๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
VMware/Carbon Black

VMware Carbon Black ์ œํ’ˆ๊ตฐ - 1

by Seungming 2023. 3. 22.
๋ฐ˜์‘ํ˜•

๋“œ๋””์–ด ์“ฐ๊ฒŒ ๋œ Carbon Black ํฌ์ŠคํŒ…! Carbon Black ๊ณผ ๊ฐ€๊นŒ์›Œ์ง€๊ธฐ ์œ„ํ•œ ์ฒซ๋ฒˆ์งธ ํฌ์ŠคํŒ…์ด๋‹น..
๋‚˜๋Š” VMware Docs ์™€ VMware Tech Zone ์˜ ๋„์›€์„ ๋ฐ›์•„ ์ž‘์„ฑํ•  ๊ฒƒ์ด๋‹ค.

์ •ํ™•ํžˆ ๊ตฌ๋ถ„ํ•  ์ค„ ์•Œ๋ฉด ์ดํ•ด๊ฐ€ ๋” ๋น ๋ฅด๊ฒŒ ๋˜์ง€ ์•Š์„๊นŒ? ์‹ถ์–ด์„œ, Carbon Black์˜ ์ œํ’ˆ๊ตฐ๊ณผ ๊ฐ ์ œํ’ˆ๋“ค์ด ๊ฐ€์ง„ ๊ธฐ๋Šฅ๋“ค์— ๋Œ€ํ•ด์„œ ์ •๋ฆฌํ•˜๊ณ ์ž ํ•œ๋‹ค. (์ œํ’ˆ๊ตฐ์˜ ๋ถ„๋ฅ˜๊ฐ€ ๊ธธ์–ด์ง€๋ฉด ๊ฐ ๊ธฐ๋Šฅ ์„ค๋ช…์€ ๋‹ค์Œ ํฌ์ŠคํŒ…์— ์“ธ ์ˆ˜๋„ ์žˆ์„ ๊ฑฐ ๊ฐ™๋‹ค.)

๊ตฌ๋ถ„์— ๋Œ€ํ•œ ๊ธฐ์ค€์€ ๊ตฌ์ถ• ๋ฐฉ์‹์œผ๋กœ ๊ตฌ๋ถ„ํ•˜์—ฌ ์„ค๋ช…ํ•˜๊ฑฐ๋‚˜ ๋ผ์ด์„ผ์Šค๋กœ ๊ตฌ๋ถ„ํ•˜์—ฌ ์„ค๋ช…ํ•  ์ˆ˜ ์žˆ์„ ๊ฑฐ ๊ฐ™๋‹ค.
๊ทธ์น˜๋งŒ ๋‚˜๋Š” ๊ตฌ์ถ• ๋ฐฉ์‹์œผ๋กœ ๋จผ์ € ์„ค๋ช…ํ•  ๊ฑฐ๋‹ค!! ๋‚ด ๋Š๋‚Œ ์ƒ! ๊ตฌ์ถ• ๋ฐฉ์‹์ด ๋ผ์ด์„ ์Šค ๋ณด๋‹ค ๋” ํฐ ๋ฒ”์œ„๋กœ ๋Š๊ปด์ง€๊ธฐ ๋•Œ๋ฌธ์—....ใ…Ž

์ฐธ๊ณ ๋กœ Carbon Black ์€ ๊ตญ๋‚ด ์†”๋ฃจ์…˜๊ณผ ๋‹ค๋ฅด๊ฒŒ Add on ๋ฐฉ์‹์œผ๋กœ ๋ผ์ด์„ ์Šค๋ฅผ ์ œ๊ณตํ•˜๊ณ  ์žˆ๋‹ค.

1. Carbon Black ๊ตฌ์ถ• ํ™˜๊ฒฝ

  1-1. On-Premise (์˜จ-ํ”„๋ ˆ๋ฏธ์Šค)

  ๋จผ์ € ๊ตฌ์ถ• ํ™˜๊ฒฝ์˜ ๊ทผ๋ณธ์ด ๋˜๋Š” ์˜จ-ํ”„๋ ˆ๋ฏธ์Šค ํ™˜๊ฒฝ์ด๋‹ค.
  ๊ณ ๊ฐ์‚ฌ ํ™˜๊ฒฝ์ด ํ์‡„ํ˜•์ธ ๊ฒฝ์šฐ, ์™ธ๋ถ€์™€ ํ†ต์‹ ์ด ํ—ˆ์šฉ๋˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ๋‚ด๋ถ€์— ๋งค๋‹ˆ์ €๋ฅผ ๊ตฌ์ถ•ํ•˜์—ฌ ์‚ฌ์šฉํ•˜๊ฒŒ ๋œ๋‹ค.

  ์˜จ-ํ”„๋ ˆ๋ฏธ์Šค ํ™˜๊ฒฝ์—์„œ ์ œ๊ณต๋˜๋Š” ์ œํ’ˆ์€ 2๊ฐœ๋‹ค.

