.E.7 네트워크 기반 IoC는Often 패킷 캡처 파일 형태로 네트워크 트래픽을 분석할 때 발견된다. 지표는 소스 및 목적지 IP 주소, 포트 및 프로토콜에서 찾을 수 있다. 여기에는 다음이 포함될 수 있다:
    • 알려진 악성 IP 주소로의 연결
    • 무단 네트워크 스캔
    • 네트워크 트래픽의 비정상적인 급증 또는 감속
    • 포트-응용 프로그램 트래픽 불일치

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English

When prevention fails, detection takes over. Automated tools read the log files 日志文件 that record network activity:

  • a network intrusion detection system (NIDS) 网络入侵检测系统 analyses traffic and raises an alert, but does not block;
  • a network intrusion prevention system (NIPS) 网络入侵防御系统 can also stop an attack by closing ports or blocking addresses;
  • a security information and event management (SIEM) 安全信息与事件管理 system gathers data from many sources to spot patterns.

There are two detection methods. Signature-based 基于特征 detection compares traffic to a database of known attack signatures - fast and low on false alarms, but blind to brand-new attacks. Anomaly-based 基于异常 detection compares traffic to a normal baseline 基线 and flags anything unusual - it can catch novel attacks but needs more resources and raises more false alarms. A hybrid approach combines both.

Examining captured traffic (packet-capture files), analysts hunt for network-based indicators of compromise 网络入侵指标 in the source and destination IP addresses, ports, and protocols. Four common ones: connections to known-malicious IP addresses, unauthorized network scans (an outsider probing your ports), unusual spikes or slowdowns in traffic, and mismatched port-application traffic (for example, non-web traffic flowing over port 80). These complete the host-, file-, and behaviour-based indicators a single device logs.

AI, thresholds, and alert fatigue

A medium network logs millions of events a day - far more than any team can read - so organisations train AI models to sort likely-malicious patterns from normal ones. These models are probabilistic 概率的: rather than a yes/no, each event gets a percentage likelihood of being malicious.

The organisation then sets a threshold 阈值 - the likelihood at which an alert fires - and that choice is a genuine trade-off:

  • set the threshold too high and real attacks slip through undetected;
  • set it too low and the team is overwhelmed with false alerts.

Too many false alerts cause alert fatigue 警报疲劳: responders get so used to false positives that they start assuming an alert is false before investigating it - so a real attack, when it finally comes, is waved away. This is exactly why a low false-positive rate matters: signature-based detection has almost none, while anomaly-based and hybrid detection trade a higher false-positive rate for the ability to catch novel attacks.

한국어

예방이 실패하면 탐지가 대체합니다. 자동화 도구가 네트워크 활동을 기록한 로그 파일을 읽습니다:

  • **네트워크 침입 탐지 시스템(NIDS)**은 트래픽을 분석하여 경보를 발생시키지만 차단하지는 않습니다;
  • **네트워크 침입 방지 시스템(NIPS)**은 포트를 닫거나 주소를 차단하여 공격을 차단할 수 있습니다;
  • 보안 정보 및 이벤트 관리(SIEM) 시스템은 다양한 출처에서 데이터를 수집하여 패턴을 찾아냅니다.

두 가지 탐지 방법이 있습니다. 서명 기반 탐지는 트래픽을 알려진 공격 서명 데이터베이스와 비교하여, 빠르고 위음성이 적지만 최신 공격에는 눈이 막힙니다. 이상 현상 기반 탐지는 트래픽을 정상적인 기준선과 비교하여 이상 anything를 표시합니다. 새로운 공격을 잡을 수 있지만 더 많은 자원이 필요하고 위음성이 더 많습니다. 하이브리드 방식은 두 가지를 결합합니다.

포착된 트래픽(패킷 캡처 파일)을 검토하는 분석가는 소스 및 목적지 IP 주소, 포트 및 프로토콜에서 네트워크 기반 침해 징후를 찾습니다. 네 가지 일반적인 것: 알려진 악성 IP 주소로의 연결, 불법 네트워크 스캔(외부인이 귀하의 포트를 probing), 트래픽의 비정상적인 스파이크 또는 지연, 그리고 포트-앱 트래픽 불일치(예: 웹 트래픽이 아닌 traffic이 포트 80을 통해 흐름). 이들은 단일 장치가 로그로 기록하는 호스트-, 파일-, 행동 기반 징후를 완성합니다.

AI, 임계값 및 경보 피로도

중간 규모의 네트워크는 하루에 수백만 개의 이벤트를 기록합니다. 어느 팀도 이를 모두 읽을 수 없으므로, 조직은 AI 모델을 훈련시켜 유해 가능성이 높은 패턴을 정상적인 것과 구분합니다. 이러한 모델은 확률적입니다. yes/no 대신 각 이벤트가 악성일 확률을 백분율로 부여합니다.

