Mikrotik์„ ๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ๋ณดํ˜ธํ•˜๋Š” ์‰ฌ์šด ๋ฐฉ๋ฒ•

์ €๋Š” Mikrotik์„ ์‚ฌ์šฉํ•˜์—ฌ ์™ธ๋ถ€ ๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ๋„คํŠธ์›Œํฌ์™€ ์„œ๋น„์Šค๋ฅผ ๋’ค์—์„œ "ํ›”์ณ๋ณด๋Š”" ๋ณดํ˜ธํ•˜๋Š” ๊ฐ„๋‹จํ•˜๊ณ  ํšจ๊ณผ์ ์ธ ๋ฐฉ๋ฒ•์„ ์ปค๋ฎค๋‹ˆํ‹ฐ์™€ ๊ณต์œ ํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค. ์ฆ‰, Mikrotik์—์„œ ํ—ˆ๋‹ˆํŒŸ์„ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐ๋Š” ์„ธ ๊ฐ€์ง€ ๊ทœ์น™๋งŒ ์žˆ์œผ๋ฉด ๋ฉ๋‹ˆ๋‹ค.

์ง์›๋“ค์ด ์›๊ฒฉ์œผ๋กœ ์ž‘์—…ํ•  ์ˆ˜ ์žˆ๋Š” RDP ์„œ๋ฒ„๊ฐ€ ์žˆ๊ณ  ๊ทธ ๋’ค์— ์™ธ๋ถ€ IP๊ฐ€ ์žˆ๋Š” ์†Œ๊ทœ๋ชจ ์‚ฌ๋ฌด์‹ค์ด ์žˆ๋‹ค๊ณ  ๊ฐ€์ •ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ๋ฌผ๋ก  ์ฒซ ๋ฒˆ์งธ ๊ทœ์น™์€ ์™ธ๋ถ€ ์ธํ„ฐํŽ˜์ด์Šค์˜ ํฌํŠธ 3389๋ฅผ ๋‹ค๋ฅธ ํฌํŠธ๋กœ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ด๋Š” ์˜ค๋ž˜ ๊ฐ€์ง€ ์•Š์œผ๋ฉฐ ๋ฉฐ์น  ํ›„์— ํ„ฐ๋ฏธ๋„ ์„œ๋ฒ„ ๊ฐ์‚ฌ ๋กœ๊ทธ์— ์•Œ ์ˆ˜ ์—†๋Š” ํด๋ผ์ด์–ธํŠธ๋กœ๋ถ€ํ„ฐ ์ดˆ๋‹น ์—ฌ๋Ÿฌ ๊ฑด์˜ ์‹คํŒจํ•œ ์ธ์ฆ์ด ํ‘œ์‹œ๋˜๊ธฐ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

๋˜ ๋‹ค๋ฅธ ์ƒํ™ฉ์€ Mikrotik ๋’ค์— ๋ณ„ํ‘œ๊ฐ€ ์ˆจ๊ฒจ์ ธ ์žˆ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋ฌผ๋ก  5060 udp ํฌํŠธ์—๋Š” ์—†์œผ๋ฉฐ ๋ฉฐ์น  ํ›„์— ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ฒ€์ƒ‰๋„ ์‹œ์ž‘๋ฉ๋‹ˆ๋‹ค... ์˜ˆ, ์˜ˆ, ์•Œ์•„์š”. ์ž‘์—…ํ•˜์„ธ์š”... ์˜ˆ๋ฅผ ๋“ค์–ด, ์ตœ๊ทผ ์šฐ๋ถ„ํˆฌ 2์— ์„ค์น˜ํ–ˆ๋Š”๋ฐ ๊ธฐ๋ณธ์ ์œผ๋กœ ๋™์ผํ•œ ์šฐ๋ถ„ํˆฌ ๋ฐฐํฌํŒ์˜ ๋™์ผํ•œ ์ƒ์ž์—์„œ ๋ณ„ํ‘œ์— ๋Œ€ํ•œ ํ˜„์žฌ ์„ค์ •์ด ํฌํ•จ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค๋Š” ์‚ฌ์‹ค์— ๋†€๋ž์Šต๋‹ˆ๋‹ค. ์ธํ„ฐ๋„ท ๊ฒ€์ƒ‰ ๋น ๋ฅธ ์„ค์ • ์ด๋ฏธ ๋งŒ๋“ค์–ด์ง„ "๋ ˆ์‹œํ”ผ"๋Š” ๋” ์ด์ƒ ์ž‘๋™ํ•˜์ง€ ์•Š๊ณ , ์ถœ์‹œ ํšŸ์ˆ˜๋Š” ํ•ด๊ฐ€ ๊ฐˆ์ˆ˜๋ก ๋Š˜์–ด๋‚˜๊ณ  ์žˆ์œผ๋ฉฐ, ์ด์ „ ๋ฒ„์ „์— ๋Œ€ํ•œ "๋ ˆ์‹œํ”ผ"๊ฐ€ ํฌํ•จ๋œ ๊ธฐ์‚ฌ๋Š” ๋” ์ด์ƒ ์ž‘๋™ํ•˜์ง€ ์•Š์œผ๋ฉฐ, ์ƒˆ ๋ฒ„์ „์€ ๊ฑฐ์˜ ๋‚˜ํƒ€๋‚˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค... ํ•˜์ง€๋งŒ ์ €๋Š” ์˜๊ฒฌ์ด ๋‹ค๋ฆ…๋‹ˆ๋‹ค...

