ºÝºÝߣ

ºÝºÝߣShare a Scribd company logo
??? ????? ??? ??
???

¡®???? ???? ???
IDS? ????? ??¡¯ ??
truese@daum.net
??
1. ?????
1. ?????

?? ?? ???? ?????
????¡­

[4]
1. ?????

?? ???? ?? ???? ? ???
???, ???, ??? ?? ??¡­

??? ?? ??? ?? ??¡­
?? ???, ??????? ???
????? ? ?? ?? ??
?? ??? (??? ??? ????)
??? ? ?? ??????¡­
[5]
1. ?????

? ? ?? ??????
??? ???? ??? ??

[6]
1. ?????

??? ?? ?????¡­

?? ??? ? ?? ?????¡­

[7]
1. ?????

? ???? ??
(Clifford stoll, 1951~)
? ????
? ¡®???? ?¡¯ ??

[8]
1. ?????

1980?? ??? ?????¡­

??? ???? 1? ?? ???
??? ?? ???? ??¡­

? 1??? ?????

[9]
1. ?????

Private Networks
Mobile Networks

Public Networks

??/?? ??, ??? ?

?? ??
?????? ?? ???

[10]
1. ?????

???? ??, ??? ??? ???
?? ???..

??? ???? ?? ????
??? ???¡­

[11]
1. ?????

? ??? ??
(Dorothy Denning, 1945~)
? IDS ?? ?? ??(1986)
¡ú ?? ??
¡ú ??? ??

[12]
1. ?????

? ?? ??
(Martin Roesch, 1951~)
? Snort ??(1998)
? IDS ???

[13]
1. ?????

IDS(Intrusion Detection System)

? ?? ???????

[14]
1. ?????

?? ??????
???!

[15]
1. ?????

GET /index.html HTTP/1.1
(index.html ? ?????)

HTTP/1.1 200OK
(??!)

[16]
1. ?????

??? ?? ???? ?????
??? ????¡­
?? ?? ??? ?? ?????
??? ??? ? ??¡­
??? ???? ?????
???? ????¡­

[17]
1. ?????

?? ???

????
?? ???
????
?????? ??? ?? ??

?????? ??? ?? ???

[18]
1. ?????

IDS

? ?? ?? ??
? ??

IPS

? ?? ?? ??
? ??/??

????

? ???? ?? ??
? ??/??

[19]
1. ?????

IDS ?? ???? ???? ????
??? ??????¡­

??? ?? ?? ???
IDS? ????¡­
??? ???? ???? ?????
? ??? ???¡­

[20]
1. ?????

????? ???? ?? ????
????? ???? ?

[21]
1. ?????

??? ??? ????

hacked by Anonymous

hack ?? ???

hack ??? ??

[22]
1. ?????

??? ??? ?? ????
?

?????? ??

?? ?? ???

?? ???

[23]
1. ?????

?? ??! ?? ???

[24]
1. ?????

7??? ?? ????? ??
??? ??? ?? ???¡­

?? ??? ??¡­
???? ?? ?? ??¡­

[25]
1. ?????

[26]
1. ?????

[27]
1. ?????

??? ????, ??? ???
????? ????? ??? ? ??¡­
?? ?????? ??? ???
??? ??? ?? ? ??¡­

????
[28]
1. ?????

??? ????

?? ???

[29]
1. ?????

??? ????
9?? ??? ??~?

[30]
??
1. ?????
2. ?????

????

????

DATA

BIG DATA

1?? ??

??? ??

[32]
2. ?????

???? ??? ?? ??? ???,
?? ??? ?? ?? ???!
[33]
2. ?????

?? ??? ???, ??? ?? ?? ???
[34]
1. ?????

??? ????? ???¡­

??? ??,
??? ???? ????¡­

??????
[35]
2. ?????

?? ?????
??? ????
?? ?????
?? ????

?? ??? ?????
?? ??? ????? ????...

[36]
2. ?????

¡°???? ?? ??? ????? ???
???, ???? ??? ?? ???
??? ??? ??? ? ?? ??.¡±

¡°??? ??? ?? ??? ???? ???
???? ?? ??? ??? ?? ???.
?? ???? ??? ??? ?? ??.¡±

http://www.zdnet.co.kr/news/news_view.asp?artice_id=20130514083136

[37]
2. ?????

