Alerts

Alerts

Overview

Alerts ํŽ˜์ด์ง€์—์„œ๋Š” ๋ฆฌ์†Œ์Šค ์ ‘๊ทผ๊ณผ ๊ด€๋ จํ•œ ์•Œ๋ฆผ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ฃผ์š” ์ด์ƒ ์ง•ํ›„์— ๋Œ€ํ•œ ํŠธ๋ฆฌ๊ฑฐ ์กฐ๊ฑด์„ ๋ฏธ๋ฆฌ ์„ค์ •ํ•จ์œผ๋กœ์จ ์ •์ฑ… ์œ„๋ฐ˜์‚ฌํ•ญ์„ ์‹ค์‹œ๊ฐ„์œผ๋กœ ํƒ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž ์žฌ์ ์ธ ๋ณด์•ˆ ์‚ฌ๊ณ ๋ฅผ ์‹ ์†ํ•˜๊ฒŒ ์‹๋ณ„ํ•˜๊ณ  ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์‚ฌ์ „ ์ •์˜๋œ ์ž„๊ณ„๊ฐ’์„ ์ดˆ๊ณผํ•˜๋Š” ์กฐํšŒ ๋˜๋Š” ์œ ์ถœ ๋“ฑ ๋ฏผ๊ฐํ•œ ์ •๋ณด๋ฅผ ๋ณดํ˜ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

แ„‰แ…ณแ„แ…ณแ„…แ…ตแ†ซแ„‰แ…ฃแ†บ 2024-07-28 แ„‹แ…ฉแ„’แ…ฎ 10.33.20.png
Administrator > General > Company Management > Alerts

์ด ๋ฌธ์„œ์—์„œ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋‚ด์šฉ์„ ๋‹ค๋ฃน๋‹ˆ๋‹ค.

์ง€์›ํ•˜๋Š” ์•Œ๋ฆผ ์œ ํ˜•

๊ณตํ†ต ์•Œ๋ฆผ์„ ๋น„๋กฏํ•˜์—ฌ DB ์ ‘๊ทผ์— ํŠนํ™”๋œ ์•Œ๋ฆผ๊ณผ ์‹œ์Šคํ…œ ์ ‘๊ทผ์— ํŠนํ™”๋œ ์•Œ๋ฆผ์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

์„œ๋น„์Šค๋ณ„๋กœ ์ง€์›ํ•˜๋Š” ์•Œ๋ฆผ ์œ ํ˜•์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

์„œ๋น„์Šค ๊ตฌ๋ถ„

์•Œ๋ฆผ ํƒ€์ž…๋ช…

์„ค๋ช…

์„œ๋น„์Šค ๊ตฌ๋ถ„

์•Œ๋ฆผ ํƒ€์ž…๋ช…

์„ค๋ช…

SAC, DAC, KAC

New Request

์ƒˆ๋กœ์šด ๊ฒฐ์žฌ ์š”์ฒญ ๋“ฑ๋ก ์•Œ๋ฆผ

General

Unusual Login Attempt

IP ๋Œ€์—ญ์— ๋”ฐ๋ฅธ ์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธ ํ–‰์œ„ ์•Œ๋ฆผ

DAC

SQL Execution

์ •์˜๋œ ์กฐ๊ฑด์— ํ•ด๋‹นํ•˜๋Š” SQL ๊ตฌ๋ฌธ ์‹คํ–‰ ์•Œ๋ฆผ

DAC

Prevented SQL Execution

๊ถŒํ•œ ์—†๋Š” ๊ตฌ๋ฌธ ์‹คํ–‰ ์•Œ๋ฆผ

DAC

DB Connection Attempt

DB ์ ‘์† ์„ฑ๊ณต ๋˜๋Š” ์‹คํŒจ ์•Œ๋ฆผ

DAC

Sensitive Data Access

์ •์˜๋œ ์กฐ๊ฑด์— ํ•ด๋‹นํ•˜๋Š” ๋ฏผ๊ฐ๋ฐ์ดํ„ฐ ์กฐํšŒ ์•Œ๋ฆผ

DAC

SQL Export

์ •์˜๋œ ์กฐ๊ฑด์— ํ•ด๋‹นํ•˜๋Š” SQL ๋‚ด๋ณด๋‚ด๊ธฐ ์‹คํ–‰ ์•Œ๋ฆผ

SAC

Server Connection Attempt

์„œ๋ฒ„ ์ ‘์† ์„ฑ๊ณต ๋˜๋Š” ์‹คํŒจ ์•Œ๋ฆผ

SAC

Restricted Command

์„œ๋ฒ„/์„œ๋ฒ„ ๊ทธ๋ฃน๋ณ„ ์ฐจ๋‹จ๋œ ๋ช…๋ น์–ด ์‹คํ–‰ ์•Œ๋ฆผ

SAC

Specific Command

ํŠน์ • ๋ช…๋ น์–ด ์‹คํ–‰ ์•Œ๋ฆผ

SAC

File Transfer (SFTP)

SFTP๋ฅผ ํ†ตํ•œ ํŒŒ์ผ ์ „์†ก ์‹คํ–‰ ์•Œ๋ฆผ

KAC

K8s API Request

์ฟ ๋ฒ„๋„คํ‹ฐ์Šค API ์š”์ฒญ ์•Œ๋ฆผ

  • 10.2.2 ์ดํ›„ ๋ฒ„์ „์—์„œ ์ง€์›

11.1.0๋ถ€ํ„ฐ New DAC Policy Management ๊ธฐ๋Šฅ์ด ํ™œ์„ฑํ™”๋œ ๊ฒฝ์šฐ ์•„๋ž˜์™€ ๊ฐ™์€ ์•Œ๋ฆผ ์œ ํ˜•์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • New Request - DB Policy Exception Request
    DB Policy Exception Request๋Š” Unmasking๊ณผ Restricted Data Access ๋‘ ๊ฐ€์ง€ ์œ ํ˜•์ด ์žˆ์œผ๋‚˜ ๊ตฌ๋ถ„ํ•ด์„œ ์•Œ๋ฆผ์„ ์ƒ์„ฑํ•  ์ˆ˜๋Š” ์—†์Šต๋‹ˆ๋‹ค.

