Previous Next Top Detailed TOC Last
Update: 16 Jun 2000
´ÙÀ½ ¹®¼µéÀº ·ÎÄ÷Πº¹»çµÇ¾î ÀÖ´Ù:
´ç½ÅÀÇ ½Ã½ºÅÛÀÌ Ä§ÀÔÀÚ¿¡ ÀÇÇØ ÇÔ¶ôµÈ´Ù¸é
What if your Machines are Compromised by an Intruder
Christopher Klaus of Internet Security Systems, Inc. <iss@iss.net>compromise_faq.html Tik-110.501 ³×Æ®¿÷ º¸¾È¿¡ ´ëÇÑ ¼¼¹Ì³ª
½Ç¿ëÀûÀÎ ¾ÏÈ£½Ã½ºÅÛ°ú °µµ
Practical Cryptosystems and their Strength
Janne Frosen Department of Computer Science
Helsinki University of Technology Janne.Frosen@hut.fi 2.11.1995CryptoAlgoStrength.html º¸¾ÈÆò°¡ ±âÁØ
- ITSEC
- ITSEM
- TCSEC / Orange Book
- Common criteria (old version)
º¸¾È ¸ÞÀϸµ ¸®½ºÆ® FAQ, ISS security_lists.html Sniffer FAQ, ISS sniff.html ¾Ïȣȱâ¼ú°ú °ü·ÃµÈ Á¤Ã¥ ¸®ºä
Review of Policy relating to Encryption Technologies
(The Walsh Report) Dec.1998
ÀÌ ÆÄÀÏÀº ÀÌ º¸°í¼ÀÇ ¿ÏÀüÇÑ ´ÜÀϹ®¼ ¹öÀüÀÌ´Ù. ¿øº» URL: http://www.efa.org.au/Issues/Crypto/Walsh/index.htmwalsh.zip ¾ÏÈ£¿Í ÀÚÀ¯ 1999 - ¾ÏÈ£ÈÁ¤Ã¥¿¡ ´ëÇÑ ±¹Á¦Àû ¿¬±¸
Cryptography and Liberty 1999 - An International Survey of Encryption Policy
À̰ÍÀº ³»°¡ ¾Ë°í ÀÖ´Â ±¹Á¦ ¾ÏÈ£ Á¤Ã¥ °³·Ð Áß °¡Àå ÈǸ¢ÇÏ´Ù.crytpo1999.htm.zip
www2.epic.org/reports/crypto1999.htmlÇÁ·Î±×·¡¹Ö
- À¯´Ð½º ÇÁ·Î±×·¡¹Ö ÆÁ, SunWorld.
- Code Signing: how-to
½Ã½ºÅÛ °ü¸®
- ÀÎÅÍ³Ý À¥¼¹ö: best practices
ÀÌ ¸ðµç º¸¾È ¹®Á¦¿¡¼ ÀαÇÀ» ÀØÁö ¸»µµ·Ï ÇÏÀÚ..... ƯÈ÷ ÇÁ¶óÀ̹ö½Ã Ãø¸é¿¡¼
Don't forget human rights in all of this security stuff..... especially privacy aspects.humanrights.html
Âü°í Àý¿¡¼ Ã¥ ¸ñ·ÏÀ» ±¸ÇÒ ¼ö ÀÖ´Ù.
ÀÌ ÀýÀº ÀÎÅÍ³Ý Âü°íÀڷḦ ¸¹ÀÌ Æ÷ÇÔÇϰí ÀÖ°í, °Å±â´Ù º¸¾È Á¶Á÷¿¡ ´ëÇÑ ¼³¸í°ú À̵鿡 ÀÇÇÑ º¸¾È ±Ç°í¹®µéÀÌ ¹ßÇ¥µÇ´Â °÷À» ¼Ò°³ÇÑ´Ù.
ÀÎÅͳÝÀº °è¼ÓÇØ¼ º¯ÈÇϰí ÀÖÀ¸¹Ç·Î, ³ª¿µÈ ¸µÅ©µé Áß ¸î¸îÀº ´õÀÌ»ó À¯È¿ÇÏÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù. ÀÌ·± °æ¿ì, ¾ßÈÄ ³ª ¾ËŸºñ½ºÅ¸ °°Àº °Ë»ö¿£ÁøÀ» ÀÌ¿ëÇÏ¿© Á¤º¸¸¦ ãµµ·Ï ÇÑ´Ù (¾Æ·¡ ÂüÁ¶).
Yahoo: www.yahoo.com
Alta Visa: www.altavista.com
Lycos: www.lycos.com
Google: www.google.com
¹ÙÀÌ·¯½º Contacts (oldish):
´º½º ±×·ì: comp.virus PC Viruses
PC ¹ÙÀÌ·¯½º Á¤º¸ mailto:listserv%lehiibm1.bitnet@mitvma.mit.edu
body= "SUB VIRUS-L myname@my.domain"
NCSA ftp://ftp.ncsa.com/pub/virus/WildList
¸ÅÅ©·Î ¹ÙÀÌ·¯½º ¸ñ·Ïftp://ftp.informatik.uni-hamburg.de/pub/virus/macro/
FIRST mailto:first-sec@first.org
http://www.first.org [FIRST ȨÆäÀÌÁö]SWITCH CERT ½ºÀ§½º mailto:cert-staff@switch.ch
CERT mailto:cert-advisory-request@cert.org *̵̧*
CERT µµ±¸ mailto:cert-tools-request@cert.org
ftp://cert.org/pub/cert_advisories
´Ù¸¥ À¯·´ ÆÀµé: ´ÙÀ½ Àý ÂüÁ¶.
È£ÁÖ CERT http://www.auscert.org.au/ [ÃÖ½ÅÁ¤º¸°¡ ºü¸£´Ù.]CIAC mailto:ciac-listproc@llnl.gov subject=
"subscribe CIAC-ANNOUNCE Boran, Sean MY_PHONE_NR"
"subscribe CIAC-NOTES Boran, Sean MY_PHONE_NR"
"subscribe SPI-ANNOUNCE Boran, Sean MY_PHONE_NR"
"subscribe SPI -NOTES Boran, Sean MY_PHONE_NR"
Risks forum mailto:risks-request@csl.sri.com
Best of Security (bos) mailto:majordomo@suburbia.net
º¸¾È ¸ÞÀϸµ ¸®½ºÆ® (local copy)
SANS ³×Æ®¿÷ º¸¾È ¿ä¾à Network Security Digest mailto:sans@clark.net
body='subscribe Network Security Digest your name'´º½º±×·ì º¸¾ÈÀÏ¹Ý news://comp.security.misc
±â¼úÀÇ ÇØ¾Ç Evils of technology news://comp.risks
º¸¾È °ø½Ã Security Announcements news://comp.security.announceftp://ftp.switch.ch/mirror/security [½ºÀ§½ºÀÇ ±¦ÂúÀº °Íµé]
http://coast.cs.purdue.edu/homes/spaf/spafs_hotlist.html [Spafford ÀÇ ¸µÅ© »öÀÎ: ¾ÆÁÖ ÁÁÀ½]
http://www.tezcat.com/web/security/security_http.html [¼ö¸¹Àº ³×Æ®¿÷/À¯´Ð½º ÆäÀÌÁöµé¿¡ ´ëÇÑ »öÀÎ]http://www-genome.wi.mit.edu/WWW/faqs/www-security-faq.html [WWW ¼¹ö º¸¾È]
http://www.primus.com/staff/paulp/cgi-security [±úÁø ¸µÅ©] [WWW cgi ½ºÅ©¸³Æ® º¸¾È]
http://hoohoo.ncsa.uiuc.edu/cgi/security.html [À§¿Í °°À½]
IIS º¸¾È ¼³Á¤ support.microsoft.com/support/kb/articles/Q229/6/94.asp
À¯´Ð½º º¸¾È mailto:security@cpd.com [È®ÀÎ ¾ÈµÊ]
Sun:
Sun "°í°´ °æ°í ½Ã½ºÅÛ Customer Warning System" º¸¾È °æ°í mailto:security-alert@sun.com , subject="subscribe CWS myname@my.company.domain", Tel. +1 415 688-9081
Sun sysadmin mailto:sun-managers-request@eecs.nwu.edu
body="add myname@my.domain"
º¸¾È °ø½Ã sunsolve.sun.com/sunsolve/secbulletins
Sun & ÀÚ¹Ù º¸¾È www.sun.com/security/index.html
Solaris ´º½º±×·ì news://comp.unix.solaris java.Sun.com/security
ÆÐÄ¡
°ø°³ sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access
ÆÐÄ¡ sunsolve.sun.ch/pub-cgi/us/secbul.pl
½ºÀ§½º sunsolve.sun.ch Contract patches sunsolve.sun.ch/private-cgi/us/patchpage.pl
ÆÐÄ¡ ´Ù¿î·Îµå µµ±¸ WGET sunsite.auc.dk/ftp/pub/infosystems/wget/
PatchDiag µµ±¸ sunsolve.sun.ch/sunsolve/patchdiag
Sun¿ë ÄÄÆÄÀÏµÈ ÇÁ¸®¿þ¾î www.sunfreeware.com
Solaris °¡ÀÌµå »öÀÎ: www.solarisguide.com
Sunworld sunwhere index of resources www.sunworld.com/sunworldonline/sunwhere.html
Jean ChouanardÀÇ Solaris °È ÆÐŰÁö ftp://ftp.parc.xerox.com/pub/jean/solins/solins.html
Jens VocklerÀÇ Solaris TCP/IP ½ºÅà Ʃ´×À» À§ÇÑ ½ºÅ©¸³Æ® (¼º´É, º¸¾È¿¡ ¶Ù¾î³ª°í ndd¸¦ ¹è¿ì´Â µ¥ ÁÁÀ½) http://www.rvs.uni-hannover.de/people/voeckler/tune/EN/tune.html.HP:
Hewlett Packard mailto:security-alert@hp.com
HP º¸¾È ¸®½ºÆ® mailto:support@support.mayfield.hp.com body="subscribe security_info"
HP-UX sysadmin mailto:majordome@cv.ruu.nl body="subscribe hpux-admin"
HP-UX ´º½º±×·ì news://comp.sys.hp.hpuxDEC:
mailto:rich.boren@cxo.mts.dec.com , Tel. +1 719 592-4689
OSF/1 sysadmin mailto:majordomo@ornl.gov body="subscribe alpha-osf-managers"
http://www.service.digital.com/html/patch_service.htmlBSDI sysadmin bsdi-users-request@bsdi.com
SCO: security-alert@sco.com
Santa Cruz Operation ftp://ftp.sco.com/SLS
Linux: ¸®´ª½º ºñ»ó´ëÀÀÆÀ:
http://bach.cis.temple.edu/linux/linux-security/Linux-Alerts/
www.redhat.com www.suse.com
OpenBSD: www.openbsd.orgSGI/IRIX:
À̸ÞÀÏ mailto:security-alert@sgi.com , Tel. +1 800 800-4SGI
ÆÐÄ¡: SGIÀÇ º¸¾È ±Ç°í¹® ¹× ÆÐÄ¡´Â ftp://sgigate.sgi.com ³ª ¹Ì·¯»çÀÌÆ® ftp.sgi.com ÀÇ µð·ºÅ丮 Security or Patches ¿¡¼ ftp ·Î ±¸ÇÒ ¼ö ÀÖ´Ù.
À§ ÆÐÄ¡¿Í °ü·ÃµÈ À̽´´Â, mailto:cse-security-alert@csd.sgi.comÀ» ÂüÁ¶. »õ·Î¿î À̽´´Â, mailto:security-alert@sgi.com ·Î À̸ÞÀÏ.
´º½º±×·ì ´º½º://comp.sys.sgi.bugs (IRIX bugs).IBM/AIX:
http://www.ers.ibm.com/tech-info
mailto:nrt@watson.ibm.com , Tel. +1 800 237-5511
ftp://software.watson.ibm.com/pub/aix3 [¸î¸î AIX º¸¾È ÆÐÄ¡]
http://service.software.ibm.com/pbin-usa/fixdist.pl
http://service.software.ibm.com/aixsupport
http://www.ibm.com/security [º¸¾È Á¦Ç° & ¼ºñ½º]Microsoft/Windows NT:
NT º¸¾È À̽´ mailto:request-ntsecurity@iss.net
NTBugtraq mailto:listserv@listserv.ntbugtraq.com body= "SUB NTBUGTRAQ Your Name"
www.securityfocus.com
ISSÀÇ NT º¸¾È mailto:request-ntsecurity@iss.net body="subscribe ntsecurity"
NT, Explorer º¸¾È www.ntsecurity.net *recommended*
Microsoft º¸¾È mailto:security@microsoft.com www.microsoft.com/security
www.somarsoft.com/contents.htm [NT º¸¾È]
www.iea.com/~daler/nt/faq/toc.html [NT ÀÚÁÖ ¹¯´Â Áú¹®µé]Cisco
www.cisco.com/warp/public/707/advisory.html
±â»ç ´Ù¾çÇÑ ¶ó¿ìÅÍ ÆÐ½º¿öµå ¸ÞÄ«´ÏÁò & Ãë¾àÁ¡ ¼³¸í
¹æÈº® Firewalls mailto:majordomo@greatcircle.com "subscribe firewalls"
¿ä¾àµµ ÀÖÀ½.
8lgm(8 Little Green Men): mailto:majordomo@8lgm.org body="subscribe 8lgm" www.8lgm.org
Avalon mailto:mcpheea@cadvision.comBug track discussion list mailto:bugtraq-request@fc.net
http://www.eecs.nwu.edu/~jmyers/bugtraq/index.html
´ÙÀ½À» ¾ð´õ±×¶ó¿îµå »çÀÌÆ® ¿¡ ´ëÇÑ ¸µÅ© ¸ñ·Ï °ßº»À¸·Î, À̸¦ º¸¸é ÀÎÅÍ³Ý ÇØÄ¿µéÀÌ ¾î¶² »ý°¢À» ÇÏ°í ¾î¶² Á¤º¸·ÎºÎÅÍ ½ÃÀÛÇÒÁö¿¡ ´ëÇÑ »ý°¢ÀÌ µé °ÍÀÌ´Ù.
www.insecure.org ´Ù¸¥ °Íº¸´Ùµµ nmapÀÇ È¨
www.nessus.org Èï¹Ì·Î¿î ½ºÄ³³Ê
www.rootshell.com µµ±¸ ¸ðÀ½
www.l0pht.com NT ÆÐ½º¿öµå Å©·¡Å· & NFR Ç÷¯±×ÀÎ
www-personal.engin.umich.edu/~jgotts/underground/hack-faq.html alt.2600/#hack FAQ intro.
scitsc.wlv.ac.uk/~cs6171/hack/index.html Unix /net /hack page
scitsc.wlv.ac.uk/~cs6171/phrack/phrackindex.html Phrack
mailto:phrack@well.sf.ca.us Phrack
www.unix.geek.net/~arny Unix /net /hack page ¹Ì±¹ ¹Ì·¯»çÀÌÆ®
www.paranoia.com/~coldfire/index.html Cold Fire's Web Page
www.2600.com 2600 Magazine
www-personal.engin.umich.edu/~jgotts/underground.html The Internet Underground
bush.cs.tamu.edu/~erich/alt.cp.faq.html alt.cyberpunk FAQ ¸ñ·Ï
mailto:tk0jut2@mvs.cso.niu.edu Computer Underground Digest
www.wiretrip.net/rfp/2/index.asp Rain.Forest.Puppy
www.dbnet.ece.ntua.gr/~george/security/ HawkÀÇ º¸¾È ¸µÅ©
www.hideaway.net/security_links.html Hideaway.Net - º¸¾È ¸µÅ©
www.secure.cybercomm.nl/index2.html ¾ÈÀüÇÑ »çÀ̹öÅë½Å
±âŸ:
www.scit.wlv.ac.uk/rfc/index.html HTML Çü½ÄÀÇ RFCs
www.technotronic.com/tcpudp.html tcp, udp ¹× ¼ºñ½º ¸ñ·Ï ¼³¸í
www.isi.edu/in-notes/iana/assignments/port-numbers IANA Æ÷Æ®¹øÈ£ ¸ñ·Ï
www-arc.com/sara SARA - satan °°Àº ½ºÄ³³Ê
www.wwdsi.com/saint SAINT ½ºÄ³³Ê
www.nessus.org NESSUS ½ºÄ³³Ê
www.SecuriTeam.com º°·Î ¾ÈÁÁ´Ù.tycho.usno.navy.mil The Official Source of Time for the Department of Defense and the Standard of Time for the United States
FIRST´Â »ç°í ¿¹¹æ, »ç°í¿¡ ´ëÇÑ ½Å¼ÓÇÑ ´ëÀÀÀ» À§ÇÑ Çù·ÂÀ» Á¶ÀåÇϰí ȸ¿øµé ¹× ±¤¹üÀ§ÇÑ °øµ¿Ã¼°£ÀÇ Á¤º¸°øÀ¯¸¦ ¸ñÀûÀ¸·Î ÇÏ´Â ±¹Á¦ Á¶Á÷µé (Á¤ºÎ & ¹Î°£ ºÐ¾ß ¸ðµÎ) ÀÇ ¿¬ÇÕÀÌ´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº À̵éÀÇ WWW ÆäÀÌÁö¿¡¼ ã°Å³ª www.first.org À̸ÞÀÏ mailto:first-sec@first.org·Î ¿¬¶ôÇÏ¸é µÈ´Ù. ÀϹÝÀûÀ¸·Î »ç¿ëÀÚµéÀº, FIRST °¡ Àü¼¼°è º¸¾È°ü¸®ÀÚ¸¦ À§ÇÑ ¸ÞÀϸµ ¸®½ºÆ®¸¦ ¿î¿µÇÏ°Ô Çϱ⺸´Ù´Â, °¡Àå °¡±î¿î FIRST ¿¡ ¿¬¶ôÇϰí À̵éÀÇ ¸ÞÀϸµ¸®½ºÆ®¿¡ °¡ÀÔÇØ¾ß ÇÑ´Ù!
FIRST ´Â 30°³°¡ ³Ñ´Â ȸ¿ø¼ö¸¦ °¡Áø´Ù (1995³â 11¿ù ±âÁØ). °¡Àå ¿µÇâ·ÂÀִ ȸ¿øµéÀº (ÀúÀÚÀÇ ¼Ò°ßÀ¸·Î) CERT, AUSCERT, DFN-CERT, CIAC ÀÌ´Ù. ÀÌ ±×·ìµéÀº ´ÙÀ½ Àýµé¿¡¼ ÈξÀ »ó¼¼ÇÏ°Ô ¼³¸íµÈ´Ù.
´ëºÎºÐÀÇ FIRST ȸ¿øµéÀº PGP¸¦ ½á¼ À̸ÞÀÏ¿¡ ¼¸íÇÏ°í ÆÐÄ¡ ÆÄÀÏÀÇ ¹«°á¼º °Ë»ç¿¡ MD5 ¸¦ »ç¿ëÇϹǷÎ, ÀÌµé µÎ À¯Æ¿¸®Æ¼¸¦ °¡Áö°í ÀÖÀ» °ÍÀ» ±Ç°íÇÑ´Ù.
