previous  next  Title  Contents  Index   Previous   Next   Top   Detailed TOC         Last Update: 16 Jun 2000


21 ºÎ·Ï C: Âü°íÀÚ·á

in English

21.0 °ü·Ã ÀÚ·á ¸ñ·Ï°ú »çº»

´ÙÀ½ ¹®¼­µéÀº ·ÎÄ÷Πº¹»çµÇ¾î ÀÖ´Ù:

´ç½ÅÀÇ ½Ã½ºÅÛÀÌ Ä§ÀÔÀÚ¿¡ ÀÇÇØ ÇÔ¶ôµÈ´Ù¸é
What if your Machines are Compromised by an Intruder
Christopher Klaus of Internet Security Systems, Inc. <iss@iss.net>
compromise_faq.html
Tik-110.501 ³×Æ®¿÷ º¸¾È¿¡ ´ëÇÑ ¼¼¹Ì³ª
½Ç¿ëÀûÀÎ ¾ÏÈ£½Ã½ºÅÛ°ú °­µµ
Practical Cryptosystems and their Strength
Janne Frosen Department of Computer Science
Helsinki University of Technology Janne.Frosen@hut.fi     2.11.1995
CryptoAlgoStrength.html
º¸¾ÈÆò°¡ ±âÁØ
  • ITSEC
  • ITSEM
  • TCSEC / Orange Book
  • Common criteria (old version)
 

itsec.htm
itsem.html
tcsec.html
commoncriteria.html

º¸¾È ¸ÞÀϸµ ¸®½ºÆ® FAQ, ISS security_lists.html
Sniffer FAQ, ISS sniff.html
¾Ïȣȭ±â¼ú°ú °ü·ÃµÈ Á¤Ã¥ ¸®ºä
Review of Policy relating to Encryption Technologies
(The Walsh Report) Dec.1998
ÀÌ ÆÄÀÏÀº ÀÌ º¸°í¼­ÀÇ ¿ÏÀüÇÑ ´ÜÀϹ®¼­ ¹öÀüÀÌ´Ù. ¿øº» URL: http://www.efa.org.au/Issues/Crypto/Walsh/index.htm  
walsh.zip
¾ÏÈ£¿Í ÀÚÀ¯ 1999 - ¾ÏȣȭÁ¤Ã¥¿¡ ´ëÇÑ ±¹Á¦Àû ¿¬±¸
Cryptography and Liberty 1999 - An International Survey of Encryption Policy
À̰ÍÀº ³»°¡ ¾Ë°í ÀÖ´Â ±¹Á¦ ¾ÏÈ£ Á¤Ã¥ °³·Ð Áß °¡Àå ÈǸ¢ÇÏ´Ù.
crytpo1999.htm.zip
www2.epic.org/reports/crypto1999.html  
ÇÁ·Î±×·¡¹Ö
  • À¯´Ð½º ÇÁ·Î±×·¡¹Ö ÆÁ, SunWorld.
  • Code Signing: how-to
 

swol-unix-programming.html
Doc_CodeSigning.html

½Ã½ºÅÛ °ü¸®
  • ÀÎÅÍ³Ý À¥¼­¹ö: best practices
 

webserver_practices.html

ÀÌ ¸ðµç º¸¾È ¹®Á¦¿¡¼­ ÀαÇÀ» ÀØÁö ¸»µµ·Ï ÇÏÀÚ..... ƯÈ÷ ÇÁ¶óÀ̹ö½Ã Ãø¸é¿¡¼­
Don't forget human rights in all of this security stuff..... especially privacy aspects.
humanrights.html

21.1 º¸¾È Á¤º¸: ¾îµð¿¡¼­ ¾òÀ» ¼ö ÀÖ³ª?

Âü°í Àý¿¡¼­ Ã¥ ¸ñ·ÏÀ» ±¸ÇÒ ¼ö ÀÖ´Ù.

ÀÌ ÀýÀº ÀÎÅÍ³Ý Âü°íÀڷḦ ¸¹ÀÌ Æ÷ÇÔÇϰí ÀÖ°í, °Å±â´Ù º¸¾È Á¶Á÷¿¡ ´ëÇÑ ¼³¸í°ú À̵鿡 ÀÇÇÑ º¸¾È ±Ç°í¹®µéÀÌ ¹ßÇ¥µÇ´Â °÷À» ¼Ò°³ÇÑ´Ù.
ÀÎÅͳÝÀº °è¼ÓÇØ¼­ º¯È­Çϰí ÀÖÀ¸¹Ç·Î, ³ª¿­µÈ ¸µÅ©µé Áß ¸î¸îÀº ´õÀÌ»ó À¯È¿ÇÏÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù. ÀÌ·± °æ¿ì, ¾ßÈÄ ³ª ¾ËŸºñ½ºÅ¸ °°Àº °Ë»ö¿£ÁøÀ» ÀÌ¿ëÇÏ¿© Á¤º¸¸¦ ãµµ·Ï ÇÑ´Ù (¾Æ·¡ ÂüÁ¶).

21.1.1 ¹Ù»Û »ç¶÷µéÀ» À§ÇÑ ¼Ó¼º °¡À̵å!

21.1.2 Contacts: À̸ÞÀÏ ¸®½ºÆ®, ´ëÀÀÆÀ, º¥´õ, ÆÐÄ¡ ¼Ò½º

¹ÙÀÌ·¯½º Contacts (oldish):

´º½º ±×·ì: comp.virus PC Viruses
PC ¹ÙÀÌ·¯½º Á¤º¸ mailto:listserv%lehiibm1.bitnet@mitvma.mit.edu
body= "SUB VIRUS-L myname@my.domain"
NCSA ftp://ftp.ncsa.com/pub/virus/WildList
¸ÅÅ©·Î ¹ÙÀÌ·¯½º ¸ñ·Ïftp://ftp.informatik.uni-hamburg.de/pub/virus/macro/

´ëÀÀÆÀ ¿¬¶ôó:

FIRST mailto:first-sec@first.org
http://www.first.org [FIRST ȨÆäÀÌÁö]

SWITCH CERT ½ºÀ§½º mailto:cert-staff@switch.ch
CERT mailto:cert-advisory-request@cert.org *̵̧*
CERT µµ±¸ mailto:cert-tools-request@cert.org
ftp://cert.org/pub/cert_advisories
´Ù¸¥ À¯·´ ÆÀµé: ´ÙÀ½ Àý ÂüÁ¶.
È£ÁÖ CERT http://www.auscert.org.au/ [ÃÖ½ÅÁ¤º¸°¡ ºü¸£´Ù.]

CIAC mailto:ciac-listproc@llnl.gov subject=
"subscribe CIAC-ANNOUNCE Boran, Sean MY_PHONE_NR"
"subscribe CIAC-NOTES Boran, Sean MY_PHONE_NR"
"subscribe SPI-ANNOUNCE Boran, Sean MY_PHONE_NR"
"subscribe SPI -NOTES Boran, Sean MY_PHONE_NR"

º¸¾È Àü¹Ý:

Risks forum mailto:risks-request@csl.sri.com
Best of Security (bos) mailto:majordomo@suburbia.net
º¸¾È ¸ÞÀϸµ ¸®½ºÆ® (local copy)
SANS ³×Æ®¿÷ º¸¾È ¿ä¾à Network Security Digest  mailto:sans@clark.net
     body='subscribe Network Security Digest your name'

´º½º±×·ì º¸¾ÈÀÏ¹Ý news://comp.security.misc
                    ±â¼úÀÇ ÇØ¾Ç Evils of technology news://comp.risks
                    º¸¾È °ø½Ã Security Announcements news://comp.security.announce

ftp://ftp.switch.ch/mirror/security [½ºÀ§½ºÀÇ ±¦ÂúÀº °Íµé]
http://coast.cs.purdue.edu/homes/spaf/spafs_hotlist.html [Spafford ÀÇ ¸µÅ© »öÀÎ: ¾ÆÁÖ ÁÁÀ½]
http://www.tezcat.com/web/security/security_http.html [¼ö¸¹Àº ³×Æ®¿÷/À¯´Ð½º ÆäÀÌÁöµé¿¡ ´ëÇÑ »öÀÎ]

http://www-genome.wi.mit.edu/WWW/faqs/www-security-faq.html [WWW ¼­¹ö º¸¾È]
http://www.primus.com/staff/paulp/cgi-security [±úÁø ¸µÅ©] [WWW cgi ½ºÅ©¸³Æ® º¸¾È]
http://hoohoo.ncsa.uiuc.edu/cgi/security.html [À§¿Í °°À½]
IIS º¸¾È ¼³Á¤ support.microsoft.com/support/kb/articles/Q229/6/94.asp

º¥´õ ¿¬¶ôó / ÆÐÄ¡ ¼Ò½º:

À¯´Ð½º º¸¾È mailto:security@cpd.com [È®ÀÎ ¾ÈµÊ]

Sun:
Sun "°í°´ °æ°í ½Ã½ºÅÛ Customer Warning System" º¸¾È °æ°í mailto:security-alert@sun.com , subject="subscribe CWS myname@my.company.domain", Tel. +1 415 688-9081
Sun sysadmin mailto:sun-managers-request@eecs.nwu.edu
           body="add myname@my.domain"
º¸¾È °ø½Ã sunsolve.sun.com/sunsolve/secbulletins
Sun & ÀÚ¹Ù º¸¾È   www.sun.com/security/index.html    
Solaris ´º½º±×·ì news://comp.unix.solaris     java.Sun.com/security
ÆÐÄ¡
   °ø°³  sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access
   ÆÐÄ¡ sunsolve.sun.ch/pub-cgi/us/secbul.pl  
   ½ºÀ§½º sunsolve.sun.ch   Contract patches sunsolve.sun.ch/private-cgi/us/patchpage.pl    
   ÆÐÄ¡ ´Ù¿î·Îµå µµ±¸ WGET sunsite.auc.dk/ftp/pub/infosystems/wget/
   PatchDiag µµ±¸ sunsolve.sun.ch/sunsolve/patchdiag

Sun¿ë ÄÄÆÄÀÏµÈ ÇÁ¸®¿þ¾î   www.sunfreeware.com
Solaris °¡ÀÌµå »öÀÎ:  www.solarisguide.com
Sunworld sunwhere index of resources www.sunworld.com/sunworldonline/sunwhere.html
Jean ChouanardÀÇ Solaris °­È­ ÆÐŰÁö ftp://ftp.parc.xerox.com/pub/jean/solins/solins.html
Jens VocklerÀÇ Solaris TCP/IP ½ºÅà Ʃ´×À» À§ÇÑ ½ºÅ©¸³Æ® (¼º´É, º¸¾È¿¡ ¶Ù¾î³ª°í ndd¸¦ ¹è¿ì´Â µ¥ ÁÁÀ½) http://www.rvs.uni-hannover.de/people/voeckler/tune/EN/tune.html.

HP:
Hewlett Packard mailto:security-alert@hp.com
HP º¸¾È ¸®½ºÆ® mailto:support@support.mayfield.hp.com body="subscribe security_info"
HP-UX sysadmin mailto:majordome@cv.ruu.nl body="subscribe hpux-admin"
HP-UX ´º½º±×·ì news://comp.sys.hp.hpux

DEC:
mailto:rich.boren@cxo.mts.dec.com , Tel. +1 719 592-4689
OSF/1 sysadmin mailto:majordomo@ornl.gov body="subscribe alpha-osf-managers"
http://www.service.digital.com/html/patch_service.html

BSDI sysadmin bsdi-users-request@bsdi.com
SCO: security-alert@sco.com
Santa Cruz Operation ftp://ftp.sco.com/SLS
Linux: ¸®´ª½º ºñ»ó´ëÀÀÆÀ:
http://bach.cis.temple.edu/linux/linux-security/Linux-Alerts/
www.redhat.com www.suse.com
OpenBSD: www.openbsd.org

SGI/IRIX:
À̸ÞÀÏ mailto:security-alert@sgi.com , Tel. +1 800 800-4SGI
ÆÐÄ¡: SGIÀÇ º¸¾È ±Ç°í¹® ¹× ÆÐÄ¡´Â ftp://sgigate.sgi.com ³ª ¹Ì·¯»çÀÌÆ® ftp.sgi.com ÀÇ µð·ºÅ丮 Security or Patches ¿¡¼­ ftp ·Î ±¸ÇÒ ¼ö ÀÖ´Ù.

À§ ÆÐÄ¡¿Í °ü·ÃµÈ À̽´´Â, mailto:cse-security-alert@csd.sgi.comÀ» ÂüÁ¶. »õ·Î¿î À̽´´Â, mailto:security-alert@sgi.com ·Î À̸ÞÀÏ.

´º½º±×·ì ´º½º://comp.sys.sgi.bugs (IRIX bugs).

IBM/AIX:
http://www.ers.ibm.com/tech-info
mailto:nrt@watson.ibm.com , Tel. +1 800 237-5511
ftp://software.watson.ibm.com/pub/aix3 [¸î¸î AIX º¸¾È ÆÐÄ¡]
http://service.software.ibm.com/pbin-usa/fixdist.pl
http://service.software.ibm.com/aixsupport
http://www.ibm.com/security [º¸¾È Á¦Ç° & ¼­ºñ½º]

Microsoft/Windows NT:
NT º¸¾È À̽´ mailto:request-ntsecurity@iss.net
NTBugtraq mailto:listserv@listserv.ntbugtraq.com body= "SUB NTBUGTRAQ Your Name"
www.securityfocus.com
ISSÀÇ NT º¸¾È   mailto:request-ntsecurity@iss.net body="subscribe ntsecurity"
NT, Explorer º¸¾È www.ntsecurity.net              *recommended*
Microsoft º¸¾È mailto:security@microsoft.com       www.microsoft.com/security
www.somarsoft.com/contents.htm [NT º¸¾È]
www.iea.com/~daler/nt/faq/toc.html [NT ÀÚÁÖ ¹¯´Â Áú¹®µé]

Cisco
www.cisco.com/warp/public/707/advisory.html
±â»ç ´Ù¾çÇÑ ¶ó¿ìÅÍ ÆÐ½º¿öµå ¸ÞÄ«´ÏÁò & Ãë¾àÁ¡ ¼³¸í

¹æÈ­º®:

¹æÈ­º® Firewalls mailto:majordomo@greatcircle.com "subscribe firewalls"
¿ä¾àµµ ÀÖÀ½.

º¸¾È ÇØÅ· (¿ÏÀü °ø°³) ±×·ì:

8lgm(8 Little Green Men): mailto:majordomo@8lgm.org body="subscribe 8lgm"    www.8lgm.org
Avalon mailto:mcpheea@cadvision.com

Bug track discussion list mailto:bugtraq-request@fc.net
http://www.eecs.nwu.edu/~jmyers/bugtraq/index.html

ÄÄÇ»ÅÍ ¾ð´õ±×¶ó¿îµå:

´ÙÀ½À» ¾ð´õ±×¶ó¿îµå »çÀÌÆ® ¿¡ ´ëÇÑ ¸µÅ© ¸ñ·Ï °ßº»À¸·Î, À̸¦ º¸¸é ÀÎÅÍ³Ý ÇØÄ¿µéÀÌ ¾î¶² »ý°¢À» ÇÏ°í ¾î¶² Á¤º¸·ÎºÎÅÍ ½ÃÀÛÇÒÁö¿¡ ´ëÇÑ »ý°¢ÀÌ µé °ÍÀÌ´Ù.

www.insecure.org    ´Ù¸¥ °Íº¸´Ùµµ nmapÀÇ È¨
www.nessus.org      Èï¹Ì·Î¿î ½ºÄ³³Ê
www.rootshell.com  µµ±¸ ¸ðÀ½
www.l0pht.com  NT ÆÐ½º¿öµå Å©·¡Å· & NFR Ç÷¯±×ÀÎ

www-personal.engin.umich.edu/~jgotts/underground/hack-faq.html alt.2600/#hack FAQ intro.
scitsc.wlv.ac.uk/~cs6171/hack/index.html Unix /net /hack page
scitsc.wlv.ac.uk/~cs6171/phrack/phrackindex.html Phrack
mailto:phrack@well.sf.ca.us Phrack
www.unix.geek.net/~arny Unix /net /hack page ¹Ì±¹ ¹Ì·¯»çÀÌÆ®
www.paranoia.com/~coldfire/index.html Cold Fire's Web Page
www.2600.com  2600 Magazine
www-personal.engin.umich.edu/~jgotts/underground.html The Internet Underground
bush.cs.tamu.edu/~erich/alt.cp.faq.html alt.cyberpunk FAQ ¸ñ·Ï
mailto:tk0jut2@mvs.cso.niu.edu Computer Underground Digest
www.wiretrip.net/rfp/2/index.asp Rain.Forest.Puppy

www.dbnet.ece.ntua.gr/~george/security/ HawkÀÇ º¸¾È ¸µÅ©
www.hideaway.net/security_links.html Hideaway.Net - º¸¾È ¸µÅ©
www.secure.cybercomm.nl/index2.html ¾ÈÀüÇÑ »çÀ̹öÅë½Å

±âŸ:

www.scit.wlv.ac.uk/rfc/index.html                    HTML Çü½ÄÀÇ RFCs
www.technotronic.com/tcpudp.html                  tcp, udp ¹× ¼­ºñ½º ¸ñ·Ï ¼³¸í
www.isi.edu/in-notes/iana/assignments/port-numbers   IANA Æ÷Æ®¹øÈ£ ¸ñ·Ï
www-arc.com/sara   SARA - satan °°Àº ½ºÄ³³Ê
www.wwdsi.com/saint SAINT ½ºÄ³³Ê
www.nessus.org NESSUS ½ºÄ³³Ê
www.SecuriTeam.com º°·Î ¾ÈÁÁ´Ù.

tycho.usno.navy.mil The Official Source of Time for the Department of Defense and the Standard of Time for the United States

21.2 º¸¾È Á¶Á÷

21.2.1 FIRST (Forum of Incident Response and Security Teams)

FIRST´Â »ç°í ¿¹¹æ, »ç°í¿¡ ´ëÇÑ ½Å¼ÓÇÑ ´ëÀÀÀ» À§ÇÑ Çù·ÂÀ» Á¶ÀåÇϰí ȸ¿øµé ¹× ±¤¹üÀ§ÇÑ °øµ¿Ã¼°£ÀÇ Á¤º¸°øÀ¯¸¦ ¸ñÀûÀ¸·Î ÇÏ´Â ±¹Á¦ Á¶Á÷µé (Á¤ºÎ & ¹Î°£ ºÐ¾ß ¸ðµÎ) ÀÇ ¿¬ÇÕÀÌ´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº À̵éÀÇ WWW ÆäÀÌÁö¿¡¼­ ã°Å³ª www.first.org À̸ÞÀÏ mailto:first-sec@first.org·Î ¿¬¶ôÇÏ¸é µÈ´Ù. ÀϹÝÀûÀ¸·Î »ç¿ëÀÚµéÀº, FIRST °¡ Àü¼¼°è º¸¾È°ü¸®ÀÚ¸¦ À§ÇÑ ¸ÞÀϸµ ¸®½ºÆ®¸¦ ¿î¿µÇÏ°Ô Çϱ⺸´Ù´Â, °¡Àå °¡±î¿î FIRST ¿¡ ¿¬¶ôÇϰí À̵éÀÇ ¸ÞÀϸµ¸®½ºÆ®¿¡ °¡ÀÔÇØ¾ß ÇÑ´Ù!

FIRST ´Â 30°³°¡ ³Ñ´Â ȸ¿ø¼ö¸¦ °¡Áø´Ù (1995³â 11¿ù ±âÁØ). °¡Àå ¿µÇâ·ÂÀִ ȸ¿øµéÀº (ÀúÀÚÀÇ ¼Ò°ßÀ¸·Î) CERT, AUSCERT, DFN-CERT, CIAC ÀÌ´Ù. ÀÌ ±×·ìµéÀº ´ÙÀ½ Àýµé¿¡¼­ ÈξÀ »ó¼¼ÇÏ°Ô ¼³¸íµÈ´Ù.