  • Data Access

    • Column Data Masking : ์‹  ์ •์ฑ… ๊ด€๋ฆฌ์—์„œ ์ƒ์„ฑํ•œ Column Data Masking ์ •์ฑ…์— ๊ฑธ๋ ค ์ œํ•œ๋œ ๋งˆ์Šคํ‚น ๋œ ์ƒํƒœ๋กœ ์กฐํšŒ๋œ ์ด๋ฒคํŠธ

    • Table Access Restriction : ์‹  ์ •์ฑ… ๊ด€๋ฆฌ์—์„œ ์ƒ์„ฑํ•œ Table Access Restriction ์ •์ฑ…์— ๊ฑธ๋ ค ํŠน์ • ํ…Œ์ด๋ธ” ์ ‘๊ทผ์ด ์ œํ•œ๋œ ์ด๋ฒคํŠธ

    • Column Access Restriction : ์‹  ์ •์ฑ… ๊ด€๋ฆฌ์—์„œ ์ƒ์„ฑํ•œ Column Access Restriction ์ •์ฑ…์— ๊ฑธ๋ ค ํŠน์ • ์ปฌ๋Ÿผ ์ ‘๊ทผ์ด ์ œํ•œ๋œ ์ด๋ฒคํŠธ

    • Sensitive Data Access Monitoring : ์‹  ์ •์ฑ… ๊ด€๋ฆฌ์—์„œ ์ƒ์„ฑํ•œ Sensitive Data Access Monitoring ์ •์ฑ…์˜ ์กฐ๊ฑด์— ํ•ด๋‹น๋˜๋Š” ์ด๋ฒคํŠธ

์•Œ๋ฆผ ์ƒ์„ฑํ•˜๊ธฐ

Alerts ํŽ˜์ด์ง€ ์šฐ์ƒ๋‹จ Create Alert ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์ƒˆ๋กœ์šด ์•Œ๋ฆผ์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. OK ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์•Œ๋ฆผ ์ƒ์„ฑ์„ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.

แ„‰แ…ณแ„แ…ณแ„…แ…ตแ†ซแ„‰แ…ฃแ†บ 2024-07-29 แ„‹แ…ฉแ„’แ…ฎ 2.17.28.png
Administrator > General > Company Management > Alerts > Create Alert
  1. Name : ์•Œ๋ฆผ ์ด๋ฆ„

  2. Alert Type : ์•Œ๋ฆผ ์œ ํ˜•์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

    1. ์•Œ๋ฆผ ์œ ํ˜•๋ณ„๋กœ ์„ค์ • ๊ฐ€๋Šฅํ•œ ์กฐ๊ฑด์ด ์ƒ์ดํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ํ•˜๋‹จ ๋ฌธ์„œ๋ฅผ ์ฐธ๊ณ ํ•ด์ฃผ์„ธ์š”.

  3. Message Template : ์•Œ๋ฆผ ๋ฉ”์‹œ์ง€ ํ…œํ”Œ๋ฆฟ์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

    1. Message Template Variable์—์„œ ์ง€์›ํ•˜๋Š” ํ…œํ”Œ๋ฆฟ ๋ณ€์ˆ˜๋ฅผ ํ™œ์šฉํ•˜์—ฌ ์ปค์Šคํ…€ํ•œ ๋ฉ”์‹œ์ง€๋ฅผ ์ž‘์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    2. Message Template Variable์€ Alert Type ๋ณ„๋กœ ์ƒ์ดํ•ฉ๋‹ˆ๋‹ค.

  4. Channel : ์•Œ๋ฆผ ๋ฐœ์†ก ์ฑ„๋„

    1. Administrator > General > Channels ์— ๋“ฑ๋ก๋œ ์ฑ„๋„ ์ค‘ ํ•˜๋‚˜๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

    2. ์ฑ„๋„์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์„ค๋ช…์€ Channels ๋ฌธ์„œ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

  5. Subject Title : Channel์„ Email๋กœ ์„ ํƒํ•œ ๊ฒฝ์šฐ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. ์ด๋ฉ”์ผ ์•Œ๋ฆผ์˜ ์ œ๋ชฉ์„ ์ง์ ‘ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, Message Template Variable์—์„œ ์ง€์›ํ•˜๋Š” ๋ณ€์ˆ˜๋ฅผ ๋™์ผํ•˜๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž…๋ ฅํ•˜์ง€ ์•Š์„ ๊ฒฝ์šฐ, ์‹œ์Šคํ…œ์—์„œ ๊ธฐ๋ณธ์œผ๋กœ ์„ค์ •๋œ ์ œ๋ชฉ์œผ๋กœ ๋ฐœ์†ก๋ฉ๋‹ˆ๋‹ค.

  6. Send Test Message : ์•Œ๋ฆผ ํ…Œ์ŠคํŠธ ๋ฉ”์‹œ์ง€ ๋ฐœ์†ก

    1. ์„ ํƒํ•œ ์ฑ„๋„๋กœ, ์ž…๋ ฅํ•œ ๋ฉ”์‹œ์ง€ ํ…œํ”Œ๋ฆฟ ๋‚ด์šฉ์„ ํ…Œ์ŠคํŠธ ๋ฉ”์‹œ์ง€๋กœ ์ „์†กํ•ฉ๋‹ˆ๋‹ค.

