πŸ” Security

[Security] μƒŒλ“œλ°•μŠ€(Sandbox)와 μƒŒλ“œλ°•μŠ€μ˜ 취약점

Rosieblue 2023. 5. 12. 19:05
728x90

μƒŒλ“œλ°•μŠ€

λͺ¨λž˜ μ•ˆμ—μ„œ ν”„λ‘œκ·Έλž¨μ„ μ‹€ν–‰ν•˜λŠ” λͺ¨μŠ΅. 어린이듀을 ν‘Ήμ‹ ν‘Ήμ‹ ν•œ λͺ¨λž˜ μœ„μ—μ„œ μ•ˆμ „ν•˜κ²Œ λ†€κ²Œν•˜λŠ” κ²ƒμ—μ„œ 유래됨.

 

μ•„λž˜ μƒŒλ“œλ°•μŠ€μ˜ μ •μ˜μ— λŒ€ν•΄ μ‰½κ²Œ μ„€λͺ…ν•΄ 놓은 쒋은 글이 μžˆμ–΄μ„œ 이λ₯Ό λ°œμ·Œν•΄ λ³΄μ•˜λ‹€.

"Sandboxing is a form of software virtualization that lets programs and processes run in its isolated virtual environment. Typically, programs running within the sandbox have limited access to your files and system, and they can make no permanent changes. That means that whatever happens in the sandbox stays in the sandbox." (https://web.archive.org/web/20140712130329/http://www.techhive.com/article/247416/how_to_keep_your_pc_safe_with_sandboxing.html)

 

How to Keep Your PC Safe With Sandboxing

Setting up your PC to run important apps in a sandbox can help you avoid malware infections. Here's how to do it.

web.archive.org

 

μƒŒλ“œλ°•μŠ€λŠ” μ†Œν”„νŠΈμ›¨μ–΄ 가상화 기술의 μΌμ’…μœΌλ‘œ ν”„λ‘œκ·Έλž¨κ³Ό ν”„λ‘œμ„ΈμŠ€λ“€μ„μ€ 고립된 가상 ν™˜κ²½μ—μ„œ μž‘λ™ν•  수 있게 ν•œλ‹€. 가상화 κΈ°μˆ μ— λŒ€ν•΄μ„œλŠ” λ‹€λ₯Έ 포슀트λ₯Ό μž‘μ„±ν•˜λ„λ‘ ν•˜κ² λ‹€. κ°„λ‹¨νžˆ 예λ₯Ό λ“€λ©΄ μ„œλ²„ 가상화, 도컀, vm, μƒŒλ“œλ°•μŠ€ 같은 것듀이 가상화 κΈ°μˆ μ„ μ΄μš©ν•œ 사둀이닀.

μ „ν˜•μ μœΌλ‘œ, μƒŒλ“œλ°•μŠ€ λ‚΄μ—μ„œ μ‹€ν–‰λ˜λŠ” ν”„λ‘œκ·Έλž¨λ“€μ€ 우리의 파일 μ‹œμŠ€ν…œμ— μ œν•œλœ μ ‘κ·Ό κΆŒν•œμ„ 가지고 μžˆλ‹€. λ˜ν•œ 그듀은 영ꡬ적인 변경도 μ–΄λ ΅κ²Œ ν•œλ‹€. 즉, μƒŒλ“œλ°•μŠ€ μ•ˆμ—μ„œ μΌμ–΄λ‚˜λŠ” 일듀은 계속 μƒŒλ“œλ°•μŠ€ μ•ˆμ— μžˆλŠ” 것이닀.

 

 

μœ„ 그림이 μƒŒλ“œλ°•μŠ€μ˜ 원리λ₯Ό μ§κ΄€μ μœΌλ‘œ μ•ŒκΈ° μ‰½κ²Œ 보여주고 μžˆλ‹€.

 

즉 μ™ΈλΆ€λ‘œλΆ€ν„° λ“€μ–΄μ˜¨ ν”„λ‘œκ·Έλž¨μ΄λ‚˜ μ‹€ν–‰ νŒŒμΌμ„ 가상화 λ‚΄λΆ€μ—μ„œ μ‹œν—˜μ μœΌλ‘œ λ™μž‘μ‹œμΌœλ΄„μœΌλ‘œμ¨ 가상화 λ°–μœΌλ‘œλŠ” 영ν–₯을 주지 μ•ŠλŠ”λ‹€. ν•œ λ§ˆλ””λ‘œ 가상화 κΈ°μˆ μ„ μ•…μ„±ν–‰μœ„λ‚˜ μ•…μ„±μ½”λ“œ 감지 μ‹œμŠ€ν…œμ— μ μš©ν•œ, λ³΄μ•ˆ κ°€μƒν™”μ˜ 일쒅인 것이닀. (좜처 : ITμš©μ–΄μ‚¬μ „, ν•œκ΅­μ •λ³΄ν†΅μ‹ κΈ°μˆ ν˜‘νšŒ)

 

μƒŒλ“œλ°•μŠ€λ₯Ό μ•„λž˜μ²˜λŸΌ μ“Έμˆ˜ μžˆλ‹€. 이λ₯Ό 보면 μƒŒλ“œλ°•μŠ€κ°€ 무엇인지 μ‘°κΈˆμ€ 감이 작힐 것이닀.