그 후 조직은 임계값(threshold) — 경보가 발동되는 확률 수준 — 을 설정하며, 이 결정은 실제적인 타협점(trade-off)입니다:

  • 임계값을 너무 높게 설정하면 실제 공격이 검출되지 않고 통과됩니다;
  • 너무 낮게 설정하면 팀은 **거짓 경보(false alerts)**로 과부하에 빠집니다.

거짓 경보가过多하면 **경보 피로(alert fatigue)**가 발생합니다: 대응팀이 거짓 양성(True positives)에 너무 익숙해져 조사하기 전부터 이미 경보를 거짓이라고 가정하게 되는데, 이로 인해 실제 공격이 도래했을 때 무시당합니다. 바로 이 때문에 낮은 거짓 양성율이 중요한 것입니다: 서명 기반 탐지는 거의 없으나, 이상치 기반 및 하이브리드 탐지는 새로운 공격을 포착하는 능력을 대신하여 더 높은 거짓 양성율을 감수합니다.

서명 기반 탐지는 알려진 공격과 일치하며; 이상치 기반 탐지는 정상 패턴과의 편차를 표시함
서명 기반 탐지는 알려진 공격과 일치하며; 이상치 기반 탐지는 정상 패턴과의 편차를 표시함
Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
threshold/ˈθreʃəʊld/ 임계점(threshold)
alert fatigue/əˈlɜːt fəˈtiːɡ/ 경고 피로
3.5

Exam tips · ⁨시험 팁⁩

English
  • For firewall-ACL questions, read the rules top-to-bottom and stop at the first match - a Deny rule above an Allow blocks the traffic even though the Allow exists lower down.
  • Pair each attack with its tell-tale sign: ARP poisoning = one IP with two MAC addresses; MAC flooding = a surge of new MAC addresses; DNS poisoning = an unexplained drop in web traffic.
  • Read packet captures for network-based IoCs: known-malicious IPs, unauthorized scans, traffic spikes/slowdowns, and mismatched port-application traffic.
  • Run vulnerability scanners to find known weaknesses proactively, and fix the highest-severity findings first.
  • Signature-based = fast, few false positives, misses new attacks (more false negatives); anomaly-based = catches new attacks, costs more, more false positives. Memorise this trade-off.
  • A screened subnet / DMZ holds public-facing servers between the internet and the private network - name it whenever a question separates public services from internal data.
  • WPA3 is the strong wireless encryption; WEP and original WPA are insecure.
한국어
  • 방화벽 ACL 문제의 경우, 규칙을 위에서 아래로 읽으되 첫 번째 일치 시 정지하십시오. Allow 규칙 아래에 Deny 규칙이 있다면,Allow 규칙이 하단에 존재하더라도 트래픽을 차단합니다.
  • 각 공격과 그에 해당하는 **특징적 징후(tell-tale sign)**를 짝매기십시오: ARP 폭포 = 하나의 IP 주소에 두 개의 MAC 주소; MAC 폭포 = 새로운 MAC 주소의 급증; DNS 폭포 = 설명 가능한 이유 없는 웹 트래픽 감소.
  • 네트워크 기반 IoC를 위해 **패킷 캡처(packet captures)**를 검토하십시오: 알려진 악성 IP, 무단 스캔, 트래픽 스파이크/감소, 포트와 애플리케이션 트래픽의 불일치 등.
  • **취약점 스캐너(vulnerability scanners)**를 실행하여 알려진 취약점을 사전에查找하고, 가장 중대(severity)한 결과를 우선적으로 수정하십시오.
  • 서명 기반 = 빠르고 거짓 양성율이 적지만 새로운 공격을 놓칠 수 있음(거짓 음성/false negatives 증가); 이상치 기반 = 새로운 공격을 포착하지만 비용이 더 들며 거짓 양성율이 높음. 이 타협점을 암기하십시오.
  • 스크리니드 서브넷 / DMZ는 인터넷과 사내 네트워크 사이에 공공 서비스 서버를 배치하는 구조이며, 질문에서 공공 서비스와 내부 데이터를 분리할 때 반드시 언급해야 합니다.
  • WPA3는 강력한 무선 암호화 방식이며, WEP과 초기 WPA는 보안성이 떨어집니다.

Interactive lessons on this topic · ⁨이 주제에 대한 인터랙티브 수업⁩

Work through it step by step, with instant-check exercises. · ⁨즉시 체크 기능 exercises를 통해 단계별로 진행하세요.⁩

Past Papers · ⁨과거 시험지⁩

More topics in AP Cybersecurity · ⁨AP 사이버보안⁩ · ⁨AP Cybersecurity · ⁨AP 사이버보안⁩ 내 추가 주제⁩

Log in or create account · ⁨로그인 또는 계정 만들기⁩

IGCSE, A-Level & AP