VMware by Broadcom/Carbon Black

VMware Carbon Black μ œν’ˆκ΅° - 1

Seungming 2023. 3. 22. 17:45
λ°˜μ‘ν˜•

λ“œλ””μ–΄ μ“°κ²Œ 된 Carbon Black ν¬μŠ€νŒ…! Carbon Black κ³Ό κ°€κΉŒμ›Œμ§€κΈ° μœ„ν•œ 첫번째 ν¬μŠ€νŒ…μ΄λ‹Ή..
λ‚˜λŠ” VMware Docs 와 VMware Tech Zone 의 도움을 λ°›μ•„ μž‘μ„±ν•  것이닀.

μ •ν™•νžˆ ꡬ뢄할 쀄 μ•Œλ©΄ 이해가 더 λΉ λ₯΄κ²Œ λ˜μ§€ μ•Šμ„κΉŒ? μ‹Άμ–΄μ„œ, Carbon Black의 μ œν’ˆκ΅°κ³Ό 각 μ œν’ˆλ“€μ΄ κ°€μ§„ κΈ°λŠ₯듀에 λŒ€ν•΄μ„œ μ •λ¦¬ν•˜κ³ μž ν•œλ‹€. (μ œν’ˆκ΅°μ˜ λΆ„λ₯˜κ°€ κΈΈμ–΄μ§€λ©΄ 각 κΈ°λŠ₯ μ„€λͺ…은 λ‹€μŒ ν¬μŠ€νŒ…μ— μ“Έ μˆ˜λ„ μžˆμ„ κ±° κ°™λ‹€.)

ꡬ뢄에 λŒ€ν•œ 기쀀은 ꡬ좕 λ°©μ‹μœΌλ‘œ κ΅¬λΆ„ν•˜μ—¬ μ„€λͺ…ν•˜κ±°λ‚˜ λΌμ΄μ„ΌμŠ€λ‘œ κ΅¬λΆ„ν•˜μ—¬ μ„€λͺ…ν•  수 μžˆμ„ κ±° κ°™λ‹€.
그치만 λ‚˜λŠ” ꡬ좕 λ°©μ‹μœΌλ‘œ λ¨Όμ € μ„€λͺ…ν•  κ±°λ‹€!! λ‚΄ λŠλ‚Œ 상! ꡬ좕 방식이 λΌμ΄μ„ μŠ€ 보닀 더 큰 λ²”μœ„λ‘œ λŠκ»΄μ§€κΈ° λ•Œλ¬Έμ—....γ…Ž

참고둜 Carbon Black 은 κ΅­λ‚΄ μ†”λ£¨μ…˜κ³Ό λ‹€λ₯΄κ²Œ Add on λ°©μ‹μœΌλ‘œ λΌμ΄μ„ μŠ€λ₯Ό μ œκ³΅ν•˜κ³  μžˆλ‹€.

1. Carbon Black ꡬ좕 ν™˜κ²½

  1-1. On-Premise (온-ν”„λ ˆλ―ΈμŠ€)

  λ¨Όμ € ꡬ좕 ν™˜κ²½μ˜ 근본이 λ˜λŠ” 온-ν”„λ ˆλ―ΈμŠ€ ν™˜κ²½μ΄λ‹€.
  고객사 ν™˜κ²½μ΄ νμ‡„ν˜•μΈ 경우, 외뢀와 톡신이 ν—ˆμš©λ˜μ§€ μ•ŠκΈ° λ•Œλ¬Έμ— 내뢀에 λ§€λ‹ˆμ €λ₯Ό κ΅¬μΆ•ν•˜μ—¬ μ‚¬μš©ν•˜κ²Œ λœλ‹€.

  온-ν”„λ ˆλ―ΈμŠ€ ν™˜κ²½μ—μ„œ μ œκ³΅λ˜λŠ” μ œν’ˆμ€ 2κ°œλ‹€.

  • Carbon Black EDR
  • App Control

   1-2. Cloud (ν΄λΌμš°λ“œ)

   ν΄λΌμš°λ“œ 상에 μœ„μΉ˜ν•œ Cloud Console κ³Ό ν†΅μ‹ λ˜λŠ” ν™˜κ²½μ΄λ‹€.
   μ˜¨-ν”„λ ˆλ―ΈμŠ€ ꡬ좕 ν™˜κ²½κ³Ό λΉ„κ΅ν•˜μ˜€μ„ λ•Œ, ν΄λΌμš°λ“œ ꡬ좕 ν™˜κ²½μ΄ 보닀 λ§Žμ€ κΈ°λŠ₯을 μ œκ³΅ν•˜λŠ” 것을 λ³Ό 수 μžˆλ‹€.

