ö̾ ؼ Ʈũ ʼ
ֱ ο PC ȯ ̵Ǹ鼭 NAC Ȱ å ߿ ִ. Ư ̰ ߴ 7.7 DDoS PC ȯ ߿伺 ٽ ǰ ִ. ̷ NAC ܼ PC Ʈũ ټ Ӹ ƴ϶ PC ϰ ϴ ϰ ־ ִ. NAC å ü PC ϵ ȭϰ ־ ü Ƚýۿ Ȱ뵵 ȮǾ ȴڵ ɵ ִ. ̷ NAC ַ ȿ Ʈũ ǥ ؼϰ , ø̼ Ⱑ Ʈũ ൿϴ ɷ Ȯϰ ö̾ ؼ ⸦ Ʈũ Ἲ ֵ Ѵ. NAC ̷ ֱ Ʈũ ʼ Ұ ȴ.
NAC, Ʈũ
ǥءö̾
Ʈũ ȯ ܼϰ ϰ ȼ ȭ
ͳݰ Ʈũ ߴԿ Ʈũ ǰ ߴ. ⺻ Ʈũ ǰ ȭ Ȯ ̸ پ ǰ Ʈũ ý Ʈũ ȯ濡 ߾ ǰ ɵ ȭϰ ִ.
Ʈũ WIPS(Wireless IPS : ħԹ), ý Ƚý۵ ϵǾ ǰ ִ. κ Ʈũ ý۵ ɰ ̽ Ʈũ ܺηκ ŷ Ⱑ(Giga) ̻ Ʈũ ȯ濡 ڴ 䱸 ذ ʴ.
Ư , ̷ ΰ Ʈ 巯 ִ.
2003 1.25 ķ Ʈ ʿ伺 εǾ NAC(Network Access Control : Ʈũ ) ο Ʈũ ǰ źϰ Ǿ. ÿ Gartner, IDC Ը ߾ ų Ŀ ִ. ѱͳ 2008 Ƚ ⺸ 15% ̻ ϰ ִ.
Ʈũ(NAC) ַ Ʈũ ϴ Ӵܸ ȼ ȭ ִ 㰡 ʰų ̷?? Ǽڵ忡 PC Ǵ Ʈ, ܸ Ʈũ ӵǴ õ ý ü ȣϸ ȼؿ ö̾(Compliance) ϴ θ ý̴. Ư ö̾ Ա ۷ι ǥ ִ ߿ ް ִ.
NAC µ 6 ð 帣鼭 ǰ ⼺, ַǰ ߺ , ȿ (ȿ), ġ ⼺, ǥȭ , Ⱓ Ѱ Ȳ غ Ʈũ ַμ Ȯ ִ.
NAC ַ ɺκп ġ , ȣȭ, AD/Radius , ݸ/ġ, ȭ, IPS, ڻ, ö̾ ϰ ִ. ǥذ ؼ SNMP Community, IEEE 802.1x, Wi-Fi WPA/WPA2, EAP, Switch/Router Protocol ǥ Ѿ ǵ ִ.
10 ̻ NAC ü 3~4 NAC ü ǰ ִ. NAC ǰ , Network Infra , ǰ տ پ ǰ õǰ ִ.
켱 Client/Clientless ִµ ̸ ٸ ǥ ڸ Host-Based-NAC/Network-Based-NAC ִ. ̴ ȱ ȭ Ʈ ϴĸ Enforcement ϴµ ܸġ ϴ ƴϸ Ʈũ ϴķ ְڴ. Client Ȱȭ ְ NAC ־ ϰ Ʈ, HelpDesk ٴ Ư¡ Clientless NAC ϸ å ϴ.
Out-of-Band İ In-Line Ʈũ ִ. Out-of-Band NAC Ʈũ ġ Ϲ Port Ȥ Mirroring Port ؼ NAC ǰ ϴ μ ֽ Ʈũ ū ʴ´.
ַ 麻 ġ NAC Ͽ ϴ Ϲ̸ In-Line ȸѴٴ ִ. ݸ鿡 In-Line Ʈũ Access ġ Distribution Layer ̿ ü ġϸ Traffic Flow ġϱ Ŷ ó ɷ 䰡 Ǿ Ѵ. Ʈũ ġϹǷ ֽ Ʈũ ü ȭ ų ִ ִ.
NAC ַ ȭ̳ UTM ܺθ ȣǰ θ ȣϴµ ΰ ִ. ܸ ༺ Ʈũ ü ū ִ.
⺻ ܸġ ġ/ PC Ἲ End-Point , ̷?? Ʈ ε , ҿ Ʈũ , OS ġ , USB ü , å ݿ ݸ , ༺ , Virtual Firewall(ȭ), Behavior based IPS(ħŽ), Asset Portal(ڻ) Ӹ ƴ϶ ֱٿ ö̾ ν ȣ ü ɱ ϰ ִ.
Ư ö̾ NAC Ա ȼ ִ پ ü(PCI DSS, ISO 27001, SOX ) ν ǰ ÿ ִٴ ū ִ.
Ʈũ ȯ
ֱ IT Ʈũ ȯ ũ, , Ʈ, PDA, Ʈ ũ Ȯƴ. ̿ , , Ʈ, , 繫 پ ܺ ̽ ȯ濡 ȣ Ʈũ ذؾ ġ ΰ ִ.
