¸ñÂ÷·Î À̵¿ Çѱ¹ - Çѱ¹¾î
Çѱ¹ HP.com Ȩ Á¦Ç° ¹× ¼­ºñ½º °í°´Áö¿ø & ´Ù¿î·Îµå ¼Ö·ç¼Ç ±¸ÀÔ ¹æ¹ý
» HP ¿¬¶ôó
Ãß°¡ ¿É¼Ç
Çѱ¹ HP.com Ȩ
Ignite-UX °ü¸® ¼³¸í¼­: HP-UX 11i¿ë > 6Àå º¸¾È

Ignite-UX¿¡¼­ ÀÛµ¿Çϵµ·Ï Bastille °­È­ ½Ã½ºÅÛ ¼öÁ¤

» 

±â¼ú ¹®¼­

PDF ¿Ïº»
» Çǵå¹é
³»¿ë ½ÃÀÛ À§Ä¡

 » ¸ñÂ÷

 » ¿ë¾î

 » »öÀÎ

HP-UX BastilleÀº HP-UX ¿î¿µ üÁ¦ÀÇ º¸¾ÈÀ» Çâ»ó½ÃŰ´Â µ¥ »ç¿ëÇÒ ¼ö ÀÖ´Â º¸¾È °­È­/Àá±Ý µµ±¸ÀÔ´Ï´Ù. ÀÌ µµ±¸´Â CIS(Center for Internet Security) Level 1 Benchmark for HP-UX¿Í ºñ½ÁÇÑ ±â´É ¹× ±âŸ °­È­/Àá±Ý È®ÀÎ ¸ñ·ÏÀ» ÀÎÄÚµùÇÏ¿© ½Ã½ºÅÛº°·Î »ç¿ëÀÚ Á¤ÀÇ Àá±ÝÀ» Á¦°øÇÕ´Ï´Ù. Bastille ±â¼úÀº HP-UXÀÇ HP-UX 11i v1 ÀÌ»ó ¹öÀü¿¡¼­ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÀÌ Àý¿¡¼­´Â Bastille ½Ã½ºÅÛ¿¡¼­ Ignite-UX ¿ä±¸ »çÇ×ÀÌ È°¼ºÈ­µÇµµ·Ï ÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù.

HP-UX Bastille¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº bastille(1M), bastille_drift(1M), HP-UX ½Ã½ºÅÛ °ü¸® ¼³¸í¼­: º¸¾È °ü¸®(HP-UX 11i v3À» ½ÇÇàÇϰí ÀÖ´Â °æ¿ì) ¹× ½Ã½ºÅÛ ¹× ÀÛ¾÷ ±×·ì °ü¸®: HP-UX ½Ã½ºÅÛ °ü¸®ÀÚ¸¦ À§ÇÑ ¼³¸í¼­(HP-UX 11i v2 ÀÌÀü ¹öÀüÀÌ ½ÇÇàµÇ´Â ½Ã½ºÅÛ)¸¦ ÂüÁ¶ÇϽʽÿÀ.

ÁÖÀÇ: ÀÌ ÀýÀÇ ±¸¼º ÇÁ·Î¼¼½º¿¡¼­´Â ½Ã½ºÅÛÀÇ º¸¾È µî·Ï Á¤º¸¸¦ º¯°æÇÕ´Ï´Ù. ¼­ºñ½º, ÇÁ·ÎÅäÄÝ ¹× Æ÷Æ®¸¦ Ȱ¼ºÈ­ÇÒ ¶§´Â ³×Æ®¿öÅ© ¹× ½Ã½ºÅÛ º¸¾È¿¡ ¿µÇâÀ» ÁÙ ¼ö ÀÖÀ¸¹Ç·Î ½ÅÁßÇÏ°Ô °í·ÁÇØ¾ß ÇÕ´Ï´Ù.

Ignite-UX ¼­¹ö ¿ä±¸ »çÇ× È°¼ºÈ­

¼­¹ö¿¡¼­ Ignite-UX ¿ä±¸ »çÇ×À» Ȱ¼ºÈ­ÇÏ·Á¸é ¸ÕÀú ÇöÀç Àá±Ý »óŸ¦ °Ë»öÇϰí ÇÊ¿äÇÑ °æ¿ì ÇØ´ç »óŸ¦ ¼öÁ¤ÇÏ¿© ¼±ÅÃÇÑ µ¥¸ó ¹× ¼­ºñ½º°¡ ½ÇÇàµÇµµ·Ï ÇØ¾ß ÇÕ´Ï´Ù. ¶ÇÇÑ Ignite-UX ¼­¹ö¿¡¼­ »ç¿ëÇϴ ƯÁ¤ Æ÷Æ®¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Çã¿ëÇØ¾ß ÇÕ´Ï´Ù.