CERT ´Â, ÀÎÅÍ³Ý ¿ú »ç°Çµ¿¾È º¸¿©Áø Çʿ伺¿¡ ºÎÀÀÇÏ¿© ¹Ì ±¹¹æ °íµî¿¬±¸ ÇÁ·ÎÁ§Æ® ±â°ü (US Defence Advanced Research Projects Agency, DARPA) ¿¡ ÀÇÇØ 1988³â 11¿ù ¸¸µé¾îÁø ÄÄÇ»ÅÍ ºñ»ó ´ëÀÀÆÀ (Computer Emergency Response Team) ÀÌ´Ù. CERT ¼³¸³ÃëÁö´Â ÀÎÅÍ³Ý °øµ¿Ã¼¿Í Çù·ÂÇÏ¿© ÀÎÅÍ³Ý È£½ºÆ® °ü·Ã ÄÄÇ»ÅÍ º¸¾È »ç°Ç ´ëÀÀÀ» ÃËÁøÇϰí, °øµ¿Ã¼ÀÇ ÄÄÇ»ÅÍ º¸¾È ÀνÄÀ» ³ôÀ̱â À§ÇÑ ¼øÇâÀû (proactive) Á¶Ä¡¸¦ ÃëÇϰí, ±âÁ¸ ½Ã½ºÅÛµéÀÇ º¸¾È °³¼±À» ¸ñÇ¥·Î ÇÏ´Â ¿¬±¸¸¦ ¼öÇàÇÏ´Â °ÍÀÌ´Ù.
Computer Emergency Response Team (CERT)
mailto:cert@cert.org (Åë½ÅÀº DES ³ª PGP ·Î ¾ÏÈ£È ÇÒ °ÍÀ» ±ÇÀå)
Tel. +1 412 268-7090
CERT ±Ç°í¹®Àº ÁÖ·Î À¯´Ð½º& VMS °ü¸®Àڵ鿡°Ô Èï¹ÌÀÖ´Â °ÍµéÀÌÁö¸¸, NTµµ ÀÖ°í, À©µµ¿ì³ª MacÀº °ÅÀÇ ¾ø´Ù (¾Æ·¡ CIAC ÂüÁ¶).
CERT ´Â 1988³â À¥ ÆäÀÌÁö¸¦ Àü¸é °³ÆíÇßÀ¸¸ç, Áö³ª°£ CERT ±Ç°í¹®À» HTML Çü½ÄÀ¸·Î ±¸ÇÒ ¼ö ÀÖ°í, ¶Ç ¸¹Àº °ÍµéÀÌ ÀÖ´Ù www.cert.org.
ÀÌ ¹üÀ§±îÁö´Â ÀÌ ÀýÀÌ Á¶±Ý Áߺ¹µÈ´Ù (1999).
ftp://ftp.cert.org/pub/cert_advisories/ [»öÀÎÀº 01-README ÆÄÀÏ¿¡]
ftp://ftp.cert.org/pub/cert_summaries/
ftp://ftp.cert.org/pub/cert_bulletins/
ftp://ftp.cert.org/pub/tech_tips/packet_filtering
ftp://ftp.cert.org/pub/tech_tips/UNIX_configuration_guidelines
ftp://info.cert.org/pub/tools/
ftp://info.cert.org/pub/tech_tips/security_tools
ftp://info.cert.org/pub/incident_reporting_form
ftp://info.cert.org/pub/whois_how_to
ftp://info.cert.org/pub/FIRST/first-contacts
¾Æ·¡´Â ¿ÏÀüÇÑ ±Ç°í¹® ¸ñ·ÏÀÌ´Ù:
| CA-88:01.ftpd.hole | CA-94:05.MD5.checksums |
| CA-89:01.passwd.hole | CA-94:06.utmp.vulnerability |
| CA-89:02.sun.restore.hol | CA-94:07.wuarchive.ftpd.trojan.horse |
| CA-89:03.telnet.breakin.warning | CA-94:08.ftpd.vulnerabilities |
| CA-89:04.decnet.wank.worm | CA-94:09.bin.login.vulnerability |
| CA-89:05.ultrix3.0.hole | CA-94:10.IBM.AIX.bsh.vulnerability |
| CA-89:06.ultrix3.0.update | CA-94:11.majordomo.vulnerabilities |
| CA-89:07.sun.rcp.vulnerability | CA-94:12.sendmail.vulnerabilities |
| CA-90:01.sun.sendmail.vulnerability | CA-94:13.SGI.IRIX.Help.Vulnerability |
| CA-90:02.intruder.warning | CA-94:14.trojan.horse.in.IRC.client.for.UNIX |
| CA-90:03.unisys.warning | CA-94:15.NFS.Vulnerabilities |
| CA-90:04.apollosuid.vulnerability | CA-95:01.IP.spoofing |
| CA-90:05.sunselection.vulnerability | CA-95:01.IP.spoofing.attacks.and.hijacked.terminal.connections |
| CA-90:06a.NeXT.vulnerability | CA-95:02.binmail.vulnerabilities |
| CA-90:07.VMS.ANALYZE.vulnerabiliy | CA-95:03.telnet.encryption.vulnerability |
| CA-90:08.irix.mail | CA-95:03a.telnet.encryption.vulnerability |
| CA-90:09.vms.breakins.warning | CA-95:04.NCSA.http.daemon.for.unix.vulnerability |
| CA-90:10.attack.rumour.warning | CA-95:05.sendmail.vulnerabilities |
| CA-90:11.Security.Probes | CA-95:06.satan |
| CA-90:12.SunOS.TIOCCONS.vulnerability | CA-95:07.vulnerability.in.satan |
| CA-91:01a.SunOS.mail.vulnerability | CA-95:07a.REVISED.satan.vul |
| CA-91:02a.SunOS.telnetd.vulnerability | CA-95:08.sendmail.v.5.vulnerability |
| CA-91:03.unauthorized.password.change.request | CA-95:09.Solaris-ps.vul |
| CA-91:04.social.engineering | CA-95:09.Solaris.ps.vul |
| CA-91:05.Ultrix.chroot.vulnerability | CA-95:10.ghostscript |
| CA-91:06.NeXTstep.vulnerability | CA-95:11.sun.sendmail-oR.vul |
| CA-91:07.SunOS.source.tape.vulnerability | CA-95:12.sun.loadmodule.vul |
| CA-91:08.systemV.login.vulnerability | CA-95:13.syslog.vul |
| CA-91:09.SunOS.rpc.mountd.vulnerability | CA-95:14.Telnetd_Environment_Vulnerability |
| CA-91:10a.SunOS.lpd.vulnerability | CA-95:15.SGI.lp.vul |
| CA-91:11.Ultrix.LAT-Telnet.gateway.vulnerability | CA-95:16.wu-ftp_vulnerability |
| CA-91:12.Trusted.Hosts.Configuration.vulnerability | CA-95:17.rpc.ypupdated |
| CA-91:13.Ultrix.mail.vulnerability | CA-95:18-Widespread attacks |
| CA-91:14.IRIX.mail.vulnerability | CA-96.01.UDP_service_denial |
| CA-91:15.NCSA.Telnet.vulnerability | CA-96.02 BIND Version 4.9.3 |
| CA-91:16.SunOS.SPARC.Integer_Division.vulnerability | CA-96.03 Vulnerability in Kerberos 4 & 5 |
| CA-91:17.DECnet-Internet.Gateway.vulnerability | CA-96.04 Corrupt information from Network Servers |
| CA-91:18.Active.Internet.tftp.Attacks | CA-96.05.java_applet_security_mgr |
| CA-91:19.AIX.TFTP.Daemon.vulnerability | CA-96.06.cgi_example_code |
| CA-91:20.rdist.vulnerability | CA-96.07.java_bytecode_verifier |
| CA-92:01.NeXTstep.configuration.vulnerability | CA-96.08.pcnfsd |
| CA-92:02.Michelangelo.PC.virus.warning | CA-96.09.rpc.statd |
| CA-92:03.Internet.Intruder.Activity | CA-96.10.nis+_configuration |
| CA-92:04.ATT.rexecd.vulnerability | CA-96.11.interpreters_in_cgi_bin_dir |
| CA-92:05.AIX.REXD.Daemon.vulnerability | CA-96.12.suidperl_vul |
| CA-92:06.AIX.uucp.vulnerability | CA-96.13.dip_vul |
| CA-92:07.AIX.passwd.vulnerability | CA-96.14.rdist_vul |
| CA-92:08.SGI.lp.vulnerability | CA-96.15.Solaris_KCMS_vul |
| CA-92:09.AIX.anonymous.ftp.vulnerability | CA-96.16.Solaris_admintool_vul |
| CA-92:10.AIX.crontab.vulnerability | CA-96.17.Solaris_vold_vul |
| CA-92:11:SunOS.Environment.vulnerability | CA-96.18.fm_fls |
| CA-92:12.REVISED.SunOS.rpc.mountd.vulnerability | CA-96.19.expreserve |
| CA-92:13.SunOS.NIS.vulnerability | CA-96.20.sendmail_vul |
| CA-92:14.Altered.System.Binaries.Incident | CA-96.21.tcp_syn_flooding |
| CA-92:15.Multiple.SunOS.vulnerabilities.patched | CA-96.22.bash_vuls |
| CA-92:16.VMS.Monitor.vulnerability | CA-96.23.workman_vul |
| CA-92:17.HP.NIS.ypbind.vulnerability | CA-96.24.sendmail.daemon.mode |
| CA-92:18.VMS.Monitor.vulnerability.update | CA-96.25.sendmail_groups |
| CA-92:19.Keystroke.Logging.Banner.Notice | CA-96.26.ping |
| CA-92:20.Cisco.Access.List.vulnerability | CA-96.27.hp_sw_install |
| CA-92:21.ConvexOS.vulnerabilities | CA-97.01.flex_lm |
| CA-93:01.REVISED.HP.NIS.ypbind.vulnerability | CA-97.02.hp_newgrp |
| CA-93:02a.NeXT.NetInfo._writers.vulnerabilities | CA-97.03.csetup |
| CA-93:03.SunOS.Permissions.vulnerability | CA-97.04.talkd |
| CA-93:04a.Amiga.finger.vulnerability | CA-97.05.sendmail |
| CA-93:05.OpenVMS.AXP.vulnerability | CA-97.06.rlogin-term |
| CA-93:06.wuarchive.ftpd.vulnerability | |
| CA-93:08.SCO.passwd.vulnerability | |
| CA-93:09.SunOS.expreserve.vulnerability | |
| CA-93:09a.SunOS.expreserve.vulnerability | |
| CA-93:10.anonymous.FTP.activity | |
| CA-93:11.UMN.UNIX.gopher.vulnerability | |
| CA-93:12.Novell.LOGIN.EXE.vulnerability | |
| CA-93:13.SCO.Home.Directory.Vulnerability | |
| CA-93:14.Internet.Security.Scanner | |
| CA-93:15.SunOS.and.Solaris.vulnerabilities | |
| CA-93:16.sendmail.vulnerability | |
| CA-93:16a.sendmail.vulnerability.supplement | |
| CA-93:17.xterm.logging.vulnerability | |
| CA-93:18.SunOS.Solbourne.loadmodule.modload | |
| CA-93:19.Solaris.Startup.vulnerability | |
| CA-94:01.network.monitoring.attacks | |
| CA-94:01.ongoing.network.monitoring.attacks | |
| CA-94:02.REVISED.SunOS.rpc.mountd.vulnerability | |
| CA-94:03.AIX.performance.tools | |
| CA-94:04.SunOS.rdist.vulnerability |
º¥´õ °ø½Ã:
| VB-94:01.sco | VB-95:10 - Vulnerability in elm V2.4 PL 24 | VB-96-11.free.bsd PPP |
| VB-94:02.dec | VB-96.01.splitvt | VB-96.12.free bsd RZ |
| VB-95:01.hp | VB-96.02.sgi Packages | VB-96.13 HP, elm |
| VB-95:02.sgi | VB-96.03.sun catalyst CDware | VB-96.14 SGI, IRIX tools |
| VB-95:03.hp | VB-96.04.bsdi Kernel | VB-96.15 SCO |
| VB-95:04.venema | VB-96.05.dec | VB-96.16 Transarc, AFS/DFS |
| VB-95:05.osf | VB-96.06.freebsd | VB-96.17 Linux |
| VB-95:06.cisco | VB-96.07.freebsd | VB-96.18 Sun, libc |
| VB-95:07.abell | VB-96.08.sgi | VB-96.19 SGI, systour/ OutOfBox |
| VB-95:08.X_Authentication_Vul | VB-96.09.freebsd | VB-96.20 HP, Remote Watch |
| VB-95:09 - Hewlett Packard (ftp) | VB-96.10.sco |
Cert ¿ä¾à:
| CS-95:01 | CS-96:01 | CS-96:04 | |
| CS-95:02 | CS-96:02 | CS-96:05 | |
| CS-95:03 | CS-96:03 | CS-96:06 |
SIRCE (À¯·´ Àüü)
À¯·´ Àü¹ÝÀÇ ½ÃÇèÀû ´ëÀÀÆÀÀº 1997¿¡ ½ÃÀÛÇÑ´Ù. ½ÃÇè ÇÁ·ÎÁ§Æ®´Â ÃÖ´ë 30 °³¿ù°£ Áö¼ÓµÉ °ÍÀ̰í, ±× ÀÌÈÄ¿¡´Â SIRCE (Security Incident Response Co-ordination for Europe) °¡ ¿µ±¸ÀûÀ¸·Î ¿î¿µµÉ °ÍÀÌ´Ù. ½ÃÇèÇÁ·ÎÁ§Æ®´Â UKERNA-DANTE ¿¡ ÀÇÇØ ½ÇÇöµÉ ¿¹Á¤ÀÌ´Ù.. UKERNA ´Â ¿µ±¹ÀÇ ±¹¸³ ¿¬±¸¼Ò ³×Æ®¿öÅ· Á¶Á÷À̰í DANTE´Â À¯·´ÀÇ ³×Æ®¿÷ ¿¬±¸ ºñ¿µ¸® Á¶Á÷ÀÌ´Ù.
SWITCH-CERT (½ºÀ§½º)
½ºÀ§½ºÀÇ Swiss Academic and Research Network CERT ´Â ½ºÀ§½º ½Ã½ºÅÛ °ü¸®ÀÚµéÀ» À§ÇÑ º¸¾ÈÁ¤º¸ÀÇ Áß½ÉÁö¸¦ Á¦°øÇÑ´Ù. SWITCH-CERT ´Â FIRST ȸ¿ø ¹× ƯÁ¤ ÇØÅ· ±×·ìµé·ÎºÎÅÍÀÇ ¸ðµç ±Ç°í¹®µé¿¡ ´ëÇØ ȸ¿øµé¿¡°Ô Á¤º¸¸¦ ¾Ë¸°´Ù. ½ºÀ§½ºÀÇ °ü¸®ÀÚµéÀº SWITCH-CERT ¸ÞÀϸµ ¸®½ºÆ® °¡ÀÔÀ» Àû±Ø ÃßõÇÑ´Ù. Contact cert-staff@switch.ch.
DFN-CERT (µ¶ÀÏ)
German Federal Networks CERT ´Â µ¶ÀÏÀÇ º¸¾È activityµéÀ» Á¤¸®ÇÑ´Ù. Email dfncert@cert.dfn.de , tel. +49 040 5494-2262.
Italy: cert-it@dsi.unimi.it
³×´ú¶õµå: cert-nl@surfnet.nl
À×±Û·£µå: cert@ja.net
Australian CERT ´Â Áö¸®ÀûÀ¸·Î ¶³¾îÁ® ÀÖÁö¸¸, ¶§¶§·Î »õ·Î¿î º¸¾È ¹®Á¦³ª ±×µéÀÇ ¼Ö·ç¼Ç ¶Ç´Â ÀÛ¾÷¿¡ ´ëÇØ ±Ç°íÇÒ ¶§ °¡Àå ºü¸£´Ù.
http://www.auscert.org.au/information/advisories.html µµ ÂüÁ¶ÇÑ´Ù.
Email: auscert@auscert.org
Tel: +61 7 3365 4417
NASA ÆÀÀº NASA »ç¿ëÀڵ鿡°Ô¸¸ Áö¿øÀ» Á¦°øÇÏÁö¸¸, ¹ß°ßµÈ Ãë¾àÁ¡µéÀ» FIRST ȸ¿øµé¿¡°Ô ¹ßÇ¥ÇÑ´Ù.
http://nasirc.nasa.gov
ftp://nasirc.nasa.gov
Tel. +1 800 762-7472
CIAC (Computer Incident Advisory Capability)Àº ¹Ì ¿¡³ÊÁö¼º (DOE)°ú ¹Ì ±¹¸³ º¸°Ç¿ø (National Institute for Health, NIH) À» À§ÇÑ ÄÄÇ»ÅÍ º¸¾È ´ëÀÀÆÀÀÌ´Ù. CIAC´Â FIRSTÀÇ Ã¢´Ü¸â¹öÀÌ´Ù.
Tel. +1 510 422-8193
Email: ciac@llnl.gov
ÀÌÀü CIAC °øÁö, ¾ÈƼ¹ÙÀÌ·¯½º ¼ÒÇÁÆ®¿þ¾î ¹× ±âŸ Á¤º¸µéÀ» http://ciac.llnl.gov ¶Ç´Â ftp://ciac.llnl.gov ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Ù . ³× °³ÀÇ ¼¿ÇÁ °¡ÀÔ ¸ÞÀϸµ ¸®½ºÆ®µéÀÌ ÀÖÁö¸¸ (¾Æ·¡ ÂüÁ¶), °¡Àå °¡±î¿î FIRST ¿¡¼ CIACÀÇ ¸ðµç ±Ç°í¹®À» À̼ÛÇØÁֹǷΠCIAC¿¡ Á÷Á¢ °¡ÀÔÇÒ ÇÊ¿ä´Â °ÅÀÇ ¾ø´Ù.
