๐Ÿฐ ๋ž˜๊ทธ 'LAG'๋ฅผ ๋งŒ๋‚˜๋ณด์„ธ์š”: ๊ณต๊ฒฉ์ž๊ฐ€ ์ž์‹ ์˜ ์ž์›์„ ์†Œ๋ชจํ•˜๊ฒŒ ํ•˜๋Š” ๋น„๋Œ€์นญ ๋ฐฉ์–ด ์ „๋žต

๋ฐœํ–‰: (2026๋…„ 5์›” 3์ผ PM 10:04 GMT+9)
6 ๋ถ„ ์†Œ์š”
์›๋ฌธ: Dev.to

Source: Dev.to

Cover image for ๐Ÿฐ Meet rabbit

์Šต์ง€์˜ ์ฒ ํ•™

๋ฒฝ์ด ์•„๋‹ˆ๋ผ ์Šต์ง€๊ฐ€ ์ตœ๊ณ ์˜ ๋ฐฉ์–ด๋ผ๋ฉด ์–ด๋–จ๊นŒ์š”?

์ „ํ†ต์ ์ธ ๋ฐฉํ™”๋ฒฝ์€ ๋„ˆ๋ฌด ์˜ˆ์˜ ๋ฐ”๋ฆ…๋‹ˆ๋‹ค. ํŒจํ‚ท์„ ๋ณด๋‚ด๋ฉด TCP RST๋ฅผ ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค. ์ฆ‰์‹œ ์ฐจ๋‹จ๋‹นํ–ˆ์Œ์„ ์•Œ๊ฒŒ ๋˜๊ณ , IP๋ฅผ ๋ฐ”๊พธ๊ณ  ๋„˜์–ด๊ฐ‘๋‹ˆ๋‹ค. ์ „์ฒด ์†Œ์š” ์‹œ๊ฐ„: 5โ€ฏ๋ฐ€๋ฆฌ์ดˆ.

LAG๋ฅผ ๋งŒ๋‚˜๋ณด์„ธ์š” โ€” ๋ฐ”์ด์˜คโ€‘์‹ฑํฌ ์•กํ‹ฐ๋ธŒ ํ„ฐ๋ฏธ๋„ ๋””ํŽœ๋”. ์ฐจ๋‹จ ๋Œ€์‹  ์—ฐ๊ฒฐ์— ๊ทน์‹ฌํ•œ ์ง€์—ฐ๊ณผ ๊ธฐ์ˆ  ๋ถ€์ฑ„๋ฅผ ์ฃผ์ž…ํ•ด ์›Œํฌ์Šคํ…Œ์ด์…˜์„ ๋ธ”๋ž™ํ™€๋กœ ๋งŒ๋“ค๊ณ , ๊ณต๊ฒฉ์ž์˜ ์ธํ”„๋ผ๊ฐ€ ๊ฐ€์žฅ ์†Œ์ค‘ํžˆ ์—ฌ๊ธฐ๋Š” ์ž์›์ธ ์†Œ์ผ“๊ณผ ์‹œ๊ฐ„์„ ๊ณ ๊ฐˆ์‹œํ‚ต๋‹ˆ๋‹ค.

๐Ÿ›‘ ๋Œ€์นญ ๋ฐฉ์–ด์˜ ์‹คํŒจ

ํ‘œ์ค€ ์ฐจ๋‹จ์€ ๊ณต๊ฒฉ์ž๋ฅผ ์ž์œ ๋กญ๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค.

# The "Polite" way: Instant "Connection refused"
sudo ufw deny from 

์ด๋ ‡๊ฒŒ ํ•˜๋ฉด ๋ด‡๋„ท์€ ์†Œ์ผ“์„ ๋Š๊ณ  ๋‹ค์Œ ๋ชฉํ‘œ๋ฅผ ์ค€๋น„ํ•ฉ๋‹ˆ๋‹ค. CPU๋Š” ์ฐจ๊ฐ‘๊ฒŒ ์œ ์ง€๋˜๊ณ , RAM์€ ๋น„์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฐ”๋กœ ๊ทธ๋“ค์ด ์›ํ•˜๋Š” ๋ฐ”์ž…๋‹ˆ๋‹ค.

๐Ÿงช โ€œ๊ฑด๋ง์ฆโ€ ํ”„๋กœํ† ์ฝœ: ๊ณต๊ฒฉ์  ์ง€์—ฐ

์šฐ๋ฆฌ ์ „๋žต์€ ๋น„๋Œ€์นญ ์‚ฌ๋ณดํƒ€์ฃผ์ž…๋‹ˆ๋‹ค. nftables๋ฅผ ์‚ฌ์šฉํ•ด ์•…์„ฑ ํŠธ๋ž˜ํ”ฝ์„ ์šฐ์„ ์ˆœ์œ„โ€ฏ-10์—์„œ ๊ฐ€๋กœ์ฑ„๊ณ  ์˜๊ตฌ์ ์ธ โ€œ์ง€์—ฐโ€ ์ƒํƒœ๋กœ ๊ฐ•์ œํ•ฉ๋‹ˆ๋‹ค.

