35
SolidStep Cloud Service (인프라 취약점 진단관리 클라우드 서비스)

SolidStep Cloud Servicessrinc.co.kr/upload/sscloud.pdfex) CVE-2017-0111, MS10-015 Microsoft Windows 커널 권한 상승 취약 웹소스 취약 소스코드위변조공격과같은악의적인공격에취약한부분

  • Upload
    others

  • View
    5

  • Download
    0

Embed Size (px)

Citation preview

PowerPoint IT

3
(, Vulnerability) .

1-2.
,
,
ex) Password
8 , ,

,
ex) CVE-2017-0111, MS10-015

ex)
COMPLIANCE COMPLIANCE
CCE CVE, .
Infrastructure


1-3.
, , .
- , , , ,


‘ 2 1 1
.

.
.
- ISP, IDC, VIDC


354 (2015. 11 )

500

5
1-3.
, , .

&


2016
2016 9

2016 7


6
2-1.
.
8
,
2-2.
/ .
9
: ·
/
2-3.
& .
10
?

50.1%
39.1%


!

50% 16% 15%
:
!!
2-4.
, , .
11
,
1
2
3
!
SECaaS
3-1. SECaaS?
SECaaS(Security as a Service) SaaS .
13

3-3. SECaaS
, .
14


















3-2.
Script Standard alone , SECaaS & .
15
Script
&
Agent




X, X
80% !!
3-4. SECaaS – SolidStep Cloud
SECaaS SolidStep Cloud.
16
SolidStep Cloud
4-1. – SolidStep Cloud
SolidStep Cloud SECaaS , IT .

4-2. SolidStep Cloud
SolidStep Cloud , , , 4 .
19
OS, DBMS, WEB/WAS, Network



(Percentage)


/




SolidStep .
3 * / *
-) , , -) // -)
//
//
20

192.10.10.1_Unix
3 DB ERP ? DB ??
IT
192.10.10.1_Unix
192.10.10.1_ 192.10.10.1_
or IP , Solid
Step Cloud () / .
21
4-2. –

UI ‘’ , /
.
3 Steps, OK !
ID
1
3

4 , UI ,
22

( )
,
WISWIG




AS-IS TO-BE
() , .
23

‘’ (1) 100% , (2) .

1 /

24
4-2. –
.
4-2. –
25
‘ ’ .

26
27
.
, 300 .
28
:


As - Is To - Be
, .
29
SERVICE

!
1/10 .
30
1/10 !!
, , 100% .
31
NIST, ITIL, Cobit

( )

·
ROI
FFIEC, HIPPA
: Non-Compliance Item : Compliance Item : Non-Compliance Item : Compliance Item
IT & .
32
A
Group
D
Group
6 4 9 3 10 8 4 1 Windows WEB Linux WAS Linux DBMS Windows WAS
.
33

IBM - AIX * 5.1 ~ 7.2
Oracle Solaris * SPARC 5.7 ~ 5.9, x86 10 ~ 11
DBMS
MySQL * MySQL 5.0 ~ 5.6
IBM - DB2 * DB2 9/10
Tmax - Tibero * Tibero 5 ~ 6
Altibase * Altibase Database 6 ~ 6.5
Postgre SQL * PostgreSQL 9.1 ~ 9.6 (PPAS )
MariaDB * MariaDB 5.1 ~ 5.5, 10.0 ~ 10.2
WEB
Iplanet * Iplanet 6.1
Oracle Weblogic Server * Oracle Weblogic Server 10 ~ 11
Tmax JEUS * Tmax JEUS 5 ~7
IBM WebSphere * IBM WebSphere 8
Nginx * Nginx 1.4 ~ 1.10
Jboss * Jboss 5 ~ 7
Resin * Resin 2 ~ 3
Juniper * Junos OS 12.1X45 ~ Junos OS 16.1
HP(3COM) * 3Com H3C - 4500, 5500, 4200G, 4500G, 4800G, 5500G, 7750, 7900E, 8800
Alteon * Alteon OS - version 23.2.2, version 24.0.7
Alcatel * Alcatel AOS - 6400, 6850, 6850E, 6855,. 9000E
Extreme * ExtremeXOS
()

Zero-Day
. .
!!
34
Tel. 02) 6959-0126~7
E-mail : [email protected]