  • Carbon Black EDR
  • App Control

   1-2. Cloud (ํด๋ผ์šฐ๋“œ)

   ํด๋ผ์šฐ๋“œ ์ƒ์— ์œ„์น˜ํ•œ Cloud Console ๊ณผ ํ†ต์‹ ๋˜๋Š” ํ™˜๊ฒฝ์ด๋‹ค.
   ์˜จ-ํ”„๋ ˆ๋ฏธ์Šค ๊ตฌ์ถ• ํ™˜๊ฒฝ๊ณผ ๋น„๊ตํ•˜์˜€์„ ๋•Œ, ํด๋ผ์šฐ๋“œ ๊ตฌ์ถ• ํ™˜๊ฒฝ์ด ๋ณด๋‹ค ๋งŽ์€ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•˜๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

  • Carbon Black Cloud EDR
  • Enterprise EDR
  • Audit and Remediation
  • Carbon Black Workload
  • Container
  • Host-Based Firewall
  • XDR

VMware Blogs ์— ์˜ฌ๋ผ์˜จ ๋‹ค์ด์–ด๊ทธ๋žจ์„ ๋ณด๋ฉด ์ œํ’ˆ๊ตฐ ์ดํ•ด๊ฐ€ ํ•œ ๋ˆˆ์— ๋“ค์–ด์˜ค๋‹ˆ ์ฐธ๊ณ ํ•˜๋ฉด ์ข‹์„ ๊ฒƒ ๊ฐ™๋‹ค.
https://blogs.vmware.com/vov/2021/10/05/how-carbon-black-brought-cybersecurity-out-of-the-dark-ages/

 

How Carbon Black Brought Cybersecurity Out of the Dark Ages

Enterprise environments have become amazingly complex ecosystems, and that makes ensuring security for endpoints, servers, and containers a significant challenge. Realizing a different approach than the traditional was required, VMware security experts tra

blogs.vmware.com

 

3. On-Premise (์˜จ-ํ”„๋ ˆ๋ฏธ์Šค) ์ œํ’ˆ ๊ธฐ๋Šฅ

3-1. Carbon Black EDR

์—”๋“œํฌ์ธํŠธ๋ฅผ ์‹ค์‹œ๊ฐ„์œผ๋กœ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ ํƒ์ง€ํ•˜๊ณ  ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ๋Š” ์ œํ’ˆ์ด๋‹ค. 
๊ธฐ์กด ๋ฐ”์ด๋Ÿฌ์Šค ๋ฐฑ์‹ ๊ณผ ๊ฐ™์ด ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํƒ์ง€ํ•˜๊ณ  ๋Œ€์‘ํ•˜๋Š” ๊ธฐ๋Šฅ์€ ์ œ๊ณต๋˜์ง€ ์•Š๋Š”๋‹ค.

  • ๋ชจ๋‹ˆํ„ฐ๋ง (๋„คํŠธ์›Œํฌ, ์—”๋“œํฌ์ธํŠธ ํŠธ๋ž˜ํ”ฝ, ํ–‰์œ„)
  • ์œ„ํ˜‘ ์‹๋ณ„
  • ์œ„ํ˜‘ ๋Œ€์‘
  • ์•Œ๋ฆผ
  • ์œ„ํ˜‘ ๋ถ„์„ 

๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ ์‹๋ณ„๋œ ์œ„ํ˜‘์— ๋Œ€ํ•˜์—ฌ ๋Œ€์‘ ๋ฐ ๋ถ„์„ํ•˜์—ฌ ์—”๋“œํฌ์ธํŠธ๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ์ œํ’ˆ์ด๋‹ค

3-2. App Control

์—”๋“œํฌ์ธํŠธ ๋””๋ฐ”์ด์Šค๋ฅผ Control ํ•  ์ˆ˜ ์žˆ๋Š” ์ œํ’ˆ์ด๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ์ ‘๊ทผ์„ ๊ฑฐ๋ถ€ํ•˜์—ฌ ์—”๋“œํฌ์ธํŠธ๋ฅผ ๋ณดํ˜ธํ•˜๊ณ  ์žˆ๋‹ค.

  • ์†Œํ”„ํŠธ์›จ์–ด ์ œ์–ด 
  • ๋ฉ€์›จ์–ด, ๋žœ์„ฌ์›จ์–ด ๋“ฑ ๊ณต๊ฒฉ ๋ฐฉ์ง€
  • ๋งค์ฒด ์ œ์–ด
  • ํŒŒ์ผ ๋ฐ ์†Œํ”„ํŠธ์›จ์–ด ๋ณ€์กฐ ๋ฐฉ์ง€ (๋ฌด๊ฒฐ์„ฑ ์ œ์–ด)

App Control ์€ EDR ๊ณผ ์—ฐ๋™ํ•˜์—ฌ ์‚ฌ์šฉ์ด ๊ฐ€๋Šฅํ•˜๋‹ค.



(Carbon Black Cloud ๋Š” ์†Œ๊ฐœํ•  ๊ธฐ๋Šฅ์ด ๋งŽ๊ธฐ ๋•Œ๋ฌธ์— ๋‹ค์Œ ํฌ์ŠคํŒ…์— ์ด์–ด์„œ ์ž‘์„ฑํ•ด์•ผ๊ฒ ๋‹ค..)

๋ฐ˜์‘ํ˜•

๋Œ“๊ธ€