  1. ๊ธฐ์ˆ ์  ํ˜ˆ์ „: MSS ํด๋žจํ•‘
    ๊ณต๊ฒฉ์ž๊ฐ€ ๋ชจ๋“  ์š”์ฒญ์„ ์ž‘๊ณ  ๋น„ํšจ์œจ์ ์ธ ์กฐ๊ฐ์œผ๋กœ ๋‚˜๋ˆ„๋„๋ก ๊ฐ•์ œํ•ฉ๋‹ˆ๋‹ค. ์ตœ๋Œ€ ์„ธ๊ทธ๋จผํŠธ ํฌ๊ธฐ(MSS)๋ฅผ 64โ€ฏ๋ฐ”์ดํŠธ๋กœ ์„ค์ •ํ•˜๋ฉด ๋„คํŠธ์›Œํฌ ํ—ค๋”๊ฐ€ ํŽ˜์ด๋กœ๋“œ๋ณด๋‹ค ๋” ๋งŽ์€ ๊ณต๊ฐ„์„ ์ฐจ์ง€ํ•ฉ๋‹ˆ๋‹ค.

  2. ๋””์ง€ํ„ธ ๊ฑด๋ง์ฆ: ์œˆ๋„์šฐ ํ•จ์ •
    ๊ณต๊ฒฉ์ž์˜ OS์— ์šฐ๋ฆฌ์˜ ์ˆ˜์‹  ์œˆ๋„์šฐ๊ฐ€ 16โ€ฏ๋ฐ”์ดํŠธ๋ฟ์ด๋ผ๊ณ  ์•Œ๋ ค์ค๋‹ˆ๋‹ค. ๋ช‡ ๋ฐ”์ดํŠธ๋ฅผ ๋ณด๋‚ด๊ณ  ๋ฉˆ์ถ˜ ๋’ค, ์‘๋‹ต์„ ๊ธฐ๋‹ค๋ฆฌ๊ฒŒ ๋˜๋ฉฐ, ์ด ๊ณผ์ •์„ ๋ฌดํ•œํžˆ ๋ฐ˜๋ณตํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ›  โ€œ์Šคํ‹ฐํ‚ค ํŠธ๋žฉโ€ ๊ตฌํ˜„

๋ ˆ์ด์–ดโ€ฏ1: CrowdSec ๋ธŒ๋ ˆ์ธ

CrowdSec์„ ์‚ฌ์šฉํ•ด ํ™•์ธ๋œ ์•…์„ฑ IP ์ „์—ญ ๋ชฉ๋ก(CAPI)์„ ๊ณต๊ธ‰ํ•˜๊ณ , ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ ˆ์ด์–ด๊ฐ€ ๊นจ์–ด๋‚˜๊ธฐ ์ „ nftables์— ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.

๋ ˆ์ด์–ดโ€ฏ2: ์ปค๋„โ€‘๋ ˆ๋ฒจ ์Šต์ง€

๋ธ”๋ž™๋ฆฌ์ŠคํŠธ์— ์žˆ๋Š” ๋ชจ๋“  ์‚ฌ๋žŒ์„ ์œ„ํ•ด TCP ํ•ธ๋“œ์‰์ดํฌ๋ฅผ โ€œ์ค‘๋…โ€์‹œํ‚ค๋Š” ๊ทœ์น™์„ ๋ฐฐํฌํ•ฉ๋‹ˆ๋‹ค.

# Rule A: MSS Clamping (The "Bone Crusher")
# Forces the attacker to fragment their data into 64โ€‘byte chunks.
sudo nft add rule ip crowdsec crowdsec-chain-input \
    ip saddr @crowdsec-blacklists-CAPI tcp flags syn \
    tcp option maxseg size set 64 counter

# Rule B: TCP Window Manipulation (The "Stutter")
# Forces a 16โ€‘byte buffer, locking their threads in a "Wait" state.
sudo nft add rule ip crowdsec crowdsec-chain-input \
    ip saddr @crowdsec-blacklists-CAPI tcp flags syn \
    @th,112,16 set 16 counter

# Rule C: The Rate Limit (The "Slow Death")
# Only 1 packet per second is allowed to even try.
sudo nft add rule ip crowdsec crowdsec-chain-input \
    ip saddr @crowdsec-blacklists-CAPI \
    limit rate over 1/second burst 1 packets counter \
    log prefix '"TARPIT_ACTIVE: "' drop