??? ???? ???

??? ????

[38]
2. ?????

????

?? ???
????

????

?? ???
???? ?????
[39]
2. ?????

??? ??

?

? ?? ???,
??? ??? ??

?? ??

????

[40]
1. ?????

??? ?? ???? ??? ????¡­
? ? ??? ?????
??? ???? ??¡­

?? ?? ?? ?!

[41]
2. ?????

???
???
+ ???? = ????
=
????
????

????
+ ???? ? ????
????

[42]
1. ?????

????? ???
?????? ??? ????¡­
????? ??????

????? ???? ??? ? ????

[43]
2. ?????

GET /index.php?id=5677

HTTP/1.1 200 OK

GET /index.php?id=5677%20and%201=1

HTTP/1.1 200 OK

[44]
1. ?????

??? ?? ????? ??
??? ??? ?????
???? ??? ?? ???

?? ??? ??? ?? ?? ?? ??¡­

[45]
1. ?????

??? ???? ???
????? ?? ????¡­
????
??? ??? ? ????? ?????¡­
??? ????, ????¡­??????
[46]
2. ?????

?????????(ÐÞÉíýR¼ÒÖ·ø ƽÌìÏÂ)

? ?? ??? ?????

????? ??? ?? ?????

[47]
??
1. ?????
3. ???? ??
?? ? ?????

tcp syn flooding
2001?
3GB

udp port scan

2011?
????
?? ???
70GB
(???????)

slammer worm
[49]
3. ???? ??
??? ???? ??? ?? ???¡­
?? ??? ???!

????¡­??? ?? 1??? 11~15TB? ???? ?
??? ???? ?? ? ???? ???? ???? ?
?? ?? ??? ?? ??? ????.

1TB? ? 1? ?? ??? ??

http://dailysecu.com/news_view.php?article_id=4754
[50]
1. ?????

? ??? ????¡­? ?????

1??? ????? ?? ???
??? ?? ??¡­????

[51]
3. ???? ??

[52]
3. ???? ??

?? ????? ??? ???? ??¡­
[53]
3. ???? ??

???? ?

????

???? ?

??? ????? ???
[54]
3. ???? ??

??

???

???

?????

???

?????

00:00:01

sql injection and

10.0.0.1

8357

192.168.0.1

80

00:00:02

sql injection or

10.0.0.2

54479

192.168.0.2

8080

00:00:03

udp floding

10.0.0.3

5444

192.168.0.3

544

00:00:04

http RFI

10.0.0.4

4789

192.168.0.4

80

00:00:05

sql injection and

10.0.0.5

10658

192.168.0.5

80

00:00:06

tcp syn flooding

10.0.0.6

8523

192.168.0.6

80

00:00:07

icmp scan

10.0.0.7

0

192.168.0.7

0

00:00:08

sql injection or

10.0.0.8

26503

192.168.0.8

9701

00:00:09

sql injection and

10.0.0.9

3170

192.168.0.9

????

80

?
[55]
3. ???? ??

???????
?????? ???¡­

??? ??? ?? ????
????? ????¡­

[56]
1. ?????

????? ??? ??? ?? ???¡­

??? ??? ??? ??¡­

?? ????? ?????¡­

[57]
3. ???? ??

? ?? ? ? ??, ? ?? ? ? ??
??? ?? ????
??? ??? ????
??? ?? ???? ?? ? ??

[58]
3. ???? ??

?? ????
? ??? ??
?? ??? ??