ciac-listproc@llnl.gov ·Î º»¹®¿¡ ´ÙÀ½ Áß Çϳª (¶Ç´Â ±× ÀÌ»ó)ÀÇ ÇàÀ» Æ÷ÇÔ½ÃÄÑ À̸ÞÀÏÀ» º¸³½´Ù:
subscribe CIAC-ANNOUNCE MYNAME, MYFORENAME MY_PHONE_NR
subscribe CIAC-NOTES MYNAME, MYFORENAME MY_PHONE_NR
subscribe SPI-ANNOUNCE MYNAME, MYFORENAME MY_PHONE_NR
subscribe SPI -NOTES MYNAME, MYFORENAME MY_PHONE_NR
CIAC Àº ´ÙÀ½ ÇüÅ·ΠÁ¤º¸¸¦ Á¦°øÇÑ´Ù:
| A-01: Internet Attacks | D-01: Novell NetWare Access Rights Vulnerability |
| A-02: The W.COM Worm affecting VAX VMS Systems | D-02: Internet Attack Advisory |
| A-03: Tools to check the spread of the "WANK" Worm | D-03: Patch Available for VAX/VMS MONITOR Vulnerability |
| A-04: New version of the "WANK" worm | D-04: 18 New and Upgraded Security Patches For SunOS |
| A-05: Vulnerability in the SUN rcp utility | D-05: Revised Hewlett-Packard NIS ypbind Vulnerability |
| A-06: Trojan horse in Norton Utilities for IBM PCs and clones | D-06: Failure to disable user accounts for VMS 5.3 to 5.5-2 |
| A-07: Information about a UNICOS Problem | D-07: UNICOS Vulnerabilities |
| A-08: Information about a UNICOS Problem | D-08: Vulnerability in VMS V5 |
| A-09: Information about the WDEF virus | D-09: OpenVMS VAX Patch Problems |
| A-10: Information about the PC CYBORG (AIDS) trojan horse | D-10: November 17 Virus on MS DOS Computers |
| A-11: Problem in the Texas Instr. D3 Process Control System | D-11: Sun Security Patches and Software Updates |
| A-12: DECNET Hacker Attack Alert | D-12: UNICOS Vulnerabilities |
| A-13: Vulnerability in DECODE alias | D-13: wuarchive FTP daemon vulnerability |
| A-14: Additional info on the vulnerability in the DECODE alias | D-14: UNICOS Vulnerabilities |
| A-15: CIAC Bulletin A-15 | D-15: Vulnerability in Cisco Routers used as Firewalls |
| A-16: Vulnerability in SUN sendmail program | D-16: Vulnerability in SunOS expreserve Utility |
| A-17: Eradicating WDEF using Disinfectant 1.5 or 1.6 | D-17: LIMITED DISTRIBUTION BULLETIN |
| A-18: Notice of Availability of Patch for SmarTerm 240 | D-18: Solaris 2.x expreserve patches available |
| A-19: UNIX Internet Attack Advisory | D-19: Wide-spread Attacks on Anonymous FTP Servers |
| A-20: The Twelve Tricks Trojan Horse | D-20: Summary of SunOS Security Patches |
| A-21: Additional Information on Current UNIX Internet Attacks | D-21: Novell NetWare LOGIN.EXE Security Patch |
| A-22: Logon Messages and Hacker/Cracker Attacks | D-22: Satan Bug Virus on MS-DOS computers |
| A-24: Password Problems with Unisys U5000 /etc/passwd | D-23: Cray UltraNet Security Vulnerability |
| A-25: The MDEF or Garfield Virus on Macintosh Computers | D-24: SCO Home Directory Vulnerability |
| A-26: A New Macintosh Trojan Horse Threat--STEROID | D-25: Automated Scanning of Network Vulnerabilities |
| A-27: The Disk Killer (Orge) Virus on MS DOS Computers | D-26: Limited Distribution Bulletin |
| A-28: The Stoned (Marijuana or New Zealand) Virus on DOS | E-01: Sun sendmail, tar, and audio Vulnerabilities |
| A-29: The 4096 (4k, Stealth, IDF, etc.) Virus on MS DOS | E-02: Vulnerabilities in SGI IRIX Default Configuration |
| A-30: Apollo Domain/OS suid_exec Problem | E-03: UNIX sendmail Vulnerabilities |
| A-32: SunView/SunTools selection_svc Vulnerability | E-04: xterm Logfile Vulnerability |
| A-33: Virus Propagation in Novell and Other Network | E-05: SunOS/Solbourne loadmodule and modload Vulnerability |
| A-34: End of FY90 Update | E-06: Solaris System Startup Vulnerability |
| B-01: Security Problem on the NeXT Operating System | E-07: UNIX sendmail Vulnerabilities Update |
| B-02: UNIX Security Problem with Silicon Graphics Mail | E-09: Network Monitoring Attacks |
| B-04: VMS Security Problem :ANALYZE/PROCESS_DUMP | E-11: Lotus cc:Mail Security Upgrade Available |
| B-05: HP-UX Trusted Systems 6.5 or 7.0, Authorization | E-12: Network Monitoring Attacks Update |
| B-07: BITNET Worm | E-13: Sun Announces Patches for /etc/utmp Vulnerability |
| B-08: Detection/Eradication Procedures for VMSCRTL.EXE Trojan Horse | E-14: wuarchive ftpd Trojan Horse |
| B-09: Update on Internet Activity | E-17: FTP Daemon Vulnerabilities |
| B-10: Patch for TIOCCON in SunOS 4.1 and 4.1.1 Available | E-18: Sun Announces Patches for automountd Vulnerability |
| B-11: OpenWindows 2.0 selection_svc Vulnerability | E-19: nVir A Virus Found on CD-ROM |
| B-12: GAME2 MODULE "Worm" on BITNET | E-20: Trojan Attack on Chinon CD-ROM Drives |
| B-13: UNIX Security Problem with /bin/mail in SunOS | E-23: Vulnerability in HP-UX systems with HP Vue 3.0 |
| B-14: Additional Info. about /bin/mailin SunOS | E-24: Security Patch Kits for ULTRIX, and OSF/1 |
| B-15: Network intrus. through TCP/IP and DECnet Gateways | E-25: BSD lpr Vulnerability in SGI IRIX |
| B-16: Virus Information Update | E-26: UNIX /bin/login Vulnerability |
| B-17: Increasing Security on Your UNICOS System | E-29: IBM AIX bsh Queue Vulnerability |
| B-18: MVS Security Problem with TSO Reconnect Facility | E-30: Majordomo distribution list administrator vulnerabilities |
| B-19: Vulnerability in UNIX System V on 386/486 Platforms | E-31: Sendmail -d and Sendmail -oE Vulnerabilities |
| B-20: Patch Available for SunOS in.telnetd | E-32: KAOS4 Virus |
| B-21: Patch for SunOS 4.0.3 in.telnetd and in.rlogind | E-33: Vulnerabilities in the SGI IRIX Help System |
| B-22: Attempts by Network Intruders to Obtain Passwords | E-34: One_half Virus (MS-DOS) |
| B-24: Ultrix V4.0 and V4.1 Vulnerability | F-01: SGI IRIX serial_ports Vulnerability |
| B-25: Configuration Problems in the NeXT Operating System | F-02: Summary of HP Security Bulletins |
| B-26: Inconsis. Dir. and File Perms. in SunOS 4.1 and4.1.1 | F-04: Security Vulnerabilities in DECnet/OSI for OpenVMS |
| B-27: sunsrc setuid Installation Problem | F-05: SCO Unix at, login, prwarn, sadc, and pt_chmod Patches |
| B-28: AT&T System V Release 4 Patch for /bin/login | F-06: Novell UnixWare sadc, urestore, and suid_exec |
| B-30: SunOS lpd Problem | F-07: New and Revised HP Bulletins |
| B-31: CRAY UNICOS 6.0 and 6.1 accton vulnerability | F-08: Internet Address Spoofing and Hijacked Session Attacks |
| B-32: Ultrix /usr/bin/mail Security Problem | F-09: Unix /bin/mail Vulnerabilities |
| B-33: New SunOS lpd Problem | F-10: HP-UX Remote Watch |
| B-33A: New SunOS lpd Problem -- Correction | F-11: Unix NCSA httpd Vulnerability |
| B-35: Brunswick Virus on MS DOS Computers | F-12: Kerberos Telnet Encryption Vulnerability |
| B-36: New patch available for /usr/ucb/telnet on ULTRIX | F-13: Unix Sendmail Vulnerabilities |
| B-37: Security Problem with UNIX Trusted System Files | F-14: HP-UX Malicious Code Sequences |
| B-38: Vulnerability in Silicon Graphics Inc. "IRIX" /usr/sbin/fmt | F-15: HP-UX ?t' and ?ron' vulnerabilities |
| B-40: Virus distributed in PCNFS software fix for MS-DOS | F-16: SGI IRIX Desktop Permissions Tool Vulnerability |
| B-41: Vulnerability in SunOS SPARC Integer Division | F-18: MPE/iX Vulnerabilities |
| B-42: Security Issues with Macintosh System 7 | F-19: Protecting HP-UX Systems Against SATAN |
| B-43: Vulnerability in ULTRIX DECnet-Internet Gateway | F-20: SATAN |
| B-44: Automated tftp Probe Attacks on UNIX Systems | F-21: Protecting SUN OS Systems Against SATAN |
| B-45: End of FY91 Update | F-22: SATAN password disclosure |
| C-01: New TFTPD server available for IBM RS6000 systems | F-23: Protecting IBM AIX Systems Against SATAN |
| C-02: Dir II Virus on MS DOS Computers | F-24: Protecting SGI IRIX Systems Against SATAN |
| C-04: Vulnerability in the rdist utility on UNIX platforms | F-25: Cisco IOS Router Software Vulnerability |
| C-05: Preliminary Information about SYSMAN.EXE Trojan | F-26: OSF/DCE Security Hole |
| C-06: Security Problem in SunOS fsirand Program | F-27: Incorrect Permissions on /tmp |
| C-07: Additional Information about the SYSMAN.EXE Trojan | F-28A: Vulnerability in SunOS 4.1.* Sendmail (-oR option) |
| C-08: SunOS /usr/ucb/rdist patch | G-01: Telnetd Vulnerability |
| C-10: OpenWindows V.3 patch | G-02: SunOS 4.1.X Loadmodule Vulnerability |
| C-11: Novell Network Support Encyclopaedia Update Virus | G-03: AOLGOLD Trojan Program |
| C-12: Hewlett Packard/Apollo Domain/OS crp Vulnerability | G-04: X Authentication Vulnerability |
| C-13: NeXTstep NetInfo Configuration Vulnerability | G-05: HP-UX FTP Vulnerability |
| C-15: Michelangelo Virus on MS DOS Computers | G-06a Windows 95 Vulnerabilities |
| C-16: New Internet Intrusions Detected | G-07: SGI Object Server Vulnerability |
| C-17: New Virus on Macintosh Computers: MBDF A | G-08: splitvt() vulnerability |
| C-18: Vulnerability In AT&T /usr/etc/rexecd | G-09: Unix Sendmail Vulnerability |
| C-19: Vulnerabilities in SAS?System 5.18 for VMS | G-10: Winword & Excel Macro Viruses |
| C-20: SGI 3.3.X Pseudo-tty Vulnerability | G-11: HP syslog Vulnerability |
| C-21: AIX REXD Daemon Vulnerability | G-12: SGI ATT Packaging Utility Security |
| C-25: SunOS ypserv, ypxfrd, and portmap Patch | G-13: Kerberos 4 Key Server Vulnerability |
| C-26: SunOS Environment Variables and setuid/setgid | G-14: Domain Name Service Vulnerability |
| C-27: PKZIP Trojan Alert | G-15: Sunsoft Demo CD Vulnerability |
| C-28: SunOS Security Patches | G-16: SGI rpc.statd Program Security Vulnerability |
| C-29: Summary of SunOS Security Patches | G-17: Vulnerabilities in Sample HTTPD CGIs |
| C-30: VAX/VMS Security Vulnerability in MONITOR | G-18: Digital OSF/1 dxconsole Security Vulnerability |
| CIAC-01: Authentication Bypass in Sun 386i Machines | G-19: IBM AIX rmail Vulnerability |
| CIAC-02: Columbus Day Virus | G-20: Vulnerability in NCSA and Apache httpd Servers |
| CIAC-03: ULTRIX DECWindows Vulnerability | G-21: Vulnerabilities in PCNFSD Program |
| CIAC-04: Jerusalem/Israeli/Friday the 13th Virus | G-22: rpc.statd Vulnerability |
| CIAC-05: Security Holes in UNIX Systems | G-23: Solaris NIS+ Configuration Vulnerability |
| CIAC-06: Patch for rwalld/wall | G-24: FreeBSD Security Vulnerabilities |
| CIAC-07: Vulnerability Involving rcp and rdist | G-25: SUN statd Program Vulnerability |
| CIAC-08: Vulnerability in the SunOS Restore Utility | G-26: IRIX Desktop Permissions Panel Vulnerability |
| CIAC-09: Macintosh nVIR Virus | G-27: SCO Kernel Security Vulnerability |
| CIAC-10: IBM PC Columbus Day (Datacrime) Virus | G-28a: suidperl Vulnerability |
| CIAC-11: Telnet Trojan Horse | |
| CIAC-12: Patch for rcp and rdist | |
| CIAC-13: Macintosh and IBM PC NCSA Telnet Vulnerability |
Clusis (TBD)
NSA (National Security Agency, ±¹°¡ ¾Èº¸±¹)
NSA ´Â TCSEC°ú °ü·Ã Rainbow books¸¦ °³¹ßÇß´Ù. À̵éÀº ±¹¹æ¼º (DOD)ÀÇ ÀÏ¿øÀ¸·Î¼, °·ÂÇÑ Á¤º¸Á¶Á÷À¸·Î ´õ Àß ¾Ë·ÁÁ® ÀÖ´Ù.
NIST (National Institute of Standards and Technology, ±¹¸³ Ç¥Áرâ¼ú¿¬±¸¼Ò)
NIST ´Â Rainbow books ¿Í ±âŸ ´Ù¸¥ º¸¾È ¼ÒÃ¥ÀÚµéÀ» ¹èÆ÷ÇÑ´Ù. À̵éÀº NSA¿Í ¸Å¿ì ±ä¹ÐÇÏ°Ô ÀÏÇÑ´Ù (NSAÀÇ ÀϺκÐÀΰ¡?)
TBD: ÃÖ¼Ò º¸¾È ±â´ÉÀû ¿ä±¸»çÇ× Minimum Security Functional Requirement (MSFR)
NIST, Computer Security Labs,
Gaithersburg, Maryland 20899, USA
Tel. 301-975-2000
NCSC (National Computer Security Center, ±¹¸³ ÄÄÇ»ÅÍ º¸¾È ¼¾ÅÍ)
NSAÀÇ ÀÏ¿øÀ¸·Î, TCSEC Ç¥ÁØ¿¡ µû¶ó IT Á¦Ç°µéÀ» Æò°¡ÇÑ´Ù. Rainbow books ÀÇ ¿ø·¡ ÃâÆÇÀÚµéÀÌ´Ù.
NCSC
9800 Savage Road, Fort Meade, Maryland 20755,
Tel. 301-859-4371
NCSA (National Computer Security Association, ±¹¸³ ÄÄÇ»ÅÍ º¸¾È Çùȸ)
(Á¤ºÎ ÈÄ¿øÀÇ) NCSA ´Â ±³À°, ÄÁÆÛ·±½º, ´º½º·¹ÅÍ µî ´Ù¾çÇÑ IT ¼ºñ½º¸¦ Á¦°øÇÏ°í ¹ÙÀÌ·¯½º »ç°ÇµéÀ» ²Ï ±ä¹ÐÇÏ°Ô ÃßÀûÇÏ´Â µ¶¸³ Á¶Á÷ÀÌ´Ù.
À̵éÀº ÃÖ±Ù ¹æÈº®°ú ÀÎÅÍ³Ý »çÀÌÆ® ÀÎÁõÀ» ½ÃÀÛÇß´Ù. NCSA ´Â ¶ÇÇÑ ¿ö½ÌÅÏ¿¡¼ º¸¾È °ü·Ã À̽´µéÀÇ Åë°ú¿îµ¿(lobby)À» Çϱ⵵ ÇÑ´Ù.
¹Ì±¹ ¿Ü ȸ»çµé¿¡ ´ëÇÑ ¿¬°£ ȸ¿øºñ´Â $175- Á¤µµ ÇÑ´Ù.
À̵éÀÇ "Á¤º¸Àü" ÄÁÆÛ·±½º°¡ ±¦Âú´Ù.
NSCA 10 S. Courthouse Ave.,
Carlisle, Pennsylvania 17013, USA
Tel. 717-258-1816
COAST (Computer Operations, Audit and Security Technology)
Purdue ´ëÇп¡ ÀÖ´Â COAST ´Â º¸¾È ¿¬±¸ÀÇ Áß½ÉÁöÀÌ´Ù.
http://www.coast.cs.purdue.edu.
ÀÌ ±×·ìµéÀº ¹ß°ßµÈ º¸¾ÈȦµé¿¡ ´ëÇØ »ó¼¼ Á¤º¸¸¦ ¸¸µé¾î ³½´Ù. ¾î¶² °æ¿ì¿¡´Â, ±× ȦÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ´Â ¿¹Á¦ ÄÚµåµéµµ ¹ßÇ¥µÈ´Ù. CERT ¿¡¼ ÀÌµé ±×·ìÀÌ ¹ßÇ¥ÇÑ ±Ç°í¹®µéÀ» ¹ßÇ¥Çϴµ¥ 6°³¿ùÁ¤µµ °É¸± ?°¡ ¸¹À¸¹Ç·Î, º¸¾ÈÀÌ Àڽſ¡°Ô ³ôÀº Á߿伺À» ¶ì°í ÀÖ´Ù¸é À̵éÀÇ ¸ÞÀϸµ ¸®½ºÆ®¿¡ °¡ÀÔÇϵµ·Ï ÇÑ´Ù.
8lgm (8 Little Green Men / 8 Legged Groove Machine)
ÀÌ À̸ÞÀÏ ¸®½ºÆ®¿¡ °¡ÀÔÇÏ·Á¸é (Ãßõ), body="subscribe 8lgm" À¸·Î ÇÏ¿© majordomo@8lgm.org·Î À̸ÞÀÏÀ» º¸³½´Ù. http://www.8lgm.org µµ ÂüÁ¶ÇÑ´Ù. ´ÙÀ½À½ WWW »çÀÌÆ®¿¡ ¾ð±ÞµÈ »çÇ×ÀÌ´Ù:
[8LGM] Àº ½Ã½ºÅÛ °ü¸®ÀÚµéÀÌ ÀÚ½ÅÀÇ ½Ã½ºÅÛµéÀ» °íÄ¥ ¼ö ÀÖ°Ô Çϱâ À§ÇØ, ÀÌ Á¤º¸µéÀ» ¼±ÀÇ·Î Á¦°øÇÑ´Ù. ÇÏÁö¸¸ [8LGM] Àº ¾î¶² ¸ñÀûÀ¸·Îµç ÀÌ Á¤º¸ÀÇ »ç¿ëÀ» ÁöÁöÇÏÁö´Â ¾Ê´Â´Ù.
±Ç°í¹® ¸ñ·Ï (1997³â 2¿ù):
| [8lgm]-Advisory-1.UNIX.rdist.23-Apr-1991 | [8lgm]-Advisory-16.UNIX.sendmail-6-Dec-1994 |
| [8lgm]-Advisory-2.UNIX.autoreply.12-Jul-1991 | [8lgm]-Advisory-16.UNIX.sendmail-6-Dec-1994.UPDATE |
| [8lgm]-Advisory-3.UNIX.lpr.19-Aug-1991 | [8lgm]-Advisory-17.UNIX.sendmailV5-2-May-1995 |
| [8lgm]-Advisory-4.UNIX.gopher.12-Feb-1992 | [8lgm]-Advisory-18.UNIX.SunOS-kernel.4-Dec-1994 |
| [8lgm]-Advisory-5.UNIX.mail.24-Jan-1992 | [8lgm]-Advisory-19.UNIX.SunOS-kernel.1-Jun-1994 |
| [8lgm]-Advisory-5.UNIX.mail.24-Jan-1992.PATCH | [8lgm]-Advisory-20.UNIX.SunOS-sendmailV5.1-Aug-1995 |
| [8lgm]-Advisory-6.UNIX.mail2.2-May-1994 | [8lgm]-Advisory-21.UNIX.SunOS-sendmailV5.22-Aug-1995 |
| [8lgm]-Advisory-7.UNIX.passwd.11-May-1994 | [8lgm]-Advisory-22.UNIX.syslog.2-Aug-1995 |
| [8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX | [8lgm]-Advisory-23.UNIX.SunOS-loadmodule.2-Jan-1995 |
| [8lgm]-Advisory-8.UNIX.SunOS-kernel.11-Nov-1994 | [8lgm]-Advisory-24.UNIX.CERT.Advisory.CA-95:11.20-9-1995 |
| [8lgm]-Advisory-9.UNIX.urestore.10-Feb-1993 | [8lgm]-Advisory-25.UNIX.sun4c.locore.01-09-1995 |
| [8lgm]-Advisory-10.UNIX.SCO-at.10-Feb-1992 | [8lgm]-Advisory-26.UNIX.rdist.20-3-1996 |
| [8lgm]-Advisory-11.UNIX.sadc.07-Jan-1992 | |
| 8lgm]-Advisory-12.UNIX.suid_exec.27-Jul-1991 | |
| [8lgm]-Advisory-13.UNIX.SCO-login.15-Apr-1994 | |
| [8lgm]-Advisory-14.UNIX.SCO-prwarn.12-Nov-1994 | |
| [8lgm]-Advisory-15.UNIX.mail3.28-Nov-1994 |
ASR (Avalon Security Research)
ÃÖ±Ù ('95³â 11¿ù) ½º½º·Î¸¦ "Avalon Security Research" ¶ó°í ºÎ¸£´Â »õ·Î¿î ±×·ìÀÌ º¸¾È Ȧ°ú ÀÌ¿ë¹æ¹ý ¿¡ ´ëÇÑ ±â»çµéÀ» ÀÎÅͳݿ¡ ¿Ã¸®±â ½ÃÀÛÇß´Ù.
