Skip to content

mytlsdnkr/wazuh

ย 
ย 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

11,227 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

Wazuh

Slack Email Documentation Documentation Coverity

Wazuh๋Š” ์šด์˜ ์ฒด์ œ ๋ฐ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ์ˆ˜์ค€์—์„œ ํ˜ธ์ŠคํŠธ๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ ์ธํ”„๋ผ์— ๋Œ€ํ•œ ๊ฐ•๋ ฅํ•œ ๋ณด์•ˆ ๊ฐ€์‹œ์„ฑ์„ ์–ป์„ ์ˆ˜ ์žˆ๋„๋ก ๋„์™€์ค๋‹ˆ๋‹ค. ๊ฐ€๋ฒผ์šด ๋ฉ€ํ‹ฐ ํ”Œ๋žซํผ ์—์ด์ „ํŠธ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœํ•˜๋Š” ์ด ์†”๋ฃจ์…˜์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

  • ๋กœ๊ทธ ๊ด€๋ฆฌ ๋ฐ ๋ถ„์„: Wazuh ์—์ด์ „ํŠธ๋Š” ์šด์˜ ์ฒด์ œ ๋ฐ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋กœ๊ทธ๋ฅผ ์ฝ๊ณ , ์ด๋ฅผ ๊ทœ์น™ ๊ธฐ๋ฐ˜ ๋ถ„์„ ๋ฐ ์ €์žฅ์„ ์œ„ํ•ด ์ค‘์•™ ๊ด€๋ฆฌ์ž์—๊ฒŒ ์•ˆ์ „ํ•˜๊ฒŒ ์ „๋‹ฌํ•ฉ๋‹ˆ๋‹ค.

  • ํŒŒ์ผ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์‚ฌ: Wazuh๋Š” ํŒŒ์ผ ์‹œ์Šคํ…œ์˜ ๋‚ด์šฉ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ ๋‚ด์šฉ ๋ณ€๊ฒฝ, ์‚ฌ์šฉ ๊ถŒํ•œ, ์†Œ์œ ๊ถŒ ๋ฐ ํŒŒ์ผ ํŠน์„ฑ๋“ฑ์˜ ๋ณ€๊ฒฝ์„ ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค.

  • ์นจ์ž„ ๋ฐ ์ด์ƒ ํƒ์ง€: ์—์ด์ „ํŠธ๋Š” malware, rootkits ๋˜๋Š” ์˜์‹ฌ์Šค๋Ÿฌ์šด ๋ณ€๊ฒฝ์„ ์ฐพ๊ธฐ์œ„ํ•ด์„œ ์‹œ์Šคํ…œ์„ ์Šค์บ”ํ•˜๊ณ , ์ˆจ๊ฒจ์ง„ ํŒŒ์ผ, ์€ํ ๋œ ํ”„๋กœ์„ธ์Šค ๋˜๋Š” ๋“ฑ๋ก๋˜์ง€ ์•Š์€ ๋„คํŠธ์›Œํฌ ๋ฆฌ์Šค๋„ˆ, ์‹œ์Šคํ…œ ์ฝœ ์‘๋‹ต์˜ ๋ถˆ์ผ์น˜๋ฅผ ๋ฐœ๊ฒฌ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • ์ •์ฑ… ๋ฐ ์ค€์ˆ˜ ๋ชจ๋‹ˆํ„ฐ๋ง: Wazuh๋Š” ๊ตฌ์„ฑ ํŒŒ์ผ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ ๋ณด์•ˆ ์ •์ฑ…, ํ‘œ์ค€ ๋˜๋Š” ๊ฐ•ํ™” ๊ฐ€์ด๋“œ๋ฅผ ์ค€์ˆ˜ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์—์ด์ „ํŠธ๋Š” ์ทจ์•ฝ์„ฑ, ํŒจ์น˜ ๋ถ€์กฑ ๋˜๋Š” ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ๊ฒƒ์œผ๋กœ ์•Œ๋ ค์ง„ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์„ ํƒ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ์ฃผ๊ธฐ์ ์œผ๋กœ ๊ฒ€์‚ฌ๋ฅผ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