´ëºÎºÐÀÇ FIRST ȸ¿øµéÀº PGP¸¦ ½á¼­ À̸ÞÀÏ¿¡ ¼­¸íÇÏ°í ÆÐÄ¡ ÆÄÀÏÀÇ ¹«°á¼º °Ë»ç¿¡ MD5 ¸¦ »ç¿ëÇϹǷÎ, ÀÌµé µÎ À¯Æ¿¸®Æ¼¸¦ °¡Áö°í ÀÖÀ» °ÍÀ» ±Ç°íÇÑ´Ù.

21.2.1.1 CERT

CERT ´Â, ÀÎÅÍ³Ý ¿ú »ç°Çµ¿¾È º¸¿©Áø Çʿ伺¿¡ ºÎÀÀÇÏ¿© ¹Ì ±¹¹æ °íµî¿¬±¸ ÇÁ·ÎÁ§Æ® ±â°ü (US Defence Advanced Research Projects Agency, DARPA) ¿¡ ÀÇÇØ 1988³â 11¿ù ¸¸µé¾îÁø ÄÄÇ»ÅÍ ºñ»ó ´ëÀÀÆÀ (Computer Emergency Response Team) ÀÌ´Ù. CERT ¼³¸³ÃëÁö´Â ÀÎÅÍ³Ý °øµ¿Ã¼¿Í Çù·ÂÇÏ¿© ÀÎÅÍ³Ý È£½ºÆ® °ü·Ã ÄÄÇ»ÅÍ º¸¾È »ç°Ç ´ëÀÀÀ» ÃËÁøÇϰí, °øµ¿Ã¼ÀÇ ÄÄÇ»ÅÍ º¸¾È ÀνÄÀ» ³ôÀ̱â À§ÇÑ ¼øÇâÀû (proactive) Á¶Ä¡¸¦ ÃëÇϰí, ±âÁ¸ ½Ã½ºÅÛµéÀÇ º¸¾È °³¼±À» ¸ñÇ¥·Î ÇÏ´Â ¿¬±¸¸¦ ¼öÇàÇÏ´Â °ÍÀÌ´Ù.

Computer Emergency Response Team (CERT)
mailto:cert@cert.org (Åë½ÅÀº DES ³ª PGP ·Î ¾Ïȣȭ ÇÒ °ÍÀ» ±ÇÀå)
Tel. +1 412 268-7090

CERT ±Ç°í¹®Àº ÁÖ·Î À¯´Ð½º& VMS °ü¸®Àڵ鿡°Ô Èï¹ÌÀÖ´Â °ÍµéÀÌÁö¸¸, NTµµ ÀÖ°í, À©µµ¿ì³ª MacÀº °ÅÀÇ ¾ø´Ù (¾Æ·¡ CIAC ÂüÁ¶).
CERT ´Â 1988³â À¥ ÆäÀÌÁö¸¦ Àü¸é °³ÆíÇßÀ¸¸ç, Áö³ª°£ CERT ±Ç°í¹®À» HTML Çü½ÄÀ¸·Î ±¸ÇÒ ¼ö ÀÖ°í, ¶Ç ¸¹Àº °ÍµéÀÌ ÀÖ´Ù www.cert.org. ÀÌ ¹üÀ§±îÁö´Â ÀÌ ÀýÀÌ Á¶±Ý Áߺ¹µÈ´Ù (1999).

ftp://ftp.cert.org/pub/cert_advisories/ [»öÀÎÀº 01-README ÆÄÀÏ¿¡]
ftp://ftp.cert.org/pub/cert_summaries/
ftp://ftp.cert.org/pub/cert_bulletins/
ftp://ftp.cert.org/pub/tech_tips/packet_filtering
ftp://ftp.cert.org/pub/tech_tips/UNIX_configuration_guidelines
ftp://info.cert.org/pub/tools/
ftp://info.cert.org/pub/tech_tips/security_tools
ftp://info.cert.org/pub/incident_reporting_form
ftp://info.cert.org/pub/whois_how_to
ftp://info.cert.org/pub/FIRST/first-contacts

An ÀÎÅÍ³Ý »óÀÇ º¸¾È »ç°í ºÐ¼® 1989-1995

¾Æ·¡´Â ¿ÏÀüÇÑ ±Ç°í¹® ¸ñ·ÏÀÌ´Ù:

CA-88:01.ftpd.hole CA-94:05.MD5.checksums
CA-89:01.passwd.hole CA-94:06.utmp.vulnerability
CA-89:02.sun.restore.hol CA-94:07.wuarchive.ftpd.trojan.horse
CA-89:03.telnet.breakin.warning CA-94:08.ftpd.vulnerabilities
CA-89:04.decnet.wank.worm CA-94:09.bin.login.vulnerability
CA-89:05.ultrix3.0.hole CA-94:10.IBM.AIX.bsh.vulnerability
CA-89:06.ultrix3.0.update CA-94:11.majordomo.vulnerabilities
CA-89:07.sun.rcp.vulnerability CA-94:12.sendmail.vulnerabilities
CA-90:01.sun.sendmail.vulnerability CA-94:13.SGI.IRIX.Help.Vulnerability
CA-90:02.intruder.warning CA-94:14.trojan.horse.in.IRC.client.for.UNIX
CA-90:03.unisys.warning CA-94:15.NFS.Vulnerabilities
CA-90:04.apollosuid.vulnerability CA-95:01.IP.spoofing
CA-90:05.sunselection.vulnerability CA-95:01.IP.spoofing.attacks.and.hijacked.terminal.connections
CA-90:06a.NeXT.vulnerability CA-95:02.binmail.vulnerabilities
CA-90:07.VMS.ANALYZE.vulnerabiliy CA-95:03.telnet.encryption.vulnerability
CA-90:08.irix.mail CA-95:03a.telnet.encryption.vulnerability
CA-90:09.vms.breakins.warning CA-95:04.NCSA.http.daemon.for.unix.vulnerability
CA-90:10.attack.rumour.warning CA-95:05.sendmail.vulnerabilities
CA-90:11.Security.Probes CA-95:06.satan
CA-90:12.SunOS.TIOCCONS.vulnerability CA-95:07.vulnerability.in.satan
CA-91:01a.SunOS.mail.vulnerability CA-95:07a.REVISED.satan.vul
CA-91:02a.SunOS.telnetd.vulnerability CA-95:08.sendmail.v.5.vulnerability
CA-91:03.unauthorized.password.change.request CA-95:09.Solaris-ps.vul
CA-91:04.social.engineering CA-95:09.Solaris.ps.vul
CA-91:05.Ultrix.chroot.vulnerability CA-95:10.ghostscript
CA-91:06.NeXTstep.vulnerability CA-95:11.sun.sendmail-oR.vul
CA-91:07.SunOS.source.tape.vulnerability CA-95:12.sun.loadmodule.vul
CA-91:08.systemV.login.vulnerability CA-95:13.syslog.vul
CA-91:09.SunOS.rpc.mountd.vulnerability CA-95:14.Telnetd_Environment_Vulnerability
CA-91:10a.SunOS.lpd.vulnerability CA-95:15.SGI.lp.vul
CA-91:11.Ultrix.LAT-Telnet.gateway.vulnerability CA-95:16.wu-ftp_vulnerability
CA-91:12.Trusted.Hosts.Configuration.vulnerability CA-95:17.rpc.ypupdated
CA-91:13.Ultrix.mail.vulnerability CA-95:18-Widespread attacks
CA-91:14.IRIX.mail.vulnerability CA-96.01.UDP_service_denial
CA-91:15.NCSA.Telnet.vulnerability CA-96.02 BIND Version 4.9.3
CA-91:16.SunOS.SPARC.Integer_Division.vulnerability CA-96.03 Vulnerability in Kerberos 4 & 5
CA-91:17.DECnet-Internet.Gateway.vulnerability CA-96.04 Corrupt information from Network Servers
CA-91:18.Active.Internet.tftp.Attacks CA-96.05.java_applet_security_mgr
CA-91:19.AIX.TFTP.Daemon.vulnerability CA-96.06.cgi_example_code
CA-91:20.rdist.vulnerability CA-96.07.java_bytecode_verifier
CA-92:01.NeXTstep.configuration.vulnerability CA-96.08.pcnfsd
CA-92:02.Michelangelo.PC.virus.warning CA-96.09.rpc.statd
CA-92:03.Internet.Intruder.Activity CA-96.10.nis+_configuration
CA-92:04.ATT.rexecd.vulnerability CA-96.11.interpreters_in_cgi_bin_dir
CA-92:05.AIX.REXD.Daemon.vulnerability CA-96.12.suidperl_vul
CA-92:06.AIX.uucp.vulnerability CA-96.13.dip_vul
CA-92:07.AIX.passwd.vulnerability CA-96.14.rdist_vul
CA-92:08.SGI.lp.vulnerability CA-96.15.Solaris_KCMS_vul
CA-92:09.AIX.anonymous.ftp.vulnerability CA-96.16.Solaris_admintool_vul
CA-92:10.AIX.crontab.vulnerability CA-96.17.Solaris_vold_vul
CA-92:11:SunOS.Environment.vulnerability CA-96.18.fm_fls
CA-92:12.REVISED.SunOS.rpc.mountd.vulnerability CA-96.19.expreserve
CA-92:13.SunOS.NIS.vulnerability CA-96.20.sendmail_vul
CA-92:14.Altered.System.Binaries.Incident CA-96.21.tcp_syn_flooding
CA-92:15.Multiple.SunOS.vulnerabilities.patched CA-96.22.bash_vuls
CA-92:16.VMS.Monitor.vulnerability CA-96.23.workman_vul
CA-92:17.HP.NIS.ypbind.vulnerability CA-96.24.sendmail.daemon.mode
CA-92:18.VMS.Monitor.vulnerability.update CA-96.25.sendmail_groups
CA-92:19.Keystroke.Logging.Banner.Notice CA-96.26.ping
CA-92:20.Cisco.Access.List.vulnerability CA-96.27.hp_sw_install
CA-92:21.ConvexOS.vulnerabilities CA-97.01.flex_lm
CA-93:01.REVISED.HP.NIS.ypbind.vulnerability CA-97.02.hp_newgrp
CA-93:02a.NeXT.NetInfo._writers.vulnerabilities CA-97.03.csetup
CA-93:03.SunOS.Permissions.vulnerability CA-97.04.talkd
CA-93:04a.Amiga.finger.vulnerability CA-97.05.sendmail
CA-93:05.OpenVMS.AXP.vulnerability CA-97.06.rlogin-term
CA-93:06.wuarchive.ftpd.vulnerability  
CA-93:08.SCO.passwd.vulnerability  
CA-93:09.SunOS.expreserve.vulnerability  
CA-93:09a.SunOS.expreserve.vulnerability  
CA-93:10.anonymous.FTP.activity  
CA-93:11.UMN.UNIX.gopher.vulnerability  
CA-93:12.Novell.LOGIN.EXE.vulnerability  
CA-93:13.SCO.Home.Directory.Vulnerability  
CA-93:14.Internet.Security.Scanner  
CA-93:15.SunOS.and.Solaris.vulnerabilities  
CA-93:16.sendmail.vulnerability  
CA-93:16a.sendmail.vulnerability.supplement  
CA-93:17.xterm.logging.vulnerability  
CA-93:18.SunOS.Solbourne.loadmodule.modload  
CA-93:19.Solaris.Startup.vulnerability  
CA-94:01.network.monitoring.attacks  
CA-94:01.ongoing.network.monitoring.attacks  
CA-94:02.REVISED.SunOS.rpc.mountd.vulnerability  
CA-94:03.AIX.performance.tools  
CA-94:04.SunOS.rdist.vulnerability  

º¥´õ °ø½Ã:

VB-94:01.sco VB-95:10 - Vulnerability in elm V2.4 PL 24 VB-96-11.free.bsd PPP
VB-94:02.dec VB-96.01.splitvt VB-96.12.free bsd RZ
VB-95:01.hp VB-96.02.sgi Packages VB-96.13 HP, elm
VB-95:02.sgi VB-96.03.sun catalyst CDware VB-96.14 SGI, IRIX tools
VB-95:03.hp VB-96.04.bsdi Kernel VB-96.15 SCO
VB-95:04.venema VB-96.05.dec VB-96.16 Transarc, AFS/DFS
VB-95:05.osf VB-96.06.freebsd VB-96.17 Linux
VB-95:06.cisco VB-96.07.freebsd VB-96.18 Sun, libc
VB-95:07.abell VB-96.08.sgi VB-96.19 SGI, systour/ OutOfBox
VB-95:08.X_Authentication_Vul VB-96.09.freebsd VB-96.20 HP, Remote Watch
VB-95:09 - Hewlett Packard (ftp) VB-96.10.sco  

Cert ¿ä¾à:

CS-95:01 CS-96:01 CS-96:04
CS-95:02 CS-96:02 CS-96:05
CS-95:03 CS-96:03 CS-96:06

21.2.1.2 À¯·´ ºñ»ó´ëÀÀÆÀ

SIRCE (À¯·´ Àüü)

À¯·´ Àü¹ÝÀÇ ½ÃÇèÀû ´ëÀÀÆÀÀº 1997¿¡ ½ÃÀÛÇÑ´Ù. ½ÃÇè ÇÁ·ÎÁ§Æ®´Â ÃÖ´ë 30 °³¿ù°£ Áö¼ÓµÉ °ÍÀ̰í, ±× ÀÌÈÄ¿¡´Â SIRCE (Security Incident Response Co-ordination for Europe) °¡ ¿µ±¸ÀûÀ¸·Î ¿î¿µµÉ °ÍÀÌ´Ù. ½ÃÇèÇÁ·ÎÁ§Æ®´Â UKERNA-DANTE ¿¡ ÀÇÇØ ½ÇÇöµÉ ¿¹Á¤ÀÌ´Ù.. UKERNA ´Â ¿µ±¹ÀÇ ±¹¸³ ¿¬±¸¼Ò ³×Æ®¿öÅ· Á¶Á÷À̰í DANTE´Â À¯·´ÀÇ ³×Æ®¿÷ ¿¬±¸ ºñ¿µ¸® Á¶Á÷ÀÌ´Ù.

SWITCH-CERT (½ºÀ§½º)

½ºÀ§½ºÀÇ Swiss Academic and Research Network CERT ´Â ½ºÀ§½º ½Ã½ºÅÛ °ü¸®ÀÚµéÀ» À§ÇÑ º¸¾ÈÁ¤º¸ÀÇ Áß½ÉÁö¸¦ Á¦°øÇÑ´Ù. SWITCH-CERT ´Â FIRST ȸ¿ø ¹× ƯÁ¤ ÇØÅ· ±×·ìµé·ÎºÎÅÍÀÇ ¸ðµç ±Ç°í¹®µé¿¡ ´ëÇØ ȸ¿øµé¿¡°Ô Á¤º¸¸¦ ¾Ë¸°´Ù. ½ºÀ§½ºÀÇ °ü¸®ÀÚµéÀº SWITCH-CERT ¸ÞÀϸµ ¸®½ºÆ® °¡ÀÔÀ» Àû±Ø ÃßõÇÑ´Ù. Contact cert-staff@switch.ch.

DFN-CERT (µ¶ÀÏ)

German Federal Networks CERT ´Â µ¶ÀÏÀÇ º¸¾È activityµéÀ» Á¤¸®ÇÑ´Ù. Email dfncert@cert.dfn.de , tel. +49 040 5494-2262.

Italy: cert-it@dsi.unimi.it
³×´ú¶õµå: cert-nl@surfnet.nl
À×±Û·£µå: cert@ja.net

21.2.1.3 AUSCERT

Australian CERT ´Â Áö¸®ÀûÀ¸·Î ¶³¾îÁ® ÀÖÁö¸¸, ¶§¶§·Î »õ·Î¿î º¸¾È ¹®Á¦³ª ±×µéÀÇ ¼Ö·ç¼Ç ¶Ç´Â ÀÛ¾÷¿¡ ´ëÇØ ±Ç°íÇÒ ¶§ °¡Àå ºü¸£´Ù.

http://www.auscert.org.au/information/advisories.html µµ ÂüÁ¶ÇÑ´Ù.
Email: auscert@auscert.org
Tel: +61 7 3365 4417

21.2.1.4 NASIRC (NASA ´ëÀÀÆÀ)

NASA ÆÀÀº NASA »ç¿ëÀڵ鿡°Ô¸¸ Áö¿øÀ» Á¦°øÇÏÁö¸¸, ¹ß°ßµÈ Ãë¾àÁ¡µéÀ» FIRST ȸ¿øµé¿¡°Ô ¹ßÇ¥ÇÑ´Ù.

http://nasirc.nasa.gov
ftp://nasirc.nasa.gov
Tel. +1 800 762-7472

21.2.1.5 CIAC (¹Ì±¹ ¿¡³ÊÁö¼º [Department of Energy, DOE] ´ëÀÀÆÀ) ('96 ³â 6¿ù)

CIAC (Computer Incident Advisory Capability)Àº ¹Ì ¿¡³ÊÁö¼º (DOE)°ú ¹Ì ±¹¸³ º¸°Ç¿ø (National Institute for Health, NIH) À» À§ÇÑ ÄÄÇ»ÅÍ º¸¾È ´ëÀÀÆÀÀÌ´Ù. CIAC´Â FIRSTÀÇ Ã¢´Ü¸â¹öÀÌ´Ù.

