์ž๋ฃŒ์‹ค ์„œ๋ธŒ ํƒ€์ดํ‹€ ์•„์ด์ฝ˜

๊ธฐ์ˆ ๋ฌธ์„œ

 > 

๋ณด์•ˆ

๐Ÿ”’ IIS ๋ณด์•ˆ ์„ค์ •์— ํ•„์š”ํ•œ ํ•ต์‹ฌ ์‚ฌํ•ญ

๐Ÿ”’ IIS ๋ณด์•ˆ ์„ค์ •์— ํ•„์š”ํ•œ ํ•ต์‹ฌ ์‚ฌํ•ญ

์ฃผ์š” ํ”„๋กœ๊ทธ๋žจ ์ŠคํŽ™

  • ํ‰์ : 10.0
  • ๋ผ์ด์„ ์Šค: free
  • ์šด์˜์ฒด์ œ:
  • ํŒŒ์ผ ํฌ๊ธฐ: 0

ํ”ผ๋“œ๋ฐฑ ๋ฐ ๋‹ค์šด๋กœ๋“œ

  • ์‚ฌ์šฉ์ž ํ‰์ : 10.0
  • ๋‹ค์šด๋กœ๋“œ ์ˆ˜: 0
  • ์กฐํšŒ์ˆ˜: 6

์ œ์กฐ์‚ฌ ๋ฐ ๋“ฑ๋ก ์ •๋ณด

  • ์ œ์ž‘์‚ฌ: LUZENSOFT
  • ๋“ฑ๋ก์ผ: 2025-11-18 10:46:51
  •  

- ์„ค๋ช…

IIS(Internet Information Services) ์„œ๋ฒ„์˜ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๊ธฐ ์œ„ํ•ด ํ•„์ˆ˜์ ์œผ๋กœ ๊ณ ๋ คํ•ด์•ผ ํ•  ์‚ฌํ•ญ๋“ค์„ ์—ญํ• ๋ณ„๋กœ ๋‚˜๋ˆ„์–ด ์•ˆ๋‚ดํ•ด ๋“œ๋ฆฝ๋‹ˆ๋‹ค.


uploadImage

1. ์„œ๋ฒ„ ๋ฐ OS ์ˆ˜์ค€ ๋ณด์•ˆ


IIS ์ž์ฒด ์„ค์ • ์ด์ „์— ์„œ๋ฒ„ ์šด์˜์ฒด์ œ(OS) ์ˆ˜์ค€์—์„œ ๊ธฐ๋ณธ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • ์ •๊ธฐ์ ์ธ ํŒจ์น˜ ๋ฐ ์—…๋ฐ์ดํŠธ: Windows Server ๋ฐ IIS๋ฅผ ์ตœ์‹  ์ƒํƒœ๋กœ ์œ ์ง€ํ•˜์—ฌ ์•Œ๋ ค์ง„ ์ทจ์•ฝ์ ์„ ๋ฐฉ์–ดํ•ฉ๋‹ˆ๋‹ค.

  • ๋ฐฉํ™”๋ฒฝ ์„ค์ •: ํ•„์š”ํ•œ ํฌํŠธ(80, 443)๋งŒ ์™ธ๋ถ€๋กœ ๊ฐœ๋ฐฉํ•˜๊ณ , ๊ด€๋ฆฌ ํฌํŠธ(3389)๋Š” ํŠน์ • IP ๋Œ€์—ญ์—์„œ๋งŒ ์ ‘๊ทผํ•˜๋„๋ก ์ œํ•œํ•ฉ๋‹ˆ๋‹ค.

  • ์ตœ์†Œ ๊ถŒํ•œ ์›์น™:

    • ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํ’€(Application Pool)์€ ์ „์šฉ ๊ณ„์ •์„ ์‚ฌ์šฉํ•˜๋ฉฐ, ์ด ๊ณ„์ •์—๋Š” **ํ•„์š”ํ•œ ํด๋”(๋กœ๊ทธ, ์—…๋กœ๋“œ ๋“ฑ)์—๋งŒ ์ตœ์†Œํ•œ์˜ ๊ถŒํ•œ(์ฝ๊ธฐ, ์“ฐ๊ธฐ)**์„ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค.

    • ๊ด€๋ฆฌ์ž(Administrator) ๊ณ„์ •์„ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์‹คํ–‰์— ์‚ฌ์šฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.