์ด๋Ÿฌํ•œ ๋‹ค์–‘ํ•œ ๊ธฐ๋Šฅ๋“ค์€ OSSEC, OpenSCAP, Elastic Stack๊ณผ ํ•จ๊ป˜ ํ†ตํ•ฉ ์†”๋ฃจ์…˜์œผ๋กœ ์ œ๊ณต๋˜๊ณ , ์„ค์ •๊ณผ ๊ด€๋ฆฌ๋ฅผ ๋‹จ์ˆœํ™”ํ•ฉ๋‹ˆ๋‹ค.

Wazuh๋Š” ์—…๋ฐ์ดํŠธ ๋œ ๋กœ๊ทธ ๋ถ„์„ ruleset๊ณผ ๋ชจ๋“  Wazuh ์—์ด์ „ํŠธ์˜ ์ƒํƒœ ๋ฐ ๊ตฌ์„ฑ์„ ๋ชจ๋‹ˆํ„ฐ ํ•  ์ˆ˜์žˆ๋Š” RESTful API๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

Wazuh๋Š” ๋˜ํ•œ ๋กœ๊ทธ ๋ถ„์„ ๊ฒฝ๊ณ  ๋ฐ Wazuh ์ธํ”„๋ผ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•œ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ (Kibana ์•ฑ)์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.

Wazuh Open Source components and contributions

  • Wazuh๋Š” OSSEC HIDS๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๋งŒ๋“ค์–ด์กŒ๊ณ , ์ƒˆ๋กœ์šด ๊ธฐ๋Šฅ๋“ค์„ ์ถ”๊ฐ€ํ•˜๊ณ , ๋ฒ„๊ทธ๋ฅผ ์ˆ˜์ •ํ•˜์˜€์Šต๋‹ˆ๋‹ค.

  • Wazuh App์€ ๋กœ๊ทธ ๋ถ„์„ ๋ฐ ๊ฒฝ๊ณ , Wazuh ์ธํ”„๋ผ๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ธฐ ์œ„ํ•œ Kibana app์— ํ†ตํ•ฉํ•  ์ˆ˜ ์žˆ๋Š” ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ž…๋‹ˆ๋‹ค.

  • Wazuh Ruleset์€ decorders, rules, rootchecks ๊ทธ๋ฆฌ๊ณ  SCAP ๋“ฑ์„ ๊ด€๋ฆฌํ•˜๋Š” ์ €์žฅ์†Œ ์ž…๋‹ˆ๋‹ค. ruleset์€ ๊ด€๋ฆฌ์ž๊ฐ€ ๊ณต๊ฒฉ, ์นจ์ž…, ์†Œํ”„ํŠธ์›จ์–ด ์˜ค์šฉ, ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ์˜ค๋ฅ˜, ๋ฉ€์›จ์–ด, ๋ฃจํŠธํ‚ท, ์‹œ์Šคํ…œ ์ด์ƒ ๋˜๋Š” ๋ณด์•ˆ ์ •์ฑ… ์œ„๋ฐ˜์„ ํƒ์ง€ํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ๋˜ํ•œ PCI DSS v3.1 ๋ฐ CIS์™€์˜ ๋งคํ•‘์„ ํฌํ•ฉํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž๋Š” pull request๋ฅผ ์ด์šฉํ•˜์—ฌ ์ด ruleset์„ ์šฐ๋ฆฌ์˜ Github repository์— ๊ธฐ์—ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • Wazuh RESTful API๋Š” Wazuh ์„ค์น˜๋ฅผ ๋ชจ๋‹ˆํ„ฐํ•˜๊ณ  ์ œ์–ดํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋˜๋ฉฐ HTTP ์š”์ฒญ์„ ๋ณด๋‚ผ ์ˆ˜์žˆ๋Š” ๋ชจ๋“  ๊ฒƒ์—์„œ ๊ด€๋ฆฌ์ž์™€ ์ƒํ˜ธ ์ž‘์šฉํ•  ์ˆ˜์žˆ๋Š” ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