๊ฐ„๋‹จํžˆ ๋งํ•ด์„œ ํ—ˆ๋‹ˆํŒŸ์ด๋ž€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ? ์ด๊ฒƒ์€ ํ—ˆ๋‹ˆํŒŸ์ž…๋‹ˆ๋‹ค. ์šฐ๋ฆฌ์˜ ๊ฒฝ์šฐ ์™ธ๋ถ€ IP์˜ ์ธ๊ธฐ ํฌํŠธ์ด๋ฉฐ ์™ธ๋ถ€ ํด๋ผ์ด์–ธํŠธ์—์„œ ์ด ํฌํŠธ์— ๋Œ€ํ•œ ๋ชจ๋“  ์š”์ฒญ์€ src ์ฃผ์†Œ๋ฅผ ๋ธ”๋ž™๋ฆฌ์ŠคํŠธ๋กœ ๋ณด๋ƒ…๋‹ˆ๋‹ค. ๋ชจ๋‘.

/ip firewall filter
add action=add-src-to-address-list address-list="Honeypot Hacker" 
    address-list-timeout=30d0h0m chain=input comment="block honeypot ssh rdp winbox" 
    connection-state=new dst-port=22,3389,8291 in-interface=
    ether4-wan protocol=tcp
add action=add-src-to-address-list address-list="Honeypot Hacker" 
    address-list-timeout=30d0h0m chain=input comment=
    "block honeypot asterisk" connection-state=new dst-port=5060 
    in-interface=ether4-wan protocol=udp 
/ip firewall raw
add action=drop chain=prerouting in-interface=ether4-wan src-address-list=
    "Honeypot Hacker"

ether22-wan ์™ธ๋ถ€ ์ธํ„ฐํŽ˜์ด์Šค์˜ ์ธ๊ธฐ ์žˆ๋Š” TCP ํฌํŠธ 3389, 8291, 4์— ๋Œ€ํ•œ ์ฒซ ๋ฒˆ์งธ ๊ทœ์น™์€ "guest" IP๋ฅผ "Honeypot Hacker" ๋ชฉ๋ก์œผ๋กœ ๋ณด๋ƒ…๋‹ˆ๋‹ค(ssh, rdp ๋ฐ winbox์šฉ ํฌํŠธ๋Š” ๋ฏธ๋ฆฌ ๋น„ํ™œ์„ฑํ™”๋˜๊ฑฐ๋‚˜ ๋‹ค๋ฅธ ํฌํŠธ๋กœ ๋ณ€๊ฒฝ๋ฉ๋‹ˆ๋‹ค). ๋‘ ๋ฒˆ์งธ๋Š” ๋„๋ฆฌ ์‚ฌ์šฉ๋˜๋Š” UDP 5060์—์„œ ๋™์ผํ•œ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

์‚ฌ์ „ ๋ผ์šฐํŒ… ๋‹จ๊ณ„์˜ ์„ธ ๋ฒˆ์งธ ๊ทœ์น™์€ "Honeypot Hacker"์— srs ์ฃผ์†Œ๊ฐ€ ํฌํ•จ๋œ "guests"์˜ ํŒจํ‚ท์„ ์‚ญ์ œํ•ฉ๋‹ˆ๋‹ค.

๋‚ด ์ง‘ Mikrotik์—์„œ XNUMX์ฃผ ๋™์•ˆ ์ž‘์—…ํ•œ ํ›„ "Honeypot Hacker" ๋ชฉ๋ก์—๋Š” ๋‚ด ๋„คํŠธ์›Œํฌ ๋ฆฌ์†Œ์Šค๋ฅผ "์œ ๋ฐฉ์— ๋ณด๊ด€"ํ•˜๋Š” ๊ฒƒ์„ ์ข‹์•„ํ•˜๋Š” ์‚ฌ๋žŒ๋“ค์˜ ์•ฝ XNUMX๊ฐœ IP ์ฃผ์†Œ๊ฐ€ ํฌํ•จ๋˜์—ˆ์Šต๋‹ˆ๋‹ค(์ง‘์—๋Š” ๋‚ด ์ „ํ™”, ๋ฉ”์ผ, nextcloud, rdp) ๋ฌด์ฐจ๋ณ„ ๊ณต๊ฒฉ์ด ์ค‘๋‹จ๋˜๊ณ  ํ–‰๋ณต์ด ์ฐพ์•„์™”์Šต๋‹ˆ๋‹ค.