Tel. +1 510 422-8193
Email: ciac@llnl.gov

ÀÌÀü CIAC °øÁö, ¾ÈƼ¹ÙÀÌ·¯½º ¼ÒÇÁÆ®¿þ¾î ¹× ±âŸ Á¤º¸µéÀ» http://ciac.llnl.gov ¶Ç´Â ftp://ciac.llnl.gov ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù . ³× °³ÀÇ ¼¿ÇÁ °¡ÀÔ ¸ÞÀϸµ ¸®½ºÆ®µéÀÌ ÀÖÁö¸¸ (¾Æ·¡ ÂüÁ¶), °¡Àå °¡±î¿î FIRST ¿¡¼­ CIACÀÇ ¸ðµç ±Ç°í¹®À» À̼ÛÇØÁֹǷΠCIAC¿¡ Á÷Á¢ °¡ÀÔÇÒ ÇÊ¿ä´Â °ÅÀÇ ¾ø´Ù.

ciac-listproc@llnl.gov ·Î º»¹®¿¡ ´ÙÀ½ Áß Çϳª (¶Ç´Â ±× ÀÌ»ó)ÀÇ ÇàÀ» Æ÷ÇÔ½ÃÄÑ À̸ÞÀÏÀ» º¸³½´Ù:
subscribe CIAC-ANNOUNCE MYNAME, MYFORENAME MY_PHONE_NR
subscribe CIAC-NOTES MYNAME, MYFORENAME MY_PHONE_NR
subscribe SPI-ANNOUNCE MYNAME, MYFORENAME MY_PHONE_NR
subscribe SPI -NOTES MYNAME, MYFORENAME MY_PHONE_NR

CIAC Àº ´ÙÀ½ ÇüÅ·ΠÁ¤º¸¸¦ Á¦°øÇÑ´Ù:

  1. Tools: µµ½º, À¯´Ð½º & ¸ÅŲÅä½Ã¿ë ´Ù¾çÇÑ µµ±¸µéÀ» ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ´Ù.
  2. Notes: ÇöÀç º¸¾È ¹®Á¦Á¡µéÀ» »ó¼¼È÷ ¼³¸íÇÏ´Â Á¤±â º¸°í¼­°¡ ³ª¿Â´Ù. 1996³â 6¿ù¿¡´Â Notes 1, 2, 94-03a, 94-04c, 94-05d, 95-06 ¿¡¼­ 95-12 ±×¸®°í 96-01 À» ±¸ÇÒ ¼ö ÀÖ¾ú´Ù.
  3. Bulletins: ÀÌ ¹®¼­µéÀ» ƯÁ¤ÇÑ ¹®Á¦Á¡µéÀ» °­Á¶ÇÑ´Ù. ÇöÀç (95³â 12¿ù 20ÀÏ) CIAC Bulletins ¸ñ·ÏÀº ±×·ì A-G·Î ³ª´µ¾î, A ´Â 1989 ±×¸®°í G 1995/96ÀÌ´Ù (°³·«ÀûÀ¸·Î):
A-01: Internet Attacks D-01: Novell NetWare Access Rights Vulnerability
A-02: The W.COM Worm affecting VAX VMS Systems D-02: Internet Attack Advisory
A-03: Tools to check the spread of the "WANK" Worm D-03: Patch Available for VAX/VMS MONITOR Vulnerability
A-04: New version of the "WANK" worm D-04: 18 New and Upgraded Security Patches For SunOS
A-05: Vulnerability in the SUN rcp utility D-05: Revised Hewlett-Packard NIS ypbind Vulnerability
A-06: Trojan horse in Norton Utilities for IBM PCs and clones D-06: Failure to disable user accounts for VMS 5.3 to 5.5-2
A-07: Information about a UNICOS Problem D-07: UNICOS Vulnerabilities
A-08: Information about a UNICOS Problem D-08: Vulnerability in VMS V5
A-09: Information about the WDEF virus D-09: OpenVMS VAX Patch Problems
A-10: Information about the PC CYBORG (AIDS) trojan horse D-10: November 17 Virus on MS DOS Computers
A-11: Problem in the Texas Instr. D3 Process Control System D-11: Sun Security Patches and Software Updates
A-12: DECNET Hacker Attack Alert D-12: UNICOS Vulnerabilities
A-13: Vulnerability in DECODE alias D-13: wuarchive FTP daemon vulnerability
A-14: Additional info on the vulnerability in the DECODE alias D-14: UNICOS Vulnerabilities
A-15: CIAC Bulletin A-15 D-15: Vulnerability in Cisco Routers used as Firewalls
A-16: Vulnerability in SUN sendmail program D-16: Vulnerability in SunOS expreserve Utility
A-17: Eradicating WDEF using Disinfectant 1.5 or 1.6 D-17: LIMITED DISTRIBUTION BULLETIN
A-18: Notice of Availability of Patch for SmarTerm 240 D-18: Solaris 2.x expreserve patches available
A-19: UNIX Internet Attack Advisory D-19: Wide-spread Attacks on Anonymous FTP Servers
A-20: The Twelve Tricks Trojan Horse D-20: Summary of SunOS Security Patches
A-21: Additional Information on Current UNIX Internet Attacks D-21: Novell NetWare LOGIN.EXE Security Patch
A-22: Logon Messages and Hacker/Cracker Attacks D-22: Satan Bug Virus on MS-DOS computers
A-24: Password Problems with Unisys U5000 /etc/passwd D-23: Cray UltraNet Security Vulnerability
A-25: The MDEF or Garfield Virus on Macintosh Computers D-24: SCO Home Directory Vulnerability
A-26: A New Macintosh Trojan Horse Threat--STEROID D-25: Automated Scanning of Network Vulnerabilities
A-27: The Disk Killer (Orge) Virus on MS DOS Computers D-26: Limited Distribution Bulletin
A-28: The Stoned (Marijuana or New Zealand) Virus on DOS E-01: Sun sendmail, tar, and audio Vulnerabilities
A-29: The 4096 (4k, Stealth, IDF, etc.) Virus on MS DOS E-02: Vulnerabilities in SGI IRIX Default Configuration
A-30: Apollo Domain/OS suid_exec Problem E-03: UNIX sendmail Vulnerabilities
A-32: SunView/SunTools selection_svc Vulnerability E-04: xterm Logfile Vulnerability
A-33: Virus Propagation in Novell and Other Network E-05: SunOS/Solbourne loadmodule and modload Vulnerability
A-34: End of FY90 Update E-06: Solaris System Startup Vulnerability
B-01: Security Problem on the NeXT Operating System E-07: UNIX sendmail Vulnerabilities Update
B-02: UNIX Security Problem with Silicon Graphics Mail E-09: Network Monitoring Attacks
B-04: VMS Security Problem :ANALYZE/PROCESS_DUMP E-11: Lotus cc:Mail Security Upgrade Available
B-05: HP-UX Trusted Systems 6.5 or 7.0, Authorization E-12: Network Monitoring Attacks Update
B-07: BITNET Worm E-13: Sun Announces Patches for /etc/utmp Vulnerability
B-08: Detection/Eradication Procedures for VMSCRTL.EXE Trojan Horse E-14: wuarchive ftpd Trojan Horse
B-09: Update on Internet Activity E-17: FTP Daemon Vulnerabilities
B-10: Patch for TIOCCON in SunOS 4.1 and 4.1.1 Available E-18: Sun Announces Patches for automountd Vulnerability
B-11: OpenWindows 2.0 selection_svc Vulnerability E-19: nVir A Virus Found on CD-ROM
B-12: GAME2 MODULE "Worm" on BITNET E-20: Trojan Attack on Chinon CD-ROM Drives
B-13: UNIX Security Problem with /bin/mail in SunOS E-23: Vulnerability in HP-UX systems with HP Vue 3.0
B-14: Additional Info. about /bin/mailin SunOS E-24: Security Patch Kits for ULTRIX, and OSF/1
B-15: Network intrus. through TCP/IP and DECnet Gateways E-25: BSD lpr Vulnerability in SGI IRIX
B-16: Virus Information Update E-26: UNIX /bin/login Vulnerability
B-17: Increasing Security on Your UNICOS System E-29: IBM AIX bsh Queue Vulnerability
B-18: MVS Security Problem with TSO Reconnect Facility E-30: Majordomo distribution list administrator vulnerabilities
B-19: Vulnerability in UNIX System V on 386/486 Platforms E-31: Sendmail -d and Sendmail -oE Vulnerabilities
B-20: Patch Available for SunOS in.telnetd E-32: KAOS4 Virus
B-21: Patch for SunOS 4.0.3 in.telnetd and in.rlogind E-33: Vulnerabilities in the SGI IRIX Help System
B-22: Attempts by Network Intruders to Obtain Passwords E-34: One_half Virus (MS-DOS)
B-24: Ultrix V4.0 and V4.1 Vulnerability F-01: SGI IRIX serial_ports Vulnerability
B-25: Configuration Problems in the NeXT Operating System F-02: Summary of HP Security Bulletins
B-26: Inconsis. Dir. and File Perms. in SunOS 4.1 and4.1.1 F-04: Security Vulnerabilities in DECnet/OSI for OpenVMS
B-27: sunsrc setuid Installation Problem F-05: SCO Unix at, login, prwarn, sadc, and pt_chmod Patches
B-28: AT&T System V Release 4 Patch for /bin/login F-06: Novell UnixWare sadc, urestore, and suid_exec
B-30: SunOS lpd Problem F-07: New and Revised HP Bulletins
B-31: CRAY UNICOS 6.0 and 6.1 accton vulnerability F-08: Internet Address Spoofing and Hijacked Session Attacks
B-32: Ultrix /usr/bin/mail Security Problem F-09: Unix /bin/mail Vulnerabilities
B-33: New SunOS lpd Problem F-10: HP-UX Remote Watch
B-33A: New SunOS lpd Problem -- Correction F-11: Unix NCSA httpd Vulnerability
B-35: Brunswick Virus on MS DOS Computers F-12: Kerberos Telnet Encryption Vulnerability
B-36: New patch available for /usr/ucb/telnet on ULTRIX F-13: Unix Sendmail Vulnerabilities
B-37: Security Problem with UNIX Trusted System Files F-14: HP-UX Malicious Code Sequences
B-38: Vulnerability in Silicon Graphics Inc. "IRIX" /usr/sbin/fmt F-15: HP-UX ?t' and ?ron' vulnerabilities
B-40: Virus distributed in PCNFS software fix for MS-DOS F-16: SGI IRIX Desktop Permissions Tool Vulnerability
B-41: Vulnerability in SunOS SPARC Integer Division F-18: MPE/iX Vulnerabilities
B-42: Security Issues with Macintosh System 7 F-19: Protecting HP-UX Systems Against SATAN
B-43: Vulnerability in ULTRIX DECnet-Internet Gateway F-20: SATAN
B-44: Automated tftp Probe Attacks on UNIX Systems F-21: Protecting SUN OS Systems Against SATAN
B-45: End of FY91 Update F-22: SATAN password disclosure
C-01: New TFTPD server available for IBM RS6000 systems F-23: Protecting IBM AIX Systems Against SATAN
C-02: Dir II Virus on MS DOS Computers F-24: Protecting SGI IRIX Systems Against SATAN
C-04: Vulnerability in the rdist utility on UNIX platforms F-25: Cisco IOS Router Software Vulnerability
C-05: Preliminary Information about SYSMAN.EXE Trojan F-26: OSF/DCE Security Hole
C-06: Security Problem in SunOS fsirand Program F-27: Incorrect Permissions on /tmp
C-07: Additional Information about the SYSMAN.EXE Trojan F-28A: Vulnerability in SunOS 4.1.* Sendmail (-oR option)
C-08: SunOS /usr/ucb/rdist patch G-01: Telnetd Vulnerability
C-10: OpenWindows V.3 patch G-02: SunOS 4.1.X Loadmodule Vulnerability
C-11: Novell Network Support Encyclopaedia Update Virus G-03: AOLGOLD Trojan Program
C-12: Hewlett Packard/Apollo Domain/OS crp Vulnerability G-04: X Authentication Vulnerability
C-13: NeXTstep NetInfo Configuration Vulnerability G-05: HP-UX FTP Vulnerability
C-15: Michelangelo Virus on MS DOS Computers G-06a Windows 95 Vulnerabilities
C-16: New Internet Intrusions Detected G-07: SGI Object Server Vulnerability
C-17: New Virus on Macintosh Computers: MBDF A G-08: splitvt() vulnerability
C-18: Vulnerability In AT&T /usr/etc/rexecd G-09: Unix Sendmail Vulnerability
C-19: Vulnerabilities in SAS?System 5.18 for VMS G-10: Winword & Excel Macro Viruses
C-20: SGI 3.3.X Pseudo-tty Vulnerability G-11: HP syslog Vulnerability
C-21: AIX REXD Daemon Vulnerability G-12: SGI ATT Packaging Utility Security
C-25: SunOS ypserv, ypxfrd, and portmap Patch G-13: Kerberos 4 Key Server Vulnerability
C-26: SunOS Environment Variables and setuid/setgid G-14: Domain Name Service Vulnerability
C-27: PKZIP Trojan Alert G-15: Sunsoft Demo CD Vulnerability
C-28: SunOS Security Patches G-16: SGI rpc.statd Program Security Vulnerability
C-29: Summary of SunOS Security Patches G-17: Vulnerabilities in Sample HTTPD CGIs
C-30: VAX/VMS Security Vulnerability in MONITOR G-18: Digital OSF/1 dxconsole Security Vulnerability
CIAC-01: Authentication Bypass in Sun 386i Machines G-19: IBM AIX rmail Vulnerability
CIAC-02: Columbus Day Virus G-20: Vulnerability in NCSA and Apache httpd Servers
CIAC-03: ULTRIX DECWindows Vulnerability G-21: Vulnerabilities in PCNFSD Program
CIAC-04: Jerusalem/Israeli/Friday the 13th Virus G-22: rpc.statd Vulnerability
CIAC-05: Security Holes in UNIX Systems G-23: Solaris NIS+ Configuration Vulnerability
CIAC-06: Patch for rwalld/wall G-24: FreeBSD Security Vulnerabilities
CIAC-07: Vulnerability Involving rcp and rdist G-25: SUN statd Program Vulnerability
CIAC-08: Vulnerability in the SunOS Restore Utility G-26: IRIX Desktop Permissions Panel Vulnerability
CIAC-09: Macintosh nVIR Virus G-27: SCO Kernel Security Vulnerability
CIAC-10: IBM PC Columbus Day (Datacrime) Virus G-28a: suidperl Vulnerability
CIAC-11: Telnet Trojan Horse  
CIAC-12: Patch for rcp and rdist  
CIAC-13: Macintosh and IBM PC NCSA Telnet Vulnerability  

21.2.2 ÇÁ¶û½º Á¶Á÷ (TBD)

Clusis (TBD)

21.2.3 ¹Ì Á¶Á÷ / ±â°ü

NSA (National Security Agency, ±¹°¡ ¾Èº¸±¹)
NSA ´Â TCSEC°ú °ü·Ã Rainbow books¸¦ °³¹ßÇß´Ù. À̵éÀº ±¹¹æ¼º (DOD)ÀÇ ÀÏ¿øÀ¸·Î¼­, °­·ÂÇÑ Á¤º¸Á¶Á÷À¸·Î ´õ Àß ¾Ë·ÁÁ® ÀÖ´Ù.

NIST (National Institute of Standards and Technology, ±¹¸³ Ç¥Áرâ¼ú¿¬±¸¼Ò)
NIST ´Â Rainbow books ¿Í ±âŸ ´Ù¸¥ º¸¾È ¼ÒÃ¥ÀÚµéÀ» ¹èÆ÷ÇÑ´Ù. À̵éÀº NSA¿Í ¸Å¿ì ±ä¹ÐÇÏ°Ô ÀÏÇÑ´Ù (NSAÀÇ ÀϺκÐÀΰ¡?)
TBD: ÃÖ¼Ò º¸¾È ±â´ÉÀû ¿ä±¸»çÇ× Minimum Security Functional Requirement (MSFR)

NIST, Computer Security Labs,
Gaithersburg, Maryland 20899, USA
Tel. 301-975-2000

NCSC (National Computer Security Center, ±¹¸³ ÄÄÇ»ÅÍ º¸¾È ¼¾ÅÍ)
NSAÀÇ ÀÏ¿øÀ¸·Î, TCSEC Ç¥ÁØ¿¡ µû¶ó IT Á¦Ç°µéÀ» Æò°¡ÇÑ´Ù. Rainbow books ÀÇ ¿ø·¡ ÃâÆÇÀÚµéÀÌ´Ù.

NCSC
9800 Savage Road, Fort Meade, Maryland 20755,
Tel. 301-859-4371

NCSA (National Computer Security Association, ±¹¸³ ÄÄÇ»ÅÍ º¸¾È Çùȸ)
(Á¤ºÎ ÈÄ¿øÀÇ) NCSA ´Â ±³À°, ÄÁÆÛ·±½º, ´º½º·¹ÅÍ µî ´Ù¾çÇÑ IT ¼­ºñ½º¸¦ Á¦°øÇÏ°í ¹ÙÀÌ·¯½º »ç°ÇµéÀ» ²Ï ±ä¹ÐÇÏ°Ô ÃßÀûÇÏ´Â µ¶¸³ Á¶Á÷ÀÌ´Ù. À̵éÀº ÃÖ±Ù ¹æÈ­º®°ú ÀÎÅÍ³Ý »çÀÌÆ® ÀÎÁõÀ» ½ÃÀÛÇß´Ù. NCSA ´Â ¶ÇÇÑ ¿ö½ÌÅÏ¿¡¼­ º¸¾È °ü·Ã À̽´µéÀÇ Åë°ú¿îµ¿(lobby)À» Çϱ⵵ ÇÑ´Ù.
¹Ì±¹ ¿Ü ȸ»çµé¿¡ ´ëÇÑ ¿¬°£ ȸ¿øºñ´Â $175- Á¤µµ ÇÑ´Ù.
À̵éÀÇ "Á¤º¸Àü" ÄÁÆÛ·±½º°¡ ±¦Âú´Ù.

NSCA 10 S. Courthouse Ave.,
Carlisle, Pennsylvania 17013, USA
Tel. 717-258-1816

COAST (Computer Operations, Audit and Security Technology)
Purdue ´ëÇп¡ ÀÖ´Â COAST ´Â º¸¾È ¿¬±¸ÀÇ Áß½ÉÁöÀÌ´Ù.
http://www.coast.cs.purdue.edu.


21.3 ÀÎÅÍ³Ý ÇØÅ· ±×·ì

ÀÌ ±×·ìµéÀº ¹ß°ßµÈ º¸¾ÈȦµé¿¡ ´ëÇØ »ó¼¼ Á¤º¸¸¦ ¸¸µé¾î ³½´Ù. ¾î¶² °æ¿ì¿¡´Â, ±× ȦÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ´Â ¿¹Á¦ ÄÚµåµéµµ ¹ßÇ¥µÈ´Ù. CERT ¿¡¼­ ÀÌµé ±×·ìÀÌ ¹ßÇ¥ÇÑ ±Ç°í¹®µéÀ» ¹ßÇ¥Çϴµ¥ 6°³¿ùÁ¤µµ °É¸± ?°¡ ¸¹À¸¹Ç·Î, º¸¾ÈÀÌ Àڽſ¡°Ô ³ôÀº Á߿伺À» ¶ì°í ÀÖ´Ù¸é À̵éÀÇ ¸ÞÀϸµ ¸®½ºÆ®¿¡ °¡ÀÔÇϵµ·Ï ÇÑ´Ù.

8lgm (8 Little Green Men / 8 Legged Groove Machine)
ÀÌ À̸ÞÀÏ ¸®½ºÆ®¿¡ °¡ÀÔÇÏ·Á¸é (Ãßõ), body="subscribe 8lgm" À¸·Î ÇÏ¿© majordomo@8lgm.org·Î À̸ÞÀÏÀ» º¸³½´Ù. http://www.8lgm.org µµ ÂüÁ¶ÇÑ´Ù. ´ÙÀ½À½ WWW »çÀÌÆ®¿¡ ¾ð±ÞµÈ »çÇ×ÀÌ´Ù:

[8LGM] Àº ½Ã½ºÅÛ °ü¸®ÀÚµéÀÌ ÀÚ½ÅÀÇ ½Ã½ºÅÛµéÀ» °íÄ¥ ¼ö ÀÖ°Ô Çϱâ À§ÇØ, ÀÌ Á¤º¸µéÀ» ¼±ÀÇ·Î Á¦°øÇÑ´Ù. ÇÏÁö¸¸ [8LGM] Àº ¾î¶² ¸ñÀûÀ¸·Îµç ÀÌ Á¤º¸ÀÇ »ç¿ëÀ» ÁöÁöÇÏÁö´Â ¾Ê´Â´Ù.