  1. ÇöÀç Àá±Ý »óŸ¦ °Ë»öÇÕ´Ï´Ù.

    • Bastille 3.0 ÀÌ»óÀ» »ç¿ëÇϰí ÀÖ´Â °æ¿ì ±¸¼º º¸°í¼­¸¦ ¸¸µì´Ï´Ù. º¸°í¼­´Â /var/opt/sec_mgmt/bastille/log/Assessment/assessment-log.config¿¡ ¸¸µé¾îÁý´Ï´Ù.

      # bastille --assessnobrowser

    • 3.0 ÀÌÀü ¹öÀüÀÇ BastilleÀ» »ç¿ëÇϰí ÀÖ´Â °æ¿ì Bastille¿¡¼­ »ç¿ëÇÏ´Â Ãֽб¸¼º ÆÄÀÏÀ» °¡Á®¿É´Ï´Ù.

      # bastille -l

    Âü°í: ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö°¡ Ç¥½ÃµÉ ¼ö ÀÖ½À´Ï´Ù.
    NOTE:    The system is in its pre-bastilled state.
    ÀÌ·± °æ¿ì Ignite-UX¿¡ ÇÊ¿äÇÑ µ¥¸ó, ¼­ºñ½º ¹× Æ÷Æ®°¡ Bastille ÀÌÀü »óÅ·ΠÀá°Ü ÀÖÁö ¾ÊÀ¸¹Ç·Î ÀÌ ±¸¼ºÀ» °è¼Ó ÁøÇàÇÒ Çʿ䰡 ¾ø½À´Ï´Ù.

  2. »ç¿ëµÈ ¸¶Áö¸· ±¸¼º ÆÄÀÏÀ̳ª Æò°¡ º¸°í¼­¸¦ ¼±ÅÃÇÑ À§Ä¡¿¡ º¹»çÇÕ´Ï´Ù.

  3. Bastille GUI¿¡ Ãֽб¸¼ºÀ» Ç¥½ÃÇÕ´Ï´Ù.

    # bastille --os [HP-UX11.00 | HP-UX11.11 | HPUX11.23 | HPUX11.31] -f filename

  4. ´ÙÀ½°ú °°Àº µ¥¸ó ¹× ¼­ºñ½º¿¡ ´ëÇÑ ±¸¼º ÆÄÀÏÀÇ ¼³Á¤ÀÌ No·Î ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ¼³Á¤À» Yes¿¡¼­ No·Î º¯°æÇØ¾ß ÇÏ´Â °æ¿ì ½Ã½ºÅÛ¿¡¼­ ÇØ´ç µ¥¸óÀ̳ª ¼­ºñ½º¸¦ Ȱ¼ºÈ­ÇØ¾ß »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. ¼³Á¤À» º¯°æÇÑ ÈÄ ±¸¼º ÆÄÀÏÀ» ¼±ÅÃÇÑ À§Ä¡¿¡ ÀúÀåÇÕ´Ï´Ù.

    Would you like to deactivate the NFS server on this system
    Would you like to deactivate NIS client programs?
    Should Bastille ensure inetd's bootp service does not run on this system?
    Should Bastille ensure inetd's TFTP service does not run on this system?
    

  5. ¹æÈ­º®À» ¾÷µ¥ÀÌÆ®Çϰųª Bastille¿¡¼­ »õ ¹æÈ­º®À» ¸¸µéµµ·Ï ÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

    1. /etc/opt/ipf/ipf.conf ÆÄÀÏÀ» ¼±ÅÃÇÑ À§Ä¡¿¡ ¹é¾÷ÇÕ´Ï´Ù.

    2. /etc/opt/sec_mgmt/bastille/ipf.customrules ÆÄÀÏÀ» ÆíÁýÇÏ°í ´ÙÀ½°ú °°ÀÌ º¯°æÇÏ¿© Bastille »ç¿ë HP-UX IPFilter ¹æÈ­º®¿¡ ´ëÇÑ Æ÷Æ® Á¤º¸¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù.

