CyberGuard FirewallÀÇ Report->Audit Logs Criteria À©µµ¿ì¸¦ »ç¿ëÇÏ¸é ¹æÈº®¿¡ ÀúÀåµÇ¾î ÀÖ´Â °¢Á¾ ±â·ÏµéÀ» ¿î¿µÀÚ°¡ ¿øÇÏ´Â Ç׸ñ¿¡ °ü·ÃµÈ »çÇ׸¸ »Ì¾Æ º¼ ¼ö ÀÖ´Ù.
¿¹¸¦µé¾î, Audit logs CriteriaÀÇ
Type : Network Event
Constraint : permit
¶ó°í ÁöÁ¤Çϰí, Time Range¸¦ Àû´çÈ÷ ÁöÁ¤ÇÑ ÈÄ Apply ¹öưÀ» ´©¸£¸é ¾Æ·¡¿Í °°Àº ÅØ½ºÆ®°¡ Ãâ·ÂµÈ´Ù.
Command Line Entered: /usr/sbin/auditrpt -M -B 020612001998 -E 020613001998 -n permit
DATE: 0206, LOG NUMBER: 001, AUDIT VERSION: 4.0
MACHINE ID: UNIX_SV cyber 4.2MP 2.1 i386
DATE: 0206, LOG NUMBER: 002, AUDIT VERSION: 4.0
MACHINE ID: UNIX_SV cyber 4.2MP 2.1 i386
12:00:00:06:02:98,ng_permit,P-1,s,nobody:nobody,nobody:nobody,S-1,,src addr=210.122.78.136,src intf=dec0,dst addr=210.116.8.21,dstintf=dec1,tcp,src port=1571,dst port=80,tcp_flags=0x2,permit,receive
12:00:00:06:02:98,ng_permit,P-1,s,nobody:nobody,nobody:nobody,S-1,,src addr=210.122.76.28,src intf=dec0,dst addr=210.115.128.1,dstintf=dec1,tcp,src port=1249,dst port=80,tcp_flags=0x2,permit,receive
12:00:03:06:02:98,ng_permit,P-1,s,nobody:nobody,nobody:nobody,S-1,,src addr=210.122.76.135,src intf=dec0,dst addr=203.252.3.14,dstintf=dec1,tcp,src port=1215,dst port=80,tcp_flags=0x2,permit,receive
12:00:04:06:02:98,ng_permit,P-1,s,nobody:nobody,nobody:nobody,S-1,,src addr=210.122.76.135,src intf=dec0,dst addr=203.252.3.14,dstintf=dec1,tcp,src port=1216,dst port=80,tcp_flags=0x2,permit,receive
12:00:05:06:02:98,ng_permit,P-1,s,nobody:nobody,nobody:nobody,S-1,,src addr=210.122.78.136,src intf=dec0,dst addr=203.248.208.2,dstintf=dec1,tcp,src port=1573,dst port=80,tcp_flags=0x2,permit,receive
12:00:05:06:02:98,ng_permit,P-1,s,nobody:nobody,nobody:nobody,S-1,,src addr=210.122.76.135,src intf=dec0,dst addr=203.252.3.14,dstintf=dec1,tcp,src port=1217,dst port=80,tcp_flags=0x2,permit,receive
......
¸Ç ÀÁÙÀº ½ÇÁ¦ ·Î±× °Ë»öÀ» À§ÇØ Ä¿¸Çµå¶óÀο¡¼ ½ÇÇàµÈ ¸í·ÉÀ» º¸¿©ÁÖ°í ÀÖ´Ù. µû¶ó¼ ¿©±â¿¡ ³ªÅ¸³ ¸í·ÉÀ» Shell Window¿¡¼ ½ÇÇàÇØµµ °°Àº Ãâ·ÂÀ» ¾òÀ» ¼ö ÀÖ´Ù.