ASR ÇØÅ· ±×·ìÀº ÀÚ±âµéÀÌ ¹ß°ßÇØ³½ º¸¾È ȦµéÀÇ Á¤º¸¸¦ ¹ßÇ¥ÇÑ´Ù. À̵éÀº ÀÚ±âµéÀ» ´ÙÀ½°ú °°ÀÌ ¼³¸íÇÑ´Ù:
ASR Àº ¾Æ¹«·¸°Ô³ª Á¶Á÷µÈ ºñ¿µ¸® ±×·ìÀÌ´Ù. ¿ì¸®´Â Áö±Ý±îÁö ¾à 4³â°£ ´Ü¼ÓÀûÀ¸·Î ÇÔ²² ÀÏÇØ¿Ô´Ù. ÃÖ±Ù ¿ì¸®´Â ¿ì¸®ÀÇ ¿¬±¸¸¦ ¹ßÇ¥Çϱâ·Î °áÁ¤Çß´Ù. ÀÌ °áÁ¤Àº ¼ö¸¹Àº ¿äÀο¡ ±Ù°ÅÇÑ °ÍÀ̾ú´Ù. ¿ì¼± ¿ì¸®´Â ÄÄÇ»ÅÍ º¸¾ÈÀÌ ÀÌÁ¦´Â ¾Æ¸¶ ¾î´À¶§º¸´Ùµµ °Å´ëÇÑ ÀÎÅÍ³Ý °øµ¿Ã¼ÀÇ °¡Àå Áß¿äÇÑ Çùµ¿À̶ó´Â °ÍÀ» ±ú´Þ¾Ò´Ù. ½ÇÁ¤ÀÌ ÀÌ·¯ÇϹǷΠ¿ì¸®´Â ¸ðµç Ä«µå°¡ Å×À̺í À§¿¡ ³õ¿©Á®¾ß ÇÑ´Ù°í »ý°¢ÇÑ´Ù. ¿ì¸®¿¡°Ô À̰ÍÀº ¿ÏÀüÇÑ °ø°³Àû ŵµ¿¡ ´ëÇÑ °·ÂÇÑ ÁöÁö¸¦ ¶æÇÑ´Ù.... ±×¸®°í exploits¸¸ ¾Æ´Ï¶ó ´Ù¾çÇÑ Æ¯¼ºÀÇ º¸¾È °¨»ç µµ±¸µéÀ» ¹ßÇ¥ÇÒ °èȹµµ...
¸ÞÀϸµ¸®½ºÆ®¿¡ °¡ÀÔÇÏ·Á¸é, mcphee@cadvision.com ¿¡°Ô ¸ÞÀÏÀ» º¸³½´Ù.
¾Æ·¡´Â 96³â 2¿ù 12ÀÏ ¹ßÇ¥µÈ ¹ö±×¿Í Ȱ¿ë ½ºÅ©¸³Æ® ¸ñ·ÏÀÌ´Ù.
ÀÌ ÀýÀº Á» ¿À·¡µÇ°í, ´ëºÎºÐÀÌ ¿Â¶óÀÎÀ¸·Î ±¸ÇÒ ¼ö Àֱ⠶§¹®¿¡ ´ú À¯¿ëÇÏ´Ù (óÀ½ ½ÃÀÛÇÒ ¶§´Â 1996³âµµ°¡ ¾Æ´Ï¾ú´Ù). °ü·Ã Ç¥ÁصéÀÇ ÃֽŠAcrobat »çº»Àº www.itsec.gov.uk À» Çѹø º¸±â ¹Ù¶õ´Ù.
Rainbow books ´Â Ç¥Áö »ö±ò·Î À¯¸íÇÑ IT º¸¾È ¹®¼ ½Ã¸®ÁîÀÌ´Ù. °¡Àå Àß ¾Ë·ÁÁø °ÍÀº TCSEC Áï Orange Book ÀÌ´Ù (´ÙÀ½ Àý ÂüÁ¶). ´ÙÀ½Àº ÀÌ Ã¥µé°ú »ö±ò, DoD ÂüÁ¶ ¹øÈ£ ¹× Á¦¸ñ¿¡ ´ëÇÑ ¸ñ·ÏÀÌ´Ù. ¿ÏÀüÇÑ ¸ñ·ÏÀ» ¸¸µé·Á°í ¾Ö½èÁö¸¸, ÇÑ µÎ ±ÇÀÇ Ã¥ÀÌ ºüÁ³À» ¼ö ÀÖ´Ù. ¸ñ·ÏÀÇ Ã³À½ ¼¼ Ã¥µéÀÌ Á¦ÀÏ ±¦Âú´Ù.
Orange Book DoD 5200.28-STD DoD TCSEC (Trusted Computer System Evaluation Criteria)
½Å·ÚµÇ´Â ÄÄÇ»ÅÍ ½Ã½ºÅÛ Æò°¡ ±âÁØ
Green Book CSC-STD-002-85 Department of Defense Password Management Guideline
±¹¹æ¼º ÆÐ½º¿öµå °ü¸®Áöħ
Yellow Book CSC-STD-003-85 Computer Security Requirements -- Guidance for Applying TCSEC in Specific Environments
ÄÄÇ»ÅÍ º¸¾È ¿ä±¸»çÇ× -- ƯÁ¤ ȯ°æ¿¡¼ TCSEC Àû¿ë¿¡ ´ëÇÑ °¡À̵å
Yellow Book CSC-STD-004-85 Technical Rationale Behind the above document.
À§ ¹®¼µé¿¡ ´ëÇÑ ±â¼úÀû Á¤´ç¼º
Tan Book NCSC-TG-001 A Guide to Understanding Audit in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅ۵鿡¼ °¨»çÀÇ ÀÌÇØ¿¡ ´ëÇÑ ¾È³»¼
Bright Blue Book NCSC-TG-002 Trusted Product Evaluation - A Guide for Vendors
½Å·ÚµÇ´Â Á¦Ç° Æò°¡ - º¥´õ¸¦ À§ÇÑ ¾È³»¼
Light Blue Book NCSC-TG-002-85 PC Security Considerations
PC º¸¾È °í·Á»çÇ×
Neon Orange Book NCSC-TG-003 Understanding Discretionary Access Control in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ ÀÓÀÇÀû Á¢±ÙÅëÁ¦¿¡ ´ëÇÑ ÀÌÇØ
Teal Green Book NCSC-TG-004 Glossary of Computer Security Terms
ÄÄÇ»ÅÍ º¸¾È ¿ë¾î ÇØ¼³
Red Book NCSC-TG-005 Trusted Network Interpretation of the TCSEC
TCSECÀÇ ½Å·ÚµÇ´Â ³×Æ®¿÷ ÇØ¼®
Orange Book NCSC-TG-006 Understanding Configuration Management in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ ±¸¼º°ü¸® ÀÌÇØ
Burgundy Book NCSC-TG-007 Understanding Design Documentation in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ ¼³°è¹®¼È¿¡ ´ëÇÑ ÀÌÇØ
Dark Lavender Book NCSC-TG-008 Understanding Trusted Distribution in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ ½Å·ÚµÇ´Â ºÐ»ê¿¡ ´ëÇÑ ÀÌÇØ
Venice Blue Book NCSC-TG-009 Computer Security Subsystem Interpretation of the TCSEC
TCSECÀÇ ÄÄÇ»ÅÍ º¸¾È ¼ºê½Ã½ºÅÛ ÇØ¼®
Aqua Book NCSC-TG-010 Understanding Security Modelling in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ º¸¾È ¸ðµ¨¸µ ÀÌÇØ
Dark Red Book NCSC-TG-011 Trusted Network Interpretation Environments Guideline - Guidance for Applying the Trusted Network Interpretation
½Å·ÚµÇ´Â ³×Æ®¿÷ ÇØ¼® ȯ°æ Áöħ - ½Å·ÚµÇ´Â ³×Æ®¿÷ ÇØ¼®ÀÇ Àû¿ë¿¡ ´ëÇÑ ¾È³»¼
Pink Book NCSC-TG-013 Rating Maintenance Phase -- Program Document
Æò°¡µî±Þ À¯Áö ´Ü°è -- ÇÁ·Î±×·¥ ¹®¼È
Purple Book NCSC-TG-014 Guidelines for Formal Verification Systems
°ø½Ä °ËÁõ ½Ã½ºÅÛÀ» À§ÇÑ Áöħ
Brown Book NCSC-TG-015 Understanding Trusted Facility Management
½Å·ÚµÇ´Â ¼³ºñ°ü¸® ÀÌÇØ
Yellow-Green Book NCSC-TG-016 Guidelines for Writing Trusted Facility Manuals
½Å·ÚµÇ´Â ¼³ºñ ¸Å´º¾ó ÀÛ¼ºÀ» À§ÇÑ Áöħ
Light Blue NCSC-TG-017 Understanding Identification and Authentication in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ÀÇ ½Äº°°ú ÀÎÁõ¿¡ ´ëÇÑ ÀÌÇØ
Light Blue Book NCSC-TG-018 A Guide to Understanding Object Reuse in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ °´Ã¼ Àç»ç¿ëÀÇ ÀÌÇØ¿¡ ´ëÇÑ °¡À̵å
Blue Book NCSC-TG-019 Trusted Product Evaluation Questionnaire
½Å·ÚµÇ´Â Á¦Ç° Æò°¡ ÁúÀǼ
Gray Book NCSC-TG-020A Trusted Unix Working Group (TRUSIX) Rationale for Selecting
½Å·ÚµÇ´Â À¯´Ð½º ÀÛ¾÷ ±×·ìÀÇ ¼±Á¤±Ù°Å
Access Control List Features for the Unix System
À¯´Ð½º ½Ã½ºÅÛÀ» À§ÇÑ Á¢±ÙÅëÁ¦¸ñ·Ï ±â´É
Lavender Book NCSC-TG-021 Trusted Data Base Management System Interpretation of TCSEC
TCSECÀÇ ½Å·ÚµÇ´Â µ¥ÀÌŸº£À̽º °ü¸® ½Ã½ºÅÛ ÇØ¼®
Yellow Book NCSC-TG-022 A Guide to Understanding Trusted Recovery in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ ½Å·ÚµÇ´Â º¹±¸ÀÇ ÀÌÇØ¿¡ ´ëÇÑ °¡À̵å
Bright Orange Book NCSC-TG-023 Understanding Security Testing and Test Documentation in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼ º¸¾È Å×½ºÆÃ°ú Å×½ºÆ® ¹®¼ ÀÌÇØ
Purple Book NCSC-TG-024 (Volume 1/4) A Guide to Procurement of Trusted Systems: An Introduction to Procurement Initiators on Computer Security Requirements
½Å·ÚµÇ´Â ½Ã½ºÅÛ ±¸¸Å °¡À̵å: ±¸¸Å ¹ß±âÀεéÀ» À§ÇÑ ÄÄÇ»ÅÍ º¸¾È¿ä±¸»çÇ× ¼Ò°³
Purple Book NCSC-TG-024 (Volume 2/4) A Guide to Procurement of Trusted Systems: Language for RFP Specifications and Statements of Work - An Aid to Procurement initiators.
½Å·ÚµÇ´Â ½Ã½ºÅÛ ±¸¸Å °¡À̵å: RFP »ç¾ç°ú ÀÛ¾÷ º¸°í¼¸¦ À§ÇÑ ¾ð¾î - ±¸¸Å ¹ß±âÀεéÀ» À§ÇÑ µµ¿ò
Purple Book NCSC-TG-024 (Volume 3/4) A Guide to Procurement of Trusted Systems: Computer Security Contract Data Requirements List and Data Item Description Tutorial
½Å·ÚµÇ´Â ½Ã½ºÅÛ ±¸¸Å °¡À̵å: ÄÄÇ»ÅÍ º¸¾È °è¾à µ¥ÀÌŸ ¿ä±¸»çÇ× ¸ñ·Ï ¹× µ¥ÀÌŸ Ç׸ñ ¼³¸í Áöµµ¼
Purple Book NCSC-TG-024 (Volume 4/4) A Guide to Procurement of Trusted Systems: How to Evaluate a Bidder's Proposal Document - An Aid to Procurement Initiators and Contractors
½Å·ÚµÇ´Â ½Ã½ºÅÛ ±¸¸Å °¡À̵å: ÀÔÂûÀÚÀÇ Á¦¾È¼ Æò°¡ ¹æ¹ý - ±¸¸Å ¹ß±âÀΰú °è¾àÀÚµéÀ» À§ÇÑ µµ¿ò
Green Book NCSC-TG-025 Understanding Data Remanence in Automated Information Systems
ÀÚµ¿ÈµÈ Á¤º¸½Ã½ºÅÛ¿¡¼ÀÇ ÀÜ·ù µ¥ÀÌŸ ÀÌÇØ
Hot Peach Book NCSC-TG-026 Writing the Security Features User's Guide for Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ º¸¾È ±â´É »ç¿ëÀÚ ¼³¸í¼ ÀÛ¼ºÇϱâ
Turquoise Book NCSC-TG-027 A Guide to Understanding Information System Security Officer Responsibilities for Automated Information Systems
ÀÚµ¿ÈµÈ Á¤º¸½Ã½ºÅÛ¿¡ ´ëÇÑ Á¤º¸½Ã½ºÅÛ º¸¾È Ã¥ÀÓÀÚÀÇ Àǹ«¿¡ ´ëÇÑ ÀÌÇØ¸¦ À§ÇÑ °¡À̵å
Violet Book NCSC-TG-028 Assessing Controlled Access Protection
ÅëÁ¦µÈ Á¢±Ù º¸È£ Æò°¡Çϱâ
Blue Book NCSC-TG-029 Introduction to Certification and Accreditation
º¸Áõ°ú Àΰ¡/½ÅÀÓÀå¿¡ ´ëÇÑ ¼Ò°³
Light Pink Book NCSC-TG-030 A Guide to Understanding Covert Channel Analysis of Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛÀÇ ºñ¹Ðä³Î ºÐ¼® ÀÌÇØ¸¦ À§ÇÑ °¡À̵å
1983³â, ¹Ì ±¹¹æ¼º (DoD)Àº (»ç½ÇÀº ±¹¸³ ÄÄÇ»ÅÍ º¸¾È ¼¾ÅÍ National Computer Security Centre[1]), TCSEC Áï ¿À·»ÁöºÏÀÇ Ã¹¹øÂ° ¹öÀüÀ» ¹ßÇ¥ÇÏ¿´´Ù (¿À·»Áö»ö Ç¥Áö¸¦ µû¶ó¼ ¸í¸íµÈ). 1985 ³â ´õ ÇÑÃþ °»½ÅµÇ¾î Ç¥ÁØÀ¸·Î ¹ßÇàµÇ¾ú´Ù (DOD5200.28-STD). ¿À·»ÁöºÏÀº ÄÄÇ»ÅÍ ½Ã½ºÅÛµéÀÇ º¸¾ÈÀ» Æò°¡Çϱâ À§ÇÑ ÁöħÀ» ±ÔÁ¤ÇÑ´Ù. ±âŸ ´Ù¸¥ ¸¹Àº °ü·Ã Ç¥Áص鵵 ÀÛ¼ºµÇ¾î, "·¹Àκ¸¿ì ½Ã¸®Áî" ·Î ¾Ë·ÁÁ® ÀÖ´Ù.
Infosec Awareness Office [¹®¼ ÁÖ¹®]
+1 (410) 766-8729Government Printing Office [Á¤º¸º¸È£ ½Ã½ºÅÛ & º¸¾È īŻ·Î±× ÁÖ¹®]
+1 (202) 512-1800Evaluations Office
+1 (410) 859-4458´ÙÀ½Àº C1°ú C2¿¡ °üÇØ ¿À·»ÁöºÏ¿¡¼ Á÷Á¢ ¹ßÃéÇØ¿Â °ÍÀÌ´Ù:
ÀÌ ºÎ¹®¿¡ ÀÖ´Â µî±ÞµéÀº ÀÓÀÇÀû (¾Ë¾Æ¾ßÇÒ ÇÊ¿ä,need-to-know) º¸È£¸¦ Á¦°øÇϸç, °¨»ç ´É·ÂÀ» Æ÷ÇÔÇϰí ÀÖ¾î, ÁÖü ¹× À̵éÀÌ ½ÃÀÛÇÑ Á¶À۵鿡 ´ëÇÑ Ã¥ÀÓÃßÀû¼ºÀ» Á¦°øÇÑ´Ù.
µî±Þ (C1): ÀÓÀÇÀû º¸¾È º¸È£ DISCRETIONARY SECURITY PROTECTION
µî±Þ (C1) ½Ã½ºÅÛÀÇ Trusted Computing Base (TCB) ´Â »ç¿ëÀÚ¿Í µ¥ÀÌŸÀÇ ºÐ¸®¸¦ Á¦°øÇÔÀ¸·Î½á ¸í¸ñ»óÀ¸·Î ÀÓÀÇÀû º¸¾È ¿ä±¸»çÇ×À» ¸¸Á·½ÃŲ´Ù.
À̰ÍÀº °³Àκ°·Î Á¢±Ù Á¦ÇÑÀ» µÑ ¼ö ÀÖ´Â ¾î¶² ÇüÅÂÀÇ ¹ÏÀ»¸¸ÇÑ ÅëÁ¦¸¦ Æ÷ÇÔÇÑ´Ù, Áï Ç¥¸é»óÀ¸·Î »ç¿ëÀÚµéÀÌ ÇÁ·ÎÁ§Æ®³ª °³ÀÎ Á¤º¸¸¦ º¸È£Çϰí, ´Ù¸¥ »ç¿ëÀÚµéÀÌ ¿ì¿¬È÷ Àڱ⠵¥ÀÌŸ¸¦ Àаųª ÆÄ±«ÇÏÁö ¸øÇϵµ·Ï ÇÒ ¼ö ÀÖ°Ô Çϴµ¥ Àû´çÇÏ´Ù. µî±Þ (C1) ȯ°æÀº µ¿ÀÏÇÑ ¹Î°¨¼º ¼öÁØÀÇ µ¥ÀÌŸ¸¦ ó¸®ÇÏ´Â Çù·Â »ç¿ëÀÚµé·Î ¿¹»óµÈ´Ù.
´ÙÀ½Àº µî±Þ (C1)¿¡ ÇÒ´çµÈ ½Ã½ºÅ۵鿡 ´ëÇÑ ÃÖ¼Ò ¿ä±¸»çÇ×ÀÌ´Ù:
2.1.1 º¸¾È Á¤Ã¥
2.1.1.1 ÀÓÀÇÀû Á¢±ÙÅëÁ¦: TCB ´Â ADP ½Ã½ºÅÛÀÇ ÁöÁ¤µÈ »ç¿ëÀÚµé°ú ÁöÁ¤µÈ °´Ã¼µé(Áï ÆÄÀÏ ¹× ÇÁ·Î±×·¥µé) °£ÀÇ Á¢±ÙÀ» Á¤ÀÇÇϰí ÅëÁ¦ÇØ¾ß ÇÑ´Ù.