2. SSL/TLS ๋ฐ ํ†ต์‹  ๋ณด์•ˆ


์•”ํ˜ธํ™”๋œ ํ†ต์‹ ์€ ์›น ์„œ๋ฒ„ ๋ณด์•ˆ์˜ ๊ธฐ๋ณธ์ž…๋‹ˆ๋‹ค.

  • HTTPS ์‚ฌ์šฉ ๊ฐ•์ œ: ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์„ **HTTP ๋Œ€์‹  HTTPS(443 ํฌํŠธ)**๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ฐ•์ œ ์ „ํ™˜(๋ฆฌ๋‹ค์ด๋ ‰์…˜)ํ•ฉ๋‹ˆ๋‹ค.

  • TLS ๋ฒ„์ „ ๊ด€๋ฆฌ: SSL v2/v3 ๋ฐ TLS 1.0/1.1๊ณผ ๊ฐ™์€ ๊ตฌํ˜• ํ”„๋กœํ† ์ฝœ์„ ๋น„ํ™œ์„ฑํ™”ํ•˜๊ณ , TLS 1.2 ๋˜๋Š” TLS 1.3๋งŒ ์‚ฌ์šฉํ•˜๋„๋ก ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

  • ๊ฐ•๋ ฅํ•œ ์•”ํ˜ธํ™” ์Šค์œ„ํŠธ(Cipher Suites): ์ทจ์•ฝํ•œ ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜์€ ๋น„ํ™œ์„ฑํ™”ํ•˜๊ณ , AES์™€ ๊ฐ™์€ ๊ฐ•๋ ฅํ•œ ์•”ํ˜ธํ™” ๋ฐฉ์‹๋งŒ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.



3. IIS ๊ธฐ๋Šฅ ๋ฐ ์„ค์ • ๋ณด์•ˆ


๊ฐ€์žฅ ์ค‘์š”ํ•œ IIS ๊ด€๋ฆฌ์ž ๋‚ด๋ถ€ ์„ค์ •์ž…๋‹ˆ๋‹ค.


A. ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ


  • ์ต๋ช… ์ธ์ฆ: ์™ธ๋ถ€ ์‚ฌ์šฉ์ž์—๊ฒŒ ์›น์‚ฌ์ดํŠธ๋ฅผ ๊ณต๊ฐœํ•˜๋Š” ๊ฒฝ์šฐ ๊ธฐ๋ณธ์œผ๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ์ต๋ช… ์‚ฌ์šฉ์ž ๊ณ„์ •(IUSR)์˜ ๊ถŒํ•œ์€ ์ตœ์†Œํ™”ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • ํด๋” ๊ถŒํ•œ ์ œํ•œ:

    • ์Šคํฌ๋ฆฝํŠธ/์ฝ”๋“œ ํด๋”: ์‹คํ–‰ ๊ถŒํ•œ์„ ์ œ์™ธํ•œ ์ฝ๊ธฐ ๊ถŒํ•œ๋งŒ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค.

    • ์—…๋กœ๋“œ ํด๋”: ์“ฐ๊ธฐ ๊ถŒํ•œ๋งŒ ๋ถ€์—ฌํ•˜๊ณ , ์‹คํ–‰ ๊ถŒํ•œ์€ ๋ฐ˜๋“œ์‹œ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค.


B. ์š”์ฒญ ํ•„ํ„ฐ๋ง (Request Filtering)


์ด ๊ธฐ๋Šฅ์€ ์•…์˜์ ์ธ HTTP ์š”์ฒญ์œผ๋กœ๋ถ€ํ„ฐ ์„œ๋ฒ„๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ํ•ต์‹ฌ ๋ฐฉ์–ด๋ฒฝ์ž…๋‹ˆ๋‹ค.

  • ํŒŒ์ผ ํ™•์žฅ์ž ์ฐจ๋‹จ: ์‹คํ–‰๋  ํ•„์š”๊ฐ€ ์—†๋Š” ํ™•์žฅ์ž(.bak, .config, .pdb, .rsp ๋“ฑ)๋ฅผ ์ฐจ๋‹จํ•˜์—ฌ, ์„ค์ • ํŒŒ์ผ ๋…ธ์ถœ์ด๋‚˜ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์„ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.