New Request

์ƒˆ๋กœ์šด ๊ฒฐ์žฌ ์š”์ฒญ ๋“ฑ๋ก ์•Œ๋ฆผ

  • Request Type : Workflow ์š”์ฒญ ์œ ํ˜•

    • DB Access Request, SQL Request, SQL Export Request, Server Access Request, Access Role Request, Unmasking Request ์ค‘ ํƒ ์ผ

    • All Requests (*) : ๋ชจ๋“  ์š”์ฒญ ํƒ€์ž…์— ๋Œ€ํ•ด ์•Œ๋ฆผ ๋ฐœ์†ก

  • Urgent Mode : ์‚ฌํ›„ ์Šน์ธ ์—ฌ๋ถ€

    • All : ๋ชจ๋“  ์Šน์ธ ์š”์ฒญ ๊ฑด์— ์•Œ๋ฆผ ๋ฐœ์†ก

    • Urgent Mode Only : ์‚ฌํ›„ ์Šน์ธ ์š”์ฒญ ๊ฑด๋งŒ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Send email only to those involved in this request : Channel์„ Email๋กœ ์„ ํƒํ•œ ๊ฒฝ์šฐ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. ์ด ์˜ต์…˜์„ ํ™œ์„ฑํ™”ํ•˜๋ฉด ํ•ด๋‹น ์š”์ฒญ์˜ ๊ด€๋ จ์ž(์š”์ฒญ์ž, ์Šน์ธ์ž ๋“ฑ)์—๊ฒŒ Message Template์˜ ๋‚ด์šฉ์„ ๋‹ด์€ ์•Œ๋ฆผ์ด ๋ฐœ์†ก๋ฉ๋‹ˆ๋‹ค.

ย 

10.2.2 ์Šฌ๋ž™ ๋ฉ”์‹œ์ง€ ํ…œํ”Œ๋ฆฟ ๋ณ€๊ฒฝ ์‚ฌํ•ญ

  • Slack > API ๋ฐฉ์‹์˜ Channel๋กœ ์ „์†ก๋˜๋Š” ์•Œ๋ฆผ ๋ฉ”์‹œ์ง€์—์„œ {{assignees}} ์— ๋Œ€ํ•œ Slack ์‚ฌ์šฉ์ž ๋ฉ˜์…˜์ด ์ง€์›๋ฉ๋‹ˆ๋‹ค.

  • Request Type ์„ ํƒ์— ๋”ฐ๋ผ ์ง€์›๋˜๋Š” ํ…œํ”Œ๋ฆฟ ๋ณ€์ˆ˜๊ฐ€ ์ƒ์ดํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๋ณ„๋„์˜ New Request > ์š”์ฒญ ํƒ€์ž…๋ณ„ ํ…œํ”Œ๋ฆฟ ๋ณ€์ˆ˜ ๋ฌธ์„œ๋ฅผ ์ฐธ๊ณ ํ•ด์ฃผ์„ธ์š”.

10.2.8 ์Šฌ๋ž™ ๋ฉ”์‹œ์ง€ ํ…œํ”Œ๋ฆฟ ๋ณ€๊ฒฝ ์‚ฌํ•ญ

  • Sensitive Data Access ์ด๋ฒคํŠธ์—์„œ ์Šฌ๋ž™ ๋ฉ”์‹œ์ง€์— ์ฟผ๋ฆฌ๋ฅผ ํฌํ•จํ•˜์—ฌ ์ „์†กํ•˜๋„๋ก ๊ฐœ์„ ๋˜๋ฉด์„œ {{queryPreview}} ๋ณ€์ˆ˜๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์Šฌ๋ž™ ํŠน์„ฑ์ƒ 3000์ž ์ด์ƒ์˜ ๋ฉ”์‹œ์ง€ ๋ฐœ์†ก ์š”์ฒญ์„ ํ•˜๋ฉด ์—๋Ÿฌ ๋ฐ˜ํ™˜ ์—†์ด ๋ฉ”์‹œ์ง€ ๋ฐœ์†ก์ด ์‹คํŒจํ•˜๋ฏ€๋กœ queryPreview๋ฅผ ํ†ตํ•ด ๋ณผ ์ˆ˜ ์žˆ๋Š” ์ฟผ๋ฆฌ๋Š” 100์ž๋กœ ์ œํ•œ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

11.1.0 Request Type ๋ณ€๊ฒฝ ์‚ฌํ•ญ

  • Databases > General > Configurations์—์„œ New DAC Policy Management ๊ธฐ๋Šฅ์ด ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๋‹ค๋ฉด Alert์˜ Request Type์— DB Policy Exception Request๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • DB Policy Exception Request๋Š” Column Data Masking, Table Access Restriction, Column Data Access Restriction์— ๋Œ€ํ•œ ์ •์ฑ… ์˜ˆ์™ธ ์š”์ฒญ ์ด๋ฒคํŠธ๊ฐ€ ๋ฐœ์ƒํ–ˆ์„ ๋•Œ ์•Œ๋ฆผ์ด ๋ฐœ์†ก๋˜๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.

11.2.0 ์ด๋ฉ”์ผ ์•Œ๋ฆผ ํ…œํ”Œ๋ฆฟ ๋ณ€๊ฒฝ ์‚ฌํ•ญ

  • Alert์˜ Channel์„ Email๋กœ ์ง€์ •ํ•  ๊ฒฝ์šฐ, Subject Title (์ด๋ฉ”์ผ ์ œ๋ชฉ) ์„ ์ง์ ‘ ์ž…๋ ฅํ•˜๋Š” ๊ธฐ๋Šฅ์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

  • Workflow ๊ด€๋ จ Alert ์„ค์ • ์‹œ Channel์ด Email์ธ ๊ฒฝ์šฐ, Send email only to those involved in this request ์˜ต์…˜์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ด ์˜ต์…˜์„ ํ™œ์„ฑํ™”ํ•˜๋ฉด ํ•ด๋‹น ์š”์ฒญ์˜ ๊ด€๋ จ์ž(์š”์ฒญ์ž, ์Šน์ธ์ž ๋“ฑ)์—๊ฒŒ Message Template์˜ ๋‚ด์šฉ์œผ๋กœ ์•Œ๋ฆผ์ด ๋ฐœ์†ก๋ฉ๋‹ˆ๋‹ค.