Àû¿ë ¸ÞÄ«´ÏÁòÀº »ç¿ëÀÚµéÀÌ, ±×·¯ÇÑ °´Ã¼µéÀÇ °øÀ¯¸¦ ÁöÁ¤µÈ °³ÀÎÀ̳ª Á¤ÀÇµÈ ±×·ì ¶Ç´Â µÑ´Ù¿¡ µû¶ó ±ÔÁ¤Çϰí ÅëÁ¦ÇÒ ¼ö ÀÖµµ·Ï ÇØÁÖ¾î¾ß ÇÑ´Ù.
2.1.2 Ã¥ÀÓÃßÀû¼º Accountability
2.1.2.1 ½Äº°°ú ÀÎÁõ: TCB´Â »ç¿ëÀÚ¿¡°Ô, TCBÀÇ ÁßÀ縦 ¹Þµµ·Ï µÇ¾î ÀÖ´Â ´Ù¸¥ ¾î¶² Á¶ÀÛÀÇ ¼öÇàÀ» ½ÃÀÛÇϱâ Àü¿¡, »ç¿ëÀÚ¸¦ TCB¿¡°Ô ½Äº°½Ãų °ÍÀ» ¿ä±¸ÇØ¾ß ÇÑ´Ù.
´õ ³ª¾Æ°¡, TCB´Â º¸È£µÇ´Â ¸ÞÄ«´ÏÁòÀ» »ç¿ëÇÏ¿© (e.g., ÆÐ½º¿öµå) »ç¿ëÀÚÀÇ ½Å¿øÀ» ÀÎÁõÇØ¾ß ÇÑ´Ù. TCB´Â ÀÎÁõ µ¥ÀÌŸ¸¦ º¸È£ÇÏ¿© ¾î¶°ÇÑ ºñÀΰ¡ »ç¿ëÀÚ¿¡ ÀÇÇØ¼µµ Á¢±ÙµÇÁö ¾Êµµ·Ï ÇØ¾ß ÇÑ´Ù.
2.1.3 º¸Áõ
2.1.3.1 ±â´É»óÀÇ º¸Áõ
2.1.3.1.1 ½Ã½ºÅÛ ±¸Á¶: TCB´Â ¿ÜºÎÀÇ °£¼·À̳ª Âü°ß(e.g., Äڵ峪 µ¥ÀÌŸ±¸Á¶ º¯°æ¿¡ ÀÇÇÑ) À¸·ÎºÎÅÍ TCB¸¦ º¸È£ÇÏ´Â, ÀÚ½ÅÀ» À§ÇÑ µµ¸ÞÀÎÀ» À¯ÁöÇØ¾ß ÇÑ´Ù.
TCB¿¡ ÀÇÇØ ÅëÁ¦µÇ´Â ÀÚ¿øµéÀº ADP ½Ã½ºÅÛ³»ÀÇ ÁÖü ¹× °´Ã¼µéÀÇ Á¤ÀÇµÈ ¼ºê¼ÂÀÏ ¼ö ÀÖ´Ù.
2.1.3.1.2 ½Ã½ºÅÛ ¹«°á¼º: TCBÀÇ ÇöÀå Çϵå¿þ¾î ¹× Æß¿þ¾î ¿ä¼ÒµéÀÇ ¿Ã¹Ù¸¥ µ¿ÀÛÀ» ÁÖ±âÀûÀ¸·Î È®ÁõÇÏ´Â µ¥ ¾µ ¼ö ÀÖ´Â Çϵå¿þ¾î ¹×/¶Ç´Â ¼ÒÇÁÆ®¿þ¾î ±â´ÉµéÀÌ Á¦°øµÇ¾î¾ß ÇÑ´Ù.
2.1.3.2 ¶óÀÌÇÁ »çÀÌŬ º¸Áõ
2.1.3.2.1º¸¾È Å×½ºÆÃ: ADP ½Ã½ºÅÛÀÇ º¸¾È ¸ÞÄ«´ÏÁòÀº Å×½ºÆ®µÇ¾î ½Ã½ºÅÛ ¹®¼¿¡¼ ÁÖÀåÇÏ´Â ´ë·Î µ¿ÀÛÇÏ´Â °ÍÀÌ È®ÀεǾî¾ß ÇÑ´Ù. Å×½ºÆÃÀº ºñÀΰ¡ »ç¿ëÀÚ°¡ TCBÀÇ º¸¾È º¸È£ ¸ÞÄ«´ÏÁòÀ» ¿ìȸÇϰųª À̱æ¼ö ÀÖ´Â ¸í¹éÇÑ ¹æ¹ýÀÌ ¾ø´Ù´Â °ÍÀ» È®½ÇÈ÷ Çϵµ·Ï ¼öÇàµÇ¾î¾ß ÇÑ´Ù (º¸¾È Å×½ºÆÃ Áöħ ÂüÁ¶).
2.1.4 ¹®¼
2.1.4.1 º¸¾È ±â´É »ç¿ëÀÚ °¡À̵å: »ç¿ëÀÚ ¹®¼ Áß ÇϳªÀÇ ¿ä¾à, Àå, ¶Ç´Â ¸Å´º¾óÀº TCB ¿¡¼ Á¦°øÇÏ´Â º¸È£ ¸ÞÄ«´ÏÁòµé, À̵éÀÇ »ç¿ë¿¡ ´ëÇÑ Áöħ, ±×¸®°í À̵éÀÌ ¼·Î ¾î¶»°Ô »óÈ£ÀÛ¿ëÇÏ´ÂÁö¸¦ ¼³¸íÇØ¾ß ÇÑ´Ù.
2.1.4.2 ½Å·ÚµÇ´Â ¼³ºñ ¸Å´º¾ó: ADP ½Ã½ºÅÛ °ü¸®ÀÚ¸¦ À§ÇÑ ¸Å´º¾óÀº ¾ÈÀüÇÑ ¼³ºñ¸¦ ¿î¿µÇÒ ¶§ ÅëÁ¦µÇ¾î¾ß ÇÒ ±â´É ¹× Ư±Ç¿¡ ´ëÇÑ ÁÖÀÇ»çÇ×À» Ç¥½ÃÇØ¾ß ÇÑ´Ù.
2.1.4.3 Å×½ºÆ® ¹®¼: ½Ã½ºÅÛ °³¹ßÀÚ´Â º¸¾È ¸ÞÄ«´ÏÁòÀÌ ¾î¶»°Ô Å×½ºÆ®µÇ¾ú´ÂÁö¿Í º¸¾È ¸ÞÄ«´ÏÁòÀÇ ±â´ÉÀû Å×½ºÆÃ °á°ú¸¦ º¸¿©ÁÖ´Â Å×½ºÆ® °èȹ°ú Å×½ºÆ® ÀýÂ÷¸¦ ¼¼úÇÏ´Â ¹®¼¸¦ Æò°¡ÀÚ¿¡°Ô Á¦°øÇØ¾ß ÇÑ´Ù.
2.1.4.4 ¼³°è¹®¼: Á¦ÀÛÀÚÀÇ º¸È£¿¡ ´ëÇÑ ¹æÄ§(öÇÐ)°ú ÀÌ ¹æÄ§ÀÌ TCB·Î ¾î¶»°Ô º¯È¯µÇ¾ú´ÂÁö¿¡ ´ëÇØ ¼³¸íÇÏ´Â ¹®¼°¡ ÀÖ¾î¾ß ÇÑ´Ù. TCB°¡ º°°³ÀÇ ¸ðµâµé·Î ÀÌ·ç¾îÁ® ÀÖ´Ù¸é, ÀÌ ¸ðµâµé°£ÀÇ ÀÎÅÍÆäÀ̽º°¡ ¼¼úµÇ¾î¾ß ÇÑ´Ù.
CLASS (C2):CONTROLLED ACCESS PROTECTION
ÀÌ µî±Þ¿¡ ÀÖ´Â ½Ã½ºÅÛµéÀº, ·Î±×ÀÎ ÀýÂ÷, º¸¾È°ü·Ã À̺¥Æ® °¨»ç, ±×¸®°í ÀÚ¿ø °í¸³À» ÅëÇØ »ç¿ëÀÚµéÀÌ °³º°ÀûÀ¸·Î ÀÚ±â ÇàÀ§¿¡ ´ëÇØ Ã¥ÀÓÀÌ ÀÖ°Ô ÇÏ¿©, (C1) ½Ã½ºÅ۵麸´Ù ¼¼¹ÐÇÑ ÀÓÀÇÀû Á¢±Ù ÅëÁ¦¸¦ Á¦°øÇÑ´Ù. ´ÙÀ½Àº µî±Þ (C2)¸¦ ºÎ¿©¹ÞÀº ½Ã½ºÅ۵鿡 ´ëÇÑ ÃÖ¼Ò ¿ä±¸»çÇ×ÀÌ´Ù:
2.2.1 º¸¾È Á¤Ã¥
2.2.1.1 ÀÓÀÇÀû Á¢±ÙÅëÁ¦:TCB ´Â ADP ½Ã½ºÅÛÀÇ ÁöÁ¤µÈ »ç¿ëÀÚµé°ú ÁöÁ¤µÈ °´Ã¼µé(Áï ÆÄÀÏ ¹× ÇÁ·Î±×·¥µé) °£ÀÇ Á¢±ÙÀ» Á¤ÀÇÇϰí ÅëÁ¦ÇØ¾ß ÇÑ´Ù.
Àû¿ë ¸ÞÄ«´ÏÁòÀº »ç¿ëÀÚµéÀÌ, ±×·¯ÇÑ °´Ã¼µéÀÇ °øÀ¯¸¦ ÁöÁ¤µÈ °³ÀÎÀ̳ª Á¤ÀÇµÈ ±×·ì ¶Ç´Â µÑ´Ù¿¡ µû¶ó ±ÔÁ¤Çϰí ÅëÁ¦ÇÒ ¼ö ÀÖµµ·Ï ÇØÁÖ¾î¾ß Çϰí, Á¢±Ù±ÇÇÑÀÇ Àü´Þ, º¸±ÞÀ» Á¦ÇÑÇÒ ¼ö ÀÖ´Â ÅëÁ¦¸¦ Á¦°øÇØ¾ß ÇÑ´Ù. ÀÓÀÇÀû Á¢±Ù ÅëÁ¦ ¸ÞÄ«´ÏÁòÀº, ¸í¹éÇÑ »ç¿ëÀÚ ÇàÀ§¿¡ ÀÇÇØ¼³ª µð?Æ®¿¡ ÀÇÇØ, °´Ã¼¸¦ ºñÀΰ¡ Á¢±ÙÀ¸·ÎºÎÅÍ º¸È£ÇØ¾ß ÇÑ´Ù.
ÀÌ·± Á¢±ÙÅëÁ¦µéÀº ´ÜÀÏ »ç¿ëÀÚ ´ÜÀ§¿¡ ´ëÇØ¼±îÁö Á¢±Ù¿¡ Æ÷ÇÔ½ÃŰ°Å³ª ¹èÁ¦½Ãų ¼ö ÀÖ¾î¾ß ÇÑ´Ù. ¾ÆÁ÷ Á¢±ÙÇã°¡¸¦ °¡Áö°í ÀÖÁö ¾ÊÀº »ç¿ëÀÚ¿¡ ´ëÇÑ °´Ã¼ Á¢±Ù Çã°¡´Â Àΰ¡µÈ »ç¿ëÀÚ¿¡ ÀÇÇØ¼¸¸ ºÎ¿©µÇ¾î¾ß ÇÑ´Ù.
2.2.1.2 °´Ã¼ Àç»ç¿ë: ÀúÀå °´Ã¼¿¡ Æ÷ÇÔµÈ Á¤º¸¿¡ ´ëÇÑ ¸ðµç Àΰ¡´Â TCBÀÇ ºñ»ç¿ë ÀúÀ尴ü Ç®·ÎºÎÅÍ ÁÖü¿¡°Ô Ãʱ⠺ο©, ÇÒ´ç ¶Ç´Â ÀçÇÒ´çµÇ±â Àü¿¡ öȸµÇ¾î¾ß ÇÑ´Ù.
ÀÌÀü ÁÖüÀÇ Á¶ÀÛ¿¡ ÀÇÇØ ¸¸µé¾îÁø, ¾ÏÈ£ÈµÈ Á¤º¸¸¦ Æ÷ÇÔÇÑ ¾î¶°ÇÑ Á¤º¸µµ, ½Ã½ºÅÛÀ¸·Î ´Ù½Ã ÇØÁ¦µÇ¾ú´ø °´Ã¼·ÎÀÇ Á¢±ÙÀ» ¾ò´Â ¾î¶² ÁÖü¿¡ ÀÇÇØ¼µµ ÀÌ¿ëµÉ ¼ö À־ ¾ÈµÈ´Ù.
2.2.2 Ã¥ÀÓÃßÀû¼º
2.2.2.1 ½Äº°°ú ÀÎÁõ: TCB´Â »ç¿ëÀÚ¿¡°Ô, TCBÀÇ ÁßÀ縦 ¹Þµµ·Ï µÇ¾î ÀÖ´Â ´Ù¸¥ ¾î¶² Á¶ÀÛÀÇ ¼öÇàÀ» ½ÃÀÛÇϱâ Àü¿¡, »ç¿ëÀÚ¸¦ TCB¿¡°Ô ½Äº°½Ãų °ÍÀ» ¿ä±¸ÇØ¾ß ÇÑ´Ù.
´õ ³ª¾Æ°¡, TCB´Â º¸È£µÇ´Â ¸ÞÄ«´ÏÁòÀ» »ç¿ëÇÏ¿© (e.g., ÆÐ½º¿öµå) »ç¿ëÀÚÀÇ ½Å¿øÀ» ÀÎÁõÇØ¾ß ÇÑ´Ù. TCB´Â ÀÎÁõ µ¥ÀÌŸ¸¦ º¸È£ÇÏ¿© ¾î¶°ÇÑ ºñÀΰ¡ »ç¿ëÀÚ¿¡ ÀÇÇØ¼µµ Á¢±ÙµÇÁö ¾Êµµ·Ï ÇØ¾ß ÇÑ´Ù. TCB´Â °¢ °³º° ADP ½Ã½ºÅÛ »ç¿ëÀÚ¸¦ À¯ÀÏÇÏ°Ô ½Äº°ÇÒ ¼ö ÀÖ´Â ´É·ÂÀ» Á¦°øÇÔÀ¸·Î½á °³Àκ° Ã¥ÀÓÃßÀû¼ºÀ» Àû¿ëÇØ¾ß ÇÑ´Ù.
TCB´Â ¶ÇÇÑ ÀÌ ½Å¿ø°ú ±× °³Àο¡ ÀÇÇÑ ¸ðµç °¨»ç°¡´ÉÇÑ Á¶ÀÛµéÀ» ¿¬°ü½Ãų ¼ö ÀÖ´Â ´É·ÂÀ» Á¦°øÇØ¾ß ÇÑ´Ù.
2.2.2.2 °¨»ç: TCB´Â ÀڱⰡ º¸È£ÇÏ´Â °´Ã¼µé¿¡ ´ëÇÑ Á¢±ÙÀÇ °¨»çÁõÀûÀ» »ý¼º, À¯Áö, ±×¸®°í º¯Á¶³ª ºñÀΰ¡Á¢±Ù ¶Ç´Â ÆÄ±«·ÎºÎÅÍ º¸È£ÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù.
°¨»ç µ¥ÀÌŸ´Â ÀÌ¿¡ ´ëÇÑ Àбâ Á¢±ÙÀÌ °¨»ç µ¥ÀÌŸ¿¡ ´ëÇÑ Àΰ¡¸¦ ¹ÞÀº »ç¶÷µé·Î¸¸ Á¦ÇÑµÉ ¼ö ÀÖµµ·Ï TCB¿¡ ÀÇÇØ º¸È£µÇ¾î¾ß ÇÑ´Ù.
TCB ´Â ´ÙÀ½ À¯ÇüÀÇ À̺¥Æ®µéÀ» ±â·ÏÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù: ½Äº° ¹× ÀÎÁõ ¸ÞÄ«´ÏÁòÀÇ »ç¿ë, »ç¿ëÀÚÀÇ ÁÖ¼Ò °ø°£¿¡ °´Ã¼¸¦ µµÀÔ (e.g., ÆÄÀÏ¿±â, initiation), °´Ã¼ÀÇ »èÁ¦, ±×¸®°í ÄÄÇ»ÅÍ ¿î¿µÀÚ¿Í ½Ã½ºÅÛ °ü¸®ÀÚ ¹×/¶Ç´Â ½Ã½ºÅÛ º¸¾È Ã¥ÀÓÀڵ鿡 ÀÇÇÑ Á¶ÀÛ(ÇàÀ§), ±×¸®°í ±âŸ º¸¾È °ü·Ã À̺¥Æ®µé.
±â·ÏµÇ´Â °¢ À̺¥Æ®¿¡ ´ëÇØ, °¨»ç ±â·ÏÀº ´ÙÀ½À» ½Äº°ÇØ¾ß ÇÑ´Ù: À̺¥Æ®ÀÇ ³¯Â¥½Ã°£, »ç¿ëÀÚ, À̺¥Æ® À¯Çü, ±×¸®°í À̺¥Æ®ÀÇ ¼º°ø/½ÇÆÐ¿©ºÎ.
½Äº°/ÀÎÁõ À̺¥Æ®µé¿¡ ´ëÇØ¼´Â ¿äûÀÇ ¹ß¿øÁö (e.g., ´Ü¸» ID)°¡ °¨»ç ±â·Ï¿¡ Æ÷ÇԵǾî¾ß ÇÑ´Ù. »ç¿ëÀÚÀÇ ÁÖ¼Ò °ø°£¿¡ °´Ã¼¸¦ µµÀÔÇÏ´Â À̺¥Æ® ¹× °´Ã¼ »èÁ¦ À̺¥Æ®¿¡ ´ëÇØ °¨»ç±â·ÏÀº °´Ã¼À̸§À» Æ÷ÇÔÇØ¾ß ÇÑ´Ù. ADP ½Ã½ºÅÛ °ü¸®ÀÚ´Â °³º° ½Å¿ø¿¡ ±Ù°ÅÇÏ¿© ¾î´À »ç¿ëÀÚµç Çϳª ¶Ç´Â ±× ÀÌ»óÀÇ »ç¿ëÀÚ Á¶ÀÛ(ÇàÀ§)À» ¼±ÅÃÀûÀ¸·Î °¨»çÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù.
2.2.3 º¸Áõ
2.2.3.1 ±â´É»óÀÇ º¸Áõ
2.2.3.1.1 ½Ã½ºÅÛ ±¸Á¶: TCB´Â ¿ÜºÎÀÇ °£¼·À̳ª Âü°ß(e.g., Äڵ峪 µ¥ÀÌŸ±¸Á¶ º¯°æ¿¡ ÀÇÇÑ) À¸·ÎºÎÅÍ TCB¸¦ º¸È£ÇÏ´Â, ÀÚ½ÅÀ» À§ÇÑ µµ¸ÞÀÎÀ» À¯ÁöÇØ¾ß ÇÑ´Ù.
TCB¿¡ ÀÇÇØ ÅëÁ¦µÇ´Â ÀÚ¿øµéÀº ADP ½Ã½ºÅÛ³»ÀÇ ÁÖü ¹× °´Ã¼µéÀÇ Á¤ÀÇµÈ ¼ºê¼ÂÀÏ ¼ö ÀÖ´Ù. TCB´Â º¸È£µÇ¾î¾ß ÇÒ ÀÚ¿øµéÀ» °Ý¸®½ÃÄÑ À̵éÀÌ Á¢±ÙÅëÁ¦¿Í °¨»ç ¿ä±¸»çÇ׿¡ Á¾¼ÓµÇµµ·Ï ÇØ¾ß ÇÑ´Ù.