  • ์ˆจ๊ฒจ์ง„ ์„ธ๊ทธ๋จผํŠธ ์ฐจ๋‹จ: bin ํด๋”๋‚˜ .svn, .git ํด๋”์™€ ๊ฐ™์ด ์›น ๋ธŒ๋ผ์šฐ์ €๋กœ ์ ‘๊ทผํ•  ํ•„์š”๊ฐ€ ์—†๋Š” ๋””๋ ‰ํ„ฐ๋ฆฌ๋ฅผ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค.

  • ์ตœ๋Œ€ ์š”์ฒญ ํฌ๊ธฐ ์ œํ•œ: **maxAllowedContentLength**์™€ **maxRequestLength**๋ฅผ ์„ค์ •ํ•˜์—ฌ DDoS ๊ณต๊ฒฉ์ด๋‚˜ ๋Œ€์šฉ๋Ÿ‰ ์•…์„ฑ ํŒŒ์ผ ์—…๋กœ๋“œ๋ฅผ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.


C. ์‘๋‹ต ํ—ค๋” ๊ด€๋ฆฌ


  • ๋ฏผ๊ฐํ•œ ์ •๋ณด ์ œ๊ฑฐ: HTTP ์‘๋‹ต ํ—ค๋”์—์„œ X-Powered-By (์˜ˆ: ASP.NET ๋ฒ„์ „), Server (์˜ˆ: IIS/10.0)์™€ ๊ฐ™์ด ์„œ๋ฒ„ ์ •๋ณด๋ฅผ ๋…ธ์ถœํ•˜๋Š” ํ—ค๋”๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค.

  • ๋ณด์•ˆ ํ—ค๋” ์ถ”๊ฐ€: X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, Content-Security-Policy ๋“ฑ์˜ ๋ณด์•ˆ ๊ด€๋ จ HTTP ํ—ค๋”๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ XSS ๋ฐ Clickjacking ๊ณต๊ฒฉ์„ ๋ฐฉ์–ดํ•ฉ๋‹ˆ๋‹ค.



4. ๋กœ๊น… ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง


๋ณด์•ˆ ์ด๋ฒคํŠธ ๋ฐœ์ƒ ์‹œ ์›์ธ์„ ํŒŒ์•…ํ•˜๊ณ  ์ถ”ํ›„ ๊ฐ์‚ฌ๋ฅผ ์œ„ํ•ด ํ•„์ˆ˜์ ์ž…๋‹ˆ๋‹ค.

  • ๋กœ๊น… ํ™œ์„ฑํ™”: ๋ชจ๋“  ์›น ์‚ฌ์ดํŠธ์— ๋Œ€ํ•ด ์„ฑ๊ณต/์‹คํŒจ ์š”์ฒญ์„ ํฌํ•จํ•œ ์ƒ์„ธ ๋กœ๊น…์„ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.

  • ๋กœ๊ทธ ๊ด€๋ฆฌ: ๋กœ๊ทธ ํŒŒ์ผ์€ ์„œ๋ฒ„์˜ ๋‹ค๋ฅธ ์˜์—ญ์— ๋ณด๊ด€ํ•˜๋ฉฐ, ์ •๊ธฐ์ ์œผ๋กœ ๋ฐฑ์—… ๋ฐ ๊ฒ€ํ† ํ•ฉ๋‹ˆ๋‹ค.



5. DDoS ๋ฐ ์•…์„ฑ ์ฝ”๋“œ ๋ฐฉ์–ด


  • ๋™์  IP ์ œํ•œ (Dynamic IP Restrictions, DIR): ์งง์€ ์‹œ๊ฐ„ ๋‚ด์— ๋น„์ •์ƒ์ ์œผ๋กœ ๋งŽ์€ ์š”์ฒญ์„ ๋ณด๋‚ด๋Š” IP ์ฃผ์†Œ๋ฅผ ์ž๋™์œผ๋กœ ์ฐจ๋‹จํ•˜์—ฌ DDoS ๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ์„œ๋ฒ„๋ฅผ ๋ณดํ˜ธํ•ฉ๋‹ˆ๋‹ค.

  • URL ์žฌ์ž‘์„ฑ ๋ชจ๋“ˆ (URL Rewrite Module): ๋ณต์žกํ•œ ๋ณด์•ˆ ๊ทœ์น™์„ ์ ์šฉํ•˜๊ฑฐ๋‚˜ ์•…์„ฑ ์š”์ฒญ ํŒจํ„ด์„ ์ฐจ๋‹จํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.