11.3.0 Alert ์ƒ์„ฑํ™”๋ฉด์—์„œ Channel ์„ ํƒ ํ•ญ๋ชฉ

  • Alert ์ƒ์„ฑํ™”๋ฉด์—์„œ Channel ์„ ํƒ ํ•ญ๋ชฉ์—์„œ ๋Œ€์ƒ์„ ์‹๋ณ„ํ•˜๊ธฐ ์šฉ์ดํ•˜๋„๋ก ์•„์ด์ฝ˜์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

Unusual Login Attempt

IP ๋Œ€์—ญ์— ๋”ฐ๋ฅธ ์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธ ํ–‰์œ„ ์•Œ๋ฆผ

  • Action Count : ์•Œ๋ฆผ ๋ฐœ์†กํ•  ์ธ์ฆ ์‹คํŒจ ํšŸ์ˆ˜

    • 2 ์ด์ƒ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • Specific Time Interval (Minutes) : ์•Œ๋ฆผ ๋ฐœ์†ก ๊ธฐ์ค€ ์‹œ๊ฐ„(๋ถ„)

    • 1 ์ด์ƒ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

์˜ˆ) ๋น„์ •์ƒ์ ์ธ ๋กœ๊ทธ์ธ ์‹œ๋„ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก - 5๋ถ„๊ฐ„ QueryPie ๋กœ๊ทธ์ธ ์‹คํŒจ 3ํšŒ ๋ˆ„์  ์‹œ

  • Action Count : 3

  • Specific Time Internal (Minutes) : 5

SQL Execution

์ •์˜๋œ ์กฐ๊ฑด์— ํ•ด๋‹นํ•˜๋Š” SQL ๊ตฌ๋ฌธ ์‹คํ–‰ ์•Œ๋ฆผ

  • Rows : ์•Œ๋ฆผ ๋ฐœ์†ก ๊ธฐ์ค€ ํ–‰ ์ˆ˜

    • ๋ ˆ์ฝ”๋“œ ๋ณ€๊ฒฝ์ด ์—†๋Š” SQL Event : 0 ์ž…๋ ฅ ์‹œ ์ •์ƒ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

      • Create, Drop, Revoke, Truncate ๋“ฑ

    • ๊ทธ ์™ธ SQL Events : 1 ์ด์ƒ ์ž…๋ ฅ ์‹œ ์ •์ƒ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

  • Specific Time Interval (Minutes) : ์•Œ๋ฆผ ๋ฐœ์†ก ๊ธฐ์ค€ ์‹œ๊ฐ„(๋ถ„) (10.2.2 ์ดํ›„ ๋ฒ„์ „)

    • 0 ์ž…๋ ฅ ์‹œ, ์‹œ๊ฐ„ ์กฐ๊ฑด ์—†์ด ๋‹จ๊ฑด์˜ SQL ์‹คํ–‰์„ ๊ธฐ์ค€์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

    • ์ตœ๋Œ€ 1440๊นŒ์ง€ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • SQL Events : ์•Œ๋ฆผ ๋ฐœ์†กํ•  SQL ์ฟผ๋ฆฌ (๋‹ค์ค‘ ์„ ํƒ)

  • Connection : ์ฟผ๋ฆฌ ์‹คํ–‰ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋Œ€์ƒ ์ปค๋„ฅ์…˜ (10.2.2 ์ดํ›„ ๋ฒ„์ „ - ๋‹ค์ค‘ ์„ ํƒ)

    • All Connections (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ์ปค๋„ฅ์…˜ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

์˜ˆ 1) 100๊ฑด ์ด์ƒ์˜ ๋Œ€๋Ÿ‰ ๋ฐ์ดํ„ฐ ์กฐํšŒ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Rows : 100

  • SQL Events : SELECT

์˜ˆ 2) ๋ฐ์ดํ„ฐ ๋ณ€๊ฒฝ ๋ฐ ์‚ญ์ œ ์‹œ๋„ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Rows : 1

  • SQL Events : UPDATE, DELETE

Prevented SQL Execution

๊ถŒํ•œ ์—†๋Š” ๊ตฌ๋ฌธ ์‹คํ–‰ ์•Œ๋ฆผ

  • Connection : ์ฟผ๋ฆฌ ์‹คํ–‰ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋Œ€์ƒ ์ปค๋„ฅ์…˜ (10.2.2 ์ดํ›„ ๋ฒ„์ „ - ๋‹ค์ค‘ ์„ ํƒ)

    • All Connections (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ์ปค๋„ฅ์…˜ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

DB Connection Attempt

DB ์ ‘์† ์„ฑ๊ณต ๋˜๋Š” ์‹คํŒจ ์•Œ๋ฆผ

  • Alert Trigger Condition : ์•Œ๋ฆผ ๋ฐœ์†ก ์กฐ๊ฑด (๋ณต์ˆ˜ ์„ ํƒ)

    • Success : DB ์ ‘์† ์„ฑ๊ณต ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

    • Failure : DB ์ ‘์† ์‹คํŒจ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Connection Failure Trigger with Interval : ์ ‘์† ์‹คํŒจ ํšŸ์ˆ˜/๊ธฐ๊ฐ„ ์•Œ๋ฆผ ์กฐ๊ฑด ์„ค์ •

    • Failure๊ฐ€ ์„ ํƒ๋œ ๊ฒฝ์šฐ์—๋งŒ ํ™œ์„ฑํ™” ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ํ™œ์„ฑํ™” ์‹œ ์ถ”๊ฐ€ ์ž…๋ ฅ ์กฐ๊ฑด์ด ๋…ธ์ถœ๋ฉ๋‹ˆ๋‹ค.