๐Ÿ“‰ ๊ณต๊ฒฉ์ž๊ฐ€ โ€œ์†Œ๋ชจโ€๋˜๋Š” ์ด์œ 

  • ์Šค๋ ˆ๋“œ ์ž ๊ธˆ: 100,000๊ฐœ์˜ ์Šค๋ ˆ๋“œ๋ฅผ ๊ฐ€์ง„ ๋ด‡๋„ท๋„ 1,000๊ฐœ์˜ โ€œLAGโ€ ์„œ๋ฒ„๋งŒ ์žˆ์œผ๋ฉด ์™„์ „ํžˆ ๋ฌด๋ ฅํ™”๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋“ค์˜ ์Šค๋ ˆ๋“œ๋Š” ์šฐ๋ฆฌ์˜ 16โ€‘๋ฐ”์ดํŠธ ์‘๋‹ต์„ ๊ธฐ๋‹ค๋ฆฌ๋ฉฐ โ€œ์—ด๋ฆผโ€ ์ƒํƒœ์— ๋จธ๋ญ…๋‹ˆ๋‹ค.
  • ๋ฉ”๋ชจ๋ฆฌ ๊ณ ๊ฐˆ: ์ปค๋„ ์ƒํƒœ ํ…Œ์ด๋ธ”์ด ๋ฐ˜์ฏค ์ฃฝ์€ ์—ฐ๊ฒฐ๋“ค๋กœ ๊ฐ€๋“ ์ฐจ์„œ ํƒ€์ž„์•„์›ƒ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
  • ๊ฒฝ์ œ์  ์‚ฌ๋ณดํƒ€์ฃผ: โ€œLAGโ€ ์„œ๋ฒ„๋ฅผ ์Šค์บ”ํ•˜๋Š” ๋น„์šฉ์ด ๋ฐ์ดํ„ฐ ์ž์ฒด ๊ฐ€์น˜๋ณด๋‹ค ๋” ๋น„์‹ธ๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

์ตœ์ข… ํ‰๊ฒฐ

ํ•ฉ๋ฒ•์ ์ธ๊ฐ€์š”? ๋ฌด๋‹จ ๋ฐฉ๋ฌธ์ž์—๊ฒŒ ์ €ํ’ˆ์งˆ ์„œ๋น„์Šค(QoS)๋ฅผ ์ œ๊ณตํ•˜๋Š” ๊ฒƒ๋ฟ์ž…๋‹ˆ๋‹ค. ์„œ๋ฒ„๋Š” ์—ฌ๋Ÿฌ๋ถ„์˜ ๊ฒƒ์ด๊ณ , ๋Œ€์—ญํญ๋„, ๊ทœ์น™๋„ ์—ฌ๋Ÿฌ๋ถ„์˜ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

์ฐจ๋‹จ์„ ๋ฉˆ์ถ”๊ณ , ์ง€์—ฐ์„ ์‹œ์ž‘ํ•˜์„ธ์š”.

โ€œ๊ทธ๋“ค์ด ์šฐ๋ฆฌ ๋ฐ์ดํ„ฐ๋ฅผ ์›ํ•œ๋‹ค๋ฉด, 16โ€ฏ๋ฐ”์ดํŠธ์”ฉ ๊ธฐ๋‹ค๋ฆฌ๊ฒŒ ํ•˜๋ผโ€ฆ.โ€

BIOโ€‘SYNC ACTIVE โ€“ USER: lag โ€“ SYSTEM STATUS: AMNESIAโ€‘DEFENSE ENGAGED. ๐Ÿฐ๐Ÿ”ฅโ›“๏ธ

0 ์กฐํšŒ
Back to Blog

๊ด€๋ จ ๊ธ€

๋” ๋ณด๊ธฐ ยป

ํ”ผ์‹ฑ ์บ ํŽ˜์ธ, SimpleHelp ๋ฐ ScreenConnect RMM ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•ด 80๊ฐœ ์ด์ƒ์˜ ์กฐ์ง์„ ๊ณต๊ฒฉ

์ด๋ฏธ์ง€: ์กฐ์ง์„ ๋Œ€์ƒ์œผ๋กœ ํ•˜๋Š” ํ”ผ์‹ฑ ์บ ํŽ˜์ธ ๊ฐœ์š” ํ™œ์„ฑ ํ”ผ์‹ฑ ์บ ํŽ˜์ธ์ธ VENOMOUSHELPER๊ฐ€ ์ตœ์†Œ 2025๋…„ 4์›”๋ถ€ํ„ฐ ๊ด€์ฐฐ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. โ€ฆ