??? ?? ??
[59]
??? ????? ??? ??
Ad

Recommended

????? ??
????? ??
Myounghun Kang
?
Korean information security practices ?? ????
Korean information security practices ?? ????
Bill Hagestad II
?
2017 BoB 3rd BISC conference
2017 BoB 3rd BISC conference
Korea University
?
(FICON2015) #1 ??? ??? ????
(FICON2015) #1 ??? ??? ????
plainbit
?
Sua ???????? ??_????
Sua ???????? ??_????
Lee Chanwoo
?
Netsec-kr 2013 ???? - ???? ??? ?? ?? ?? (???)
Netsec-kr 2013 ???? - ???? ??? ?? ?? ?? (???)
Korea University
?
??? - ??? ???? ??? ??? (Man in the middle) (2014Y07M26D)
??? - ??? ???? ??? ??? (Man in the middle) (2014Y07M26D)
Ubuntu Korea Community
?
[D2 CAMPUS] ??? ?? '??' ????
[D2 CAMPUS] ??? ?? '??' ????
NAVER D2
?
IDG 2017 ???? ?? ??????
IDG 2017 ???? ?? ??????
Logpresso
?
[NetSec-KR 2018] 2017 ???? R&D ??? ???? ?? ??? Data-Driven Security
[NetSec-KR 2018] 2017 ???? R&D ??? ???? ?? ??? Data-Driven Security
Korea University
?
?? ???? ??? ???? ????
?? ???? ??? ???? ????
Logpresso
?
[??? '15.11.27]???? ??? ??? new(??_???)
[??? '15.11.27]???? ??? ??? new(??_???)
james yoo
?
??? ??? ?? Intro to korean cyber security
??? ??? ?? Intro to korean cyber security
Bill Hagestad II
?
201412 ???? ??????
201412 ???? ??????
??????
?
2013 ???? ???_??(?)??_sua_??
2013 ???? ???_??(?)??_sua_??
Lee Chanwoo
?
(FICON2015) #4 ??? ??????
(FICON2015) #4 ??? ??????
plainbit
?
Security Intelligence by log analysis, A3-SMS 2012
Security Intelligence by log analysis, A3-SMS 2012
Korea University
?
AI ?? ??? ???? ???
AI ?? ??? ???? ???
Logpresso
?
Apt(advanced persistent threat) ??? ??? ?? ??
Apt(advanced persistent threat) ??? ??? ?? ??
Youngjun Chang
?
(Ficon2016) #1 ??????, ???? ??
(Ficon2016) #1 ??????, ???? ??
INSIGHT FORENSIC
?
????????? ?? ???
????????? ?? ???
Logpresso
?
???? ??? ????
???? ??? ????
? ??
?
?? ?? ??? ?? ??
?? ?? ??? ?? ??
Youngjun Chang
?
???????????????????????? ??????????? ??????
???????????????????????? ??????????? ??????
?? ?
?
[???]????, ?? ??? ??
[???]????, ?? ??? ??
hyundai-mnsoft
?
???????????????? ???(???)
???????????????? ???(???)
Kyuhyung Cho
?
Sua ???????? ????(2015.3.28)_???
Sua ???????? ????(2015.3.28)_???
Lee Chanwoo
?
2015? 1?? ?? ???? ?? 20150512 ???
2015? 1?? ?? ???? ?? 20150512 ???
Minseok(Jacky) Cha
?
??????, ??? ??!
??????, ??? ??!
SeungYong Yoon
?
(Fios#02) 7. ??? 10 ??? ??
(Fios#02) 7. ??? 10 ??? ??
INSIGHT FORENSIC
?

More Related Content

What's hot (20)