±Ç°í¹® ¸ñ·Ï (1997³â 2¿ù):

[8lgm]-Advisory-1.UNIX.rdist.23-Apr-1991 [8lgm]-Advisory-16.UNIX.sendmail-6-Dec-1994
[8lgm]-Advisory-2.UNIX.autoreply.12-Jul-1991 [8lgm]-Advisory-16.UNIX.sendmail-6-Dec-1994.UPDATE
[8lgm]-Advisory-3.UNIX.lpr.19-Aug-1991 [8lgm]-Advisory-17.UNIX.sendmailV5-2-May-1995
[8lgm]-Advisory-4.UNIX.gopher.12-Feb-1992 [8lgm]-Advisory-18.UNIX.SunOS-kernel.4-Dec-1994
[8lgm]-Advisory-5.UNIX.mail.24-Jan-1992 [8lgm]-Advisory-19.UNIX.SunOS-kernel.1-Jun-1994
[8lgm]-Advisory-5.UNIX.mail.24-Jan-1992.PATCH [8lgm]-Advisory-20.UNIX.SunOS-sendmailV5.1-Aug-1995
[8lgm]-Advisory-6.UNIX.mail2.2-May-1994 [8lgm]-Advisory-21.UNIX.SunOS-sendmailV5.22-Aug-1995
[8lgm]-Advisory-7.UNIX.passwd.11-May-1994 [8lgm]-Advisory-22.UNIX.syslog.2-Aug-1995
[8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX [8lgm]-Advisory-23.UNIX.SunOS-loadmodule.2-Jan-1995
[8lgm]-Advisory-8.UNIX.SunOS-kernel.11-Nov-1994 [8lgm]-Advisory-24.UNIX.CERT.Advisory.CA-95:11.20-9-1995
[8lgm]-Advisory-9.UNIX.urestore.10-Feb-1993 [8lgm]-Advisory-25.UNIX.sun4c.locore.01-09-1995
[8lgm]-Advisory-10.UNIX.SCO-at.10-Feb-1992 [8lgm]-Advisory-26.UNIX.rdist.20-3-1996
[8lgm]-Advisory-11.UNIX.sadc.07-Jan-1992  
8lgm]-Advisory-12.UNIX.suid_exec.27-Jul-1991  
[8lgm]-Advisory-13.UNIX.SCO-login.15-Apr-1994  
[8lgm]-Advisory-14.UNIX.SCO-prwarn.12-Nov-1994  
[8lgm]-Advisory-15.UNIX.mail3.28-Nov-1994  

ASR (Avalon Security Research)
ÃÖ±Ù ('95³â 11¿ù) ½º½º·Î¸¦ "Avalon Security Research" ¶ó°í ºÎ¸£´Â »õ·Î¿î ±×·ìÀÌ º¸¾È Ȧ°ú ÀÌ¿ë¹æ¹ý ¿¡ ´ëÇÑ ±â»çµéÀ» ÀÎÅͳݿ¡ ¿Ã¸®±â ½ÃÀÛÇß´Ù. ASR ÇØÅ· ±×·ìÀº ÀÚ±âµéÀÌ ¹ß°ßÇØ³½ º¸¾È ȦµéÀÇ Á¤º¸¸¦ ¹ßÇ¥ÇÑ´Ù. À̵éÀº ÀÚ±âµéÀ» ´ÙÀ½°ú °°ÀÌ ¼³¸íÇÑ´Ù:

ASR Àº ¾Æ¹«·¸°Ô³ª Á¶Á÷µÈ ºñ¿µ¸® ±×·ìÀÌ´Ù. ¿ì¸®´Â Áö±Ý±îÁö ¾à 4³â°£ ´Ü¼ÓÀûÀ¸·Î ÇÔ²² ÀÏÇØ¿Ô´Ù. ÃÖ±Ù ¿ì¸®´Â ¿ì¸®ÀÇ ¿¬±¸¸¦ ¹ßÇ¥Çϱâ·Î °áÁ¤Çß´Ù. ÀÌ °áÁ¤Àº ¼ö¸¹Àº ¿äÀο¡ ±Ù°ÅÇÑ °ÍÀ̾ú´Ù. ¿ì¼± ¿ì¸®´Â ÄÄÇ»ÅÍ º¸¾ÈÀÌ ÀÌÁ¦´Â ¾Æ¸¶ ¾î´À¶§º¸´Ùµµ °Å´ëÇÑ ÀÎÅÍ³Ý °øµ¿Ã¼ÀÇ °¡Àå Áß¿äÇÑ Çùµ¿À̶ó´Â °ÍÀ» ±ú´Þ¾Ò´Ù. ½ÇÁ¤ÀÌ ÀÌ·¯ÇϹǷΠ¿ì¸®´Â ¸ðµç Ä«µå°¡ Å×À̺í À§¿¡ ³õ¿©Á®¾ß ÇÑ´Ù°í »ý°¢ÇÑ´Ù. ¿ì¸®¿¡°Ô À̰ÍÀº ¿ÏÀüÇÑ °ø°³Àû ŵµ¿¡ ´ëÇÑ °­·ÂÇÑ ÁöÁö¸¦ ¶æÇÑ´Ù.... ±×¸®°í exploits¸¸ ¾Æ´Ï¶ó ´Ù¾çÇÑ Æ¯¼ºÀÇ º¸¾È °¨»ç µµ±¸µéÀ» ¹ßÇ¥ÇÒ °èȹµµ...

¸ÞÀϸµ¸®½ºÆ®¿¡ °¡ÀÔÇÏ·Á¸é, mcphee@cadvision.com ¿¡°Ô ¸ÞÀÏÀ» º¸³½´Ù.
¾Æ·¡´Â 96³â 2¿ù 12ÀÏ ¹ßÇ¥µÈ ¹ö±×¿Í Ȱ¿ë ½ºÅ©¸³Æ® ¸ñ·ÏÀÌ´Ù.


21.4 º¸¾È Ç¥ÁØ

ÀÌ ÀýÀº Á» ¿À·¡µÇ°í, ´ëºÎºÐÀÌ ¿Â¶óÀÎÀ¸·Î ±¸ÇÒ ¼ö Àֱ⠶§¹®¿¡ ´ú À¯¿ëÇÏ´Ù (óÀ½ ½ÃÀÛÇÒ ¶§´Â 1996³âµµ°¡ ¾Æ´Ï¾ú´Ù). °ü·Ã Ç¥ÁصéÀÇ ÃֽŠAcrobat »çº»Àº www.itsec.gov.uk À» Çѹø º¸±â ¹Ù¶õ´Ù.

21.4.1 ¹Ì±¹ Ç¥ÁØ: The Rainbow Books (·ÎÄà ¸ñ·Ï)

Rainbow books ´Â Ç¥Áö »ö±ò·Î À¯¸íÇÑ IT º¸¾È ¹®¼­ ½Ã¸®ÁîÀÌ´Ù. °¡Àå Àß ¾Ë·ÁÁø °ÍÀº TCSEC Áï Orange Book ÀÌ´Ù (´ÙÀ½ Àý ÂüÁ¶). ´ÙÀ½Àº ÀÌ Ã¥µé°ú »ö±ò, DoD ÂüÁ¶ ¹øÈ£ ¹× Á¦¸ñ¿¡ ´ëÇÑ ¸ñ·ÏÀÌ´Ù. ¿ÏÀüÇÑ ¸ñ·ÏÀ» ¸¸µé·Á°í ¾Ö½èÁö¸¸, ÇÑ µÎ ±ÇÀÇ Ã¥ÀÌ ºüÁ³À» ¼ö ÀÖ´Ù. ¸ñ·ÏÀÇ Ã³À½ ¼¼ Ã¥µéÀÌ Á¦ÀÏ ±¦Âú´Ù.

Orange Book DoD 5200.28-STD DoD TCSEC (Trusted Computer System Evaluation Criteria)
½Å·ÚµÇ´Â ÄÄÇ»ÅÍ ½Ã½ºÅÛ Æò°¡ ±âÁØ Green Book CSC-STD-002-85 Department of Defense Password Management Guideline
±¹¹æ¼º ÆÐ½º¿öµå °ü¸®Áöħ
Yellow Book CSC-STD-003-85 Computer Security Requirements -- Guidance for Applying TCSEC in Specific Environments
ÄÄÇ»ÅÍ º¸¾È ¿ä±¸»çÇ× -- ƯÁ¤ ȯ°æ¿¡¼­ TCSEC Àû¿ë¿¡ ´ëÇÑ °¡À̵å

Yellow Book CSC-STD-004-85 Technical Rationale Behind the above document.
À§ ¹®¼­µé¿¡ ´ëÇÑ ±â¼úÀû Á¤´ç¼º
Tan Book NCSC-TG-001 A Guide to Understanding Audit in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅ۵鿡¼­ °¨»çÀÇ ÀÌÇØ¿¡ ´ëÇÑ ¾È³»¼­
Bright Blue Book NCSC-TG-002 Trusted Product Evaluation - A Guide for Vendors
½Å·ÚµÇ´Â Á¦Ç° Æò°¡ - º¥´õ¸¦ À§ÇÑ ¾È³»¼­
Light Blue Book NCSC-TG-002-85 PC Security Considerations
PC º¸¾È °í·Á»çÇ×
Neon Orange Book NCSC-TG-003 Understanding Discretionary Access Control in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ ÀÓÀÇÀû Á¢±ÙÅëÁ¦¿¡ ´ëÇÑ ÀÌÇØ
Teal Green Book NCSC-TG-004 Glossary of Computer Security Terms
ÄÄÇ»ÅÍ º¸¾È ¿ë¾î ÇØ¼³
Red Book NCSC-TG-005 Trusted Network Interpretation of the TCSEC
TCSECÀÇ ½Å·ÚµÇ´Â ³×Æ®¿÷ ÇØ¼®
Orange Book NCSC-TG-006 Understanding Configuration Management in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ ±¸¼º°ü¸® ÀÌÇØ
Burgundy Book NCSC-TG-007 Understanding Design Documentation in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ ¼³°è¹®¼­È­¿¡ ´ëÇÑ ÀÌÇØ
Dark Lavender Book NCSC-TG-008 Understanding Trusted Distribution in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ ½Å·ÚµÇ´Â ºÐ»ê¿¡ ´ëÇÑ ÀÌÇØ
Venice Blue Book NCSC-TG-009 Computer Security Subsystem Interpretation of the TCSEC
TCSECÀÇ ÄÄÇ»ÅÍ º¸¾È ¼­ºê½Ã½ºÅÛ ÇØ¼®
Aqua Book NCSC-TG-010 Understanding Security Modelling in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ º¸¾È ¸ðµ¨¸µ ÀÌÇØ
Dark Red Book NCSC-TG-011 Trusted Network Interpretation Environments Guideline - Guidance for Applying the Trusted Network Interpretation
½Å·ÚµÇ´Â ³×Æ®¿÷ ÇØ¼® ȯ°æ Áöħ - ½Å·ÚµÇ´Â ³×Æ®¿÷ ÇØ¼®ÀÇ Àû¿ë¿¡ ´ëÇÑ ¾È³»¼­
Pink Book NCSC-TG-013 Rating Maintenance Phase -- Program Document
Æò°¡µî±Þ À¯Áö ´Ü°è -- ÇÁ·Î±×·¥ ¹®¼­È­
Purple Book NCSC-TG-014 Guidelines for Formal Verification Systems
°ø½Ä °ËÁõ ½Ã½ºÅÛÀ» À§ÇÑ Áöħ
Brown Book NCSC-TG-015 Understanding Trusted Facility Management
½Å·ÚµÇ´Â ¼³ºñ°ü¸® ÀÌÇØ
Yellow-Green Book NCSC-TG-016 Guidelines for Writing Trusted Facility Manuals
½Å·ÚµÇ´Â ¼³ºñ ¸Å´º¾ó ÀÛ¼ºÀ» À§ÇÑ Áöħ
Light Blue NCSC-TG-017 Understanding Identification and Authentication in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ÀÇ ½Äº°°ú ÀÎÁõ¿¡ ´ëÇÑ ÀÌÇØ
Light Blue Book NCSC-TG-018 A Guide to Understanding Object Reuse in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ °´Ã¼ Àç»ç¿ëÀÇ ÀÌÇØ¿¡ ´ëÇÑ °¡À̵å
Blue Book NCSC-TG-019 Trusted Product Evaluation Questionnaire
½Å·ÚµÇ´Â Á¦Ç° Æò°¡ ÁúÀǼ­
Gray Book NCSC-TG-020A Trusted Unix Working Group (TRUSIX) Rationale for Selecting
½Å·ÚµÇ´Â À¯´Ð½º ÀÛ¾÷ ±×·ìÀÇ ¼±Á¤±Ù°Å

Access Control List Features for the Unix System
À¯´Ð½º ½Ã½ºÅÛÀ» À§ÇÑ Á¢±ÙÅëÁ¦¸ñ·Ï ±â´É
Lavender Book NCSC-TG-021 Trusted Data Base Management System Interpretation of TCSEC
TCSECÀÇ ½Å·ÚµÇ´Â µ¥ÀÌŸº£À̽º °ü¸® ½Ã½ºÅÛ ÇØ¼®
Yellow Book NCSC-TG-022 A Guide to Understanding Trusted Recovery in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ ½Å·ÚµÇ´Â º¹±¸ÀÇ ÀÌÇØ¿¡ ´ëÇÑ °¡À̵å
Bright Orange Book NCSC-TG-023 Understanding Security Testing and Test Documentation in Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛ¿¡¼­ º¸¾È Å×½ºÆÃ°ú Å×½ºÆ® ¹®¼­ ÀÌÇØ
Purple Book NCSC-TG-024 (Volume 1/4) A Guide to Procurement of Trusted Systems: An Introduction to Procurement Initiators on Computer Security Requirements
½Å·ÚµÇ´Â ½Ã½ºÅÛ ±¸¸Å °¡À̵å: ±¸¸Å ¹ß±âÀεéÀ» À§ÇÑ ÄÄÇ»ÅÍ º¸¾È¿ä±¸»çÇ× ¼Ò°³
Purple Book NCSC-TG-024 (Volume 2/4) A Guide to Procurement of Trusted Systems: Language for RFP Specifications and Statements of Work - An Aid to Procurement initiators.
½Å·ÚµÇ´Â ½Ã½ºÅÛ ±¸¸Å °¡À̵å: RFP »ç¾ç°ú ÀÛ¾÷ º¸°í¼­¸¦ À§ÇÑ ¾ð¾î - ±¸¸Å ¹ß±âÀεéÀ» À§ÇÑ µµ¿ò
Purple Book NCSC-TG-024 (Volume 3/4) A Guide to Procurement of Trusted Systems: Computer Security Contract Data Requirements List and Data Item Description Tutorial
½Å·ÚµÇ´Â ½Ã½ºÅÛ ±¸¸Å °¡À̵å: ÄÄÇ»ÅÍ º¸¾È °è¾à µ¥ÀÌŸ ¿ä±¸»çÇ× ¸ñ·Ï ¹× µ¥ÀÌŸ Ç׸ñ ¼³¸í Áöµµ¼­
Purple Book NCSC-TG-024 (Volume 4/4) A Guide to Procurement of Trusted Systems: How to Evaluate a Bidder's Proposal Document - An Aid to Procurement Initiators and Contractors
½Å·ÚµÇ´Â ½Ã½ºÅÛ ±¸¸Å °¡À̵å: ÀÔÂûÀÚÀÇ Á¦¾È¼­ Æò°¡ ¹æ¹ý - ±¸¸Å ¹ß±âÀΰú °è¾àÀÚµéÀ» À§ÇÑ µµ¿ò
Green Book NCSC-TG-025 Understanding Data Remanence in Automated Information Systems
ÀÚµ¿È­µÈ Á¤º¸½Ã½ºÅÛ¿¡¼­ÀÇ ÀÜ·ù µ¥ÀÌŸ ÀÌÇØ
Hot Peach Book NCSC-TG-026 Writing the Security Features User's Guide for Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ º¸¾È ±â´É »ç¿ëÀÚ ¼³¸í¼­ ÀÛ¼ºÇϱâ
Turquoise Book NCSC-TG-027 A Guide to Understanding Information System Security Officer Responsibilities for Automated Information Systems
ÀÚµ¿È­µÈ Á¤º¸½Ã½ºÅÛ¿¡ ´ëÇÑ Á¤º¸½Ã½ºÅÛ º¸¾È Ã¥ÀÓÀÚÀÇ Àǹ«¿¡ ´ëÇÑ ÀÌÇØ¸¦ À§ÇÑ °¡À̵å
Violet Book NCSC-TG-028 Assessing Controlled Access Protection
ÅëÁ¦µÈ Á¢±Ù º¸È£ Æò°¡Çϱâ
Blue Book NCSC-TG-029 Introduction to Certification and Accreditation
º¸Áõ°ú Àΰ¡/½ÅÀÓÀå¿¡ ´ëÇÑ ¼Ò°³
Light Pink Book NCSC-TG-030 A Guide to Understanding Covert Channel Analysis of Trusted Systems
½Å·ÚµÇ´Â ½Ã½ºÅÛÀÇ ºñ¹Ðä³Î ºÐ¼® ÀÌÇØ¸¦ À§ÇÑ °¡À̵å

21.4.2 The TCSEC "Orange Book" (·ÎÄà »çº», ¶Ç´Â UK ITSEC) ÂüÁ¶

21.4.2.1 µµÀÔ

1983³â, ¹Ì ±¹¹æ¼º (DoD)Àº (»ç½ÇÀº ±¹¸³ ÄÄÇ»ÅÍ º¸¾È ¼¾ÅÍ National Computer Security Centre[1]), TCSEC Áï ¿À·»ÁöºÏÀÇ Ã¹¹øÂ° ¹öÀüÀ» ¹ßÇ¥ÇÏ¿´´Ù (¿À·»Áö»ö Ç¥Áö¸¦ µû¶ó¼­ ¸í¸íµÈ). 1985 ³â ´õ ÇÑÃþ °»½ÅµÇ¾î Ç¥ÁØÀ¸·Î ¹ßÇàµÇ¾ú´Ù (DOD5200.28-STD). ¿À·»ÁöºÏÀº ÄÄÇ»ÅÍ ½Ã½ºÅÛµéÀÇ º¸¾ÈÀ» Æò°¡Çϱâ À§ÇÑ ÁöħÀ» ±ÔÁ¤ÇÑ´Ù. ±âŸ ´Ù¸¥ ¸¹Àº °ü·Ã Ç¥Áص鵵 ÀÛ¼ºµÇ¾î, "·¹Àκ¸¿ì ½Ã¸®Áî" ·Î ¾Ë·ÁÁ® ÀÖ´Ù.

21.4.2.2 Contacts

Infosec Awareness Office [¹®¼­ ÁÖ¹®]
+1 (410) 766-8729

Government Printing Office [Á¤º¸º¸È£ ½Ã½ºÅÛ & º¸¾È īŻ·Î±× ÁÖ¹®]
+1 (202) 512-1800

Evaluations Office
+1 (410) 859-4458

´ÙÀ½Àº C1°ú C2¿¡ °üÇØ ¿À·»ÁöºÏ¿¡¼­ Á÷Á¢ ¹ßÃéÇØ¿Â °ÍÀÌ´Ù:

21.4.2.3 2.0 DIVISION C: DISCRETIONARY PROTECTION

ÀÌ ºÎ¹®¿¡ ÀÖ´Â µî±ÞµéÀº ÀÓÀÇÀû (¾Ë¾Æ¾ßÇÒ ÇÊ¿ä,need-to-know) º¸È£¸¦ Á¦°øÇϸç, °¨»ç ´É·ÂÀ» Æ÷ÇÔÇϰí ÀÖ¾î, ÁÖü ¹× À̵éÀÌ ½ÃÀÛÇÑ Á¶À۵鿡 ´ëÇÑ Ã¥ÀÓÃßÀû¼ºÀ» Á¦°øÇÑ´Ù.