2.2.3.1.2 ½Ã½ºÅÛ ¹«°á¼º: TCBÀÇ ÇöÀå Çϵå¿þ¾î ¹× Æß¿þ¾î ¿ä¼ÒµéÀÇ ¿Ã¹Ù¸¥ µ¿ÀÛÀ» ÁÖ±âÀûÀ¸·Î È®ÁõÇÏ´Â µ¥ ¾µ ¼ö ÀÖ´Â Çϵå¿þ¾î ¹×/¶Ç´Â ¼ÒÇÁÆ®¿þ¾î ±â´ÉµéÀÌ Á¦°øµÇ¾î¾ß ÇÑ´Ù.
2.2.3.2 ¶óÀÌÇÁ »çÀÌŬ º¸Áõ
2.2.3.2.1 º¸¾È Å×½ºÆÃ: ADP ½Ã½ºÅÛÀÇ º¸¾È ¸ÞÄ«´ÏÁòÀº Å×½ºÆ®µÇ¾î ½Ã½ºÅÛ ¹®¼¿¡¼ ÁÖÀåÇÏ´Â ´ë·Î µ¿ÀÛÇÏ´Â °ÍÀÌ È®ÀεǾî¾ß ÇÑ´Ù. Å×½ºÆÃÀº ºñÀΰ¡ »ç¿ëÀÚ°¡ TCBÀÇ º¸¾È º¸È£ ¸ÞÄ«´ÏÁòÀ» ¿ìȸÇϰųª À̱æ¼ö ÀÖ´Â ¸í¹éÇÑ ¹æ¹ýÀÌ ¾ø´Ù´Â °ÍÀ» È®½ÇÈ÷ Çϵµ·Ï ¼öÇàµÇ¾î¾ß ÇÑ´Ù.
Å×½ºÆÃÀº ¶ÇÇÑ ÀÚ¿ø °Ý¸®¸¦ À§¹ÝÇϵµ·Ï ÇÒ ¼ö Àְųª, °¨»ç ¶Ç´Â ÀÎÁõ µ¥ÀÌŸ¿¡ ´ëÇÑ ºñÀΰ¡ Á¢±ÙÀ» Çã¿ëÇÒ ¼ö ÀÖ´Â ¸í¹éÇÑ °áÇÔÀ» ã´Â Àϵµ Æ÷ÇÔÇØ¾ß ÇÑ´Ù (º¸¾È Å×½ºÆÃ Áöħ ÂüÁ¶).
2.2.4 ¹®¼
2.2.4.1 º¸¾È ±â´É »ç¿ëÀÚ °¡À̵å: »ç¿ëÀÚ ¹®¼ Áß ÇϳªÀÇ ¿ä¾à, Àå, ¶Ç´Â ¸Å´º¾óÀº TCB ¿¡¼ Á¦°øÇÏ´Â º¸È£ ¸ÞÄ«´ÏÁòµé, À̵éÀÇ »ç¿ë¿¡ ´ëÇÑ Áöħ, ±×¸®°í À̵éÀÌ ¼·Î ¾î¶»°Ô »óÈ£ÀÛ¿ëÇÏ´ÂÁö¸¦ ¼³¸íÇØ¾ß ÇÑ´Ù.
2.2.4.2 ½Å·ÚµÇ´Â ¼³ºñ ¸Å´º¾ó: ADP ½Ã½ºÅÛ °ü¸®ÀÚ¸¦ À§ÇÑ ¸Å´º¾óÀº ¾ÈÀüÇÑ ¼³ºñ¸¦ ¿î¿µÇÒ ¶§ ÅëÁ¦µÇ¾î¾ß ÇÒ ±â´É ¹× Ư±Ç¿¡ ´ëÇÑ ÁÖÀÇ»çÇ×À» Ç¥½ÃÇØ¾ß ÇÑ´Ù.
°¨»ç ÆÄÀÏÀ» °Ë»çÇϰí À¯ÁöÇϱâ À§ÇÑ ÀýÂ÷¿Í °¨»ç À̺¥Æ® °¢°¢ÀÇ À¯Çü¿¡ ´ëÇÑ »ó¼¼ °¨»ç ·¹ÄÚµå ±¸Á¶°¡ ÁÖ¾îÁ®¾ß ÇÑ´Ù.
2.2.4.3 Å×½ºÆ® ¹®¼: ½Ã½ºÅÛ °³¹ßÀÚ´Â º¸¾È ¸ÞÄ«´ÏÁòÀÌ ¾î¶»°Ô Å×½ºÆ®µÇ¾ú´ÂÁö¿Í º¸¾È ¸ÞÄ«´ÏÁòÀÇ ±â´ÉÀû Å×½ºÆÃ °á°ú¸¦ º¸¿©ÁÖ´Â Å×½ºÆ® °èȹ°ú Å×½ºÆ® ÀýÂ÷¸¦ ¼¼úÇÏ´Â ¹®¼¸¦ Æò°¡ÀÚ¿¡°Ô Á¦°øÇØ¾ß ÇÑ´Ù.
2.2.4.4 ¼³°è¹®¼: Á¦ÀÛÀÚÀÇ º¸È£¿¡ ´ëÇÑ ¹æÄ§(öÇÐ)°ú ÀÌ ¹æÄ§ÀÌ TCB·Î ¾î¶»°Ô º¯È¯µÇ¾ú´ÂÁö¿¡ ´ëÇØ ¼³¸íÇÏ´Â ¹®¼°¡ ÀÖ¾î¾ß ÇÑ´Ù. TCB°¡ º°°³ÀÇ ¸ðµâµé·Î ÀÌ·ç¾îÁ® ÀÖ´Ù¸é, ÀÌ ¸ðµâµé°£ÀÇ ÀÎÅÍÆäÀ̽º°¡ ¼¼úµÇ¾î¾ß ÇÑ´Ù.
ITSEC (Information Technology Security Evaluation Criteria) Àº ÇÁ¶û½º, µ¶ÀÏ, ³×´ú¶õµå, ¿µ±¹¿¡¼ ¸¸µç Á¶ÈµÈ Æò°¡±âÁØÀÇ ÁýÇÕÀÌ´Ù. À̰ÍÀº 1995³â 4¿ù EU (À¯·´ °øµ¿Ã¼) ¿¡ÀÇÇØ ¸ðµç ȸ¿ø±¹µéÀ» À§ÇÑ Ç¥ÁØÀ¸·Î äÅõǾú´Ù. ITSEC¿¡ µû¶ó Æò°¡µÈ »ó¿ë ¿î¿µÃ¼Á¦¿¡ ´ëÇÑ ¿ä¾àÀ» "¿î¿µÃ¼Á¦ °³·Ð" Àå¿¡¼ ã¾Æº¼ ¼ö ÀÖ´Ù. ITSEM [itsem] Àº ITSECÀ» »ç¿ëÇÏ´Â µ¥ ´ëÇÑ ¾È³»¼ÀÌ´Ù - ´ÙÀ½ Àý¿¡¼ ¼¼úÇÑ´Ù.
Á¦Ç°À̳ª ½Ã½ºÅÛ (¿©±â¼ºÎÅÍ´Â TOE ¶ó°í ÇÑ´Ù : target of Evaluation Æò°¡´ë»ó) ÀÌ ITSEC¿¡ µû¶ó Æò°¡µÉ ¶§:
ITSEC Àº TCSEC µî±Þ¿¡ ´ëÀÀµÇ´Â ±â´É¼º µî±Þ Ç¥º» F-C1, C2, B1, B2, B3 ¸¦ Á¤ÀÇÇϰí, ³×Æ®¿öÅ·À» Æ÷ÇÔÇϰí ÀÖ¾î °ü½ÉÀ» ²ô´Â IN, AV, DI, DC ¹× DX ÀÇ »õ·Î¿î µî±ÞÀ» Á¤ÀÇÇÑ´Ù. ÀÌ µî±ÞµéÀº Ç¥ÁØ º¸¾È ±â´ÉÀÇ ÁýÇÕÀ» ¼¼úÇÑ´Ù. ITSEC °ú TCSECÀº ¾Æ·¡¿Í °°ÀÌ ´ëÀÀµÈ´Ù:
ITSEC TCSEC
E1, F-C1 == C1
E2, F-C2 == C2
E3, F-B1 == B1
E4, F-B2 == B2
E5, F-B3 == B3
E6, F-B3 == A1
ITSEC Àº TCSEC ¿¡ Ãß°¡ÇÏ¿© ´ÙÀ½ÀÇ ±â´É¼º µî±ÞµéÀ» Á¤ÀÇÇÑ´Ù:
IN ÀÌ µî±ÞÀº µ¥ÀÌŸ & ÇÁ·Î±×·¥¿¡ ´ëÇÑ ³ôÀº ¹«°á¼ºÀÌ ¿ä±¸µÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
AV ÀÌ µî±ÞÀº ³ôÀº °¡¿ë¼º ±â´ÉÀ» °¡Áö´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
DI ÀÌ µî±ÞÀº µ¥ÀÌŸ Àü¼Û¿¡ ´ëÇØ ³ôÀº ¹«°á¼ºÀÌ ¿ä±¸µÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
DC ÀÌ µî±ÞÀº µ¥ÀÌŸ Àü¼Û¿¡ ´ëÇØ ³ôÀº ±â¹Ð¼ºÀÌ ¿ä±¸µÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
DX ÀÌ µî±ÞÀº µ¥ÀÌŸ Àü¼Û¿¡ ´ëÇØ ³ôÀº ¹«°á¼º & ±â¹Ð¼ºÀÌ ¿ä±¸µÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
ITSEC Àº ´ÙÀ½ Ç¥Á¦µé ¾Æ·¡ ¿ä±¸»çÇ×ÀÌ ºÐ¼®µÉ °ÍÀ» Á¦¾ÈÇÑ´Ù: Ã¥ÀÓÃßÀû¼º Accountability, ½Äº° ¹× ÀÎÁõ Identification & Authentication, °¨»ç Audit, °´Ã¼ Àç»ç¿ë Object Reuse, Á¢±ÙÅëÁ¦ Access Control, Á¤È®¼º Accuracy, µ¥ÀÌŸ ±³È¯ Data Exchange ¹× ¼ºñ½º ½Å·Ú¼º Reliability of Service. ¸ÞÄ«´ÏÁòÀ̳ª ´ëÀÀÃ¥ÀÇ °µµ´Â ±âº» basic, Áß°£ medium ¶Ç´Â ³ôÀ½ high À¸·Î ±ÔÁ¤µÈ´Ù.
°£·«È÷ Çϱâ À§ÇØ ¿©±â¿¡´Â TCSEC¿¡ ¾ø´Â »õ·Î¿î ¸®ºä ±âÁØÀÌ Æ÷ÇÔµÈ µî±Þ F-DX ¸¸ ¼³¸íÇÑ´Ù.
´ÙÀ½ ITSECÀÇ ´ë´ëÀûÀÎ ±¹Á¦ ¹öÀü 1.2°¡, ¹ßÇàÀϷκÎÅÍ 2³âÀÇ ÀáÁ¤±â°£µ¿¾È Æò°¡ ¹× Àΰ¡ °èȹ¿¡¼ÀÇ »ç¿ë¿¡ ´ëÇØ (ºñ°ø½Ä) EC ÀÚ¹®±×·ìÀÎ SOG-IS (Senior Officials Group - Information Systems Security) ÀÇ ½ÂÀÎÀ» ¾ò¾î ¹ßÇàµÇ¾ú´Ù. ½ÀµæµÈ ½ÇÁ¦ °æÇèÀº ÀÌ ±â°£ÀÇ Á¾¹Ý¿¡ ITSECÀ» Àç°ËÅäÇÏ°í ´õ ½ÉµµÀÖ°Ô °³¹ßÇϴµ¥ ÀÌ¿ëµÉ °ÍÀÌ´Ù. µ¡ºÙ¿©, ÇÑÃþ ´õÇÑ ±¹Á¦Àû Á¶È·ÎºÎÅÍ ³ª¿Ã °í·Á»çÇ׵鵵 ¿°µÎ¿¡ µÑ °ÍÀÌ´Ù.
0.1 °Ü¿ì 40³âÀ» Áö³ª¿À´Â µ¿¾È, Á¤º¸±â¼ú(IT)Àº Á¶Á÷»çȸÀÇ °ÅÀÇ ¸ðµç ºÎºÐ¿¡¼ Áß¿äÇϰí, ¶Ç ´ë°³ ÇʼöÀûÀÎ, ¿ªÇÒÀ» ¼öÇàÇÏ°Ô µÇ¾ú´Ù. °á°úÀûÀ¸·Î, º¸¾ÈÀº Á¤º¸±â¼úÀÇ ÇʼöÀûÀÎ Ãø¸éÀÌ µÇ¾ú´Ù.
0.2 ÀÌ·± »óȲ¿¡¼, IT º¸¾ÈÀÌ ÀǹÌÇÏ´Â °ÍÀº,
- ±â¹Ð¼³ - Á¤º¸ÀÇ Àΰ¡µÇÁö ¾ÊÀº °ø°³ ¹æÁö;
- ¹«°á¼º - Á¤º¸ÀÇ Àΰ¡µÇÁö ¾ÊÀº º¯Á¶ ¹æÁö;
- °¡¿ë¼º - Á¤º¸³ª ÀÚ¿ø¿¡ ´ëÇÑ Àΰ¡µÇÁö ¾ÊÀº Á¦Áö¸¦ ¹æÁö.
0.3 IT½Ã½ºÅÛÀ̳ª Á¦Ç°Àº ±â¹Ð¼º, ¹«°á¼º, ±×¸®°í °¡¿ë¼º À¯Áö¸¦ À§ÇÑ °¢ÀÚÀÇ ¿ä±¸»çÇ×À» °¡Áö°í ÀÖÀ» °ÍÀÌ´Ù. ÀÌ ¿ä±¸»çÇ×µéÀ» ¸¸Á·ÇÏ·Á¸é, ¿¹¸¦ µé¾î Á¢±ÙÅëÁ¦, °¨»ç, ±×¸®°í ¿¡·¯ º¹±¸°°Àº ºÐ¾ß¸¦ ´ã´çÇÏ´Â ¼ö¸¹Àº ±â¼úÀû º¸¾È ¼ö´Ü (ÀÌ ¹®¼¿¡¼ ÁöĪÇÏ´Â ¹Ù¿¡ ÀÇÇÏ¸é º¸¾È Àû¿ë ±â´É) À» ±¸ÇöÇØ¾ßÇÑ´Ù.
ÀÌ ±â´Éµé¿¡ ´ëÇØ ¾Ë¸ÂÀº ½Å·Ú°¡ ÇÊ¿äÇÏ´Ù: ÀÌ ¹®¼¿¡¼ À̰ÍÀº º¸ÁõÀ̶ó´Â ¸»·Î ĪÇÑ´Ù, ±×°ÍÀÌ º¸¾ÈÀû¿ë ±â´ÉÀÇ Á¤È®¼º¿¡ ´ëÇÑ ½Å·ÚÀÌ°Ç (°³¹ß°ú ¿î¿µÀû °üÁ¡ ¸ðµÎ¿¡¼) ¶Ç´Â ±×·± ±â´ÉµéÀÇ À¯È¿¼º¿¡ ´ëÇÑ ½Å·ÚÀ̰Ç.
0.4 ½Ã½ºÅÛÀÇ »ç¿ëÀÚµéÀº ÀÚ±âµéÀÌ »ç¿ëÇϰí ÀÖ´Â ½Ã½ºÅÛÀÇ º¸¾È¿¡ ´ëÇÑ È®½ÅÀÌ ÇÊ¿äÇÏ´Ù. À̵éÀº ¶ÇÇÑ ±¸¸Å¸¦ »ý°¢ÁßÀÎ IT Á¦Ç°µéÀÇ º¸¾È ´É·ÂµéÀ» ºñ±³ÇÒ Ã´µµ°¡ ÇÊ¿äÇÏ´Ù.
»ç¿ëÀÚµéÀÌ ¹®Á¦ÀÇ ½Ã½ºÅÛ ¹× Á¦Ç°µéÀÇ Á¦Á¶¾÷ÀÚ³ª º¥´õÀÇ ¸»¿¡ ÀÇÁ¸ÇÒ ¼öµµ ÀÖ°ÚÁö¸¸, ¶Ç´Â ½º½º·Î Å×½ºÆ®¸¦ ÇØº¼ ¼öµµ ÀÖ°ÚÁö¸¸, ¸¹Àº »ç¿ëÀÚµéÀº µ¶¸³ÀûÀÎ ´Üü¿¡ ÀÇÇÑ ¾î¶² ÇüÅÂÀÇ °øÁ¤ÇÑ Æò°¡¸¦ ¼±È£ÇÒ °Í °°´Ù. ½Ã½ºÅÛÀ̳ª Á¦Ç°¿¡ ´ëÇÑ ±×·± Æò°¡´Â °´°üÀûÀ̰í Àß Á¤ÀÇµÈ º¸¾È Æò°¡ ±âÁØ ¹× Æò°¡°¡ ÀûÀýÇÏ°Ô ¼öÇàµÇ¾úÀ½À» ÀÔÁõÇÏ´Â º¸ÁõüÀÇ Á¸À縦 ÇÊ¿ä·Î ÇÑ´Ù. ½Ã½ºÅÛ º¸¾È ¸ñÇ¥´Â ¹®Á¦ÀÇ ½Ã½ºÅÛÀ» »ç¿ëÇÏ´Â »ç¶÷ÀÇ °³º°ÀûÀÎ Çʿ伺¿¡ ƯÁ¤ÇÒ °ÍÀ̰í, ¹Ý¸é Á¦Ç° º¸¾È ¸ñÇ¥´Â, À̸¦ ¸¸Á·ÇÏ´Â Á¦Ç°ÀÌ, ºñ½ÁÇÏÁö¸¸ ²À µ¿ÀÏÇÏÁö´Â ¾ÊÀº º¸¾È ¿ä±¸»çÇ×À» °¡Áö´Â ¸¹Àº ½Ã½ºÅ۵鿡 ÅëÇÕµÉ ¼ö ÀÖµµ·Ï, º¸´Ù ÀϹÝÀûÀÏ °ÍÀÌ´Ù.
0.5 ½Ã½ºÅÛ¿¡ ´ëÇØ¼, ÀÌÀÇ º¸¾È ´É·Â¿¡ ´ëÇÑ Æò°¡´Â, °³°³ÀÇ È¯°æ¾È¿¡¼ »ç¿ëÀ» À§ÇØ IT ½Ã½ºÅÛÀ» ¹Þ¾ÆµéÀÌ´Â °Í¿¡ ´ëÇÑ º¸´Ù °ø½ÄÀûÀÎ ÀýÂ÷ÀÇ ÀϺηΠº¼ ¼ö ÀÖ´Ù.
ÀÎÁ¤ Accreditation À̶ó´Â ¸»ÀÌ Á¾Á¾ ÀÌ ÀýÂ÷¸¦ ±â¼úÇÏ´Â µ¥ ¾²ÀδÙ.