  • Carbon Black Cloud EDR
  • Enterprise EDR
  • Audit and Remediation
  • Carbon Black Workload
  • Container
  • Host-Based Firewall
  • XDR

VMware Blogs 에 올라온 λ‹€μ΄μ–΄κ·Έλž¨μ„ 보면 μ œν’ˆκ΅° 이해가 ν•œ λˆˆμ— λ“€μ–΄μ˜€λ‹ˆ μ°Έκ³ ν•˜λ©΄ 쒋을 것 κ°™λ‹€.
https://blogs.vmware.com/vov/2021/10/05/how-carbon-black-brought-cybersecurity-out-of-the-dark-ages/

 

How Carbon Black Brought Cybersecurity Out of the Dark Ages

Enterprise environments have become amazingly complex ecosystems, and that makes ensuring security for endpoints, servers, and containers a significant challenge. Realizing a different approach than the traditional was required, VMware security experts tra

blogs.vmware.com

 

3. On-Premise (온-ν”„λ ˆλ―ΈμŠ€) μ œν’ˆ κΈ°λŠ₯

3-1. Carbon Black EDR

μ—”λ“œν¬μΈνŠΈλ₯Ό μ‹€μ‹œκ°„μœΌλ‘œ λͺ¨λ‹ˆν„°λ§ν•˜μ—¬ νƒμ§€ν•˜κ³  λŒ€μ‘ν•  수 μžˆλŠ” μ œν’ˆμ΄λ‹€. 
κΈ°μ‘΄ λ°”μ΄λŸ¬μŠ€ λ°±μ‹ κ³Ό 같이 μ‹œκ·Έλ‹ˆμ²˜λ₯Ό 기반으둜 νƒμ§€ν•˜κ³  λŒ€μ‘ν•˜λŠ” κΈ°λŠ₯은 μ œκ³΅λ˜μ§€ μ•ŠλŠ”λ‹€.

  • λͺ¨λ‹ˆν„°λ§ (λ„€νŠΈμ›Œν¬, μ—”λ“œν¬μΈνŠΈ νŠΈλž˜ν”½, ν–‰μœ„)
  • μœ„ν˜‘ 식별
  • μœ„ν˜‘ λŒ€μ‘
  • μ•Œλ¦Ό
  • μœ„ν˜‘ 뢄석 

λͺ¨λ‹ˆν„°λ§ν•˜μ—¬ μ‹λ³„λœ μœ„ν˜‘μ— λŒ€ν•˜μ—¬ λŒ€μ‘ 및 λΆ„μ„ν•˜μ—¬ μ—”λ“œν¬μΈνŠΈλ₯Ό λ³΄ν˜Έν•˜λŠ” μ œν’ˆμ΄λ‹€

3-2. App Control

μ—”λ“œν¬μΈνŠΈ λ””λ°”μ΄μŠ€λ₯Ό Control ν•  수 μžˆλŠ” μ œν’ˆμ΄λ‹€. 기본적으둜 접근을 κ±°λΆ€ν•˜μ—¬ μ—”λ“œν¬μΈνŠΈλ₯Ό λ³΄ν˜Έν•˜κ³  μžˆλ‹€.

  • μ†Œν”„νŠΈμ›¨μ–΄ μ œμ–΄ 
  • 멀웨어, λžœμ„¬μ›¨μ–΄ λ“± 곡격 λ°©μ§€
  • 맀체 μ œμ–΄
  • 파일 및 μ†Œν”„νŠΈμ›¨μ–΄ λ³€μ‘° λ°©μ§€ (무결성 μ œμ–΄)

App Control 은 EDR κ³Ό μ—°λ™ν•˜μ—¬ μ‚¬μš©μ΄ κ°€λŠ₯ν•˜λ‹€.



(Carbon Black Cloud λŠ” μ†Œκ°œν•  κΈ°λŠ₯이 많기 λ•Œλ¬Έμ— λ‹€μŒ ν¬μŠ€νŒ…μ— μ΄μ–΄μ„œ μž‘μ„±ν•΄μ•Όκ² λ‹€..)

λ°˜μ‘ν˜•