µî±Þ (C1): ÀÓÀÇÀû º¸¾È º¸È£ DISCRETIONARY SECURITY PROTECTION
µî±Þ (C1) ½Ã½ºÅÛÀÇ Trusted Computing Base (TCB) ´Â »ç¿ëÀÚ¿Í µ¥ÀÌŸÀÇ ºÐ¸®¸¦ Á¦°øÇÔÀ¸·Î½á ¸í¸ñ»óÀ¸·Î ÀÓÀÇÀû º¸¾È ¿ä±¸»çÇ×À» ¸¸Á·½ÃŲ´Ù. À̰ÍÀº °³Àκ°·Î Á¢±Ù Á¦ÇÑÀ» µÑ ¼ö ÀÖ´Â ¾î¶² ÇüÅÂÀÇ ¹ÏÀ»¸¸ÇÑ ÅëÁ¦¸¦ Æ÷ÇÔÇÑ´Ù, Áï Ç¥¸é»óÀ¸·Î »ç¿ëÀÚµéÀÌ ÇÁ·ÎÁ§Æ®³ª °³ÀÎ Á¤º¸¸¦ º¸È£Çϰí, ´Ù¸¥ »ç¿ëÀÚµéÀÌ ¿ì¿¬È÷ Àڱ⠵¥ÀÌŸ¸¦ Àаųª ÆÄ±«ÇÏÁö ¸øÇϵµ·Ï ÇÒ ¼ö ÀÖ°Ô Çϴµ¥ Àû´çÇÏ´Ù. µî±Þ (C1) ȯ°æÀº µ¿ÀÏÇÑ ¹Î°¨¼º ¼öÁØÀÇ µ¥ÀÌŸ¸¦ ó¸®ÇÏ´Â Çù·Â »ç¿ëÀÚµé·Î ¿¹»óµÈ´Ù. ´ÙÀ½Àº µî±Þ (C1)¿¡ ÇÒ´çµÈ ½Ã½ºÅ۵鿡 ´ëÇÑ ÃÖ¼Ò ¿ä±¸»çÇ×ÀÌ´Ù:

2.1.1 º¸¾È Á¤Ã¥
2.1.1.1 ÀÓÀÇÀû Á¢±ÙÅëÁ¦: TCB ´Â ADP ½Ã½ºÅÛÀÇ ÁöÁ¤µÈ »ç¿ëÀÚµé°ú ÁöÁ¤µÈ °´Ã¼µé(Áï ÆÄÀÏ ¹× ÇÁ·Î±×·¥µé) °£ÀÇ Á¢±ÙÀ» Á¤ÀÇÇϰí ÅëÁ¦ÇØ¾ß ÇÑ´Ù. Àû¿ë ¸ÞÄ«´ÏÁòÀº »ç¿ëÀÚµéÀÌ, ±×·¯ÇÑ °´Ã¼µéÀÇ °øÀ¯¸¦ ÁöÁ¤µÈ °³ÀÎÀ̳ª Á¤ÀÇµÈ ±×·ì ¶Ç´Â µÑ´Ù¿¡ µû¶ó ±ÔÁ¤Çϰí ÅëÁ¦ÇÒ ¼ö ÀÖµµ·Ï ÇØÁÖ¾î¾ß ÇÑ´Ù.
2.1.2 Ã¥ÀÓÃßÀû¼º Accountability
2.1.2.1 ½Äº°°ú ÀÎÁõ: TCB´Â »ç¿ëÀÚ¿¡°Ô, TCBÀÇ ÁßÀ縦 ¹Þµµ·Ï µÇ¾î ÀÖ´Â ´Ù¸¥ ¾î¶² Á¶ÀÛÀÇ ¼öÇàÀ» ½ÃÀÛÇϱâ Àü¿¡, »ç¿ëÀÚ¸¦ TCB¿¡°Ô ½Äº°½Ãų °ÍÀ» ¿ä±¸ÇØ¾ß ÇÑ´Ù. ´õ ³ª¾Æ°¡, TCB´Â º¸È£µÇ´Â ¸ÞÄ«´ÏÁòÀ» »ç¿ëÇÏ¿© (e.g., ÆÐ½º¿öµå) »ç¿ëÀÚÀÇ ½Å¿øÀ» ÀÎÁõÇØ¾ß ÇÑ´Ù. TCB´Â ÀÎÁõ µ¥ÀÌŸ¸¦ º¸È£ÇÏ¿© ¾î¶°ÇÑ ºñÀΰ¡ »ç¿ëÀÚ¿¡ ÀÇÇØ¼­µµ Á¢±ÙµÇÁö ¾Êµµ·Ï ÇØ¾ß ÇÑ´Ù.
2.1.3 º¸Áõ
2.1.3.1 ±â´É»óÀÇ º¸Áõ
2.1.3.1.1 ½Ã½ºÅÛ ±¸Á¶: TCB´Â ¿ÜºÎÀÇ °£¼·À̳ª Âü°ß(e.g., Äڵ峪 µ¥ÀÌŸ±¸Á¶ º¯°æ¿¡ ÀÇÇÑ) À¸·ÎºÎÅÍ TCB¸¦ º¸È£ÇÏ´Â, ÀÚ½ÅÀ» À§ÇÑ µµ¸ÞÀÎÀ» À¯ÁöÇØ¾ß ÇÑ´Ù. TCB¿¡ ÀÇÇØ ÅëÁ¦µÇ´Â ÀÚ¿øµéÀº ADP ½Ã½ºÅÛ³»ÀÇ ÁÖü ¹× °´Ã¼µéÀÇ Á¤ÀÇµÈ ¼­ºê¼ÂÀÏ ¼ö ÀÖ´Ù.
2.1.3.1.2 ½Ã½ºÅÛ ¹«°á¼º: TCBÀÇ ÇöÀå Çϵå¿þ¾î ¹× Æß¿þ¾î ¿ä¼ÒµéÀÇ ¿Ã¹Ù¸¥ µ¿ÀÛÀ» ÁÖ±âÀûÀ¸·Î È®ÁõÇÏ´Â µ¥ ¾µ ¼ö ÀÖ´Â Çϵå¿þ¾î ¹×/¶Ç´Â ¼ÒÇÁÆ®¿þ¾î ±â´ÉµéÀÌ Á¦°øµÇ¾î¾ß ÇÑ´Ù.
2.1.3.2 ¶óÀÌÇÁ »çÀÌŬ º¸Áõ
2.1.3.2.1º¸¾È Å×½ºÆÃ: ADP ½Ã½ºÅÛÀÇ º¸¾È ¸ÞÄ«´ÏÁòÀº Å×½ºÆ®µÇ¾î ½Ã½ºÅÛ ¹®¼­¿¡¼­ ÁÖÀåÇÏ´Â ´ë·Î µ¿ÀÛÇÏ´Â °ÍÀÌ È®ÀεǾî¾ß ÇÑ´Ù. Å×½ºÆÃÀº ºñÀΰ¡ »ç¿ëÀÚ°¡ TCBÀÇ º¸¾È º¸È£ ¸ÞÄ«´ÏÁòÀ» ¿ìȸÇϰųª À̱æ¼ö ÀÖ´Â ¸í¹éÇÑ ¹æ¹ýÀÌ ¾ø´Ù´Â °ÍÀ» È®½ÇÈ÷ Çϵµ·Ï ¼öÇàµÇ¾î¾ß ÇÑ´Ù (º¸¾È Å×½ºÆÃ Áöħ ÂüÁ¶).
2.1.4 ¹®¼­
2.1.4.1 º¸¾È ±â´É »ç¿ëÀÚ °¡À̵å: »ç¿ëÀÚ ¹®¼­ Áß ÇϳªÀÇ ¿ä¾à, Àå, ¶Ç´Â ¸Å´º¾óÀº TCB ¿¡¼­ Á¦°øÇÏ´Â º¸È£ ¸ÞÄ«´ÏÁòµé, À̵éÀÇ »ç¿ë¿¡ ´ëÇÑ Áöħ, ±×¸®°í À̵éÀÌ ¼­·Î ¾î¶»°Ô »óÈ£ÀÛ¿ëÇÏ´ÂÁö¸¦ ¼³¸íÇØ¾ß ÇÑ´Ù.
2.1.4.2 ½Å·ÚµÇ´Â ¼³ºñ ¸Å´º¾ó: ADP ½Ã½ºÅÛ °ü¸®ÀÚ¸¦ À§ÇÑ ¸Å´º¾óÀº ¾ÈÀüÇÑ ¼³ºñ¸¦ ¿î¿µÇÒ ¶§ ÅëÁ¦µÇ¾î¾ß ÇÒ ±â´É ¹× Ư±Ç¿¡ ´ëÇÑ ÁÖÀÇ»çÇ×À» Ç¥½ÃÇØ¾ß ÇÑ´Ù.
2.1.4.3 Å×½ºÆ® ¹®¼­: ½Ã½ºÅÛ °³¹ßÀÚ´Â º¸¾È ¸ÞÄ«´ÏÁòÀÌ ¾î¶»°Ô Å×½ºÆ®µÇ¾ú´ÂÁö¿Í º¸¾È ¸ÞÄ«´ÏÁòÀÇ ±â´ÉÀû Å×½ºÆÃ °á°ú¸¦ º¸¿©ÁÖ´Â Å×½ºÆ® °èȹ°ú Å×½ºÆ® ÀýÂ÷¸¦ ¼­¼úÇÏ´Â ¹®¼­¸¦ Æò°¡ÀÚ¿¡°Ô Á¦°øÇØ¾ß ÇÑ´Ù.
2.1.4.4 ¼³°è¹®¼­: Á¦ÀÛÀÚÀÇ º¸È£¿¡ ´ëÇÑ ¹æÄ§(öÇÐ)°ú ÀÌ ¹æÄ§ÀÌ TCB·Î ¾î¶»°Ô º¯È¯µÇ¾ú´ÂÁö¿¡ ´ëÇØ ¼³¸íÇÏ´Â ¹®¼­°¡ ÀÖ¾î¾ß ÇÑ´Ù. TCB°¡ º°°³ÀÇ ¸ðµâµé·Î ÀÌ·ç¾îÁ® ÀÖ´Ù¸é, ÀÌ ¸ðµâµé°£ÀÇ ÀÎÅÍÆäÀ̽º°¡ ¼­¼úµÇ¾î¾ß ÇÑ´Ù.

CLASS (C2):CONTROLLED ACCESS PROTECTION
ÀÌ µî±Þ¿¡ ÀÖ´Â ½Ã½ºÅÛµéÀº, ·Î±×ÀÎ ÀýÂ÷, º¸¾È°ü·Ã À̺¥Æ® °¨»ç, ±×¸®°í ÀÚ¿ø °í¸³À» ÅëÇØ »ç¿ëÀÚµéÀÌ °³º°ÀûÀ¸·Î ÀÚ±â ÇàÀ§¿¡ ´ëÇØ Ã¥ÀÓÀÌ ÀÖ°Ô ÇÏ¿©, (C1) ½Ã½ºÅ۵麸´Ù ¼¼¹ÐÇÑ ÀÓÀÇÀû Á¢±Ù ÅëÁ¦¸¦ Á¦°øÇÑ´Ù. ´ÙÀ½Àº µî±Þ (C2)¸¦ ºÎ¿©¹ÞÀº ½Ã½ºÅ۵鿡 ´ëÇÑ ÃÖ¼Ò ¿ä±¸»çÇ×ÀÌ´Ù:

2.2.1 º¸¾È Á¤Ã¥
2.2.1.1 ÀÓÀÇÀû Á¢±ÙÅëÁ¦:TCB ´Â ADP ½Ã½ºÅÛÀÇ ÁöÁ¤µÈ »ç¿ëÀÚµé°ú ÁöÁ¤µÈ °´Ã¼µé(Áï ÆÄÀÏ ¹× ÇÁ·Î±×·¥µé) °£ÀÇ Á¢±ÙÀ» Á¤ÀÇÇϰí ÅëÁ¦ÇØ¾ß ÇÑ´Ù. Àû¿ë ¸ÞÄ«´ÏÁòÀº »ç¿ëÀÚµéÀÌ, ±×·¯ÇÑ °´Ã¼µéÀÇ °øÀ¯¸¦ ÁöÁ¤µÈ °³ÀÎÀ̳ª Á¤ÀÇµÈ ±×·ì ¶Ç´Â µÑ´Ù¿¡ µû¶ó ±ÔÁ¤Çϰí ÅëÁ¦ÇÒ ¼ö ÀÖµµ·Ï ÇØÁÖ¾î¾ß Çϰí, Á¢±Ù±ÇÇÑÀÇ Àü´Þ, º¸±ÞÀ» Á¦ÇÑÇÒ ¼ö ÀÖ´Â ÅëÁ¦¸¦ Á¦°øÇØ¾ß ÇÑ´Ù. ÀÓÀÇÀû Á¢±Ù ÅëÁ¦ ¸ÞÄ«´ÏÁòÀº, ¸í¹éÇÑ »ç¿ëÀÚ ÇàÀ§¿¡ ÀÇÇØ¼­³ª µð?Æ®¿¡ ÀÇÇØ, °´Ã¼¸¦ ºñÀΰ¡ Á¢±ÙÀ¸·ÎºÎÅÍ º¸È£ÇØ¾ß ÇÑ´Ù. ÀÌ·± Á¢±ÙÅëÁ¦µéÀº ´ÜÀÏ »ç¿ëÀÚ ´ÜÀ§¿¡ ´ëÇØ¼­±îÁö Á¢±Ù¿¡ Æ÷ÇÔ½ÃŰ°Å³ª ¹èÁ¦½Ãų ¼ö ÀÖ¾î¾ß ÇÑ´Ù. ¾ÆÁ÷ Á¢±ÙÇã°¡¸¦ °¡Áö°í ÀÖÁö ¾ÊÀº »ç¿ëÀÚ¿¡ ´ëÇÑ °´Ã¼ Á¢±Ù Çã°¡´Â Àΰ¡µÈ »ç¿ëÀÚ¿¡ ÀÇÇØ¼­¸¸ ºÎ¿©µÇ¾î¾ß ÇÑ´Ù.
2.2.1.2 °´Ã¼ Àç»ç¿ë: ÀúÀå °´Ã¼¿¡ Æ÷ÇÔµÈ Á¤º¸¿¡ ´ëÇÑ ¸ðµç Àΰ¡´Â TCBÀÇ ºñ»ç¿ë ÀúÀ尴ü Ç®·ÎºÎÅÍ ÁÖü¿¡°Ô Ãʱ⠺ο©, ÇÒ´ç ¶Ç´Â ÀçÇÒ´çµÇ±â Àü¿¡ öȸµÇ¾î¾ß ÇÑ´Ù. ÀÌÀü ÁÖüÀÇ Á¶ÀÛ¿¡ ÀÇÇØ ¸¸µé¾îÁø, ¾ÏȣȭµÈ Á¤º¸¸¦ Æ÷ÇÔÇÑ ¾î¶°ÇÑ Á¤º¸µµ, ½Ã½ºÅÛÀ¸·Î ´Ù½Ã ÇØÁ¦µÇ¾ú´ø °´Ã¼·ÎÀÇ Á¢±ÙÀ» ¾ò´Â ¾î¶² ÁÖü¿¡ ÀÇÇØ¼­µµ ÀÌ¿ëµÉ ¼ö À־´Â ¾ÈµÈ´Ù.
2.2.2 Ã¥ÀÓÃßÀû¼º
2.2.2.1 ½Äº°°ú ÀÎÁõ: TCB´Â »ç¿ëÀÚ¿¡°Ô, TCBÀÇ ÁßÀ縦 ¹Þµµ·Ï µÇ¾î ÀÖ´Â ´Ù¸¥ ¾î¶² Á¶ÀÛÀÇ ¼öÇàÀ» ½ÃÀÛÇϱâ Àü¿¡, »ç¿ëÀÚ¸¦ TCB¿¡°Ô ½Äº°½Ãų °ÍÀ» ¿ä±¸ÇØ¾ß ÇÑ´Ù. ´õ ³ª¾Æ°¡, TCB´Â º¸È£µÇ´Â ¸ÞÄ«´ÏÁòÀ» »ç¿ëÇÏ¿© (e.g., ÆÐ½º¿öµå) »ç¿ëÀÚÀÇ ½Å¿øÀ» ÀÎÁõÇØ¾ß ÇÑ´Ù. TCB´Â ÀÎÁõ µ¥ÀÌŸ¸¦ º¸È£ÇÏ¿© ¾î¶°ÇÑ ºñÀΰ¡ »ç¿ëÀÚ¿¡ ÀÇÇØ¼­µµ Á¢±ÙµÇÁö ¾Êµµ·Ï ÇØ¾ß ÇÑ´Ù. TCB´Â °¢ °³º° ADP ½Ã½ºÅÛ »ç¿ëÀÚ¸¦ À¯ÀÏÇÏ°Ô ½Äº°ÇÒ ¼ö ÀÖ´Â ´É·ÂÀ» Á¦°øÇÔÀ¸·Î½á °³Àκ° Ã¥ÀÓÃßÀû¼ºÀ» Àû¿ëÇØ¾ß ÇÑ´Ù. TCB´Â ¶ÇÇÑ ÀÌ ½Å¿ø°ú ±× °³Àο¡ ÀÇÇÑ ¸ðµç °¨»ç°¡´ÉÇÑ Á¶ÀÛµéÀ» ¿¬°ü½Ãų ¼ö ÀÖ´Â ´É·ÂÀ» Á¦°øÇØ¾ß ÇÑ´Ù.
2.2.2.2 °¨»ç: TCB´Â ÀڱⰡ º¸È£ÇÏ´Â °´Ã¼µé¿¡ ´ëÇÑ Á¢±ÙÀÇ °¨»çÁõÀûÀ» »ý¼º, À¯Áö, ±×¸®°í º¯Á¶³ª ºñÀΰ¡Á¢±Ù ¶Ç´Â ÆÄ±«·ÎºÎÅÍ º¸È£ÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù. °¨»ç µ¥ÀÌŸ´Â ÀÌ¿¡ ´ëÇÑ Àбâ Á¢±ÙÀÌ °¨»ç µ¥ÀÌŸ¿¡ ´ëÇÑ Àΰ¡¸¦ ¹ÞÀº »ç¶÷µé·Î¸¸ Á¦ÇÑµÉ ¼ö ÀÖµµ·Ï TCB¿¡ ÀÇÇØ º¸È£µÇ¾î¾ß ÇÑ´Ù.
TCB ´Â ´ÙÀ½ À¯ÇüÀÇ À̺¥Æ®µéÀ» ±â·ÏÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù: ½Äº° ¹× ÀÎÁõ ¸ÞÄ«´ÏÁòÀÇ »ç¿ë, »ç¿ëÀÚÀÇ ÁÖ¼Ò °ø°£¿¡ °´Ã¼¸¦ µµÀÔ (e.g., ÆÄÀÏ¿­±â, initiation), °´Ã¼ÀÇ »èÁ¦, ±×¸®°í ÄÄÇ»ÅÍ ¿î¿µÀÚ¿Í ½Ã½ºÅÛ °ü¸®ÀÚ ¹×/¶Ç´Â ½Ã½ºÅÛ º¸¾È Ã¥ÀÓÀڵ鿡 ÀÇÇÑ Á¶ÀÛ(ÇàÀ§), ±×¸®°í ±âŸ º¸¾È °ü·Ã À̺¥Æ®µé.
±â·ÏµÇ´Â °¢ À̺¥Æ®¿¡ ´ëÇØ, °¨»ç ±â·ÏÀº ´ÙÀ½À» ½Äº°ÇØ¾ß ÇÑ´Ù: À̺¥Æ®ÀÇ ³¯Â¥½Ã°£, »ç¿ëÀÚ, À̺¥Æ® À¯Çü, ±×¸®°í À̺¥Æ®ÀÇ ¼º°ø/½ÇÆÐ¿©ºÎ.
½Äº°/ÀÎÁõ À̺¥Æ®µé¿¡ ´ëÇØ¼­´Â ¿äûÀÇ ¹ß¿øÁö (e.g., ´Ü¸» ID)°¡ °¨»ç ±â·Ï¿¡ Æ÷ÇԵǾî¾ß ÇÑ´Ù. »ç¿ëÀÚÀÇ ÁÖ¼Ò °ø°£¿¡ °´Ã¼¸¦ µµÀÔÇÏ´Â À̺¥Æ® ¹× °´Ã¼ »èÁ¦ À̺¥Æ®¿¡ ´ëÇØ °¨»ç±â·ÏÀº °´Ã¼À̸§À» Æ÷ÇÔÇØ¾ß ÇÑ´Ù. ADP ½Ã½ºÅÛ °ü¸®ÀÚ´Â °³º° ½Å¿ø¿¡ ±Ù°ÅÇÏ¿© ¾î´À »ç¿ëÀÚµç Çϳª ¶Ç´Â ±× ÀÌ»óÀÇ »ç¿ëÀÚ Á¶ÀÛ(ÇàÀ§)À» ¼±ÅÃÀûÀ¸·Î °¨»çÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù.
2.2.3 º¸Áõ
2.2.3.1 ±â´É»óÀÇ º¸Áõ
2.2.3.1.1 ½Ã½ºÅÛ ±¸Á¶: TCB´Â ¿ÜºÎÀÇ °£¼·À̳ª Âü°ß(e.g., Äڵ峪 µ¥ÀÌŸ±¸Á¶ º¯°æ¿¡ ÀÇÇÑ) À¸·ÎºÎÅÍ TCB¸¦ º¸È£ÇÏ´Â, ÀÚ½ÅÀ» À§ÇÑ µµ¸ÞÀÎÀ» À¯ÁöÇØ¾ß ÇÑ´Ù. TCB¿¡ ÀÇÇØ ÅëÁ¦µÇ´Â ÀÚ¿øµéÀº ADP ½Ã½ºÅÛ³»ÀÇ ÁÖü ¹× °´Ã¼µéÀÇ Á¤ÀÇµÈ ¼­ºê¼ÂÀÏ ¼ö ÀÖ´Ù. TCB´Â º¸È£µÇ¾î¾ß ÇÒ ÀÚ¿øµéÀ» °Ý¸®½ÃÄÑ À̵éÀÌ Á¢±ÙÅëÁ¦¿Í °¨»ç ¿ä±¸»çÇ׿¡ Á¾¼ÓµÇµµ·Ï ÇØ¾ß ÇÑ´Ù.
2.2.3.1.2 ½Ã½ºÅÛ ¹«°á¼º: TCBÀÇ ÇöÀå Çϵå¿þ¾î ¹× Æß¿þ¾î ¿ä¼ÒµéÀÇ ¿Ã¹Ù¸¥ µ¿ÀÛÀ» ÁÖ±âÀûÀ¸·Î È®ÁõÇÏ´Â µ¥ ¾µ ¼ö ÀÖ´Â Çϵå¿þ¾î ¹×/¶Ç´Â ¼ÒÇÁÆ®¿þ¾î ±â´ÉµéÀÌ Á¦°øµÇ¾î¾ß ÇÑ´Ù.
2.2.3.2 ¶óÀÌÇÁ »çÀÌŬ º¸Áõ
2.2.3.2.1 º¸¾È Å×½ºÆÃ: ADP ½Ã½ºÅÛÀÇ º¸¾È ¸ÞÄ«´ÏÁòÀº Å×½ºÆ®µÇ¾î ½Ã½ºÅÛ ¹®¼­¿¡¼­ ÁÖÀåÇÏ´Â ´ë·Î µ¿ÀÛÇÏ´Â °ÍÀÌ È®ÀεǾî¾ß ÇÑ´Ù. Å×½ºÆÃÀº ºñÀΰ¡ »ç¿ëÀÚ°¡ TCBÀÇ º¸¾È º¸È£ ¸ÞÄ«´ÏÁòÀ» ¿ìȸÇϰųª À̱æ¼ö ÀÖ´Â ¸í¹éÇÑ ¹æ¹ýÀÌ ¾ø´Ù´Â °ÍÀ» È®½ÇÈ÷ Çϵµ·Ï ¼öÇàµÇ¾î¾ß ÇÑ´Ù. Å×½ºÆÃÀº ¶ÇÇÑ ÀÚ¿ø °Ý¸®¸¦ À§¹ÝÇϵµ·Ï ÇÒ ¼ö Àְųª, °¨»ç ¶Ç´Â ÀÎÁõ µ¥ÀÌŸ¿¡ ´ëÇÑ ºñÀΰ¡ Á¢±ÙÀ» Çã¿ëÇÒ ¼ö ÀÖ´Â ¸í¹éÇÑ °áÇÔÀ» ã´Â Àϵµ Æ÷ÇÔÇØ¾ß ÇÑ´Ù (º¸¾È Å×½ºÆÃ Áöħ ÂüÁ¶).
2.2.4 ¹®¼­
2.2.4.1 º¸¾È ±â´É »ç¿ëÀÚ °¡À̵å: »ç¿ëÀÚ ¹®¼­ Áß ÇϳªÀÇ ¿ä¾à, Àå, ¶Ç´Â ¸Å´º¾óÀº TCB ¿¡¼­ Á¦°øÇÏ´Â º¸È£ ¸ÞÄ«´ÏÁòµé, À̵éÀÇ »ç¿ë¿¡ ´ëÇÑ Áöħ, ±×¸®°í À̵éÀÌ ¼­·Î ¾î¶»°Ô »óÈ£ÀÛ¿ëÇÏ´ÂÁö¸¦ ¼³¸íÇØ¾ß ÇÑ´Ù.
2.2.4.2 ½Å·ÚµÇ´Â ¼³ºñ ¸Å´º¾ó: ADP ½Ã½ºÅÛ °ü¸®ÀÚ¸¦ À§ÇÑ ¸Å´º¾óÀº ¾ÈÀüÇÑ ¼³ºñ¸¦ ¿î¿µÇÒ ¶§ ÅëÁ¦µÇ¾î¾ß ÇÒ ±â´É ¹× Ư±Ç¿¡ ´ëÇÑ ÁÖÀÇ»çÇ×À» Ç¥½ÃÇØ¾ß ÇÑ´Ù. °¨»ç ÆÄÀÏÀ» °Ë»çÇϰí À¯ÁöÇϱâ À§ÇÑ ÀýÂ÷¿Í °¨»ç À̺¥Æ® °¢°¢ÀÇ À¯Çü¿¡ ´ëÇÑ »ó¼¼ °¨»ç ·¹ÄÚµå ±¸Á¶°¡ ÁÖ¾îÁ®¾ß ÇÑ´Ù.
2.2.4.3 Å×½ºÆ® ¹®¼­: ½Ã½ºÅÛ °³¹ßÀÚ´Â º¸¾È ¸ÞÄ«´ÏÁòÀÌ ¾î¶»°Ô Å×½ºÆ®µÇ¾ú´ÂÁö¿Í º¸¾È ¸ÞÄ«´ÏÁòÀÇ ±â´ÉÀû Å×½ºÆÃ °á°ú¸¦ º¸¿©ÁÖ´Â Å×½ºÆ® °èȹ°ú Å×½ºÆ® ÀýÂ÷¸¦ ¼­¼úÇÏ´Â ¹®¼­¸¦ Æò°¡ÀÚ¿¡°Ô Á¦°øÇØ¾ß ÇÑ´Ù.
2.2.4.4 ¼³°è¹®¼­: Á¦ÀÛÀÚÀÇ º¸È£¿¡ ´ëÇÑ ¹æÄ§(öÇÐ)°ú ÀÌ ¹æÄ§ÀÌ TCB·Î ¾î¶»°Ô º¯È¯µÇ¾ú´ÂÁö¿¡ ´ëÇØ ¼³¸íÇÏ´Â ¹®¼­°¡ ÀÖ¾î¾ß ÇÑ´Ù. TCB°¡ º°°³ÀÇ ¸ðµâµé·Î ÀÌ·ç¾îÁ® ÀÖ´Ù¸é, ÀÌ ¸ðµâµé°£ÀÇ ÀÎÅÍÆäÀ̽º°¡ ¼­¼úµÇ¾î¾ß ÇÑ´Ù.