½Ã½ºÅÛÀÌ ÀǵµÇÏ´Â ¸ñÀû¿¡ ¸Â´Â °ÍÀ¸·Î º¸ÀÏ ¼ö ÀÖ±â À§Çؼ´Â ¿©·¯°¡Áö °í·ÁÇÒ ¿ä¼ÒµéÀÌ ÇÊ¿äÇÏ´Ù:
½Ã½ºÅÛÀÌ Á¦°øÇÏ´Â º¸¾È¿¡ ´ëÇÑ º¸Áõ, º¸¾È¿¡ ´ëÇÑ °æ¿µÁøÀÇ Ã¥ÀÓ¿¡ ´ëÇÑ È®ÀÎ, °ü·Ã ±â¼ú ¹× ¹ý/±Ô¹ü ¿ä±¸»çÇ× Áؼö, ±×¸®°í ½Ã½ºÅÛ È¯°æ³»¿¡ Á¦°øµÇ´Â ´Ù¸¥ ºñ±â¼úÀû º¸¾È¹æÃ¥µéÀÇ ÀûÇÕ¼º¿¡ ´ëÇÑ È®½ÅÀÌ ÇÊ¿äÇÏ´Ù.
ÀÌ ¹®¼¿¡ Æ÷ÇÔµÈ ±âÁصéÀº ÁÖ·Î ±â¼úÀûÀÎ º¸¾È¹æÃ¥°ú °ü°è°¡ ÀÖÁö¸¸, Àλç, ¹°¸®Àû ¹× ÀýÂ÷Àû º¸¾ÈÀ» À§ÇÑ ¾ÈÀüÇÑ ¿î¿µ ÀýÂ÷¿Í °°Àº ÀϺΠºñ±â¼úÀû Ãø¸éµéµµ ´Ù·é´Ù (±×·¯³ª À̵éÀÌ ±â¼úÀû º¸¾È¹æÃ¥µé¿¡ ´êÀ» ¶§¸¸).
0.6 IT º¸¾È Æò°¡ ±âÁØ °³¹ß¿¡ ´ëÇØ ¸¹Àº ÀÛ¾÷ÀÌ ÀÌÀü¿¡ ÀÖ¾ú´Ù, ºñ·Ï °ü·Ã ±¹°¡³ª ´ÜüµéÀÇ Æ¯Á¤ÇÑ ¿ä±¸»çÇ׿¡ µû¶ó ¾à°£ ´Ù¸¥ ¸ñÀûµéÀ» °¡Áö°í ÀÖÁö¸¸.
À̵é Áß °¡Àå Áß¿äÇÑ °ÍÀº, ±×¸®°í ¿©·¯°¡Áö ¸é¿¡¼ ´Ù¸¥ °³¹ßµé¿¡ ´ëÇÑ ¼±±¸ÀÚ´Â, Trusted Computer System Evaluation Criteria [TCSEC] À̾úÀ¸¸ç, Åë»óÀûÀ¸·Î TCSEC ¶Ç´Â "¿À·»ÁöºÏ" À¸·Î ¾Ë·ÁÁ® ÀÖ°í, ¹Ì ±¹¹æ¼º¿¡¼ ÃâÆÇÇϰí Á¦Ç° Æò°¡¿¡ ÀÌ¿ëµÈ´Ù.
´Ù¸¥³ª¶óµéµµ, ´ëºÎºÐ À¯·´ ±¹°¡µéÀε¥, IT º¸¾È Æò°¡¿¡ »ó´çÇÑ °æÇèÀ» °¡Áö°í ÀÖ°í ÀÚüÀûÀÎ IT º¸¾È ±âÁØÀ» °³¹ßÇß´Ù.
¿µ±¹¿¡¼´Â Á¤ºÎ¿ëÀ¸·Î °³¹ßµÈ CESG Memorandum Number 3 [CESG3], »ó¿ë IT º¸¾È Á¦Ç°À» À§ÇÑ Åë»ó»ê¾÷ºÎ Á¦¾È "Green Book" [DTIEC]ÀÌ ¿©±â Æ÷ÇԵȴÙ.
µ¶ÀÏ¿¡¼´Â µ¶ÀÏ Á¤º¸ º¸¾È±¹¿¡¼ 1989³â ÀÚü ±âÁØ ÃÊÆÇÀ» ¹ßÇàÇÏ¿´À¸¸ç[ZSIEC], °°Àº ½Ã±â¿¡ ÇÁ¶û½º¿¡¼µµ ±âÁØÀÌ °³¹ßµÇ°í ÀÖ¾ú´Âµ¥, ¼ÒÀ§ "Blue-White-Red Book"ÀÌ´Ù [SCSSI].
0.7 ÀÌ ºÐ¾ß¿¡¼ ÀÛ¾÷ÀÌ ÁøÇàµÇ°í, ¾ÆÁ÷µµ ÇØ¾ßÇÒ °ÍµéÀÌ ¸¹ÀÌ ³²¾Æ ÀÖ´Â °ÍÀ» º¸°í, ÇÁ¶û½º, µ¶ÀÏ, ³×´ú¶õµå ±×¸®°í ¿µ±¹¿¡¼´Â ÀÌ ÀÛ¾÷ÀÌ Çù·ÂÀûÀÎ ¹æÇâÀ¸·Î Á¢±ÙµÇ¾î¾ß Çϰí, °øÅëµÇ°í Á¶ÈµÈ IT º¸¾È±âÁØÀÌ ³ª¿Í¾ß ÇÑ´Ù´Â °ÍÀ» ÀÎÁöÇß´Ù.
Á¶È½ÃŰ´Â µ¥¿¡´Â ¼¼ °¡Áö ÀÌÀ¯°¡ ÀÖ´Ù:
a) ¿©·¯ ³ª¶ó¿¡¼ ¸¹Àº °æÇèµéÀÌ ¸ð¾ÆÁ³°í, ±× °æÇèÀ» ¹ÙÅÁÀ¸·Î ÇÔ²² ±¸ÃàÇÔÀ¸·Î½á ¾òÀ» ¼ö ÀÖ´Â °ÍÀÌ ¸¹¾Ò´Ù;
b) ¾÷°è¿¡¼´Â ¼·Î ´Ù¸¥ ³ª¶óµé¿¡¼ ¼·Î ´Ù¸¥ º¸¾È ±âÁØÀ» ¿øÇÏÁö ¾Ê¾Ò´Ù;
c) ³ª¶óµé °£¿¡, ±×¸®°í ¹Î°£, Á¤ºÎ ¹× ¹æÀ§ ÀÀ¿ë¿¡¼Á¶Â÷µµ ±âº» °³³ä°ú Á¢±Ù¹ýÀº µ¿ÀÏÇß´Ù.
0.8 µû¶ó¼ ¿©·¯ ³ª¶óµéÀÇ ¼±µµ¸¦ ¹ÙÅÁÀ¸·Î ±¸ÃàÇÏ¿©, ÀÌ¹Ì ½ÃÇàµÇ¾ú´ø Ư¡µéÀ» ÃëÇØ À̵éÀÌ ÀϰüµÇ°í ü°èÀûÀ¸·Î ±ÕÇüÀ» ÀÌ·çµµ·Ï Çϱâ·Î °áÁ¤µÇ¾ú´Ù.
±âÁ¸ ÀÛ¾÷, °¡Àå Áß¿äÇϰԴ ¹Ì±¹ TCSEC, °úÀÇ ÃÖ´ëÀÇ ÀûÀÀ¼º°ú ȣȯ¼ºÀÌ ÀÌ ÇÁ·Î¼¼½º¿¡¼ ºÎ´ÜÇÑ °í·Á»çÇ×À̾ú´Ù.
ºñ·Ï óÀ½¿¡´Â ÀÌ ÀÛ¾÷ÀÌ ±âÁ¸ ±âÁصéÀ» Á¶È½ÃŰ´Â µ¥ ±×Ä¥ °ÍÀ̶ó°í »ý°¢µÇ¾úÀ¸³ª, ¶§¶§·Î ÀÌ¹Ì Á¸ÀçÇÏ´Â °ÍÀ» È®ÀåÇÏ´Â °ÍÀÌ ÇÊ¿äÇÒ ¶§°¡ ÀÖ¾ú´Ù.
EU Commission of the European Communities
Directorate XII/F SOG-IS Secretariat
Rue De la Loi 200
B-1049 Brussels, Belgium
Germany Bundesamt f? Sicherheit in der Informatik
Am Nippenkreuz 19, D-5300 Bonn
+49-228-9582.111 General Number
+49-228-9582.129 Certification information
+49-228-9582.141 DocumentationNetherlands Netherlands National Comsec Agency
Bezuidenhoutseweg 67
P.O. Box 200061, NL-2500 EB The HagueFrance Service Central de la S?urit?des Syst?es d'Information
Division Information et Syst?es
18 Rue du Docteur Zamenhof, F-92131 Issy les MoulineauxUK Head of the Certification Body
UK IT Security Evaluation and Certification Scheme
P.O. Box 152, Cheltenham, GB-GL52 5UF
+41-1242-238739 ext. 5103
cbsec@itsec.gov.uk
http://www.itsec.gov.uk
¸ñÀû
A.100 Ç¥º» ±â´É¼º µî±Þ F-DX ´Â ±³È¯µÉ Á¤º¸ÀÇ ±â¹Ð¼º°ú ¹«°á¼º¿¡ ´ëÇÑ ¿ä±¸°¡ ³ôÀº ³×Æ®¿÷À» À§ÇÑ °ÍÀÌ´Ù. ¿¹¸¦ µé¸é, ¹Î°¨ÇÑ Á¤º¸°¡ ¾ÈÀüÇÏÁö ¾ÊÀº ³×Æ®¿÷À» ÅëÇØ (¿¡¸¦µé¸é °øÁ߸Á) ±³È¯µÇ¾î¾ß ÇÏ´Â °æ¿ì°¡ µÉ ¼ö ÀÖ´Ù.
½Äº°°ú ÀÎÁõ
A.101 TOE´Â »ç¿ëÀÚ¸¦ À¯ÀÏÇÏ°Ô ½Äº°Çϰí ÀÎÁõÇØ¾ß ÇÑ´Ù. ÀÌ ½Äº°°ú ÀÎÁõÀº TOE¿Í »ç¿ëÀÚ°£ÀÇ ´Ù¸¥ ¸ðµç »óÈ£ÀÛ¿ë¿¡ ¾Õ¼ ÀϾ¾ß ÇÑ´Ù.
´Ù¸¥ »óÈ£ÀÛ¿ëµéÀº ¼º°øÀûÀÎ ½Äº°°ú ÀÎÁõ ÀÌÈÄ¿¡¸¸ °¡´ÉÇØ¾ß ÇÑ´Ù. ÀÎÁõÁ¤º¸´Â Àΰ¡µÈ »ç¿ëÀÚ¿¡ ÀÇÇÑ ¸®ºä³ª º¯°æÀ» À§Çؼ¸¸ Á¢±ÙµÉ ¼ö ÀÖ´Â ¹æ¹ýÀ¸·Î ÀúÀåµÇ¾î¾ß ÇÑ´Ù.
¸ðµç »óÈ£ÀÛ¿ë¿¡ ´ëÇØ TOE´Â »ç¿ëÀÚÀÇ ½Å¿øÀ» ÀÔÁõÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù.
A.102 »ç¿ëÀÚ µ¥ÀÌŸ¸¦ ±³È¯Çϱâ Àü¿¡ Åë½Å »ó´ë °³Ã¼ (ÄÄÇ»ÅÍ, ÇÁ·Î¼¼½º ¶Ç´Â »ç¿ëÀÚ) ´Â À¯ÀÏÇÏ°Ô ½Äº° ¹× ÀÎÁõµÇ¾î¾ß ÇÑ´Ù. »ç¿ëÀÚ µ¥ÀÌŸ´Â ½Äº° ¹× ÀÎÁõÀÌ ¼º°øÀûÀ¸·Î ¿Ï¼öµÈ ÀÌÈÄ¿¡¸¸ ±³È¯µÇ¾î¾ß ÇÑ´Ù. µ¥ÀÌŸ¸¦ ¹ÞÀ¸¸é µ¥ÀÌŸÀÇ ¹ß½ÅÀÚ¸¦ À¯ÀÏÇÏ°Ô ½Äº°Çϰí ÀÎÁõÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù. ¸ðµç ÀÎÁõÁ¤º¸´Â ºñÀΰ¡ Á¢±Ù°ú À§Á¶·ÎºÎÅÍ º¸È£µÇ¾î¾ß ÇÑ´Ù.
Ã¥ÀÓÃßÀû¼º
A.103 TOE´Â ´ÙÀ½ °¢ À̺¥Æ®µé¿¡ ´ëÇØ ÇÊ¿äÇÑ µ¥ÀÌŸ¿Í ÇÔ²² À̺¥Æ®¸¦ ·Î±×ÇÒ ¼ö ÀÖ´Â, Ã¥ÀÓ(ÃßÀû¼º) ¿ä¼Ò¸¦ Æ÷ÇÔÇϰí ÀÖ¾î¾ß ÇÑ´Ù:
a) ½Äº° ¹× ÀÎÁõ ¸ÞÄ«´ÏÁòÀÇ »ç¿ë:
ÇÊ¿äÇÑ µ¥ÀÌŸ: ³¯Â¥; ½Ã°£; ½Äº° ¹× ÀÎÁõÀÇ °³½ÃÀÚ; ½Äº°µÉ ÁÖüÀÇ À̸§; ÇàÀ§ÀÇ ¼º°ø ¶Ç´Â ½ÇÆÐ ¿©ºÎ.
b) µ¥ÀÌŸ ±³È¯¿¡¼ ½Äº°µÈ ¿¡·¯:
ÇÊ¿äÇÑ µ¥ÀÌŸ: ³¯Â¥; ½Ã°£; µ¥ÀÌŸ ±³È¯¿¡¼ Åë½Å ´ç»çÀÚµé; ¿¡·¯ À¯Çü; ½ÃµµµÈ ±³Á¤ÀÇ ¼º°øÀ̳ª ½ÇÆÐ¿©ºÎ.
c) ¿¬°á ¼³Á¤:
ÇÊ¿äÇÑ µ¥ÀÌŸ: ³¯Â¥; ½Ã°£; °³½ÃÀÚÀÇ »ç¿ëÀÚ ½Å¿ø; Åë½Å »ó´ë °³Ã¼ À̸§(ÄÄÇ»ÅÍ, ÇÁ·Î¼¼½º ¶Ç´Â »ç¿ëÀÚ); ¼³Á¤ ÆÄ¶ó¹ÌÅÍ (´Þ¶óÁø´Ù¸é).
d) Ư¼öÇÑ µ¥ÀÌŸ ±³È¯ Æ®·£Àè¼Ç:
ÇÊ¿äÇÑ µ¥ÀÌŸ: ³¯Â¥; ½Ã°£; ¼Û½ÅÀÚÀÇ »ç¿ëÀÚ ½Å¿ø; ¼ö½ÅÀÚÀÇ »ç¿ëÀÚ ½Å¿ø; Åë½ÅµÈ »ç¿ëÀÚ Á¤º¸; µ¥ÀÌŸ ¼ö½Å ³¯Â¥ ¹× ½Ã°£.
A.104 ºñÀΰ¡ »ç¿ëÀڴ åÀÓ µ¥ÀÌŸ¿¡ Á¢±ÙÀÌ Çã¿ëµÇÁö ¸»¾Æ¾ß ÇÑ´Ù. Çϳª ¶Ç´Â ±× ÀÌ»ó »ç¿ëÀÚÀÇ ÇàÀ§¿¡ ´ëÇØ ¼±ÅÃÀûÀ¸·Î Ã¥ÀÓÀ» ±â·ÏÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù.
Ã¥ÀÓ ÆÄÀϵéÀ» °Ë»çÇϰí À¯ÁöÇÏ´Â µµ±¸°¡ ÀÖ¾î¾ß ÇÏ°í ¹®¼ÈµÇ¾î¾ß ÇÑ´Ù. ÀÌ µµ±¸µéÀº Çϳª ¶Ç´Â ±× ÀÌ»ó »ç¿ëÀÚÀÇ ÇàÀ§µéÀÌ ¼±ÅÃÀûÀ¸·Î ½Äº°µÉ ¼ö ÀÖµµ·Ï ÇØÁÖ¾î¾ß ÇÑ´Ù.
Ã¥ÀÓ ±â·ÏÀÇ ±¸Á¶°¡ ¿Ïº®ÇÏ°Ô ¼¼úµÇ¾î¾ß ÇÑ´Ù.
°¨»ç
A.105 °¨»ç ¸ñÀûÀ¸·Î Ã¥ÀÓ ÆÄÀÏÀ» °Ë»çÇÒ µµ±¸µéÀÌ Á¸ÀçÇÏ°í ¹®¼È µÇ¾î¾ß ÇÑ´Ù.
ÀÌ µµ±¸µéÀº Çϳª ¶Ç´Â ±× ÀÌ»ó »ç¿ëÀÚÀÇ ÇàÀ§°¡ ¼±ÅÃÀûÀ¸·Î ½Äº°µÉ ¼ö ÀÖµµ·Ï ÇØÁÖ¾î¾ß ÇÑ´Ù.
µ¥ÀÌŸ ±³È¯
Á¢±Ù ÅëÁ¦
A.106 Àΰ¡¹ÞÁö ¾ÊÀº ÇØµ¶¿¡ ÀÌ¿ëµÉ¼ö ÀÖ´Â ÀÌÀü¿¡ Àü¼ÛµÈ ¸ðµç Á¤º¸´Â, Á÷¹«¸¦ ¼öÇàÇϱâ À§ÇØ Àý´ëÀûÀ¸·Î ÀÌ µ¥ÀÌŸ¿¡ Á¢±ÙÇÒ ¼ö ÀÖ¾î¾ß ÇÏ´Â »ç¶÷¸¸ Á¢±ÙÇÒ ¼ö ÀÖ°Ô º¸È£µÇ¾î¾ß ÇÑ´Ù.
µ¥ÀÌŸ ±â¹Ð¼º
A.107 TOE´Â Åë½Åä³ÎÀÇ ³ÐÀº ºÎºÐ¿¡ °ÉÄ£ ¼ö½ÅÀÚ¿¡ ´ëÇØ ±â¹Ð¼ºÀ» º¸ÀåÇÏ´Â Á¾´Ü°£(end-to-end) ¾ÏÈ£ÈÀÇ ¼ö´ÜÀ» Á¦°øÇØ¾ß ÇÑ´Ù.
¾Æ¿ï·¯, ÁöÁ¤µÈ µ¥ÀÌŸ Åë½Å ¸µÅ©¿¡ ´ëÇÑ Æ®·¡ÇÈ È帧 ±â¹Ð¼ºµµ º¸ÀåµÇ¾î¾ß ÇÑ´Ù.
µ¥ÀÌŸ ¹«°á¼º
A.108 TOE´Â »ç¿ëÀÚ µ¥ÀÌŸ¿Í Ã¥ÀÓ µ¥ÀÌŸÀÇ ºñÀΰ¡ Á¶ÀÛ°ú µ¥ÀÌŸÀÇ ºñÀΰ¡ Àç»ýÀÌ È®½ÇÈ÷ ¿¡·¯·Î ÆÇ¸íµÇµµ·Ï ¼³°èµÇ¾î¾ß ÇÑ´Ù.
..........
0.1 Àå ¼Ò°³
0.1.5 IT º¸¾È Æò°¡ ¸Å´º¾ó (IT Security Evaluation Manual, ITSEM) Àº ITSEC ¹öÀü 1.2 ¸¦ ¹ÙÅÁÀ¸·Î ÇÏ¿©, Æò°¡ ´ë»ó(TOE)ÀÌ ÀÌ ±âÁØ¿¡ µû¶ó ¾î¶»°Ô Æò°¡µÇ¾î¾ß ÇÏ´ÂÁö¸¦ ¼¼úÇÑ´Ù. ITSEMÀÇ ¸í½ÃµÈ ¸ñÀûÀº ITSECÀ» º¸¿ÏÇÏ´Â Á¶ÈµÈ Æò°¡ ¹æ¹ý ¼¼Æ®°¡ Á¸ÀçÇϵµ·Ï Çϱâ À§ÇÑ °ÍÀÌ´Ù.