3¹øÂ°ÁÙºÎÅÍ DATE¿Í MACHINE ID ½ÖÀº ÂüÁ¶µÈ ½ÇÁ¦ ·Î±×ÆÄÀϰú ·Î±×ÀÇ ´ë»ó ±â°è¿¡ °üÇÑ Á¤º¸¸¦ °¡Áö°í ÀÖ´Ù. ½ÇÁ¦ ·Î±× º¸°í¼ ÆÄÀÏÀº 11¹øÂ° ÁÙºÎÅÍ ±× ³»¿ëÀÌ µé¾îÀÖ°í, °¢ Çʵå´Â ÄÞ¸¶(,)¸¦ ±¸ºÐÀÚ·Î Á¤·ÄµÇ¾î ÀÖ´Ù.
ù¹øÂ° Çʵå´Â ÇØ´ç À̺¥Æ®°¡ ¹ß»ýÇÑ ½Ã°£À» ³ªÅ¸³»¸ç Æ÷¸äÀº '½Ã:ºÐ:ÃÊ:ÀÏ:¿ù:³â' ÀÌ´Ù. µÎ¹øÂ° Çʵå´Â ÇØ´ç À̺¥Æ®¿¡ ´ëÇÑ ³»ºÎ À̺¥Æ® ¸íÀ̰í, ´Ù¼¸¹øÂ°¿Í ¿©¼¸¹øÂ°´Â ÇØ´ç À̺¥Æ®ÀÇ ½ÇÇàÀÚ¿Í ¼ÒÀ¯ÀÚ¸¦ UID¸¦ ±Ù°Å·Î ³ªÅ¸³½ °ÍÀÌ´Ù.9¹øÂ° Çʵå´Â Ãâ¹ßÁö ÁÖ¼Ò, 11¹øÂ° Çʵå´Â µµÂøÁö ÁÖ¼Ò, 13¹øÂ° Çʵå´Â ÇÁ·ÎÅäÄÝ Å¸ÀÔ(tcp/udp/icmp µî), 14¹øÂ° Çʵå´Â Ãâ¹ßÁö Æ÷Æ®¹øÈ£, 15¹øÂ° Çʵå´Â µµÂøÁö Æ÷Æ®¹øÈ£, 17¹øÂ°´Â ÇØ´ç À̺¥Æ®¿¡ ´ëÇÑ CyberGuard Firewall¿¡¼ÀÇ Á¢±ÙÇã°¡ Á¾·ù, 18¹øÂ°´Â ACK½ÅÈ£¸¦ Çã¿ëÇÏ´ÂÁö¿¡ ´ëÇÑ Ç׸ñÀ» ³ªÅ¸³»°í ÀÖ´Ù.
ÇöÀç CyberGuard Firewall¿¡¼´Â ·Î±× ºÐ¼®À» À§ÇÑ º°µµÀÇ ÆÐŰÁö´Â ¾øÀ¸¸ç, ¾ç½ÄÈ µÇ¾î ÀÖ´Â ·Î±× ÆÄÀÏÀ» MS-Excel °ú °°Àº ½ºÇÁ·¹Æ®½¬Æ® ÇÁ·Î±×·¥ µîÀ¸·Î ±¸ºÐÀÚ¸¦ ÄÞ¸¶(,), µîÈ£(=) µîÀ¸·Î ÁöÁ¤ÇÏ¿© Á¤·ÄÇϰí, Åë°èÄ¡ µîÀ» ºÐ¼®ÇÒ ¼ö ÀÖ´Ù.
Ãâ¹ßÁö/µµÂøÁö ÁÖ¼Ò¸¦ resolved domain nameÀ¸·Î Ç¥½ÃÇÏ·Á¸é, CyberGuard Firewall¿¡ DNS ÁöÁ¤À» ÇØ¾ßÇϴµ¥, º¸¾È »óÀÇ ÀÌÀ¯·Î ±âº»¼³Á¤Àº DNS°¡ Áö¿øµÇÁö ¾Ê´Â´Ù. ¸¸ÀÏ DNS ÁöÁ¤À» ¿øÇÏ´Â °æ¿ì´Â ¿î¿µÀÚ ¸Þ´º¾óÀÇ Split DNS ¼³Á¤À» ÂüÁ¶ÇÑ´Ù.
|