21.4.3 The ITSEC - "European Orange Book"(·ÎÄà »çº», ¶Ç´Â UK ITSEC ÂüÁ¶)

21.4.3.1 °³·Ð

ITSEC (Information Technology Security Evaluation Criteria) Àº ÇÁ¶û½º, µ¶ÀÏ, ³×´ú¶õµå, ¿µ±¹¿¡¼­ ¸¸µç Á¶È­µÈ Æò°¡±âÁØÀÇ ÁýÇÕÀÌ´Ù. À̰ÍÀº 1995³â 4¿ù EU (À¯·´ °øµ¿Ã¼) ¿¡ÀÇÇØ ¸ðµç ȸ¿ø±¹µéÀ» À§ÇÑ Ç¥ÁØÀ¸·Î äÅõǾú´Ù. ITSEC¿¡ µû¶ó Æò°¡µÈ »ó¿ë ¿î¿µÃ¼Á¦¿¡ ´ëÇÑ ¿ä¾àÀ» "¿î¿µÃ¼Á¦ °³·Ð" Àå¿¡¼­ ã¾Æº¼ ¼ö ÀÖ´Ù. ITSEM [itsem] Àº ITSECÀ» »ç¿ëÇÏ´Â µ¥ ´ëÇÑ ¾È³»¼­ÀÌ´Ù - ´ÙÀ½ Àý¿¡¼­ ¼­¼úÇÑ´Ù.

Á¦Ç°À̳ª ½Ã½ºÅÛ (¿©±â¼­ºÎÅÍ´Â TOE ¶ó°í ÇÑ´Ù : target of Evaluation Æò°¡´ë»ó) ÀÌ ITSEC¿¡ µû¶ó Æò°¡µÉ ¶§:

ITSEC Àº TCSEC µî±Þ¿¡ ´ëÀÀµÇ´Â ±â´É¼º µî±Þ Ç¥º» F-C1, C2, B1, B2, B3 ¸¦ Á¤ÀÇÇϰí, ³×Æ®¿öÅ·À» Æ÷ÇÔÇϰí ÀÖ¾î °ü½ÉÀ» ²ô´Â IN, AV, DI, DC ¹× DX ÀÇ »õ·Î¿î µî±ÞÀ» Á¤ÀÇÇÑ´Ù. ÀÌ µî±ÞµéÀº Ç¥ÁØ º¸¾È ±â´ÉÀÇ ÁýÇÕÀ» ¼­¼úÇÑ´Ù. ITSEC °ú TCSECÀº ¾Æ·¡¿Í °°ÀÌ ´ëÀÀµÈ´Ù:

ITSEC TCSEC
E1, F-C1 == C1
E2, F-C2 == C2
E3, F-B1 == B1
E4, F-B2 == B2
E5, F-B3 == B3
E6, F-B3 == A1

ITSEC Àº TCSEC ¿¡ Ãß°¡ÇÏ¿© ´ÙÀ½ÀÇ ±â´É¼º µî±ÞµéÀ» Á¤ÀÇÇÑ´Ù:

IN ÀÌ µî±ÞÀº µ¥ÀÌŸ & ÇÁ·Î±×·¥¿¡ ´ëÇÑ ³ôÀº ¹«°á¼ºÀÌ ¿ä±¸µÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
AV ÀÌ µî±ÞÀº ³ôÀº °¡¿ë¼º ±â´ÉÀ» °¡Áö´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
DI ÀÌ µî±ÞÀº µ¥ÀÌŸ Àü¼Û¿¡ ´ëÇØ ³ôÀº ¹«°á¼ºÀÌ ¿ä±¸µÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
DC ÀÌ µî±ÞÀº µ¥ÀÌŸ Àü¼Û¿¡ ´ëÇØ ³ôÀº ±â¹Ð¼ºÀÌ ¿ä±¸µÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.
DX ÀÌ µî±ÞÀº µ¥ÀÌŸ Àü¼Û¿¡ ´ëÇØ ³ôÀº ¹«°á¼º & ±â¹Ð¼ºÀÌ ¿ä±¸µÇ´Â ½Ã½ºÅÛÀ» À§ÇÑ °ÍÀÌ´Ù.

ITSEC Àº ´ÙÀ½ Ç¥Á¦µé ¾Æ·¡ ¿ä±¸»çÇ×ÀÌ ºÐ¼®µÉ °ÍÀ» Á¦¾ÈÇÑ´Ù: Ã¥ÀÓÃßÀû¼º Accountability, ½Äº° ¹× ÀÎÁõ Identification & Authentication, °¨»ç Audit, °´Ã¼ Àç»ç¿ë Object Reuse, Á¢±ÙÅëÁ¦ Access Control, Á¤È®¼º Accuracy, µ¥ÀÌŸ ±³È¯ Data Exchange ¹× ¼­ºñ½º ½Å·Ú¼º Reliability of Service. ¸ÞÄ«´ÏÁòÀ̳ª ´ëÀÀÃ¥ÀÇ °­µµ´Â ±âº» basic, Áß°£ medium ¶Ç´Â ³ôÀ½ high À¸·Î ±ÔÁ¤µÈ´Ù.

°£·«È÷ Çϱâ À§ÇØ ¿©±â¿¡´Â TCSEC¿¡ ¾ø´Â »õ·Î¿î ¸®ºä ±âÁØÀÌ Æ÷ÇÔµÈ µî±Þ F-DX ¸¸ ¼³¸íÇÑ´Ù.

21.4.3.2 ITSEC µµÀԺκÐÀ¸·ÎºÎÅÍÀÇ ¹ßÃé

´ÙÀ½ ITSECÀÇ ´ë´ëÀûÀÎ ±¹Á¦ ¹öÀü 1.2°¡, ¹ßÇàÀϷκÎÅÍ 2³âÀÇ ÀáÁ¤±â°£µ¿¾È Æò°¡ ¹× Àΰ¡ °èȹ¿¡¼­ÀÇ »ç¿ë¿¡ ´ëÇØ (ºñ°ø½Ä) EC ÀÚ¹®±×·ìÀÎ SOG-IS (Senior Officials Group - Information Systems Security) ÀÇ ½ÂÀÎÀ» ¾ò¾î ¹ßÇàµÇ¾ú´Ù. ½ÀµæµÈ ½ÇÁ¦ °æÇèÀº ÀÌ ±â°£ÀÇ Á¾¹Ý¿¡ ITSECÀ» Àç°ËÅäÇÏ°í ´õ ½ÉµµÀÖ°Ô °³¹ßÇϴµ¥ ÀÌ¿ëµÉ °ÍÀÌ´Ù. µ¡ºÙ¿©, ÇÑÃþ ´õÇÑ ±¹Á¦Àû Á¶È­·ÎºÎÅÍ ³ª¿Ã °í·Á»çÇ׵鵵 ¿°µÎ¿¡ µÑ °ÍÀÌ´Ù.

0.1 °Ü¿ì 40³âÀ» Áö³ª¿À´Â µ¿¾È, Á¤º¸±â¼ú(IT)Àº Á¶Á÷»çȸÀÇ °ÅÀÇ ¸ðµç ºÎºÐ¿¡¼­ Áß¿äÇϰí, ¶Ç ´ë°³ ÇʼöÀûÀÎ, ¿ªÇÒÀ» ¼öÇàÇÏ°Ô µÇ¾ú´Ù. °á°úÀûÀ¸·Î, º¸¾ÈÀº Á¤º¸±â¼úÀÇ ÇʼöÀûÀÎ Ãø¸éÀÌ µÇ¾ú´Ù.