0.1.6 ITSEM Àº ±â¼úÀûÀÎ ¹®¼·Î, ÁÖ·Î Æò°¡ ÆÄÆ®³Êµé (ÀÏÂ÷ÀûÀ¸·Î Æò°¡ÀÚÀÌÁö¸¸ ¹ß±âÀÚ¿Í º¸ÁõÀÚµµ) À» °Ü³ÉÇÑ °ÍÀÌÁö¸¸, º¥´õ³ª °³¹ßÀÚ, ½Ã½ºÅÛ ÀÎÁ¤ÀÚ¿Í »ç¿ëÀڵ鿡°Ôµµ °ü½ÉÀÇ ´ë»óÀÌ´Ù. ¿©±â¿¡´Â Æò°¡ ¹æ¹ýµé¿¡ ´ëÇÑ ÃæºÐÇÑ ¼¼ºÎ»çÇ×°ú ´Ù¾çÇÑ È¯°æ¿¡¼ ¼öÇàµÇ´Â Æò°¡ÀÇ ±â¼úÀû µî°¡Ä¡¸¦ ÀÔÁõÇÒ ¼ö ÀÖ°Ô ÇÏ´Â ÀýÂ÷µéÀÌ Æ÷ÇԵǾî ÀÖ´Ù. ¹®¼´Â ¹«·á·Î ¾òÀ» ¼ö ÀÖ´Ù. ITSEMÀº ¹Î°£°ú Á¤ºÎ ºÐ¾ß¿¡¼ ¼öÇàµÇ´Â Æò°¡ ¸ðµÎ¿¡ Àû¿ëµÈ´Ù.
..........
0.1 Àå ¼Ò°³
ÀÚ»ê, À§Çù, À§Çè, ½Å·Ú ¹× ´ëÀÀÃ¥
0.1.1 Á¤º¸±â¼ú(IT)Àº È¿°úÀûÀÎ »ç¾÷ ¹× ±¹°¡¾÷¹« ¼öÇà¿¡ ÇʼöÀûÀÎ °ÍÀÌ µÇ¾ú°í, IT »ç¿ëÀÇ ¿µÇâÀ» ¹Þ´Â °³ÀεéÀÇ »ç¹«¿¡¼µµ Á¡Á¡ Áß¿äÇØÁö°í ÀÖ´Ù.
Á¤º¸´Â ¾î¶² »ç¶÷ÀÇ ¾÷¹«³ª »ç¹«¸¦ ÁøÃ´½Ã۱â À§ÇØ ¾ò¾îÁö°í º¸È£µÇ¾î¾ß ÇÏ´Â ¾î¶² °ÍÀ̸ç, µû¶ó¼ ÀÚ»êÀ¸·Î °£ÁֵǾî¾ß ÇÑ´Ù.
±×·¯ÇÑ ÀÚ»êÀÇ Á߿伺Àº º¸Åë À§ÇùÀÇ Â¡ÈķκÎÅÍ ÆÄ»ýµÇ¾î °á°ú·Î¼ ÀϾ´Â ¼ÕÇØ·Î Ç¥ÇöµÈ´Ù. ¼ÕÇØ´Â Á¤º¸ÀÇ Æø·Î, ºÎÀûÀýÇÑ º¯Á¶, ÆÄ±« ¶Ç´Â ¿À¿ë¿¡ ÀÇÇØ Á÷Á¢ÀûÀ¸·Î³ª °£Á¢ÀûÀ¸·Î ¾ß±âµÉ ¼ö ÀÖ´Ù. À§ÇèÀº ¿¹»óµÇ´Â ¼ÕÇØ¿Í ³ªÅ¸³ª´Â À§ÇùÀÇ °¡´É¼ºÀÇ Å©±â¿¡ µû¶ó Áõ°¡ÇÑ´Ù.
0.1.2 IT ½Ã½ºÅÛ¿¡¼ Á¤º¸´Â Àڻ꿡 ³ª»Û ¿µÇâÀ» ¹ÌÄ¡´Â À§ÇùÀ¸·ÎºÎÅÍ º¸È£µÇ¾î¾ß ÇÑ´Ù.
À§ÇùÀº °íÀÇÀûÀ̰ųª (e.g. °ø°Ý) ÀǵµµÇÁö ¾ÊÀ» °ÍÀÏ ¼ö ÀÖ´Ù (e.g. ½Ç¼ö³ª °íÀå).
0.1.3 À§ÇèÀ» ÁÙÀ̱â À§ÇØ, ƯÁ¤ÇÑ ´ëÀÀÃ¥ÀÌ ¼±Á¤µÉ °ÍÀÌ´Ù. ÀÌ ´ëÀÀÃ¥µéÀº Ư¼º»ó ¹°¸®Àû, ÀλçÀû, ÀýÂ÷Àû ¶Ç´Â ±â¼úÀûÀÏ ¼ö ÀÖ´Ù.
±â¼úÀû ´ëÀÀÃ¥ ¶Ç´Â IT ´ëÀÀÃ¥ Àº IT ½Ã½ºÅÛÀÇ º¸¾È Àû¿ë ±â´É°ú ¸ÞÄ«´ÏÁòÀÌ´Ù;
ºñ ±â¼úÀû ´ëÀÀÃ¥ ¶Ç´Â ºñ IT ´ëÀÀÃ¥ Àº ¹°¸®Àû, ÀλçÀû, ±×¸®°í ÀýÂ÷Àû ´ëÀÀÃ¥µéÀÌ´Ù.
ITSEC Æò°¡´Â ÁÖ·Î ±â¼úÀû ´ëÀÀÃ¥°ú °ü°èµÈ´Ù.
0.1.4 IT ½Ã½ºÅÛÀÇ ÀÏÂ÷ º¸¾È ¸ñÇ¥´Â ¿¬°üµÈ À§ÇèÀ» °ü·Ã Á¶Á÷ÀÌ ¼ö¿ëÇÒ ¼ö ÀÖ´Â ¼öÁØÀ¸·Î ÁÙÀÌ´Â °ÍÀÌ´Ù.
À̰ÍÀº IT ½Ã½ºÅÛÀÇ º¸¾È ±â´É ¹× Ư¡µé¿¡ ÀÇÇØ ´Þ¼ºµÉ ¼ö ÀÖ´Ù.
0.1.5 IT ½Ã½ºÅÛÀÌ Á¦°øÇÏ´Â º¸¾È¿¡ ´ëÇØ Àû¿ëµÉ ½Å·Ú¸¦ º¸ÁõÀ̶ó°í ¸»ÇÑ´Ù. º¸ÁõÀÌ Å¬¼ö·Ï, ½Ã½ºÅÛÀÌ ÀÜÁ¸À§ÇèÀ» ¼ö¿ë°¡´ÉÇÑ ¼öÁØÀ¸·Î À¯ÁöÇϸç À§ÇùÀ¸·ÎºÎÅÍ ÀÚ»êÀ» º¸È£ÇÒ °ÍÀ̶ó´Âµ¥ ´ëÇÑ È®½Å(½Å·Ú)µµ Ä¿Áø´Ù.
0.1.6 ITSEC Æò°¡ µî±ÞÀÌ ³ô°í ¸ÞÄ«´ÏÁòÀÇ °µµ°¡ °ÇÒ¼ö·Ï, »ç¿ëÀÚ´Â IT ½Ã½ºÅÛÀ̳ª Á¦Ç°¿¡ ³»ÀçµÈ ´ëÀÀÃ¥¿¡ ´ëÇØ ´õ Å« È®½ÅÀ» °¡Áú ¼ö ÀÖ´Ù.
»ç¿ëÀÚ¿¡°Ô ÇÊ¿äÇÑ Æò°¡ µî±ÞÀº ¾Ë·ÁÁø ÀÜÁ¸À§ÇèÀÇ ¼ö¿ë°¡´ÉÇÑ ¼öÁØ¿¡ ´Þ·Á ÀÖÀ¸¸ç ±¸Ã¼ÀûÀÎ °³º° »óȲ¿¡ ´ëÇÑ À§Çù ¹× À§Çè ºÐ¼®¿¡ ÀÇÇØ¼¸¸ °áÁ¤µÉ ¼ö ÀÖ´Ù.
º¸¾È°ú ºñ¿ëÀº ±ÕÇüÀ» ÀÌ·ç¾î¾ß ÇÑ´Ù. Æò°¡µî±ÞÀÌ ³ô¾ÆÁü¿¡ µû¶ó °³¹ß ¹× Æò°¡ ºñ¿ëÀÌ Áõ°¡ÇÒ °¡´É¼ºÀÌ ¸¹À¸¹Ç·Î, ´õ ³ôÀº Æò°¡ µî±Þ Á¦Ç°À̳ª ½Ã½ºÅÛÀº ´ë°³ ´õ ºñ½Ò °ÍÀÌ´Ù. ¿¹¸¦µé¾î ȯ°æ ÆÄ¶ó¹ÌÅÍÀÇ ÇÔ¼ö·Î Æò°¡µî±ÞÀ» °áÁ¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ¾È³»°¡ [GISA2]¿¡ ÁÖ¾îÁ® ÀÖ´Ù.
ITSEM 2ºÎ¿¡ ¾ð±ÞµÈ ±¹°¡ Á¶Á÷µé·ÎºÎÅÍ Æ¯Á¤ÇÑ Á¶¾ðÀ» ±¸ÇÒ ¼öµµ ÀÖ´Ù.
..........
º¸¾È Æò°¡
6.4.11 ¿Ïº®ÇÏ°Ô ¾ÈÀüÇÑ ½ÇÁ¦ IT ½Ã½ºÅÛÀ» ¸¸µå´Â °ÍÀº ºÒ°¡´ÉÇÏ´Ù. À̰ÍÀº IT ½Ã½ºÅÛÀÇ º¹À⼺°ú, ´ëÀÀÇØ¾ß ÇÏ´Â À§ÇùÀÇ ´Ù¾ç¼º ¶§¹®ÀÌ´Ù.
6.4.12 ±×·¯³ª, ÄÄÇ»ÅÍ ½Ã½ºÅÛÀÇ º¸¾È¿¡ ´ëÇÑ ¾î´ÀÁ¤µµÀÇ È®½ÅÀ» Á¦°øÇÏ´Â °ÍÀº °¡´ÉÇÏ´Ù.
¼±È£µÇ´Â Á¢±Ù¹ýÀº µ¶¸³Àû ±â°üÀÌ (IT º¸¾È Æò°¡ ±â°ü, ITSEF À̶ó°í ºÒ¸²) ½Ã½ºÅÛ ¼³°è¿Í ¹®¼È¸¦ »ó¼¼È÷ °Ë»çÇÏ¿© º¸¾È Ãë¾àÁ¡À» ã´Â °ÍÀÌ´Ù.
½Ã½ºÅÛÀÌ ÀÌ¿ëµÉ ¼ö ÀÖ´Â º¸¾È Ãë¾àÁ¡À» °¡Áö°í ÀÖÁö ¾ÊÀº °ÍÀ¸·Î ÆÇ¸íµÇ¸é, ½Ã½ºÅÛÀº Æò°¡¸¦ Åë°úÇÏ°Ô µÈ´Ù; ¾Æ´Ï¸é ½ÇÆÐÇÑ´Ù.
6.4.13 ½Ã½ºÅÛÀÌ º¸¾È Æò°¡¸¦ Åë°úÇϸé, ÀÌ´Â ¾î´À Á¤µµÀÇ º¸¾ÈÀ» Á¦°øÇÒ ¹ý ÇÏÁö¸¸, ´ÙÀ½°ú °°Àº ÀÌÀ¯µé ¶§¹®¿¡ ¿ÏÀüÈ÷ ¾ÈÀüÇÏ´Ù°í ÇÒ ¼ö´Â ¾ø´Ù:
a) Æò°¡ÀÚ°¡ ¾òÀ» ¼ö ÀÖ´Â Á¤º¸ÀÇ ¼öÁض§¹®¿¡, Æò°¡ÀÚ°¡ ¹ß°ßÇÏÁö ¸øÇÑ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÒ ¼ö ÀÖ´Ù;
b) ½Ã½ºÅÛÀÌ ¾ÈÀüÇÏÁö ¸øÇÏ°Ô »ç¿ë, ¿î¿µ, °ü¸® ¶Ç´Â ±¸¼ºµÉ ¼ö ÀÖ´Ù;
c) ±× ȯ°æ¿¡¼ÀÇ ¾î¶² À§ÇùµéÀÌ º¸¾È ¸ñÇ¥¿¡ Æ÷ÇÔµÇÁö ¾Ê¾ÒÀ» ¼ö ÀÖ´Ù.
6.4.14 µû¶ó¼, Æò°¡µÈ ½Ã½ºÅÛÀº Á¶Á÷ÀÇ º¸¾ÈÀ» À¯ÁöÇϴµ¥ ÇϳªÀÇ ¿ªÇÒÀ» ´ã´çÇÏ´Â °ÍÀ¸·Î º¸¾Æ¾ß ÇÏÁö¸¸, º¸¾È¿¡ ´ëÇÑ ¸ðµç Ã¥ÀÓÀ» Áö´Â °ÍÀº ¾Æ´Ï´Ù.
¸ðµç À¯ÇüÀÇ »ç¿ëÀÚµéÀÌ ¿©ÀüÈ÷ ´ã´çÇÒ ºÎºÐÀÌ ÀÖ´Ù.
..........
´ÙÀ½Àº FIST WWW ÆäÀÌÁö·ÎºÎÅÍ ¹ßÃéÇÑ °ÍÀÌ´Ù:
TTAP (½Å·Ú±â¼ú Æò°¡ ÇÁ·Î±×·¥ Trust Technology Assessment Program) ´Â »ó¿ë ±â¼ºÁ¦Ç° (COTS)¿¡ ´ëÇÑ ½Å·Ú µî±ÞÀ» »ó¿ëÈÇϱâ À§ÇÑ ±¹°¡ ¾Èº¸±¹(NSA) °ú ±¹¸³ Ç¥Áرâ¼ú ¿¬±¸¼Ò(NIST)ÀÇ ÇÕÀÛǰÀÌ´Ù. National Voluntary Laboratory Accreditation Program (NVLAP) ÀÇ ÈÄ¿ø¾Æ·¡, TTAP ´Â »ó¿ë Æò°¡ ±â°üÀ» ¼³¸³, ½ÂÀÎ, °¨µ¶ÇÒ °ÍÀ̸ç, Ãʱ⿡´Â TCSEC B1¹× ±× ÀÌÇÏ ½Å·Ú ¼öÁØÀÇ ±â´É°ú º¸ÁõÀ» °¡Áö´Â Á¦Ç°µé¿¡ ÃÊÁ¡À» ¸ÂÃá´Ù.
ÃÖÃÊÀÇ TTAP ¿öÅ©¼¥Àº 1996³â º½¿¡ ÀÖÀ» °ÍÀÌ´Ù. »ç¿ëÀÚ°¡ "º¸¾È µî±Þ"¿¡ µû¶ó ¿î¿µÃ¼Á¦¸¦ ¼±ÅÃÇÒ ¼ö ÀÖ°Ô Çϱâ À§ÇØ TTAP°¡ ¾î¶² ÀÏÀ» ÇÒ Áö ÁöÄѺ¸´Â ÀÏÀÌ Èï¹Ì·Î¿õ °ÍÀÌ´Ù.
´ÙÀ½ ¼³¸íÀº NIST ( http://csrl.ncsl.nist.gov/nistpubs/cc ) ·ÎºÎÅÍ °¡Á®¿Â °ÍÀÌ´Ù:
1985 ³â ¹Ì±¹Àº TCSEC (Trusted Computer Security Evaluation Criteria ¶Ç´Â Orange book) À̶ó´Â º¸¾È Æò°¡ ±âÁØ ¼¼Æ®¸¦ ¸¸µé¾ú´Ù. ÀÌ·¯ÇÑ ±âÁØÀº ƯÁ¤ÇÑ º¸¾È ±â´É¼ºÀ» ÇÊ¿ä·Î Çϸç Á¤ÀÇµÈ Æ¯Á¤ ȯ°æ ¼¼Æ®¿¡ ÀûÇÕÇÑ ¸î°³ÀÇ µî±ÞÀ» Á¦°øÇÏ¿´´Ù (C1, C2, B1, B2, B3, A1). ÀÌ TCSEC ÀÌÈÄ, À¯·´±¹°¡µéÀÌ ITSEC (IT Security Evaluation Criteria)À» ¸¸µé°í, ij³ª´Ù´Â CTCPECÀ», ±×¸®°í ¸¶Áö¸·À¸·Î ¹Ì±¹¿¡¼ ¿¬¹æ ±âÁØÀ» ¸¸µé¾ú´Ù. ÀÌ ±âÁصéÀÌ ¼·Î ȣȯµÇÁö ¾ÊÀ¸¹Ç·Î, ÀÌ ¸ðµç ±âÁصéÀ» Common Criteria (¶Ç´Â ´Ü¼øÈ÷ CC)¶ó´Â »õ·Î¿î ÇϳªÀÇ º¸¾È Æò°¡ ±âÁØ ¼¼Æ®·Î Á¶È½Ã۱â·Î °áÁ¤µÇ¾ú´Ù.
Common Criteria ÀÇ ÁÖµÈ ¸ñÀûÀº ¸ðµç IT º¸¾È Á¦Ç°µé¿¡ ´ëÇØ »ç¿ëµÉ ¼ö ÀÖ´Â º¸¾È Æò°¡ ±âÁØ ¼¼Æ®¸¦ Á¦°øÇÏÀÚ´Â °ÍÀÌ´Ù. µ¿½Ã¿¡ À̰ÍÀº Á¦Ç°¿¡ ´ëÇØ ¹Ù¶ö ¼ö ÀÖ´Â, °¡´ÉÇÑ º¸¾È ¿ä±¸»çÇ×µéÀÇ ¸ÚÁö°í °£·«ÇÑ ¼¼Æ®¸¦ Á¦°øÇÑ´Ù.
Common Criteria ´Â ¾ÆÁ÷ ¿Ï¼ºµÇÁö ¾Ê¾Ò´Ù. ÇöÀç´Â Common Criteria for Information Technology Security (CC) version 1.0, January 31, 1996 ÀÌ ´ëÁß ¸®ºä¿Í ÀÇ°ß ¼ö·ÅÁßÀÌ´Ù. ¸®ºä¿Í ½ÃÇè Æò°¡¿¡ µû¶ó CC´Â °è¼Ó Á¤ÇØÁöÁö ¾ÊÀ» ¼ö ÀÖ´Ù. ¸ñÇ¥´Â ISO°¡ Common Criteria ¸¦ ±¹Á¦ Ç¥ÁØÀ¸·Î ¹Þ¾ÆµéÀÌ´Â °ÍÀ̸ç, ÀÌ¹Ì ISO¿¡ Á¦ÃâÇÏ¿´´Ù.
ISO/IEC/JTC1/SC27/WG3 "Evaluation Criteria for IT Security" ´Â Àü¼¼°èÀûÀΠǥÁØ ±âÁØÀ» 1998±îÁö ¸¸µé ¸ñÇ¥¸¦ °¡Áö°í ÀÖ´Ù.
°¢ÁÖ:
[1] È®½ÇÈ÷ NCSC ´Â À¥ÀÌ ÀÖÁö¸¸ ½Ã½ºÅÛÀ» Æò°¡ÇÏ´Â NSA ºÎ¹®Àº ¾ø´Ù?have now a Web presence, but not
the NSA division which evaluates systems.
Previous
Next Top Detailed TOC
Last Update: 16 Jun 2000