IDG 2017 ???? ?? ??????
IDG 2017 ???? ?? ??????
Logpresso
?
[NetSec-KR 2018] 2017 ???? R&D ??? ???? ?? ??? Data-Driven Security
[NetSec-KR 2018] 2017 ???? R&D ??? ???? ?? ??? Data-Driven Security
Korea University
?
?? ???? ??? ???? ????
?? ???? ??? ???? ????
Logpresso
?
[??? '15.11.27]???? ??? ??? new(??_???)
[??? '15.11.27]???? ??? ??? new(??_???)
james yoo
?
??? ??? ?? Intro to korean cyber security
??? ??? ?? Intro to korean cyber security
Bill Hagestad II
?
201412 ???? ??????
201412 ???? ??????
??????
?
2013 ???? ???_??(?)??_sua_??
2013 ???? ???_??(?)??_sua_??
Lee Chanwoo
?
(FICON2015) #4 ??? ??????
(FICON2015) #4 ??? ??????
plainbit
?
Security Intelligence by log analysis, A3-SMS 2012
Security Intelligence by log analysis, A3-SMS 2012
Korea University
?
AI ?? ??? ???? ???
AI ?? ??? ???? ???
Logpresso
?
Apt(advanced persistent threat) ??? ??? ?? ??
Apt(advanced persistent threat) ??? ??? ?? ??
Youngjun Chang
?
(Ficon2016) #1 ??????, ???? ??
(Ficon2016) #1 ??????, ???? ??
INSIGHT FORENSIC
?
????????? ?? ???
????????? ?? ???
Logpresso
?
???? ??? ????
???? ??? ????
? ??
?
?? ?? ??? ?? ??
?? ?? ??? ?? ??
Youngjun Chang
?
???????????????????????? ??????????? ??????
???????????????????????? ??????????? ??????
?? ?
?
[???]????, ?? ??? ??
[???]????, ?? ??? ??
hyundai-mnsoft
?
???????????????? ???(???)
???????????????? ???(???)
Kyuhyung Cho
?
Sua ???????? ????(2015.3.28)_???
Sua ???????? ????(2015.3.28)_???
Lee Chanwoo
?
2015? 1?? ?? ???? ?? 20150512 ???
2015? 1?? ?? ???? ?? 20150512 ???
Minseok(Jacky) Cha
?
IDG 2017 ???? ?? ??????
IDG 2017 ???? ?? ??????
Logpresso
?
[NetSec-KR 2018] 2017 ???? R&D ??? ???? ?? ??? Data-Driven Security
[NetSec-KR 2018] 2017 ???? R&D ??? ???? ?? ??? Data-Driven Security
Korea University
?
?? ???? ??? ???? ????
?? ???? ??? ???? ????
Logpresso
?
[??? '15.11.27]???? ??? ??? new(??_???)
[??? '15.11.27]???? ??? ??? new(??_???)
james yoo
?
??? ??? ?? Intro to korean cyber security
??? ??? ?? Intro to korean cyber security
Bill Hagestad II
?
201412 ???? ??????
201412 ???? ??????
??????
?
2013 ???? ???_??(?)??_sua_??
2013 ???? ???_??(?)??_sua_??
Lee Chanwoo
?
(FICON2015) #4 ??? ??????
(FICON2015) #4 ??? ??????
plainbit
?
Security Intelligence by log analysis, A3-SMS 2012
Security Intelligence by log analysis, A3-SMS 2012
Korea University
?
AI ?? ??? ???? ???
AI ?? ??? ???? ???
Logpresso
?
Apt(advanced persistent threat) ??? ??? ?? ??
Apt(advanced persistent threat) ??? ??? ?? ??
Youngjun Chang
?
(Ficon2016) #1 ??????, ???? ??
(Ficon2016) #1 ??????, ???? ??
INSIGHT FORENSIC
?
????????? ?? ???
????????? ?? ???
Logpresso
?
???? ??? ????
???? ??? ????
? ??
?
???????????????????????? ??????????? ??????
???????????????????????? ??????????? ??????
?? ?
?
???????????????? ???(???)
???????????????? ???(???)
Kyuhyung Cho
?
Sua ???????? ????(2015.3.28)_???
Sua ???????? ????(2015.3.28)_???
Lee Chanwoo
?
2015? 1?? ?? ???? ?? 20150512 ???
2015? 1?? ?? ???? ?? 20150512 ???
Minseok(Jacky) Cha
?

Viewers also liked (20)