      • ´ÙÀ½°ú °°ÀÌ Ç¥½ÃµÇµµ·Ï udp dp outgoing rule ³¡¿¡ keep frags¶ó´Â ´Ü¾î¸¦ Ãß°¡ÇÕ´Ï´Ù.

        pass out quick proto udp all keep state keep frags

      • ´ÙÀ½ ÁÙÀ» Á¦°ÅÇϰųª ÁÖ¼® ó¸®ÇÕ´Ï´Ù.

        block in quick proto udp from any to any port = portmap

      • End allow outgoing rules ¼½¼Ç µÚ¿¡ ´ÙÀ½ ÁÙÀ» Ãß°¡ÇÕ´Ï´Ù.

        # ports required for Ignite-UX
        ############################################################
        pass in log quick proto udp from any to any port = 69 keep state
        pass in log quick proto udp from any port = 68 to any port = 67 keep state
        pass in log quick proto udp from any port = 1068 to any port = 1067 keep state
        pass in log quick proto tcp/udp from any to any port = 2049 keep frags
        pass in log quick proto tcp from any to any port = 2121
        pass in log quick proto tcp/udp from any to any port 49152 >< 65535
        pass in log quick proto tcp from any to any port = 20
        pass in log quick proto tcp from any to any port = 21
        pass in log quick proto tcp from any to any port = 22
        pass in log quick proto tcp from any to any port = 514
        pass in log quick proto icmp from any to any icmp-type 8 keep state
        pass in log quick proto tcp from any port = 514 to any keep state
        

    3. BastilleÀÇ IPFilter ¸ðµâ¿¡¼­ ´ÙÀ½ ÁÙÀ» Yes·Î º¯°æÇÕ´Ï´Ù.

      Should Bastille setup basic firewall rules with these properties?

    4. BastilleÀ» ½ÇÇàÇÕ´Ï´Ù.

      # bastille -b -f your_configuration_file

  6. ½Ã½ºÅÛ¿¡ ´ëÇØ Bastille ±âÁØÀ» ¸¸µç °æ¿ì¿¡´Â ÇØ´ç ±âÁØÀ» ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù.

    # bastille_drift --save_baseline baseline

Ignite-UX Ŭ¶óÀÌ¾ðÆ® ¿ä±¸ »çÇ× È°¼ºÈ­

Ŭ¶óÀÌ¾ðÆ®¿¡¼­ Ignite-UX ¿ä±¸ »çÇ×À» Ȱ¼ºÈ­ÇÏ·Á¸é ¸ÕÀú ÇöÀç Àá±Ý »óŸ¦ °Ë»öÇϰí ÇÊ¿äÇÑ °æ¿ì ÇØ´ç »óŸ¦ ¼öÁ¤ÇÏ¿© NFS µ¥¸ó ¹× rtools ¼­ºñ½º°¡ ½ÇÇàµÇµµ·Ï ÇØ¾ß ÇÕ´Ï´Ù. ¶ÇÇÑ Ignite-UX Ŭ¶óÀÌ¾ðÆ®¿¡¼­ »ç¿ëÇϴ ƯÁ¤ Æ÷Æ®¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Çã¿ëÇØ¾ß ÇÕ´Ï´Ù.

  1. ÇöÀç Àá±Ý »óŸ¦ °Ë»öÇÕ´Ï´Ù.

    • Bastille 3.0 ÀÌ»óÀ» »ç¿ëÇϰí ÀÖ´Â °æ¿ì ±¸¼º º¸°í¼­¸¦ ¸¸µì´Ï´Ù. º¸°í¼­´Â /var/opt/sec_mgmt/bastille/log/Assessment/assessment-log.config¿¡ ¸¸µé¾îÁý´Ï´Ù.

      # bastille --assessnobrowser

    • 3.0 ÀÌÀü ¹öÀüÀÇ BastilleÀ» »ç¿ëÇϰí ÀÖ´Â °æ¿ì Bastille¿¡¼­ »ç¿ëÇÏ´Â Ãֽб¸¼º ÆÄÀÏÀ» °¡Á®¿É´Ï´Ù.

      # bastille -l

    Âü°í: ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö°¡ Ç¥½ÃµÉ ¼ö ÀÖ½À´Ï´Ù.
    NOTE:    The system is in its pre-bastilled state.
    ÀÌ·± °æ¿ì Ignite-UX¿¡ ÇÊ¿äÇÑ µ¥¸ó, ¼­ºñ½º ¹× Æ÷Æ®°¡ Bastille ÀÌÀü »óÅ·ΠÀá°Ü ÀÖÁö ¾ÊÀ¸¹Ç·Î ÀÌ ±¸¼ºÀ» °è¼Ó ÁøÇàÇÒ Çʿ䰡 ¾ø½À´Ï´Ù.