    • Action Count : ํšŸ์ˆ˜ ๊ธฐ์ค€

      • 1 ์ด์ƒ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

    • Specific Time Interval (Minutes) : ๊ธฐ๊ฐ„ ๊ธฐ์ค€ (๋ถ„)

      • 1 ์ด์ƒ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • Connection : ์ฟผ๋ฆฌ ์‹คํ–‰ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋Œ€์ƒ ์ปค๋„ฅ์…˜ (10.2.2 ์ดํ›„ ๋ฒ„์ „ - ๋‹ค์ค‘ ์„ ํƒ)

    • All Connections (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ์ปค๋„ฅ์…˜ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

์˜ˆ) ๋น„์ •์ƒ์ ์ธ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์ ‘์† ์‹œ๋„ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก - 5๋ถ„๊ฐ„ DB ์ ‘์† ์‹คํŒจ 3ํšŒ ๋ˆ„์  ์‹œ

  • Alert Trigger Condition : Failure

  • Connection Failure Trigger with Internal : On

  • Action Count : 3

  • Specified Time Internal (Minutes) : 5

Sensitive Data Access

์ •์˜๋œ ์กฐ๊ฑด์— ํ•ด๋‹นํ•˜๋Š” ๋ฏผ๊ฐ๋ฐ์ดํ„ฐ ์กฐํšŒ ์•Œ๋ฆผ

  • Criteria : ์•Œ๋ฆผ ๋ฐœ์†ก ๊ธฐ์ค€์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

    • Sensitive Level : Sensitive Data Policy > Rule์— ์„ค์ •๋œ ๋ฐ์ดํ„ฐ๋ณ„ ๋ฏผ๊ฐ ๋ ˆ๋ฒจ ๊ธฐ์ค€

      • Low, Medium, High ์ค‘ ํƒ ์ผ

    • Policy : ํŠน์ • Sensitive Data Policy ๊ธฐ์ค€

      • ๋“ฑ๋ก๋œ Sensitive Data Policy ์ค‘ ํƒ ์ผ

  • Rows : ์•Œ๋ฆผ ๋ฐœ์†ก ๊ธฐ์ค€ ํ–‰ ์ˆ˜ (10.2.2 ์ดํ›„ ๋ฒ„์ „)

    • 1 ์ด์ƒ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • Specific Time Interval (Minutes) : ์•Œ๋ฆผ ๋ฐœ์†ก ๊ธฐ์ค€ ์‹œ๊ฐ„(๋ถ„) (10.2.2 ์ดํ›„ ๋ฒ„์ „)

    • 0 ์ž…๋ ฅ ์‹œ, ์‹œ๊ฐ„ ์กฐ๊ฑด ์—†์ด ๋‹จ๊ฑด์˜ SQL ์‹คํ–‰์„ ๊ธฐ์ค€์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

    • ์ตœ๋Œ€ 1440๊นŒ์ง€ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

Sensitive Data Access ์•Œ๋ฆผ ํƒ€์ž… ์‚ฌ์šฉ์„ ์œ„ํ•ด์„œ๋Š” ๋ฏผ๊ฐ ๋ฐ์ดํ„ฐ ์ •์ฑ…์— ๊ฐœ์ธ์ •๋ณด๊ฐ€ ํฌํ•จ๋œ ํ…Œ์ด๋ธ” ๋ฐ ์ปฌ๋Ÿผ์„ ์‚ฌ์ „ ์ •์˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ Sensitive Data ๋ฌธ์„œ๋ฅผ ์ฐธ๊ณ ํ•ด์ฃผ์„ธ์š”.

์˜ˆ1) ๋ฏผ๊ฐ๋ ˆ๋ฒจ High ๋กœ ์„ค์ •๋œ ๊ฐœ์ธ์ •๋ณด ๋ฐ์ดํ„ฐ ์กฐํšŒ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Criteria : Sensitive Level

  • Sensitive Level : High

์˜ˆ2) ํŠน์ • ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ํฌํ•จ๋œ ๊ฐœ์ธ์ •๋ณด ๋ฐ์ดํ„ฐ ์กฐํšŒ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Criteria : Policy

  • Policy : {์‚ฌ์ „์— ๋“ฑ๋ก๋œ Sensitive Data ์ •์ฑ…}

SQL Export

์ •์˜๋œ ์กฐ๊ฑด์— ํ•ด๋‹นํ•˜๋Š” SQL ๋‚ด๋ณด๋‚ด๊ธฐ ์‹คํ–‰ ์•Œ๋ฆผ

  • Rows : ์•Œ๋ฆผ ๋ฐœ์†ก ๊ธฐ์ค€ ํ–‰ ์ˆ˜

    • 1 ์ด์ƒ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • Specific Time Interval (Minutes) : ์•Œ๋ฆผ ๋ฐœ์†ก ๊ธฐ์ค€ ์‹œ๊ฐ„(๋ถ„) (10.2.2 ์ดํ›„ ๋ฒ„์ „)

    • 0 ์ž…๋ ฅ ์‹œ, ์‹œ๊ฐ„ ์กฐ๊ฑด ์—†์ด ๋‹จ๊ฑด์˜ SQL ๋‚ด๋ณด๋‚ด๊ธฐ๋ฅผ ๊ธฐ์ค€์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

    • ์ตœ๋Œ€ 1440๊นŒ์ง€ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • Connection : SQL ๋‚ด๋ณด๋‚ด๊ธฐ ์‹คํ–‰ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋Œ€์ƒ ์ปค๋„ฅ์…˜ (10.2.2 ์ดํ›„ ๋ฒ„์ „ - ๋‹ค์ค‘ ์„ ํƒ)

    • All Connections (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ์ปค๋„ฅ์…˜ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

์˜ˆ) 100๊ฑด ์ด์ƒ์˜ ๋Œ€๋Ÿ‰ ๋ฐ์ดํ„ฐ ๋‚ด๋ณด๋‚ด๊ธฐ ์‹œ๋„ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Alert Type : SQL Export

  • Trigger Condition (Rows) : 100

Server Connection Attempt

์„œ๋ฒ„ ์ ‘์† ์„ฑ๊ณต ๋˜๋Š” ์‹คํŒจ ์•Œ๋ฆผ

  • Result : ์•Œ๋ฆผ ๋ฐœ์†ก ์กฐ๊ฑด

    • Success : ์„œ๋ฒ„ ์ ‘์† ์„ฑ๊ณต ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