??????, ??? ??!
??????, ??? ??!
SeungYong Yoon
?
(Fios#02) 7. ??? 10 ??? ??
(Fios#02) 7. ??? 10 ??? ??
INSIGHT FORENSIC
?
(Ficon2016) #5 ??? ??? ???? ????!
(Ficon2016) #5 ??? ??? ???? ????!
INSIGHT FORENSIC
?
¥µ©`¥Ð¤ò×÷¤Ã¤Æ¤ß¤¿ (4)
¥µ©`¥Ð¤ò×÷¤Ã¤Æ¤ß¤¿ (4)
SeungYong Yoon
?
Memory forensics with volatility
Memory forensics with volatility
Youngjun Chang
?
????? ??
????? ??
Myounghun Kang
?
Cloumon enterprise
Cloumon enterprise
Gruter
?
????3.0?? ???? ???? ?? ??
????3.0?? ???? ???? ?? ??
Korea Advanced Institute of Science and Technology
?
IT??? ????(Social Engineering)
IT??? ????(Social Engineering)
Youngjun Chang
?
GRUTER? ???? Big Data Platform ?? ??? ?? ??: ?? ?? ??? ?? ???? ??? ?? ??
GRUTER? ???? Big Data Platform ?? ??? ?? ??: ?? ?? ??? ?? ???? ??? ?? ??
Gruter
?
[???? ?? | ??? ???] ?????? ???? ??????(?? ??) (???)
[???? ?? | ??? ???] ?????? ???? ??????(?? ??) (???)
MINWHO Law Group
?
Sua ???????? cissp_????_????
Sua ???????? cissp_????_????
Lee Chanwoo
?
????? ?? ?? ? ?? ?? 2016.11.09
????? ?? ?? ? ?? ?? 2016.11.09
Hakyong Kim
?
???? ??
???? ??
beom kyun choi
?
IoT era and convergence security sangsujeon
IoT era and convergence security sangsujeon
SangSu Jeon
?
???? ?????? ?(2015?) v0.9_????
???? ?????? ?(2015?) v0.9_????
James (SeokHun) Hwang
?
IoT ?? ???? ??? ? ?? ?? ?? 2015.12.10
IoT ?? ???? ??? ? ?? ?? ?? 2015.12.10
Hakyong Kim
?
???? What is Blockchain?
???? What is Blockchain?
?? ?
?
Sua ???????? cissp_????_????
Sua ???????? cissp_????_????
Lee Chanwoo
?
???? ?? ??? ?? ?? ?????
???? ?? ??? ?? ?? ?????
H4C
?
(Ficon2016) #5 ??? ??? ???? ????!
(Ficon2016) #5 ??? ??? ???? ????!
INSIGHT FORENSIC
?
¥µ©`¥Ð¤ò×÷¤Ã¤Æ¤ß¤¿ (4)
¥µ©`¥Ð¤ò×÷¤Ã¤Æ¤ß¤¿ (4)
SeungYong Yoon
?
Memory forensics with volatility
Memory forensics with volatility
Youngjun Chang
?
Cloumon enterprise
Cloumon enterprise
Gruter
?
IT??? ????(Social Engineering)
IT??? ????(Social Engineering)
Youngjun Chang
?
GRUTER? ???? Big Data Platform ?? ??? ?? ??: ?? ?? ??? ?? ???? ??? ?? ??
GRUTER? ???? Big Data Platform ?? ??? ?? ??: ?? ?? ??? ?? ???? ??? ?? ??
Gruter
?
[???? ?? | ??? ???] ?????? ???? ??????(?? ??) (???)
[???? ?? | ??? ???] ?????? ???? ??????(?? ??) (???)
MINWHO Law Group
?
Sua ???????? cissp_????_????
Sua ???????? cissp_????_????
Lee Chanwoo
?
????? ?? ?? ? ?? ?? 2016.11.09
????? ?? ?? ? ?? ?? 2016.11.09
Hakyong Kim
?
IoT era and convergence security sangsujeon
IoT era and convergence security sangsujeon
SangSu Jeon
?
IoT ?? ???? ??? ? ?? ?? ?? 2015.12.10
IoT ?? ???? ??? ? ?? ?? ?? 2015.12.10
Hakyong Kim
?
???? What is Blockchain?
???? What is Blockchain?
?? ?
?
Sua ???????? cissp_????_????
Sua ???????? cissp_????_????
Lee Chanwoo
?
???? ?? ??? ?? ?? ?????
???? ?? ??? ?? ?? ?????
H4C
?
Ad

Similar to ??? ????? ??? ?? (20)