์ง์žฅ์—์„œ ๋ชจ๋“  ๊ฒƒ์ด ๊ทธ๋ ‡๊ฒŒ ๊ฐ„๋‹จํ•œ ๊ฒƒ์€ ์•„๋‹ˆ์—ˆ๊ณ  ๋ฌด์ฐจ๋ณ„ ์•”ํ˜ธ ๋Œ€์ž…์œผ๋กœ RDP ์„œ๋ฒ„๋ฅผ ๊ณ„์† ๊นจ๋œจ ๋ ธ์Šต๋‹ˆ๋‹ค.

๋ถ„๋ช…ํžˆ ํฌํŠธ ๋ฒˆํ˜ธ๋Š” ํ—ˆ๋‹ˆํŒŸ์ด ์ผœ์ง€๊ธฐ ์˜ค๋ž˜ ์ „์— ์Šค์บ๋„ˆ์— ์˜ํ•ด ๊ฒฐ์ •๋˜์—ˆ์œผ๋ฉฐ ๊ฒฉ๋ฆฌ ์ค‘์—๋Š” 100๋ช… ์ด์ƒ์˜ ์‚ฌ์šฉ์ž๋ฅผ ์žฌ๊ตฌ์„ฑํ•˜๋Š” ๊ฒƒ์ด ๊ทธ๋ฆฌ ์‰ฝ์ง€ ์•Š์œผ๋ฉฐ ๊ทธ ์ค‘ 20%๋Š” 65์„ธ ์ด์ƒ์ž…๋‹ˆ๋‹ค. ํฌํŠธ๋ฅผ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์—†๋Š” ๊ฒฝ์šฐ ์ž‘์€ ์ž‘์—… ๋ฐฉ๋ฒ•์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ธํ„ฐ๋„ท์—์„œ ๋น„์Šทํ•œ ๊ฒƒ์„ ๋ณธ ์ ์ด ์žˆ์ง€๋งŒ ๋ช‡ ๊ฐ€์ง€ ์ถ”๊ฐ€ ์‚ฌํ•ญ๊ณผ ๋ฏธ์„ธ ์กฐ์ •์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

ํฌํŠธ ๋…ธํ‚น ๊ตฌ์„ฑ ๊ทœ์น™

 /ip firewall filter
add action=add-src-to-address-list address-list=rdp_blacklist 
    address-list-timeout=15m chain=forward comment=rdp_to_blacklist 
    connection-state=new dst-port=3389 protocol=tcp src-address-list=
    rdp_stage12
add action=add-src-to-address-list address-list=rdp_stage12 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage11
add action=add-src-to-address-list address-list=rdp_stage11 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage10
add action=add-src-to-address-list address-list=rdp_stage10 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage9
add action=add-src-to-address-list address-list=rdp_stage9 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage8
add action=add-src-to-address-list address-list=rdp_stage8 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage4
add action=add-src-to-address-list address-list=rdp_stage7 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage6
add action=add-src-to-address-list address-list=rdp_stage6 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage5
add action=add-src-to-address-list address-list=rdp_stage5 
    address-list-timeout=4m chain=forward connection-state=new dst-port=
    3389 protocol=tcp src-address-list=rdp_stage4
add action=add-src-to-address-list address-list=rdp_stage4 
    address-list-timeout=4m chain=forward connection-state=new dst-port=
    3389 protocol=tcp src-address-list=rdp_stage3
add action=add-src-to-address-list address-list=rdp_stage3 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage2
add action=add-src-to-address-list address-list=rdp_stage2 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp src-address-list=rdp_stage1
add action=add-src-to-address-list address-list=rdp_stage1 
    address-list-timeout=4m chain=forward connection-state=new dst-port=3389 
    protocol=tcp 
/ip firewall raw
add action=drop chain=prerouting in-interface=ether4-wan src-address-list=
rdp_blacklist