    • Failure : ์„œ๋ฒ„ ์ ‘์† ์‹คํŒจ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

11.3.0์—์„œ Failure์˜ ํ•˜์œ„ ์˜ต์…˜์œผ๋กœ Set trigger threshold on failed attempt ์˜ต์…˜์ด ์ถ”๊ฐ€๋˜์–ด ์‹คํŒจ ํšŸ์ˆ˜์˜ ์ž„๊ณ„๊ฐ’์œผ๋กœ alert๋ฅผ ๋ฐœ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋„๋ก ๋ณ€๊ฒฝ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

  • Action Count : ์ด๋ฒคํŠธ๊ฐ€ ๋ฐœ์ƒํ•œ ํšŸ์ˆ˜์ž…๋‹ˆ๋‹ค. 1 ์ด์ƒ์˜ ๊ฐ’์„ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • Time Interval : ์ด๋ฒคํŠธ ๋ฐœ์ƒํ•˜๋Š” ์‹œ๊ฐ„ ๋ฒ”์œ„์ž…๋‹ˆ๋‹ค.

์˜ˆ) ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์„ค์ •์˜ ๊ฒฝ์šฐ Server ์ ‘์† ์‹คํŒจ ์ด๋ฒคํŠธ๊ฐ€ 5๋ถ„ ์ด๋‚ด์— 3ํšŒ ๋ฐœ์ƒ ์‹œ ์•Œ๋ฆผ์„ ๋ฐœ์†กํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

  • Action Count : 3

  • Specific Time Internal (Minutes) : 5

image-20251010-093016.png

ย 

  • Connection : ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋Œ€์ƒ ์ปค๋„ฅ์…˜ (๋‹ค์ค‘ ์„ ํƒ)

    • ์„œ๋ฒ„ ๋ฐ ์„œ๋ฒ„ ๊ทธ๋ฃน ์„ ํƒ ๊ฐ€๋Šฅํ•˜๋ฉฐ, ์ค‘๋ณต ์„ ํƒ ๊ฐ€๋Šฅ

      • ๋‹ค์ค‘ ์„ ํƒ์œผ๋กœ ์ธํ•ด ๋Œ€์ƒ์ด ์ค‘๋ณต ์„ ํƒ๋œ ๊ฒฝ์šฐ์—๋„ ์•Œ๋ฆผ์€ 1ํšŒ๋งŒ ๋ฐœ์†ก

    • All Connections (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ์ปค๋„ฅ์…˜ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

์˜ˆ) ์‚ฌ์šฉ์ž๊ฐ€ ์„œ๋ฒ„ ์ ‘์†์„ ์‹œ๋„ํ–ˆ์œผ๋‚˜ ์‹คํŒจํ•  ๊ฒฝ์šฐ์—๋งŒ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Alert Type : Server Connection Attempt

  • Alert Trigger Condition : Failure ์—๋งŒ ์ฒดํฌ

Restrict Command

์„œ๋ฒ„/์„œ๋ฒ„ ๊ทธ๋ฃน๋ณ„ ์ฐจ๋‹จ๋œ ๋ช…๋ น์–ด ์‹คํ–‰ ์•Œ๋ฆผ

  • Connection : ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋Œ€์ƒ ์ปค๋„ฅ์…˜ (๋‹ค์ค‘ ์„ ํƒ)

    • ์„œ๋ฒ„ ๋ฐ ์„œ๋ฒ„ ๊ทธ๋ฃน ์„ ํƒ ๊ฐ€๋Šฅํ•˜๋ฉฐ, ์ค‘๋ณต ์„ ํƒ ๊ฐ€๋Šฅ

      • ๋‹ค์ค‘ ์„ ํƒ์œผ๋กœ ์ธํ•ด ๋Œ€์ƒ์ด ์ค‘๋ณต ์„ ํƒ๋œ ๊ฒฝ์šฐ์—๋„ ์•Œ๋ฆผ์€ 1ํšŒ๋งŒ ๋ฐœ์†ก

    • All Connections (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ์ปค๋„ฅ์…˜ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

Specific Command

ํŠน์ • ๋ช…๋ น์–ด ์‹คํ–‰ ์•Œ๋ฆผ

  • Connection : ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋Œ€์ƒ ์ปค๋„ฅ์…˜ (๋‹ค์ค‘ ์„ ํƒ)

    • ์„œ๋ฒ„ ๋ฐ ์„œ๋ฒ„ ๊ทธ๋ฃน ์„ ํƒ ๊ฐ€๋Šฅํ•˜๋ฉฐ, ์ค‘๋ณต ์„ ํƒ ๊ฐ€๋Šฅ

      • ๋‹ค์ค‘ ์„ ํƒ์œผ๋กœ ์ธํ•ด ๋Œ€์ƒ์ด ์ค‘๋ณต ์„ ํƒ๋œ ๊ฒฝ์šฐ์—๋„ ์•Œ๋ฆผ์€ 1ํšŒ๋งŒ ๋ฐœ์†ก

    • All Connections (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ์ปค๋„ฅ์…˜ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

  • Command : ์‹คํ–‰ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋ช…๋ น์–ด ์กฐ๊ฑด

    • Keyword : ๋ช…๋ น์–ด์— ์ž…๋ ฅ๋œ ํ‚ค์›Œ๋“œ ํฌํ•จ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

    • RegExr : ์ •๊ทœํ‘œํ˜„์‹์— ํ•ด๋‹นํ•˜๋Š” ๋ช…๋ น์–ด ์‹คํ–‰ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

File Transfer (SFTP)

SFTP๋ฅผ ํ†ตํ•œ ํŒŒ์ผ ์ „์†ก ์‹คํ–‰ ์•Œ๋ฆผ

  • Alert Trigger Condition : ์•Œ๋ฆผ ๋ฐœ์†ก ์กฐ๊ฑด (๋‹ค์ค‘ ์„ ํƒ)