???? ???? ??? ?? ?? ????? ???? ?? ??&??? ?? ??
???? ???? ??? ?? ?? ????? ???? ?? ??&??? ?? ??
Donghan Kim
?
¡º?????? ????????? ?????? ???????? ?????¡» - ???????
¡º?????? ????????? ?????? ???????? ?????¡» - ???????
?? ?
?
[??? ??] bithumb_Privacy_Lecture(2021.12)
[??? ??] bithumb_Privacy_Lecture(2021.12)
Lee Chanwoo
?
How to prevent cyber attack with big data & intelligence(sfis170222)
How to prevent cyber attack with big data & intelligence(sfis170222)
Yong Suk Kang ½ªÁúÎý
?
?1? ???????-2013? ?? ??? ? ??(??)-d han-kim-2013-2-19
?1? ???????-2013? ?? ??? ? ??(??)-d han-kim-2013-2-19
Donghan Kim
?
????? 1 db??, ??? ?? why how when 20121025
????? 1 db??, ??? ?? why how when 20121025
eungjin cho
?
swu_ict_protection
swu_ict_protection
sohyunie
?
??? ?(?????? ???? ) -20110723 ??
??? ?(?????? ???? ) -20110723 ??
Bitscan
?
[???D2SF] ??? ??? ??? ?? Ncloud ????
[???D2SF] ??? ??? ??? ?? Ncloud ????
NAVER D2 STARTUP FACTORY
?
security framework2.20
security framework2.20
skccsocial
?
M-Trends 2015: ????? ? ??
M-Trends 2015: ????? ? ??
FireEye, Inc.
?
2014 data ?? ????? ??????? 20140930
2014 data ?? ????? ??????? 20140930
eungjin cho
?
120515 security framework2.20
120515 security framework2.20
skccsocial
?
201412 wapples ????_??
201412 wapples ????_??
??????
?
Sua ???????? cissp_????_????
Sua ???????? cissp_????_????
Lee Chanwoo
?
2013? ??? it ?? ?? ???-Dhan-kim-2013-12-20
2013? ??? it ?? ?? ???-Dhan-kim-2013-12-20
Donghan Kim
?
2015 1 q ibm x force-???
2015 1 q ibm x force-???
ArumIm
?
Isaca knowledge concert ???? ???? ???(2017.07.17)_final
Isaca knowledge concert ???? ???? ???(2017.07.17)_final
Lee Chanwoo
?
04.a sis to be_?????? ??1
04.a sis to be_?????? ??1
??????
?
?? ?? ??? ?? ??
?? ?? ??? ?? ??
Youngjun Chang
?
???? ???? ??? ?? ?? ????? ???? ?? ??&??? ?? ??
???? ???? ??? ?? ?? ????? ???? ?? ??&??? ?? ??
Donghan Kim
?
¡º?????? ????????? ?????? ???????? ?????¡» - ???????
¡º?????? ????????? ?????? ???????? ?????¡» - ???????
?? ?
?
[??? ??] bithumb_Privacy_Lecture(2021.12)
[??? ??] bithumb_Privacy_Lecture(2021.12)
Lee Chanwoo
?
How to prevent cyber attack with big data & intelligence(sfis170222)
How to prevent cyber attack with big data & intelligence(sfis170222)
Yong Suk Kang ½ªÁúÎý
?
?1? ???????-2013? ?? ??? ? ??(??)-d han-kim-2013-2-19
?1? ???????-2013? ?? ??? ? ??(??)-d han-kim-2013-2-19
Donghan Kim
?
????? 1 db??, ??? ?? why how when 20121025
????? 1 db??, ??? ?? why how when 20121025
eungjin cho
?
swu_ict_protection
swu_ict_protection
sohyunie
?
??? ?(?????? ???? ) -20110723 ??
??? ?(?????? ???? ) -20110723 ??
Bitscan
?
security framework2.20
security framework2.20
skccsocial
?
M-Trends 2015: ????? ? ??
M-Trends 2015: ????? ? ??
FireEye, Inc.
?
2014 data ?? ????? ??????? 20140930
2014 data ?? ????? ??????? 20140930
eungjin cho
?
120515 security framework2.20
120515 security framework2.20
skccsocial
?
201412 wapples ????_??
201412 wapples ????_??
??????
?
Sua ???????? cissp_????_????
Sua ???????? cissp_????_????
Lee Chanwoo
?
2013? ??? it ?? ?? ???-Dhan-kim-2013-12-20
2013? ??? it ?? ?? ???-Dhan-kim-2013-12-20
Donghan Kim
?
2015 1 q ibm x force-???
2015 1 q ibm x force-???
ArumIm
?
Isaca knowledge concert ???? ???? ???(2017.07.17)_final
Isaca knowledge concert ???? ???? ???(2017.07.17)_final
Lee Chanwoo
?
04.a sis to be_?????? ??1
04.a sis to be_?????? ??1
??????
?
Ad

??? ????? ??? ??