  • Automatically or manually run unknown programs in the sandbox in case they contain viruses, spyware, or other malware. (멀웨어듀을 μƒŒλ“œλ°•μŠ€μ—μ„œ 싀행함)
  • Run your Web browser within the sandbox to prevent damage from any infections you pick up while browsing, which is the most common origin of malware.(μ›ΉλΈŒλΌμš°μ €λ₯Ό μƒŒλ“œλ°•μŠ€μ—μ„œ μ‹€ν–‰μ‹œμΌœμ„œ λ©€μ›¨μ–΄λ“±μ˜ λ‹€μš΄μ— μ˜ν•œ ν”Όν•΄λ₯Ό μ΅œμ†Œν™”ν•˜κΈ°)
  • Run your browser within the sandbox to stop any existing malware on your computer from capturing your site login credentials or your online-shopping payment details. (μ›ΉλΈŒλΌμš°μ €λ₯Ό μƒŒλ“œλ°•μŠ€μ—μ„œ μ‹€ν–‰μ‹œμΌœμ„œ ν˜Ήμ‹œλ‚˜ λͺ¨λ₯Ό 정보 νƒˆμ·¨μ— λŒ€λΉ„ν•˜κΈ°)

 

 

μƒŒλ“œλ°•μŠ€ 취약점

 

λ‹€μŒμ€ '2014 κΈ°μ—… μ •λ³΄λ³΄μ•ˆ κ°€μ΄λ“œ v.9'μ—μ„œ λ°œμ·Œν•œ 글이닀.

 

  • νŒŒμ΄μ–΄μ•„μ΄κ°€ λ°œν‘œν•œ '파일기반 μƒŒλ“œλ°•μŠ€λ₯Ό μ‰½κ²Œ νšŒν”Όν•˜λŠ” μ•…μ„±μ½”λ“œ 기법' λ³΄κ³ μ„œμ—μ„œλŠ” μ•„μ£Ό κ°„λ‹¨ν•˜κ²Œ μƒŒλ“œλ°•μŠ€λ₯Ό νšŒν”Όν•˜λŠ” 기법이 μ†Œκ°œλλ‹€. κ·Έ 쀑 ν•˜λ‚˜κ°€ μ•…μ„±νŒŒμΌμ΄ μ‹€ν–‰λœ ν›„ μƒλ‹Ήν•œ μ‹œκ°„μ΄ μ§€λ‚œ λ‹€μŒ 곡격을 μ‹œμž‘ν•˜λ„λ‘ μ„€κ³„ν•˜λŠ” 것이닀. μƒŒλ“œλ°•μŠ€λŠ” μ•…μ„±νŒŒμΌλ‘œ μ˜μ‹¬λ˜λŠ” 것을 μ‹€ν–‰μ‹œμΌœ λ³Έ ν›„ μΌμ •μ‹œκ°„ λ™μ•ˆ μ˜μ‹¬μŠ€λŸ¬μš΄ μ™ΈλΆ€ μ„œλ²„μ™€ 톡신을 ν•˜λŠ”μ§€, ν˜Ήμ€ λ‹€λ₯Έ μ•…μ„±μ½”λ“œλ₯Ό μ„€μΉ˜ν•˜λŠ”μ§€ 등을 μ‚΄νŽ΄λ³Έλ‹€. 이 점을 μ•…μš©ν•œ μ•…μ„±νŒŒμΌμ€ μ‹€ν–‰ μ¦‰μ‹œ μ™ΈλΆ€ κ³΅κ²©μ„œλ²„μ™€ 톡신을 μ‹œμž‘ν•˜λŠ” 것이 μ•„λ‹ˆλΌ μƒŒλ“œλ°•μŠ€κ°€ λͺ¨λ‹ˆν„°λ§ν•˜λŠ” μ‹œκ°„μ΄ μ§€λ‚œ ν›„ 곡격을 μ‹œμž‘ν•œλ‹€.
  • 또 λ‹€λ₯Έ 방법은 ν‚€λ³΄λ“œλ‚˜ 마우슀 μ‘°μž‘μ„ κ°μ§€ν•œ ν›„ 곡격을 μ‹œμž‘ν•˜λŠ” 것이닀. μƒŒλ“œλ°•μŠ€λŠ” κ°€μƒν™˜κ²½μ—μ„œ μžλ™μœΌλ‘œ μ•…μ„±νŒŒμΌμ„ μ‹€ν–‰μ‹œμΌœλ³΄κΈ° λ•Œλ¬Έμ— ν‚€λ³΄λ“œλ‚˜ 마우슀 μ‘°μž‘μ΄ μ—†λ‹€. λ”°λΌμ„œ μ΄λŸ¬ν•œ μ‘°μž‘ 없이 파일이 μ‹€ν–‰λ˜λ©΄ 곡격을 ν•˜μ§€ μ•Šκ³ , μ‘°μž‘μ΄ μžˆμ„ λ•Œμ—λ§Œ κ³΅κ²©ν•˜λ„λ‘ μ„€κ³„ν•˜λ©΄ κ°„λ‹¨ν•˜κ²Œ μƒŒλ“œλ°•μŠ€λ₯Ό μš°νšŒν•  수 μžˆλ‹€.