4๋ถ„ ์•ˆ์— ์›๊ฒฉ ํด๋ผ์ด์–ธํŠธ๋Š” RDP ์„œ๋ฒ„์— 12๊ฐœ์˜ ์ƒˆ๋กœ์šด "์š”์ฒญ"๋งŒ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํ•œ ๋ฒˆ์˜ ๋กœ๊ทธ์ธ ์‹œ๋„๋Š” 1~4๊ฐœ์˜ "์š”์ฒญ"์ž…๋‹ˆ๋‹ค. 12๋ฒˆ์งธ "์š”์ฒญ" ์‹œ - 15๋ถ„๊ฐ„ ์ฐจ๋‹จ๋ฉ๋‹ˆ๋‹ค. ๋‚ด ๊ฒฝ์šฐ ๊ณต๊ฒฉ์ž๋Š” ์„œ๋ฒ„ ํ•ดํ‚น์„ ์ค‘๋‹จํ•˜์ง€ ์•Š๊ณ  ํƒ€์ด๋จธ๋ฅผ ์กฐ์ •ํ•˜์—ฌ ์ด์ œ ๋งค์šฐ ๋Š๋ฆฌ๊ฒŒ ์ˆ˜ํ–‰ํ•˜๋ฏ€๋กœ ์ด๋Ÿฌํ•œ ์„ ํƒ ์†๋„๋กœ ์ธํ•ด ๊ณต๊ฒฉ ํšจ์œจ์„ฑ์ด XNUMX์œผ๋กœ ๊ฐ์†Œํ•ฉ๋‹ˆ๋‹ค. ํšŒ์‚ฌ ์ง์›์€ ์ทจํ•ด์ง„ ์กฐ์น˜๋กœ ์ธํ•ด ์ง์žฅ์—์„œ ์‚ฌ์‹ค์ƒ ๋ถˆํŽธ์„ ๊ฒช์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

๋˜ ๋‹ค๋ฅธ ์ž‘์€ ํŠธ๋ฆญ
์ด ๊ทœ์น™์€ ์ผ์ •์— ๋”ฐ๋ผ ์˜ค์ „ 5์‹œ์— ์ผœ์ง€๊ณ  ์˜ค์ „ XNUMX์‹œ์— ๊บผ์ง€๋ฉฐ, ์ด๋•Œ๋Š” ์‹ค์ œ ์‚ฌ๋žŒ๋“ค์ด ํ™•์‹คํžˆ ์ž๊ณ  ์žˆ๊ณ  ์ž๋™ ์„ ํƒ๊ธฐ๊ฐ€ ๊ณ„์† ๊นจ์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

/ip firewall filter 
add action=add-src-to-address-list address-list=rdp_blacklist 
    address-list-timeout=1w0d0h0m chain=forward comment=
    "night_rdp_blacklist" connection-state=new disabled=
    yes dst-port=3389 protocol=tcp src-address-list=rdp_stage8

์ด๋ฏธ 8ํšŒ ์ ‘์†์—์„œ๋Š” ๊ณต๊ฒฉ์ž์˜ IP๊ฐ€ ์ผ์ฃผ์ผ ๋™์•ˆ ๋ธ”๋ž™๋ฆฌ์ŠคํŠธ์— ์˜ฌ๋ผ ์žˆ๋‹ค. ์•„๋ฆ„๋‹ค์›€!

์œ„์˜ ๋‚ด์šฉ ์™ธ์—๋„ ๋„คํŠธ์›Œํฌ ์Šค์บ๋„ˆ๋กœ๋ถ€ํ„ฐ Mikrotik์„ ๋ณดํ˜ธํ•˜๊ธฐ ์œ„ํ•œ ์ž‘์—… ์„ค์ •์ด ํฌํ•จ๋œ Wiki ๊ธฐ์‚ฌ์— ๋Œ€ํ•œ ๋งํฌ๋ฅผ ์ถ”๊ฐ€ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. wiki.mikrotik.com/wiki/Drop_port_scanners

๋‚ด ์žฅ์น˜์—์„œ ์ด ์„ค์ •์€ ์œ„์— ์„ค๋ช…๋œ ํ—ˆ๋‹ˆํŒŸ ๊ทœ์น™๊ณผ ํ•จ๊ป˜ ์ž‘๋™ํ•˜์—ฌ ์ด๋ฅผ ์ž˜ ๋ณด์™„ํ•ฉ๋‹ˆ๋‹ค.

UPD: ์˜๊ฒฌ์—์„œ ์ œ์•ˆํ•œ ๋Œ€๋กœ ๋ผ์šฐํ„ฐ์˜ ๋ถ€ํ•˜๋ฅผ ์ค„์ด๊ธฐ ์œ„ํ•ด ํŒจํ‚ท ์‚ญ์ œ ๊ทœ์น™์ด RAW๋กœ ์ด๋™๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : habr.com

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€