  • Pre-compiled installation packages๋Š” RedHat, CentOS, Fedora, Debian, Ubuntu and Windows์™€ ๊ฐ™์€ OS์—์„œ์˜ ๋ฏธ๋ฆฌ ์ปดํŒŒ์ผ๋œ ํŒจํ‚ค์ง€๋“ค์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

  • Puppet scripts๋Š” ์ž๋™์œผ๋กœ Wazuh๋ฅผ ๋ฐฐํฌํ•˜๊ณ  ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

  • Docker containers๋Š” Wazuh ๊ด€๋ฆฌ์ž๋ฅผ ๊ฐ€์ƒํ™” ํ•˜๊ณ , ELK ์Šคํƒ๊ณผ ํ†ตํ•ฉ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

Documentation

Branches

  • stable branch๋Š” ๊ฐ€์žฅ ์ตœ๊ทผ์˜ ์•ˆ์ •ํ™” ๋œ ๋ฒ„์ „์— ํ•ด๋‹นํ•ฉ๋‹ˆ๋‹ค.
  • master branch๋Š” ์ตœ๊ทผ์˜ ์ฝ”๋“œ๋ฅผ ํฌํ•จํ•˜๊ณ , ๋ฒ„๊ทธ๋ฅผ ๊ฐ€์งˆ ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์Šต๋‹ˆ๋‹ค.

Contribute

๋งŒ์•ฝ ๋‹น์‹ ์ด ์šฐ๋ฆฌ์˜ ํ”„๋กœ์ ํŠธ์— ๊ธฐ์—ฌํ•˜๊ณ  ์‹ถ๋‹ค๋ฉด ์ฃผ์ €ํ•˜์ง€๋ง๊ณ  request๋ฅผ ์š”์ฒญํ•˜์„ธ์š”. ๋˜ํ•œ ์šฐ๋ฆฌ์˜ mailing list์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜, ์งˆ๋ฌธ์ด ์žˆ๊ฑฐ๋‚˜ ํ† ๋ก ์— ์ฐธ์—ฌํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์Œ์˜ ์ฃผ์†Œ๋กœ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. wazuh+subscribe@googlegroups.com

Software and libraries used

  • OpenSSL์˜ SHA1, Blowfish ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์™€ zlib์„ ์ˆ˜์ •ํ•œ ๋ฒ„์ „์„ ์‚ฌ์šฉ
  • OpenSSL ํˆดํ‚ท์— ์‚ฌ์šฉ๋˜๋Š” OpenSSL ํ”„๋กœ์ ํŠธ ์‚ฌ์šฉ
  • Eric Young(eay@cryptsoft.com)์— ์˜ํ•ด์„œ ๋งŒ๋“ค์–ด์ง„ ์•”ํ˜ธํ™” ์†Œํ”„ํŠธ์›จ์–ด
  • Zlib ํ”„๋กœ์ ํŠธ (Jean-loup Gailly and Mark Adler).
  • cJSON ํ”„๋กœ์ ํŠธ (Dave Gamble).
  • Node.js (Ryan Dahl).
  • NPM packages Body Parser, Express, HTTP-Auth and Moment.
  • Guido van Rossum๊ณผ ํŒŒ์ด์ฌ ๊ฐœ๋ฐœํŒ€์—์„œ ๋งŒ๋“  Cython ์ธํ„ฐํ”„๋ฆฌํ„ฐ (https://www.python.org).
  • PyPi packages: azure-storage-blob, boto3, cryptography, docker, pytz, requests and uvloop.

Credits and Thank you

License and copyright

WAZUH Copyright (C) 2016-2019 Wazuh Inc. (License GPLv2)

Based on OSSEC Copyright (C) 2015 Trend Micro Inc.

References

About

Wazuh - Host and endpoint security

Resources

License

Stars

Watchers

Forks

Packages

 
 
 

Contributors

Languages

  • C 77.8%
  • Python 13.4%
  • Shell 4.2%
  • Perl 1.6%
  • Makefile 1.1%
  • TSQL 0.6%
  • Other 1.3%