  2. »ç¿ëµÈ ¸¶Áö¸· ±¸¼º ÆÄÀÏÀ̳ª Æò°¡ º¸°í¼­¸¦ ¼±ÅÃÇÑ À§Ä¡¿¡ º¹»çÇÕ´Ï´Ù.

  3. Bastille GUI¿¡ Ãֽб¸¼ºÀ» Ç¥½ÃÇÕ´Ï´Ù.

    # bastille --os [HP-UX11.00 | HP-UX11.11 | HPUX11.23 | HPUX11.31] -f filename

  4. NFS µ¥¸ó ¹× rtools ¼­ºñ½º¿¡ ´ëÇÑ ±¸¼º ÆÄÀÏÀÇ ¼³Á¤ÀÌ No·Î ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ¼³Á¤À» Yes¿¡¼­ No·Î º¯°æÇØ¾ß ÇÏ´Â °æ¿ì ½Ã½ºÅÛ¿¡¼­ ÇØ´ç µ¥¸óÀ̳ª ¼­ºñ½º¸¦ Ȱ¼ºÈ­ÇØ¾ß »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. ¼³Á¤À» º¯°æÇÑ ÈÄ ±¸¼º ÆÄÀÏÀ» ¼±ÅÃÇÑ À§Ä¡¿¡ ÀúÀåÇÕ´Ï´Ù.

    Would you like to deactivate the NFS client daemons?
    Should Bastille ensure that the login, shell, and exec services do not run on this system?
    

  5. ¹æÈ­º®À» ¾÷µ¥ÀÌÆ®Çϰųª Bastille¿¡¼­ »õ ¹æÈ­º®À» ¸¸µéµµ·Ï ÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

    1. /etc/opt/ipf/ipf.conf ÆÄÀÏÀ» ¼±ÅÃÇÑ À§Ä¡¿¡ ¹é¾÷ÇÕ´Ï´Ù.

    2. /etc/opt/sec_mgmt/bastille/ipf.customrules ÆÄÀÏÀ» ÆíÁýÇÏ°í ´ÙÀ½°ú °°ÀÌ º¯°æÇÏ¿© Bastille »ç¿ë HP-UX IPFilter ¹æÈ­º®¿¡ ´ëÇÑ Æ÷Æ® Á¤º¸¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù.

      • ´ÙÀ½°ú °°ÀÌ Ç¥½ÃµÇµµ·Ï udp dp outgoing rule ÁÙ ³¡¿¡ keep frags¶ó´Â ´Ü¾î¸¦ Ãß°¡ÇÕ´Ï´Ù.

        pass out quick proto udp all keep state keep frags

      • End allow outgoing rules ¼½¼Ç µÚ¿¡ ´ÙÀ½ ÁÙÀ» Ãß°¡ÇÕ´Ï´Ù.

        # ports required for Ignite-UX
        ############################################################
        pass in log quick proto icmp from any to any icmp-type 8 keep state
        pass in log quick proto tcp from any to any port = 512
        pass in log quick proto tcp from any to any port = 514
        pass in log quick proto tcp/udp from any port = 2049 to any keep frags
        pass in log quick proto tcp/udp from any to any port 49152 >< 65535

    3. BastilleÀÇ IPFilter ¸ðµâ¿¡¼­ ´ÙÀ½ ÁÙÀ» Yes·Î º¯°æÇÕ´Ï´Ù.

      Should Bastille setup basic firewall rules with these properties?

    4. BastilleÀ» ½ÇÇàÇÕ´Ï´Ù.

      # bastille -b -f your_configuration_file

  6. ½Ã½ºÅÛ¿¡ ´ëÇØ Bastille ±âÁØÀ» ¸¸µç °æ¿ì¿¡´Â ÇØ´ç ±âÁØÀ» ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù.

    # bastille_drift --save_baseline baseline

Àμâ¿ë ÆäÀÌÁö
°³ÀÎÁ¤º¸ º¸È£¹® º» »çÀÌÆ® ÀÌ¿ëÀº º» Á¶Ç׵鿡 ´ëÇÑ µ¿ÀÇ·Î °£Áֵ˴ϴÙ
© Hewlett-Packard Development Company, L.P.