    • FIle Upload : ํŒŒ์ผ ์—…๋กœ๋“œ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

    • File Download : ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Connection : ์•Œ๋ฆผ ๋ฐœ์†กํ•  ๋Œ€์ƒ ์ปค๋„ฅ์…˜ (๋‹ค์ค‘ ์„ ํƒ)

    • ์„œ๋ฒ„ ๋ฐ ์„œ๋ฒ„ ๊ทธ๋ฃน ์„ ํƒ ๊ฐ€๋Šฅํ•˜๋ฉฐ, ์ค‘๋ณต ์„ ํƒ ๊ฐ€๋Šฅ

      • ๋‹ค์ค‘ ์„ ํƒ์œผ๋กœ ์ธํ•ด ๋Œ€์ƒ์ด ์ค‘๋ณต ์„ ํƒ๋œ ๊ฒฝ์šฐ์—๋„ ์•Œ๋ฆผ์€ 1ํšŒ๋งŒ ๋ฐœ์†ก

    • All Connections (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ์ปค๋„ฅ์…˜ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

K8s API Request 10.2.2

์ฟ ๋ฒ„๋„คํ‹ฐ์Šค API ์š”์ฒญ ์•Œ๋ฆผ

  • Result : API ์š”์ฒญ ๊ฒฐ๊ณผ (๋‹ค์ค‘ ์„ ํƒ)

    • Success : ์š”์ฒญ ์„ฑ๊ณต ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

    • Failure : ์š”์ฒญ ์‹คํŒจ ์‹œ ์•Œ๋ฆผ ๋ฐœ์†ก

  • Clusters : API ์š”์ฒญ ์•Œ๋ฆผ ๋ฐœ์†ก ๋Œ€์ƒ ํด๋Ÿฌ์Šคํ„ฐ

    • All Clusters (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ํด๋Ÿฌ์Šคํ„ฐ๋ฅผ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

  • Verbs : ์•Œ๋ฆผ ๋ฐœ์†ก ๋Œ€์ƒ Verb

    • ํ˜„์žฌ ์ง€์› ๋Œ€์ƒ - create, update, patch, delete, deletecollection (5์ข…)

  • Resource Kind : ์•Œ๋ฆผ ๋ฐœ์†ก ๋Œ€์ƒ ๋ฆฌ์†Œ์Šค ์ข…๋ฅ˜

    • ํ˜„์žฌ ์ง€์› ๋Œ€์ƒ - pods, pods/exec, pods/log, pods/portforward, services, ingresses, deployments, replicasets ๋“ฑ (์ด 24์ข…)

    • All Resources (*) : ์ถ”ํ›„ ์ถ”๊ฐ€๋  ๋ชจ๋“  ๋ฆฌ์†Œ์Šค ์ข…๋ฅ˜๋ฅผ ๋Œ€์ƒ์œผ๋กœ ์•Œ๋ฆผ ์กฐ๊ฑด ์ƒ์„ฑ

Data Access 11.1.0

Databases > General > Configurations์—์„œ New DAC Policy Management ๊ธฐ๋Šฅ์ด ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๊ณ  ๊ด€๋ จ ์ •์ฑ…๋“ค์ด ์กด์žฌํ•ด์•ผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Data Access ์•Œ๋ฆผ์€ Column Data Masking, Table Access Restriction, Column Access Restriction, Sensitive Data Access Monitoring ์˜ ๋„ค๊ฐ€์ง€ policy type์„ ์„ ํƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

image-20250727-222007.png
  • Column Data Masking

    • Policy : ์•Œ๋ฆผ ๋ฐœ์ƒ ์กฐ๊ฑด์ด ๋  ๋Œ€์ƒ ์ •์ฑ… ์ด๋ฆ„์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

    • Rows : ์•Œ๋ฆผ ๋ฐœ์ƒ ๊ธฐ์ค€ ํ–‰ ์ˆ˜๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

    • Time Interval : ์•Œ๋ฆผ ๋ฐœ์ƒ ๊ธฐ์ค€ ์‹œ๊ฐ„(๋ถ„ ๋‹จ์œ„)์ž…๋‹ˆ๋‹ค.

      • 0 ์ž…๋ ฅ ์‹œ, ์‹œ๊ฐ„ ์กฐ๊ฑด ์—†์ด ๋‹จ๊ฑด์˜ SQL ์‹คํ–‰์„ ๊ธฐ์ค€์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

      • ์ตœ๋Œ€ 1440๊นŒ์ง€ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • Table Access Restriction

    • Policy : ์•Œ๋ฆผ ๋ฐœ์ƒ ์กฐ๊ฑด์ด ๋  ๋Œ€์ƒ ์ •์ฑ… ์ด๋ฆ„์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

    • Unauthorized Access Attempt Count : ์•Œ๋ฆผ ๋ฐœ์ƒ ์กฐ๊ฑด์ด ๋˜๋Š” ์ ‘๊ทผ ํšŸ์ˆ˜๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค. ๋งŒ์•ฝ Time interval ๊ฐ’์ด 0์ด๋ฉด ์‹œ๊ฐ„ ์กฐ๊ฑด ์—†์ด ๋‹จ๊ฑด์˜ ์ด๋ฒคํŠธ์— ๋Œ€ํ•ด ์•Œ๋ฆผ์ด ๋ฐœ์ƒํ•˜๋ฏ€๋กœ Unauthorized Access Attempt Count๋Š” 1๋กœ ๊ณ ์ •๋ฉ๋‹ˆ๋‹ค. ์ตœ์†Ÿ๊ฐ’์€ 1, ์ตœ๋Œ“๊ฐ’์€ 2147483647์ž…๋‹ˆ๋‹ค.

    • Time Interval : ์•Œ๋ฆผ ๋ฐœ์ƒ ๊ธฐ์ค€ ์‹œ๊ฐ„(๋ถ„ ๋‹จ์œ„)์ž…๋‹ˆ๋‹ค.