̿ پ Ʈŷ Ȱϰ ǰ ִ IT ȯ 鿡 ٹ ȯ ϰ δ Ͻ ϴ ִ. Ư Ʈ ̽ IT ȯ Ͽ ڵ å ؼϰ ִ, ý ľϱ .
̷ Ȳ , ø ̻ ȣ ö̾ ؼ ̽ Ʈũ , ֿ , Ʈũ ٿŸ, ؼ ¡ ̷ پ 迡 ִ١ ö̾ Źͽ å ߴٰ ϴ ̴ ̽ ؼž߸ ǹ̰ ִ ̶͡ ߴ.
̿ NAC ý Ʈũ ʼ Ҷ ִ. NAC ȿ Ե NAC ý Ʈũ ǥ ؼϰ , ø̼ Ⱑ Ʈũ ൿϴ ɷ Ȯϰ ö̾ ؼ ⸦ Ʈũ Ἲ ֵ Ѵ.
̻ NAC ý ϴ , Ʈ Ʈũ ö̾ ؼϰ ִٴ Ȯ ְ ̸ 꼺 Ű ʰ Ἲ ִ. ƹ͵ ʴ ͡ٵ ܼϰ ̶͡ ߴ.
NAC Ȱ å ߿
ο PC ȯ ̵Ǹ鼭 NAC Ȱ å ߿ ִ. Ư ̰ ߴ 7.7 DDoS PC ȯ ߿伺 ٽ NAC Ȱ å ϰų PC ϴ , NAC պ Ȯǰ ִ.
̿ ؼ ο ݽý ̻ Ⱥ Ʈ PC ŷ Ž ý å ̳ PC ȿ ŷ ִ ߴ.
̻ PC ŷ Ž ý 16 25 ó PC Ǵ Ʈμ ִŬ NAC PC å ȿ ϰ PC Ʈũ 뿡 ּȭ ֵ ش١ ߴ.
̾ ״ Ư Ʈ NAC Ȱ ̷ ̳ PMS, IP/MAC, ȾƮ ȭ, ʼ α üũ PC ȭ ȯ ֵ ϰ ִ١ Ʈũ Ʈ ϰ (SYN, TCP, UDP, ICMP) з Ӱġ ־ Ʈ ߾ӿ ֵ ϰ ִ. ̸ ġ Ȱȭ ε(Zero-day) Ȳ ִٴ ִ١ ٿ.
ť ̻ NAC ַ ̿ DDoS ϴ ؼ DDoS Ϲ PC Ǽڵ带 л PC Ʈũ Ʈ Ÿ꿡 ߽ õϱ Ʈũ Ʈ PC ãƳ ̸ ݸ ġν DDoS ҽų ִ١ ߴ.
̳ ̿ϴ PC PC ̿ ڰ Ǵ ڰ ֱ ش ̿ غ ʿ Ȳ̴. PC ϱ ؼ PC ൿ ľϰ Ʈũ ִ ü谡 ʿϴ. ̸ ؼ Ʈũ ڰ IP ҽ Ǵ Ʈ ּ(URL) ʴ ~ ȸ ȸϴ ܸ ϰ ϴ 䱸ȴ.
̻ Ʈ NAC ַ ݼ Ʈ ȿ ϰ PC å ݸ Ǵ ġ ִ١ ٿ.
̿ NAC ܼ PC Ʈũ ټ ƴ϶ PC ϰ ϴ ϰ ִٴ ش. ƿ å ü PC ϰ ְ ־ ӻ ð ִ.
NAC Խ
켱 Wished List ۼ ù ° Ʈ ̴. NAC ǰ ſ پ ̾ پ Ѵ. ̷ ϰ ϴ ּ ƴϴ.
ڽŰ IT , Ʈũ ̱ ؼ ݵ ǵž κ NAC ̴.
и Wished List پ ǰ غ и 100% ƴ 90% ̻ 䱸 ϴ ַ ݵ ̴. и ؾ Must-Have Ѵٴ ϱ ٶ. Wished List Ϸʸ ̴.
° ں ȱ Ȯ ؾ Ѵ. ں̶ ϴ κп 츮 ؾ Ժ ̿ܿ , Help Desk ϴ ȴ.
NAC ַ ַǿ ̴. Enfor cement ¿ Ʈũ 籸 Ȥ ̵ؾ ϴ 뵵 ϸ 翡 ɼ ǰ ִ κ ִ.
In-Line NAC ǰ Edge ؾ ϴ Ͽ ݴ ŭ Trade Off ֱ ̴.
鿡 غ ()뿡 ϱ (η Ⱓ ) ݵ غ غ ̴.
å ؼ å 꼺 ϰ Ǵ ƾ ̱ ϴ.
Enforcement ߿ Network Infra NAC Help Desk ҿǴ ݸ鿡 Host-based NAC Help Desk ҿǸ ̴ åȭ(Compliance Check) å Կ ̰ ִ.
ǰ ݽÿ ȳ ü ܸ 3,000 ڰ ȭ Ӿ Help Desk 뵵 Ѵٰ ƾ ̴. ° ǰ ̴.
< : ȣ 21c (is21@boannews.com)>
[ ȣ21c 112ȣ(info@boannews.com)]
<۱: ȴ(www.boannews.com) ->