0.2 ÀÌ·± »óȲ¿¡¼­, IT º¸¾ÈÀÌ ÀǹÌÇÏ´Â °ÍÀº,
- ±â¹Ð¼³ - Á¤º¸ÀÇ Àΰ¡µÇÁö ¾ÊÀº °ø°³ ¹æÁö;
- ¹«°á¼º - Á¤º¸ÀÇ Àΰ¡µÇÁö ¾ÊÀº º¯Á¶ ¹æÁö;
- °¡¿ë¼º - Á¤º¸³ª ÀÚ¿ø¿¡ ´ëÇÑ Àΰ¡µÇÁö ¾ÊÀº Á¦Áö¸¦ ¹æÁö.
0.3 IT½Ã½ºÅÛÀ̳ª Á¦Ç°Àº ±â¹Ð¼º, ¹«°á¼º, ±×¸®°í °¡¿ë¼º À¯Áö¸¦ À§ÇÑ °¢ÀÚÀÇ ¿ä±¸»çÇ×À» °¡Áö°í ÀÖÀ» °ÍÀÌ´Ù. ÀÌ ¿ä±¸»çÇ×µéÀ» ¸¸Á·ÇÏ·Á¸é, ¿¹¸¦ µé¾î Á¢±ÙÅëÁ¦, °¨»ç, ±×¸®°í ¿¡·¯ º¹±¸°°Àº ºÐ¾ß¸¦ ´ã´çÇÏ´Â ¼ö¸¹Àº ±â¼úÀû º¸¾È ¼ö´Ü (ÀÌ ¹®¼­¿¡¼­ ÁöĪÇÏ´Â ¹Ù¿¡ ÀÇÇÏ¸é º¸¾È Àû¿ë ±â´É) À» ±¸ÇöÇØ¾ßÇÑ´Ù. ÀÌ ±â´Éµé¿¡ ´ëÇØ ¾Ë¸ÂÀº ½Å·Ú°¡ ÇÊ¿äÇÏ´Ù: ÀÌ ¹®¼­¿¡¼­ À̰ÍÀº º¸ÁõÀ̶ó´Â ¸»·Î ĪÇÑ´Ù, ±×°ÍÀÌ º¸¾ÈÀû¿ë ±â´ÉÀÇ Á¤È®¼º¿¡ ´ëÇÑ ½Å·ÚÀÌ°Ç (°³¹ß°ú ¿î¿µÀû °üÁ¡ ¸ðµÎ¿¡¼­) ¶Ç´Â ±×·± ±â´ÉµéÀÇ À¯È¿¼º¿¡ ´ëÇÑ ½Å·ÚÀ̰Ç.
0.4 ½Ã½ºÅÛÀÇ »ç¿ëÀÚµéÀº ÀÚ±âµéÀÌ »ç¿ëÇϰí ÀÖ´Â ½Ã½ºÅÛÀÇ º¸¾È¿¡ ´ëÇÑ È®½ÅÀÌ ÇÊ¿äÇÏ´Ù. À̵éÀº ¶ÇÇÑ ±¸¸Å¸¦ »ý°¢ÁßÀÎ IT Á¦Ç°µéÀÇ º¸¾È ´É·ÂµéÀ» ºñ±³ÇÒ Ã´µµ°¡ ÇÊ¿äÇÏ´Ù. »ç¿ëÀÚµéÀÌ ¹®Á¦ÀÇ ½Ã½ºÅÛ ¹× Á¦Ç°µéÀÇ Á¦Á¶¾÷ÀÚ³ª º¥´õÀÇ ¸»¿¡ ÀÇÁ¸ÇÒ ¼öµµ ÀÖ°ÚÁö¸¸, ¶Ç´Â ½º½º·Î Å×½ºÆ®¸¦ ÇØº¼ ¼öµµ ÀÖ°ÚÁö¸¸, ¸¹Àº »ç¿ëÀÚµéÀº µ¶¸³ÀûÀÎ ´Üü¿¡ ÀÇÇÑ ¾î¶² ÇüÅÂÀÇ °øÁ¤ÇÑ Æò°¡¸¦ ¼±È£ÇÒ °Í °°´Ù. ½Ã½ºÅÛÀ̳ª Á¦Ç°¿¡ ´ëÇÑ ±×·± Æò°¡´Â °´°üÀûÀ̰í Àß Á¤ÀÇµÈ º¸¾È Æò°¡ ±âÁØ ¹× Æò°¡°¡ ÀûÀýÇÏ°Ô ¼öÇàµÇ¾úÀ½À» ÀÔÁõÇÏ´Â º¸ÁõüÀÇ Á¸À縦 ÇÊ¿ä·Î ÇÑ´Ù. ½Ã½ºÅÛ º¸¾È ¸ñÇ¥´Â ¹®Á¦ÀÇ ½Ã½ºÅÛÀ» »ç¿ëÇÏ´Â »ç¶÷ÀÇ °³º°ÀûÀÎ Çʿ伺¿¡ ƯÁ¤ÇÒ °ÍÀ̰í, ¹Ý¸é Á¦Ç° º¸¾È ¸ñÇ¥´Â, À̸¦ ¸¸Á·ÇÏ´Â Á¦Ç°ÀÌ, ºñ½ÁÇÏÁö¸¸ ²À µ¿ÀÏÇÏÁö´Â ¾ÊÀº º¸¾È ¿ä±¸»çÇ×À» °¡Áö´Â ¸¹Àº ½Ã½ºÅ۵鿡 ÅëÇÕµÉ ¼ö ÀÖµµ·Ï, º¸´Ù ÀϹÝÀûÀÏ °ÍÀÌ´Ù.
0.5 ½Ã½ºÅÛ¿¡ ´ëÇØ¼­, ÀÌÀÇ º¸¾È ´É·Â¿¡ ´ëÇÑ Æò°¡´Â, °³°³ÀÇ È¯°æ¾È¿¡¼­ »ç¿ëÀ» À§ÇØ IT ½Ã½ºÅÛÀ» ¹Þ¾ÆµéÀÌ´Â °Í¿¡ ´ëÇÑ º¸´Ù °ø½ÄÀûÀÎ ÀýÂ÷ÀÇ ÀϺηΠº¼ ¼ö ÀÖ´Ù. ÀÎÁ¤ Accreditation À̶ó´Â ¸»ÀÌ Á¾Á¾ ÀÌ ÀýÂ÷¸¦ ±â¼úÇÏ´Â µ¥ ¾²ÀδÙ. ½Ã½ºÅÛÀÌ ÀǵµÇÏ´Â ¸ñÀû¿¡ ¸Â´Â °ÍÀ¸·Î º¸ÀÏ ¼ö ÀÖ±â À§Çؼ­´Â ¿©·¯°¡Áö °í·ÁÇÒ ¿ä¼ÒµéÀÌ ÇÊ¿äÇÏ´Ù: ½Ã½ºÅÛÀÌ Á¦°øÇÏ´Â º¸¾È¿¡ ´ëÇÑ º¸Áõ, º¸¾È¿¡ ´ëÇÑ °æ¿µÁøÀÇ Ã¥ÀÓ¿¡ ´ëÇÑ È®ÀÎ, °ü·Ã ±â¼ú ¹× ¹ý/±Ô¹ü ¿ä±¸»çÇ× Áؼö, ±×¸®°í ½Ã½ºÅÛ È¯°æ³»¿¡ Á¦°øµÇ´Â ´Ù¸¥ ºñ±â¼úÀû º¸¾È¹æÃ¥µéÀÇ ÀûÇÕ¼º¿¡ ´ëÇÑ È®½ÅÀÌ ÇÊ¿äÇÏ´Ù. ÀÌ ¹®¼­¿¡ Æ÷ÇÔµÈ ±âÁصéÀº ÁÖ·Î ±â¼úÀûÀÎ º¸¾È¹æÃ¥°ú °ü°è°¡ ÀÖÁö¸¸, Àλç, ¹°¸®Àû ¹× ÀýÂ÷Àû º¸¾ÈÀ» À§ÇÑ ¾ÈÀüÇÑ ¿î¿µ ÀýÂ÷¿Í °°Àº ÀϺΠºñ±â¼úÀû Ãø¸éµéµµ ´Ù·é´Ù (±×·¯³ª À̵éÀÌ ±â¼úÀû º¸¾È¹æÃ¥µé¿¡ ´êÀ» ¶§¸¸).
0.6 IT º¸¾È Æò°¡ ±âÁØ °³¹ß¿¡ ´ëÇØ ¸¹Àº ÀÛ¾÷ÀÌ ÀÌÀü¿¡ ÀÖ¾ú´Ù, ºñ·Ï °ü·Ã ±¹°¡³ª ´ÜüµéÀÇ Æ¯Á¤ÇÑ ¿ä±¸»çÇ׿¡ µû¶ó ¾à°£ ´Ù¸¥ ¸ñÀûµéÀ» °¡Áö°í ÀÖÁö¸¸. À̵é Áß °¡Àå Áß¿äÇÑ °ÍÀº, ±×¸®°í ¿©·¯°¡Áö ¸é¿¡¼­ ´Ù¸¥ °³¹ßµé¿¡ ´ëÇÑ ¼±±¸ÀÚ´Â, Trusted Computer System Evaluation Criteria [TCSEC] À̾úÀ¸¸ç, Åë»óÀûÀ¸·Î TCSEC ¶Ç´Â "¿À·»ÁöºÏ" À¸·Î ¾Ë·ÁÁ® ÀÖ°í, ¹Ì ±¹¹æ¼º¿¡¼­ ÃâÆÇÇϰí Á¦Ç° Æò°¡¿¡ ÀÌ¿ëµÈ´Ù. ´Ù¸¥³ª¶óµéµµ, ´ëºÎºÐ À¯·´ ±¹°¡µéÀε¥, IT º¸¾È Æò°¡¿¡ »ó´çÇÑ °æÇèÀ» °¡Áö°í ÀÖ°í ÀÚüÀûÀÎ IT º¸¾È ±âÁØÀ» °³¹ßÇß´Ù. ¿µ±¹¿¡¼­´Â Á¤ºÎ¿ëÀ¸·Î °³¹ßµÈ CESG Memorandum Number 3 [CESG3], »ó¿ë IT º¸¾È Á¦Ç°À» À§ÇÑ Åë»ó»ê¾÷ºÎ Á¦¾È "Green Book" [DTIEC]ÀÌ ¿©±â Æ÷ÇԵȴÙ. µ¶ÀÏ¿¡¼­´Â µ¶ÀÏ Á¤º¸ º¸¾È±¹¿¡¼­ 1989³â ÀÚü ±âÁØ ÃÊÆÇÀ» ¹ßÇàÇÏ¿´À¸¸ç[ZSIEC], °°Àº ½Ã±â¿¡ ÇÁ¶û½º¿¡¼­µµ ±âÁØÀÌ °³¹ßµÇ°í ÀÖ¾ú´Âµ¥, ¼ÒÀ§ "Blue-White-Red Book"ÀÌ´Ù [SCSSI].
0.7 ÀÌ ºÐ¾ß¿¡¼­ ÀÛ¾÷ÀÌ ÁøÇàµÇ°í, ¾ÆÁ÷µµ ÇØ¾ßÇÒ °ÍµéÀÌ ¸¹ÀÌ ³²¾Æ ÀÖ´Â °ÍÀ» º¸°í, ÇÁ¶û½º, µ¶ÀÏ, ³×´ú¶õµå ±×¸®°í ¿µ±¹¿¡¼­´Â ÀÌ ÀÛ¾÷ÀÌ Çù·ÂÀûÀÎ ¹æÇâÀ¸·Î Á¢±ÙµÇ¾î¾ß Çϰí, °øÅëµÇ°í Á¶È­µÈ IT º¸¾È±âÁØÀÌ ³ª¿Í¾ß ÇÑ´Ù´Â °ÍÀ» ÀÎÁöÇß´Ù.
Á¶È­½ÃŰ´Â µ¥¿¡´Â ¼¼ °¡Áö ÀÌÀ¯°¡ ÀÖ´Ù:
a) ¿©·¯ ³ª¶ó¿¡¼­ ¸¹Àº °æÇèµéÀÌ ¸ð¾ÆÁ³°í, ±× °æÇèÀ» ¹ÙÅÁÀ¸·Î ÇÔ²² ±¸ÃàÇÔÀ¸·Î½á ¾òÀ» ¼ö ÀÖ´Â °ÍÀÌ ¸¹¾Ò´Ù;
b) ¾÷°è¿¡¼­´Â ¼­·Î ´Ù¸¥ ³ª¶óµé¿¡¼­ ¼­·Î ´Ù¸¥ º¸¾È ±âÁØÀ» ¿øÇÏÁö ¾Ê¾Ò´Ù;
c) ³ª¶óµé °£¿¡, ±×¸®°í ¹Î°£, Á¤ºÎ ¹× ¹æÀ§ ÀÀ¿ë¿¡¼­Á¶Â÷µµ ±âº» °³³ä°ú Á¢±Ù¹ýÀº µ¿ÀÏÇß´Ù.
0.8 µû¶ó¼­ ¿©·¯ ³ª¶óµéÀÇ ¼±µµ¸¦ ¹ÙÅÁÀ¸·Î ±¸ÃàÇÏ¿©, ÀÌ¹Ì ½ÃÇàµÇ¾ú´ø Ư¡µéÀ» ÃëÇØ À̵éÀÌ ÀϰüµÇ°í ü°èÀûÀ¸·Î ±ÕÇüÀ» ÀÌ·çµµ·Ï Çϱâ·Î °áÁ¤µÇ¾ú´Ù. ±âÁ¸ ÀÛ¾÷, °¡Àå Áß¿äÇϰԴ ¹Ì±¹ TCSEC, °úÀÇ ÃÖ´ëÀÇ ÀûÀÀ¼º°ú ȣȯ¼ºÀÌ ÀÌ ÇÁ·Î¼¼½º¿¡¼­ ºÎ´ÜÇÑ °í·Á»çÇ×À̾ú´Ù. ºñ·Ï óÀ½¿¡´Â ÀÌ ÀÛ¾÷ÀÌ ±âÁ¸ ±âÁصéÀ» Á¶È­½ÃŰ´Â µ¥ ±×Ä¥ °ÍÀ̶ó°í »ý°¢µÇ¾úÀ¸³ª, ¶§¶§·Î ÀÌ¹Ì Á¸ÀçÇÏ´Â °ÍÀ» È®ÀåÇÏ´Â °ÍÀÌ ÇÊ¿äÇÒ ¶§°¡ ÀÖ¾ú´Ù.

21.4.3.3 Contacts

EU Commission of the European Communities
Directorate XII/F SOG-IS Secretariat
Rue De la Loi 200
B-1049 Brussels, Belgium

Germany Bundesamt f? Sicherheit in der Informatik
Am Nippenkreuz 19, D-5300 Bonn
+49-228-9582.111 General Number
+49-228-9582.129 Certification information
+49-228-9582.141 Documentation

Netherlands Netherlands National Comsec Agency
Bezuidenhoutseweg 67
P.O. Box 200061, NL-2500 EB The Hague

France Service Central de la S?urit?des Syst?es d'Information
Division Information et Syst?es
18 Rue du Docteur Zamenhof, F-92131 Issy les Moulineaux

UK Head of the Certification Body
UK IT Security Evaluation and Certification Scheme
P.O. Box 152, Cheltenham, GB-GL52 5UF
+41-1242-238739 ext. 5103
cbsec@itsec.gov.uk
http://www.itsec.gov.uk

21.4.3.4 Ç¥º» ±â´É¼º µî±Þ F-DX

¸ñÀû
A.100 Ç¥º» ±â´É¼º µî±Þ F-DX ´Â ±³È¯µÉ Á¤º¸ÀÇ ±â¹Ð¼º°ú ¹«°á¼º¿¡ ´ëÇÑ ¿ä±¸°¡ ³ôÀº ³×Æ®¿÷À» À§ÇÑ °ÍÀÌ´Ù. ¿¹¸¦ µé¸é, ¹Î°¨ÇÑ Á¤º¸°¡ ¾ÈÀüÇÏÁö ¾ÊÀº ³×Æ®¿÷À» ÅëÇØ (¿¡¸¦µé¸é °øÁ߸Á) ±³È¯µÇ¾î¾ß ÇÏ´Â °æ¿ì°¡ µÉ ¼ö ÀÖ´Ù.

½Äº°°ú ÀÎÁõ
A.101 TOE´Â »ç¿ëÀÚ¸¦ À¯ÀÏÇÏ°Ô ½Äº°Çϰí ÀÎÁõÇØ¾ß ÇÑ´Ù. ÀÌ ½Äº°°ú ÀÎÁõÀº TOE¿Í »ç¿ëÀÚ°£ÀÇ ´Ù¸¥ ¸ðµç »óÈ£ÀÛ¿ë¿¡ ¾Õ¼­ ÀϾ¾ß ÇÑ´Ù. ´Ù¸¥ »óÈ£ÀÛ¿ëµéÀº ¼º°øÀûÀÎ ½Äº°°ú ÀÎÁõ ÀÌÈÄ¿¡¸¸ °¡´ÉÇØ¾ß ÇÑ´Ù. ÀÎÁõÁ¤º¸´Â Àΰ¡µÈ »ç¿ëÀÚ¿¡ ÀÇÇÑ ¸®ºä³ª º¯°æÀ» À§Çؼ­¸¸ Á¢±ÙµÉ ¼ö ÀÖ´Â ¹æ¹ýÀ¸·Î ÀúÀåµÇ¾î¾ß ÇÑ´Ù. ¸ðµç »óÈ£ÀÛ¿ë¿¡ ´ëÇØ TOE´Â »ç¿ëÀÚÀÇ ½Å¿øÀ» ÀÔÁõÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù.

A.102 »ç¿ëÀÚ µ¥ÀÌŸ¸¦ ±³È¯Çϱâ Àü¿¡ Åë½Å »ó´ë °³Ã¼ (ÄÄÇ»ÅÍ, ÇÁ·Î¼¼½º ¶Ç´Â »ç¿ëÀÚ) ´Â À¯ÀÏÇÏ°Ô ½Äº° ¹× ÀÎÁõµÇ¾î¾ß ÇÑ´Ù. »ç¿ëÀÚ µ¥ÀÌŸ´Â ½Äº° ¹× ÀÎÁõÀÌ ¼º°øÀûÀ¸·Î ¿Ï¼öµÈ ÀÌÈÄ¿¡¸¸ ±³È¯µÇ¾î¾ß ÇÑ´Ù. µ¥ÀÌŸ¸¦ ¹ÞÀ¸¸é µ¥ÀÌŸÀÇ ¹ß½ÅÀÚ¸¦ À¯ÀÏÇÏ°Ô ½Äº°Çϰí ÀÎÁõÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù. ¸ðµç ÀÎÁõÁ¤º¸´Â ºñÀΰ¡ Á¢±Ù°ú À§Á¶·ÎºÎÅÍ º¸È£µÇ¾î¾ß ÇÑ´Ù.

Ã¥ÀÓÃßÀû¼º
A.103 TOE´Â ´ÙÀ½ °¢ À̺¥Æ®µé¿¡ ´ëÇØ ÇÊ¿äÇÑ µ¥ÀÌŸ¿Í ÇÔ²² À̺¥Æ®¸¦ ·Î±×ÇÒ ¼ö ÀÖ´Â, Ã¥ÀÓ(ÃßÀû¼º) ¿ä¼Ò¸¦ Æ÷ÇÔÇϰí ÀÖ¾î¾ß ÇÑ´Ù:
a) ½Äº° ¹× ÀÎÁõ ¸ÞÄ«´ÏÁòÀÇ »ç¿ë:
ÇÊ¿äÇÑ µ¥ÀÌŸ: ³¯Â¥; ½Ã°£; ½Äº° ¹× ÀÎÁõÀÇ °³½ÃÀÚ; ½Äº°µÉ ÁÖüÀÇ À̸§; ÇàÀ§ÀÇ ¼º°ø ¶Ç´Â ½ÇÆÐ ¿©ºÎ.
b) µ¥ÀÌŸ ±³È¯¿¡¼­ ½Äº°µÈ ¿¡·¯:
ÇÊ¿äÇÑ µ¥ÀÌŸ: ³¯Â¥; ½Ã°£; µ¥ÀÌŸ ±³È¯¿¡¼­ Åë½Å ´ç»çÀÚµé; ¿¡·¯ À¯Çü; ½ÃµµµÈ ±³Á¤ÀÇ ¼º°øÀ̳ª ½ÇÆÐ¿©ºÎ.
c) ¿¬°á ¼³Á¤:
ÇÊ¿äÇÑ µ¥ÀÌŸ: ³¯Â¥; ½Ã°£; °³½ÃÀÚÀÇ »ç¿ëÀÚ ½Å¿ø; Åë½Å »ó´ë °³Ã¼ À̸§(ÄÄÇ»ÅÍ, ÇÁ·Î¼¼½º ¶Ç´Â »ç¿ëÀÚ); ¼³Á¤ ÆÄ¶ó¹ÌÅÍ (´Þ¶óÁø´Ù¸é).
d) Ư¼öÇÑ µ¥ÀÌŸ ±³È¯ Æ®·£Àè¼Ç:
ÇÊ¿äÇÑ µ¥ÀÌŸ: ³¯Â¥; ½Ã°£; ¼Û½ÅÀÚÀÇ »ç¿ëÀÚ ½Å¿ø; ¼ö½ÅÀÚÀÇ »ç¿ëÀÚ ½Å¿ø; Åë½ÅµÈ »ç¿ëÀÚ Á¤º¸; µ¥ÀÌŸ ¼ö½Å ³¯Â¥ ¹× ½Ã°£.
A.104 ºñÀΰ¡ »ç¿ëÀڴ åÀÓ µ¥ÀÌŸ¿¡ Á¢±ÙÀÌ Çã¿ëµÇÁö ¸»¾Æ¾ß ÇÑ´Ù. Çϳª ¶Ç´Â ±× ÀÌ»ó »ç¿ëÀÚÀÇ ÇàÀ§¿¡ ´ëÇØ ¼±ÅÃÀûÀ¸·Î Ã¥ÀÓÀ» ±â·ÏÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù. Ã¥ÀÓ ÆÄÀϵéÀ» °Ë»çÇϰí À¯ÁöÇÏ´Â µµ±¸°¡ ÀÖ¾î¾ß ÇÏ°í ¹®¼­È­µÇ¾î¾ß ÇÑ´Ù. ÀÌ µµ±¸µéÀº Çϳª ¶Ç´Â ±× ÀÌ»ó »ç¿ëÀÚÀÇ ÇàÀ§µéÀÌ ¼±ÅÃÀûÀ¸·Î ½Äº°µÉ ¼ö ÀÖµµ·Ï ÇØÁÖ¾î¾ß ÇÑ´Ù. Ã¥ÀÓ ±â·ÏÀÇ ±¸Á¶°¡ ¿Ïº®ÇÏ°Ô ¼­¼úµÇ¾î¾ß ÇÑ´Ù.

°¨»ç
A.105 °¨»ç ¸ñÀûÀ¸·Î Ã¥ÀÓ ÆÄÀÏÀ» °Ë»çÇÒ µµ±¸µéÀÌ Á¸ÀçÇÏ°í ¹®¼­È­ µÇ¾î¾ß ÇÑ´Ù. ÀÌ µµ±¸µéÀº Çϳª ¶Ç´Â ±× ÀÌ»ó »ç¿ëÀÚÀÇ ÇàÀ§°¡ ¼±ÅÃÀûÀ¸·Î ½Äº°µÉ ¼ö ÀÖµµ·Ï ÇØÁÖ¾î¾ß ÇÑ´Ù.

µ¥ÀÌŸ ±³È¯

Á¢±Ù ÅëÁ¦
A.106 Àΰ¡¹ÞÁö ¾ÊÀº ÇØµ¶¿¡ ÀÌ¿ëµÉ¼ö ÀÖ´Â ÀÌÀü¿¡ Àü¼ÛµÈ ¸ðµç Á¤º¸´Â, Á÷¹«¸¦ ¼öÇàÇϱâ À§ÇØ Àý´ëÀûÀ¸·Î ÀÌ µ¥ÀÌŸ¿¡ Á¢±ÙÇÒ ¼ö ÀÖ¾î¾ß ÇÏ´Â »ç¶÷¸¸ Á¢±ÙÇÒ ¼ö ÀÖ°Ô º¸È£µÇ¾î¾ß ÇÑ´Ù.

µ¥ÀÌŸ ±â¹Ð¼º
A.107 TOE´Â Åë½Åä³ÎÀÇ ³ÐÀº ºÎºÐ¿¡ °ÉÄ£ ¼ö½ÅÀÚ¿¡ ´ëÇØ ±â¹Ð¼ºÀ» º¸ÀåÇÏ´Â Á¾´Ü°£(end-to-end) ¾ÏȣȭÀÇ ¼ö´ÜÀ» Á¦°øÇØ¾ß ÇÑ´Ù. ¾Æ¿ï·¯, ÁöÁ¤µÈ µ¥ÀÌŸ Åë½Å ¸µÅ©¿¡ ´ëÇÑ Æ®·¡ÇÈ È帧 ±â¹Ð¼ºµµ º¸ÀåµÇ¾î¾ß ÇÑ´Ù.

µ¥ÀÌŸ ¹«°á¼º
A.108 TOE´Â »ç¿ëÀÚ µ¥ÀÌŸ¿Í Ã¥ÀÓ µ¥ÀÌŸÀÇ ºñÀΰ¡ Á¶ÀÛ°ú µ¥ÀÌŸÀÇ ºñÀΰ¡ Àç»ýÀÌ È®½ÇÈ÷ ¿¡·¯·Î ÆÇ¸íµÇµµ·Ï ¼³°èµÇ¾î¾ß ÇÑ´Ù.

21.4.4 ITSEM (¹ßÃé) (·ÎÄà »çº», ¶Ç´Â UK ITSEC ÂüÁ¶)

..........

0.1 Àå ¼Ò°³
0.1.5 IT º¸¾È Æò°¡ ¸Å´º¾ó (IT Security Evaluation Manual, ITSEM) Àº ITSEC ¹öÀü 1.2 ¸¦ ¹ÙÅÁÀ¸·Î ÇÏ¿©, Æò°¡ ´ë»ó(TOE)ÀÌ ÀÌ ±âÁØ¿¡ µû¶ó ¾î¶»°Ô Æò°¡µÇ¾î¾ß ÇÏ´ÂÁö¸¦ ¼­¼úÇÑ´Ù. ITSEMÀÇ ¸í½ÃµÈ ¸ñÀûÀº ITSECÀ» º¸¿ÏÇÏ´Â Á¶È­µÈ Æò°¡ ¹æ¹ý ¼¼Æ®°¡ Á¸ÀçÇϵµ·Ï Çϱâ À§ÇÑ °ÍÀÌ´Ù.