      • 0 ์ž…๋ ฅ ์‹œ, ์‹œ๊ฐ„ ์กฐ๊ฑด ์—†์ด ๋‹จ๊ฑด์˜ SQL ์‹คํ–‰์„ ๊ธฐ์ค€์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

      • ์ตœ๋Œ€ 1440๊นŒ์ง€ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • Column Access Restriction

    • Rows : ์•Œ๋ฆผ ๋ฐœ์ƒ ๊ธฐ์ค€ ํ–‰ ์ˆ˜๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

    • Time Interval : ์•Œ๋ฆผ ๋ฐœ์ƒ ๊ธฐ์ค€ ์‹œ๊ฐ„(๋ถ„ ๋‹จ์œ„)์ž…๋‹ˆ๋‹ค.

      • 0 ์ž…๋ ฅ ์‹œ, ์‹œ๊ฐ„ ์กฐ๊ฑด ์—†์ด ๋‹จ๊ฑด์˜ SQL ์‹คํ–‰์„ ๊ธฐ์ค€์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

      • ์ตœ๋Œ€ 1440๊นŒ์ง€ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  • Sensitive Data Access Monitoring

    • Policy : ์•Œ๋ฆผ ๋ฐœ์ƒ ์กฐ๊ฑด์ด ๋  ๋Œ€์ƒ ์ •์ฑ… ์ด๋ฆ„์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

    • Rows : ์•Œ๋ฆผ ๋ฐœ์ƒ ๊ธฐ์ค€ ํ–‰ ์ˆ˜๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

    • Time Interval : ์•Œ๋ฆผ ๋ฐœ์ƒ ๊ธฐ์ค€ ์‹œ๊ฐ„(๋ถ„ ๋‹จ์œ„)์ž…๋‹ˆ๋‹ค.

      • 0 ์ž…๋ ฅ ์‹œ, ์‹œ๊ฐ„ ์กฐ๊ฑด ์—†์ด ๋‹จ๊ฑด์˜ SQL ์‹คํ–‰์„ ๊ธฐ์ค€์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

      • ์ตœ๋Œ€ 1440๊นŒ์ง€ ์ž…๋ ฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค

์•Œ๋ฆผ ์ƒ์„ธ ์ •๋ณด ์กฐํšŒ ๋ฐ ์ˆ˜์ •

Alerts ํŽ˜์ด์ง€์—์„œ ์ƒ์„ธ ๋‚ด์šฉ์„ ์กฐํšŒํ•˜๋ ค๋Š” ์•Œ๋ฆผ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค. ์ƒ์„ธ ํŽ˜์ด์ง€ Details ํƒญ์—์„œ ์•Œ๋ฆผ ์ƒ์„ฑ ์‹œ์— ์ž…๋ ฅํ•œ ์•Œ๋ฆผ ์กฐ๊ฑด ๋ฐ ๋ฉ”์‹œ์ง€๋ฅผ ์กฐํšŒํ•˜๊ณ  ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์šฐ์ƒ๋‹จ Save Changes ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜๋ฉด ์ˆ˜์ • ๋‚ด์šฉ์ด ๋ฐ˜์˜๋ฉ๋‹ˆ๋‹ค.

แ„‰แ…ณแ„แ…ณแ„…แ…ตแ†ซแ„‰แ…ฃแ†บ 2024-07-29 แ„‹แ…ฉแ„’แ…ฎ 3.42.17.png
Administrator > General > Company Management > Alerts > List Details (Details)

ย 

์•Œ๋ฆผ ๋ฐœ์†ก ๋‚ด์—ญ ์กฐํšŒ

Alerts ๋ชฉ๋ก์—์„œ ๋ฐœ์†ก ๋‚ด์—ญ์„ ์กฐํšŒํ•˜๋ ค๋Š” ์•Œ๋ฆผ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค. ์ดํ›„ ์ƒ์„ธ ํŽ˜์ด์ง€ ๋‚ด Log์—์„œ ๋‚ด์—ญ์„ ์กฐํšŒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

แ„‰แ…ณแ„แ…ณแ„…แ…ตแ†ซแ„‰แ…ฃแ†บ 2024-07-29 แ„‹แ…ฉแ„’แ…ฎ 3.42.23.png
Administrator > General > Company Management > Alerts > List Details (Logs)

ย 

์•Œ๋ฆผ ์‚ญ์ œํ•˜๊ธฐ

๊ธฐ์กด์— ๋“ฑ๋ก๋œ ์•Œ๋ฆผ์„ ์‚ญ์ œํ•˜๋Š” ๋‘ ๊ฐ€์ง€ ๊ฒฝ๋กœ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

  1. Alerts ํŽ˜์ด์ง€์—์„œ ์‚ญ์ œํ•˜๊ธฐ : Alerts ๋ชฉ๋ก ๋‚ด ์‚ญ์ œํ•˜๊ณ ์ž ํ•˜๋Š” ์•Œ๋ฆผ์„ ์ฒดํฌ๋ฐ•์Šค๋กœ ์„ ํƒํ•˜๋ฉด Delete ๋ฒ„ํŠผ์ด ๋…ธ์ถœ๋ฉ๋‹ˆ๋‹ค. ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜๋ฉด ํ™•์ธ ๋ชจ๋‹ฌ์ด ๋…ธ์ถœ๋˜๋ฉฐ, OK ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์‚ญ์ œ๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.

  2. ์•Œ๋ฆผ ์ƒ์„ธ ํŽ˜์ด์ง€์—์„œ ์‚ญ์ œํ•˜๊ธฐ : ์‚ญ์ œํ•˜๊ณ ์ž ํ•˜๋Š” ์•Œ๋ฆผ์˜ ์ƒ์„ธ ํŽ˜์ด์ง€ ์šฐ์ƒ๋‹จ Delete ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜๋ฉด ํ™•์ธ ๋ชจ๋‹ฌ์ด ๋…ธ์ถœ๋˜๋ฉฐ, OK ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์‚ญ์ œ๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.