0.1.6 ITSEM Àº ±â¼úÀûÀÎ ¹®¼­·Î, ÁÖ·Î Æò°¡ ÆÄÆ®³Êµé (ÀÏÂ÷ÀûÀ¸·Î Æò°¡ÀÚÀÌÁö¸¸ ¹ß±âÀÚ¿Í º¸ÁõÀÚµµ) À» °Ü³ÉÇÑ °ÍÀÌÁö¸¸, º¥´õ³ª °³¹ßÀÚ, ½Ã½ºÅÛ ÀÎÁ¤ÀÚ¿Í »ç¿ëÀڵ鿡°Ôµµ °ü½ÉÀÇ ´ë»óÀÌ´Ù. ¿©±â¿¡´Â Æò°¡ ¹æ¹ýµé¿¡ ´ëÇÑ ÃæºÐÇÑ ¼¼ºÎ»çÇ×°ú ´Ù¾çÇÑ È¯°æ¿¡¼­ ¼öÇàµÇ´Â Æò°¡ÀÇ ±â¼úÀû µî°¡Ä¡¸¦ ÀÔÁõÇÒ ¼ö ÀÖ°Ô ÇÏ´Â ÀýÂ÷µéÀÌ Æ÷ÇԵǾî ÀÖ´Ù. ¹®¼­´Â ¹«·á·Î ¾òÀ» ¼ö ÀÖ´Ù. ITSEMÀº ¹Î°£°ú Á¤ºÎ ºÐ¾ß¿¡¼­ ¼öÇàµÇ´Â Æò°¡ ¸ðµÎ¿¡ Àû¿ëµÈ´Ù.
..........
0.1 Àå ¼Ò°³
ÀÚ»ê, À§Çù, À§Çè, ½Å·Ú ¹× ´ëÀÀÃ¥
0.1.1 Á¤º¸±â¼ú(IT)Àº È¿°úÀûÀÎ »ç¾÷ ¹× ±¹°¡¾÷¹« ¼öÇà¿¡ ÇʼöÀûÀÎ °ÍÀÌ µÇ¾ú°í, IT »ç¿ëÀÇ ¿µÇâÀ» ¹Þ´Â °³ÀεéÀÇ »ç¹«¿¡¼­µµ Á¡Á¡ Áß¿äÇØÁö°í ÀÖ´Ù. Á¤º¸´Â ¾î¶² »ç¶÷ÀÇ ¾÷¹«³ª »ç¹«¸¦ ÁøÃ´½Ã۱â À§ÇØ ¾ò¾îÁö°í º¸È£µÇ¾î¾ß ÇÏ´Â ¾î¶² °ÍÀ̸ç, µû¶ó¼­ ÀÚ»êÀ¸·Î °£ÁֵǾî¾ß ÇÑ´Ù. ±×·¯ÇÑ ÀÚ»êÀÇ Á߿伺Àº º¸Åë À§ÇùÀÇ Â¡ÈķκÎÅÍ ÆÄ»ýµÇ¾î °á°ú·Î¼­ ÀϾ´Â ¼ÕÇØ·Î Ç¥ÇöµÈ´Ù. ¼ÕÇØ´Â Á¤º¸ÀÇ Æø·Î, ºÎÀûÀýÇÑ º¯Á¶, ÆÄ±« ¶Ç´Â ¿À¿ë¿¡ ÀÇÇØ Á÷Á¢ÀûÀ¸·Î³ª °£Á¢ÀûÀ¸·Î ¾ß±âµÉ ¼ö ÀÖ´Ù. À§ÇèÀº ¿¹»óµÇ´Â ¼ÕÇØ¿Í ³ªÅ¸³ª´Â À§ÇùÀÇ °¡´É¼ºÀÇ Å©±â¿¡ µû¶ó Áõ°¡ÇÑ´Ù.
0.1.2 IT ½Ã½ºÅÛ¿¡¼­ Á¤º¸´Â Àڻ꿡 ³ª»Û ¿µÇâÀ» ¹ÌÄ¡´Â À§ÇùÀ¸·ÎºÎÅÍ º¸È£µÇ¾î¾ß ÇÑ´Ù. À§ÇùÀº °íÀÇÀûÀ̰ųª (e.g. °ø°Ý) ÀǵµµÇÁö ¾ÊÀ» °ÍÀÏ ¼ö ÀÖ´Ù (e.g. ½Ç¼ö³ª °íÀå).
0.1.3 À§ÇèÀ» ÁÙÀ̱â À§ÇØ, ƯÁ¤ÇÑ ´ëÀÀÃ¥ÀÌ ¼±Á¤µÉ °ÍÀÌ´Ù. ÀÌ ´ëÀÀÃ¥µéÀº Ư¼º»ó ¹°¸®Àû, ÀλçÀû, ÀýÂ÷Àû ¶Ç´Â ±â¼úÀûÀÏ ¼ö ÀÖ´Ù. ±â¼úÀû ´ëÀÀÃ¥ ¶Ç´Â IT ´ëÀÀÃ¥ Àº IT ½Ã½ºÅÛÀÇ º¸¾È Àû¿ë ±â´É°ú ¸ÞÄ«´ÏÁòÀÌ´Ù; ºñ ±â¼úÀû ´ëÀÀÃ¥ ¶Ç´Â ºñ IT ´ëÀÀÃ¥ Àº ¹°¸®Àû, ÀλçÀû, ±×¸®°í ÀýÂ÷Àû ´ëÀÀÃ¥µéÀÌ´Ù. ITSEC Æò°¡´Â ÁÖ·Î ±â¼úÀû ´ëÀÀÃ¥°ú °ü°èµÈ´Ù.
0.1.4 IT ½Ã½ºÅÛÀÇ ÀÏÂ÷ º¸¾È ¸ñÇ¥´Â ¿¬°üµÈ À§ÇèÀ» °ü·Ã Á¶Á÷ÀÌ ¼ö¿ëÇÒ ¼ö ÀÖ´Â ¼öÁØÀ¸·Î ÁÙÀÌ´Â °ÍÀÌ´Ù. À̰ÍÀº IT ½Ã½ºÅÛÀÇ º¸¾È ±â´É ¹× Ư¡µé¿¡ ÀÇÇØ ´Þ¼ºµÉ ¼ö ÀÖ´Ù.
0.1.5 IT ½Ã½ºÅÛÀÌ Á¦°øÇÏ´Â º¸¾È¿¡ ´ëÇØ Àû¿ëµÉ ½Å·Ú¸¦ º¸ÁõÀ̶ó°í ¸»ÇÑ´Ù. º¸ÁõÀÌ Å¬¼ö·Ï, ½Ã½ºÅÛÀÌ ÀÜÁ¸À§ÇèÀ» ¼ö¿ë°¡´ÉÇÑ ¼öÁØÀ¸·Î À¯ÁöÇϸç À§ÇùÀ¸·ÎºÎÅÍ ÀÚ»êÀ» º¸È£ÇÒ °ÍÀ̶ó´Âµ¥ ´ëÇÑ È®½Å(½Å·Ú)µµ Ä¿Áø´Ù.
0.1.6 ITSEC Æò°¡ µî±ÞÀÌ ³ô°í ¸ÞÄ«´ÏÁòÀÇ °­µµ°¡ °­ÇÒ¼ö·Ï, »ç¿ëÀÚ´Â IT ½Ã½ºÅÛÀ̳ª Á¦Ç°¿¡ ³»ÀçµÈ ´ëÀÀÃ¥¿¡ ´ëÇØ ´õ Å« È®½ÅÀ» °¡Áú ¼ö ÀÖ´Ù. »ç¿ëÀÚ¿¡°Ô ÇÊ¿äÇÑ Æò°¡ µî±ÞÀº ¾Ë·ÁÁø ÀÜÁ¸À§ÇèÀÇ ¼ö¿ë°¡´ÉÇÑ ¼öÁØ¿¡ ´Þ·Á ÀÖÀ¸¸ç ±¸Ã¼ÀûÀÎ °³º° »óȲ¿¡ ´ëÇÑ À§Çù ¹× À§Çè ºÐ¼®¿¡ ÀÇÇØ¼­¸¸ °áÁ¤µÉ ¼ö ÀÖ´Ù. º¸¾È°ú ºñ¿ëÀº ±ÕÇüÀ» ÀÌ·ç¾î¾ß ÇÑ´Ù. Æò°¡µî±ÞÀÌ ³ô¾ÆÁü¿¡ µû¶ó °³¹ß ¹× Æò°¡ ºñ¿ëÀÌ Áõ°¡ÇÒ °¡´É¼ºÀÌ ¸¹À¸¹Ç·Î, ´õ ³ôÀº Æò°¡ µî±Þ Á¦Ç°À̳ª ½Ã½ºÅÛÀº ´ë°³ ´õ ºñ½Ò °ÍÀÌ´Ù. ¿¹¸¦µé¾î ȯ°æ ÆÄ¶ó¹ÌÅÍÀÇ ÇÔ¼ö·Î Æò°¡µî±ÞÀ» °áÁ¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ¾È³»°¡ [GISA2]¿¡ ÁÖ¾îÁ® ÀÖ´Ù. ITSEM 2ºÎ¿¡ ¾ð±ÞµÈ ±¹°¡ Á¶Á÷µé·ÎºÎÅÍ Æ¯Á¤ÇÑ Á¶¾ðÀ» ±¸ÇÒ ¼öµµ ÀÖ´Ù.

..........
º¸¾È Æò°¡
6.4.11 ¿Ïº®ÇÏ°Ô ¾ÈÀüÇÑ ½ÇÁ¦ IT ½Ã½ºÅÛÀ» ¸¸µå´Â °ÍÀº ºÒ°¡´ÉÇÏ´Ù. À̰ÍÀº IT ½Ã½ºÅÛÀÇ º¹À⼺°ú, ´ëÀÀÇØ¾ß ÇÏ´Â À§ÇùÀÇ ´Ù¾ç¼º ¶§¹®ÀÌ´Ù.
6.4.12 ±×·¯³ª, ÄÄÇ»ÅÍ ½Ã½ºÅÛÀÇ º¸¾È¿¡ ´ëÇÑ ¾î´ÀÁ¤µµÀÇ È®½ÅÀ» Á¦°øÇÏ´Â °ÍÀº °¡´ÉÇÏ´Ù. ¼±È£µÇ´Â Á¢±Ù¹ýÀº µ¶¸³Àû ±â°üÀÌ (IT º¸¾È Æò°¡ ±â°ü, ITSEF À̶ó°í ºÒ¸²) ½Ã½ºÅÛ ¼³°è¿Í ¹®¼­È­¸¦ »ó¼¼È÷ °Ë»çÇÏ¿© º¸¾È Ãë¾àÁ¡À» ã´Â °ÍÀÌ´Ù. ½Ã½ºÅÛÀÌ ÀÌ¿ëµÉ ¼ö ÀÖ´Â º¸¾È Ãë¾àÁ¡À» °¡Áö°í ÀÖÁö ¾ÊÀº °ÍÀ¸·Î ÆÇ¸íµÇ¸é, ½Ã½ºÅÛÀº Æò°¡¸¦ Åë°úÇÏ°Ô µÈ´Ù; ¾Æ´Ï¸é ½ÇÆÐÇÑ´Ù.
6.4.13 ½Ã½ºÅÛÀÌ º¸¾È Æò°¡¸¦ Åë°úÇϸé, ÀÌ´Â ¾î´À Á¤µµÀÇ º¸¾ÈÀ» Á¦°øÇÒ ¹ý ÇÏÁö¸¸, ´ÙÀ½°ú °°Àº ÀÌÀ¯µé ¶§¹®¿¡ ¿ÏÀüÈ÷ ¾ÈÀüÇÏ´Ù°í ÇÒ ¼ö´Â ¾ø´Ù:
a) Æò°¡ÀÚ°¡ ¾òÀ» ¼ö ÀÖ´Â Á¤º¸ÀÇ ¼öÁض§¹®¿¡, Æò°¡ÀÚ°¡ ¹ß°ßÇÏÁö ¸øÇÑ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÒ ¼ö ÀÖ´Ù;
b) ½Ã½ºÅÛÀÌ ¾ÈÀüÇÏÁö ¸øÇÏ°Ô »ç¿ë, ¿î¿µ, °ü¸® ¶Ç´Â ±¸¼ºµÉ ¼ö ÀÖ´Ù;
c) ±× ȯ°æ¿¡¼­ÀÇ ¾î¶² À§ÇùµéÀÌ º¸¾È ¸ñÇ¥¿¡ Æ÷ÇÔµÇÁö ¾Ê¾ÒÀ» ¼ö ÀÖ´Ù.
6.4.14 µû¶ó¼­, Æò°¡µÈ ½Ã½ºÅÛÀº Á¶Á÷ÀÇ º¸¾ÈÀ» À¯ÁöÇϴµ¥ ÇϳªÀÇ ¿ªÇÒÀ» ´ã´çÇÏ´Â °ÍÀ¸·Î º¸¾Æ¾ß ÇÏÁö¸¸, º¸¾È¿¡ ´ëÇÑ ¸ðµç Ã¥ÀÓÀ» Áö´Â °ÍÀº ¾Æ´Ï´Ù. ¸ðµç À¯ÇüÀÇ »ç¿ëÀÚµéÀÌ ¿©ÀüÈ÷ ´ã´çÇÒ ºÎºÐÀÌ ÀÖ´Ù.
..........

21.4.5 TTAP

´ÙÀ½Àº FIST WWW ÆäÀÌÁö·ÎºÎÅÍ ¹ßÃéÇÑ °ÍÀÌ´Ù:

TTAP (½Å·Ú±â¼ú Æò°¡ ÇÁ·Î±×·¥ Trust Technology Assessment Program) ´Â »ó¿ë ±â¼ºÁ¦Ç° (COTS)¿¡ ´ëÇÑ ½Å·Ú µî±ÞÀ» »ó¿ëÈ­Çϱâ À§ÇÑ ±¹°¡ ¾Èº¸±¹(NSA) °ú ±¹¸³ Ç¥Áرâ¼ú ¿¬±¸¼Ò(NIST)ÀÇ ÇÕÀÛǰÀÌ´Ù. National Voluntary Laboratory Accreditation Program (NVLAP) ÀÇ ÈÄ¿ø¾Æ·¡, TTAP ´Â »ó¿ë Æò°¡ ±â°üÀ» ¼³¸³, ½ÂÀÎ, °¨µ¶ÇÒ °ÍÀ̸ç, Ãʱ⿡´Â TCSEC B1¹× ±× ÀÌÇÏ ½Å·Ú ¼öÁØÀÇ ±â´É°ú º¸ÁõÀ» °¡Áö´Â Á¦Ç°µé¿¡ ÃÊÁ¡À» ¸ÂÃá´Ù.

ÃÖÃÊÀÇ TTAP ¿öÅ©¼¥Àº 1996³â º½¿¡ ÀÖÀ» °ÍÀÌ´Ù. »ç¿ëÀÚ°¡ "º¸¾È µî±Þ"¿¡ µû¶ó ¿î¿µÃ¼Á¦¸¦ ¼±ÅÃÇÒ ¼ö ÀÖ°Ô Çϱâ À§ÇØ TTAP°¡ ¾î¶² ÀÏÀ» ÇÒ Áö ÁöÄѺ¸´Â ÀÏÀÌ Èï¹Ì·Î¿õ °ÍÀÌ´Ù.

21.4.6 Common Criteria 1.0 (¿¾³¯ V1 ·ÎÄà »çº», ¶Ç´Â º¸´Ù »õ·Î¿î V2´Â UK ITSECÂüÁ¶)

´ÙÀ½ ¼³¸íÀº NIST ( http://csrl.ncsl.nist.gov/nistpubs/cc ) ·ÎºÎÅÍ °¡Á®¿Â °ÍÀÌ´Ù:

1985 ³â ¹Ì±¹Àº TCSEC (Trusted Computer Security Evaluation Criteria ¶Ç´Â Orange book) À̶ó´Â º¸¾È Æò°¡ ±âÁØ ¼¼Æ®¸¦ ¸¸µé¾ú´Ù. ÀÌ·¯ÇÑ ±âÁØÀº ƯÁ¤ÇÑ º¸¾È ±â´É¼ºÀ» ÇÊ¿ä·Î Çϸç Á¤ÀÇµÈ Æ¯Á¤ ȯ°æ ¼¼Æ®¿¡ ÀûÇÕÇÑ ¸î°³ÀÇ µî±ÞÀ» Á¦°øÇÏ¿´´Ù (C1, C2, B1, B2, B3, A1). ÀÌ TCSEC ÀÌÈÄ, À¯·´±¹°¡µéÀÌ ITSEC (IT Security Evaluation Criteria)À» ¸¸µé°í, ij³ª´Ù´Â CTCPECÀ», ±×¸®°í ¸¶Áö¸·À¸·Î ¹Ì±¹¿¡¼­ ¿¬¹æ ±âÁØÀ» ¸¸µé¾ú´Ù. ÀÌ ±âÁصéÀÌ ¼­·Î ȣȯµÇÁö ¾ÊÀ¸¹Ç·Î, ÀÌ ¸ðµç ±âÁصéÀ» Common Criteria (¶Ç´Â ´Ü¼øÈ÷ CC)¶ó´Â »õ·Î¿î ÇϳªÀÇ º¸¾È Æò°¡ ±âÁØ ¼¼Æ®·Î Á¶È­½Ã۱â·Î °áÁ¤µÇ¾ú´Ù.

Common Criteria ÀÇ ÁÖµÈ ¸ñÀûÀº ¸ðµç IT º¸¾È Á¦Ç°µé¿¡ ´ëÇØ »ç¿ëµÉ ¼ö ÀÖ´Â º¸¾È Æò°¡ ±âÁØ ¼¼Æ®¸¦ Á¦°øÇÏÀÚ´Â °ÍÀÌ´Ù. µ¿½Ã¿¡ À̰ÍÀº Á¦Ç°¿¡ ´ëÇØ ¹Ù¶ö ¼ö ÀÖ´Â, °¡´ÉÇÑ º¸¾È ¿ä±¸»çÇ×µéÀÇ ¸ÚÁö°í °£·«ÇÑ ¼¼Æ®¸¦ Á¦°øÇÑ´Ù.
Common Criteria ´Â ¾ÆÁ÷ ¿Ï¼ºµÇÁö ¾Ê¾Ò´Ù. ÇöÀç´Â Common Criteria for Information Technology Security (CC) version 1.0, January 31, 1996 ÀÌ ´ëÁß ¸®ºä¿Í ÀÇ°ß ¼ö·ÅÁßÀÌ´Ù. ¸®ºä¿Í ½ÃÇè Æò°¡¿¡ µû¶ó CC´Â °è¼Ó Á¤ÇØÁöÁö ¾ÊÀ» ¼ö ÀÖ´Ù. ¸ñÇ¥´Â ISO°¡ Common Criteria ¸¦ ±¹Á¦ Ç¥ÁØÀ¸·Î ¹Þ¾ÆµéÀÌ´Â °ÍÀ̸ç, ÀÌ¹Ì ISO¿¡ Á¦ÃâÇÏ¿´´Ù.
ISO/IEC/JTC1/SC27/WG3 "Evaluation Criteria for IT Security" ´Â Àü¼¼°èÀûÀΠǥÁØ ±âÁØÀ» 1998±îÁö ¸¸µé ¸ñÇ¥¸¦ °¡Áö°í ÀÖ´Ù.


°¢ÁÖ:
[1] È®½ÇÈ÷ NCSC ´Â À¥ÀÌ ÀÖÁö¸¸ ½Ã½ºÅÛÀ» Æò°¡ÇÏ´Â NSA ºÎ¹®Àº ¾ø´Ù?have now a Web presence, but not the NSA division which evaluates systems.


previous  next  Title  Contents  Index         Previous     Next      Top   Detailed TOC      Last Update: 16 Jun 2000