{"id":477573,"date":"2023-08-09T09:16:45","date_gmt":"2023-08-09T09:16:45","guid":{"rendered":""},"modified":"2023-09-05T11:14:59","modified_gmt":"2023-09-05T11:14:59","slug":"indicator-of-compromise-ioc","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/kr\/wiki\/indicator-of-compromise-ioc\/","title":{"rendered":"IOC(\uce68\ud574 \uc9c0\ud45c)"},"content":{"rendered":"<p>IOC(\uce68\ud574 \uc9c0\ud45c)\ub294 \ub192\uc740 \uc2e0\ub8b0\uc131\uc744 \uac00\uc9c0\uace0 \ucef4\ud4e8\ud130 \uce68\uc785\uc744 \ub098\ud0c0\ub0b4\ub294 \ub124\ud2b8\uc6cc\ud06c \ub610\ub294 \uc6b4\uc601 \uccb4\uc81c\uc5d0\uc11c \uad00\ucc30\ub418\ub294 \uc544\ud2f0\ud329\ud2b8\ub97c \ub098\ud0c0\ub0c5\ub2c8\ub2e4. \uc774\ub294 \uc54c\ub824\uc9c4 \uc545\uc131 IP \uc8fc\uc18c, URL, \ub3c4\uba54\uc778 \uc774\ub984, \uc774\uba54\uc77c \uc8fc\uc18c, \ud30c\uc77c \ud574\uc2dc \ub610\ub294 \ub3d9\uc791\uc774\ub098 \ucf54\ub4dc \uc870\uac01\uacfc \uac19\uc740 \ub9ec\uc6e8\uc5b4\uc758 \uace0\uc720\ud55c \uc18d\uc131 \ud615\ud0dc\uc77c \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<h2>\uce68\ud574 \uc9c0\ud45c(IOC)\uc758 \uc9c4\ud654<\/h2>\n<p>IOC(\uce68\ud574 \uc9c0\ud45c)\uc758 \uac1c\ub150\uc740 \uc0ac\uc774\ubc84 \ubcf4\uc548 \uc0b0\uc5c5\uc758 \ubc1c\uc804\uc5d0 \ubfcc\ub9ac\ub97c \ub450\uace0 \uc788\uc2b5\ub2c8\ub2e4. \uc774 \uc6a9\uc5b4 \uc790\uccb4\ub294 2013\ub144\uacbd \uc815\ubcf4 \ubcf4\uc548 \ud68c\uc0ac\uc778 Mandiant\uac00 \uc0ac\uc774\ubc84 \uc704\ud611 \uc778\ud154\ub9ac\uc804\uc2a4 \uc6b4\uc601\uc758 \uc77c\ud658\uc73c\ub85c \ucc98\uc74c \ub9cc\ub4e4\uc5b4\ub0c8\uc2b5\ub2c8\ub2e4. \ubaa9\ud45c\ub294 \uae30\uc874 \ubcf4\uc548 \uc870\uce58\ubcf4\ub2e4 \ub354 \uc0ac\uc804 \uc608\ubc29\uc801\uc778 \ubc29\uc2dd\uc73c\ub85c \uc815\uad50\ud55c \uc0ac\uc774\ubc84 \uc704\ud611\uc744 \uc2dd\ubcc4, \ucd94\uc801 \ubc0f \ub300\uc751\ud558\ub294 \uac83\uc774\uc5c8\uc2b5\ub2c8\ub2e4.<\/p>\n<p>\ucd08\uae30 \ubcf4\uc548 \uc870\uce58\ub294 \uc77c\ubc18\uc801\uc73c\ub85c \ucde8\uc57d\uc131\uc774 \uc545\uc6a9\ub41c \ud6c4 \uc2dc\uc2a4\ud15c\uc744 \ud328\uce58\ud558\ub294 \ub370 \uc911\uc810\uc744 \ub450\uace0 \ub300\uc751\uc801\uc774\uc5c8\uc2b5\ub2c8\ub2e4. \uadf8\ub7ec\ub098 \uc0ac\uc774\ubc84 \uc704\ud611\uc774 \ub354\uc6b1 \uace0\ub3c4\ud654\ub418\uba74\uc11c \uc774\ub7ec\ud55c \uc870\uce58\ub294 \ubd80\uc801\uc808\ud55c \uac83\uc73c\ub85c \ud310\uba85\ub418\uc5b4 \ubcf4\ub2e4 \uc801\uadf9\uc801\uc778 \uc811\uadfc\uc774 \ud544\uc694\ud588\uc2b5\ub2c8\ub2e4. \uc774\ub85c \uc778\ud574 IOC\uac00 \uac1c\ubc1c\ub418\uc5b4 \ubcf4\uc548 \ud300\uc774 \uc7a0\uc7ac\uc801\uc778 \uc704\ud611\uc774 \ud53c\ud574\ub97c \uc785\ud788\uae30 \uc804\uc5d0 \uc774\ub97c \uac10\uc9c0\ud560 \uc218 \uc788\uac8c \ub418\uc5c8\uc2b5\ub2c8\ub2e4.<\/p>\n<h2>\uce68\ud574 \uc9c0\ud45c(IOC) \uc774\ud574<\/h2>\n<p>IOC(\uce68\ud574 \uc9c0\ud45c)\ub294 \uc2dc\uc2a4\ud15c \ub610\ub294 \ub124\ud2b8\uc6cc\ud06c \ub0b4\uc5d0\uc11c \uc545\uc758\uc801\uc778 \ud65c\ub3d9\uc744 \uc2dd\ubcc4\ud558\ub294 \ub370 \ub3c4\uc6c0\uc774 \ub418\ub294 \ud3ec\ub80c\uc2dd \ub9c8\ucee4 \uc5ed\ud560\uc744 \ud569\ub2c8\ub2e4. IOC\ub294 \uc0ac\uc774\ubc84 \ubcf4\uc548 \uc804\ubb38\uac00\uac00 \uc704\ud611\uc744 \uc870\uae30\uc5d0 \ud0d0\uc9c0\ud558\ub3c4\ub85d \uc9c0\uc6d0\ud558\uc5ec \uc704\ud611\uc5d0 \uc2e0\uc18d\ud558\uac8c \ub300\uc751\ud568\uc73c\ub85c\uc368 \uc7a0\uc7ac\uc801\uc778 \ud53c\ud574\ub97c \uc644\ud654\ud560 \uc218 \uc788\ub3c4\ub85d \ud569\ub2c8\ub2e4.<\/p>\n<p>IOC\ub294 \uacf5\uac1c \ubcf4\uace0\uc11c, \uc0ac\uace0 \ub300\uc751 \ud65c\ub3d9, \uc815\uae30\uc801\uc778 \ub85c\uadf8 \ubd84\uc11d\uc744 \ud1b5\ud574 \ud30c\uc0dd\ub429\ub2c8\ub2e4. IOC\uac00 \uc2dd\ubcc4\ub418\uba74 \uc704\ud611 \uc778\ud154\ub9ac\uc804\uc2a4 \ud53c\ub4dc\ub97c \ud1b5\ud574 \uc0ac\uc774\ubc84 \ubcf4\uc548 \ucee4\ubba4\ub2c8\ud2f0 \ub0b4\uc5d0\uc11c \uacf5\uc720\ub429\ub2c8\ub2e4. IOC\ub97c \uacf5\uc720\ud558\uba74 \uc870\uc9c1\uc740 \uc54c\ub824\uc9c4 \uc704\ud611\uc73c\ub85c\ubd80\ud130 \ub124\ud2b8\uc6cc\ud06c\ub97c \ubcf4\ud638\ud558\uace0 \uc2dd\ubcc4\ub41c IOC\uc640 \uad00\ub828\ub41c \ub124\ud2b8\uc6cc\ud06c \ud2b8\ub798\ud53d\uc744 \ucc28\ub2e8\ud558\uac70\ub098 \ubaa8\ub2c8\ud130\ub9c1\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<h2>IOC(\uce68\ud574 \uc9c0\ud45c)\uc758 \uae30\ub2a5<\/h2>\n<p>IOC(\uce68\ud574 \uc9c0\ud45c)\uc758 \ud575\uc2ec \uae30\ub2a5\uc740 \uc7a0\uc7ac\uc801\uc73c\ub85c \ubcf4\uc548 \uc0ac\uace0\ub85c \uc774\uc5b4\uc9c8 \uc218 \uc788\ub294 \uc758\uc2ec\uc2a4\ub7ec\uc6b4 \ud65c\ub3d9\uc758 \uc2e0\ud638 \uc5ed\ud560\uc744 \ud558\ub294 \uac83\uc785\ub2c8\ub2e4. \uc774\ub294 \ubcf4\uc548 \uc704\ubc18 \ub610\ub294 \uc704\ubc18 \uc2dc\ub3c4\ub97c \ub098\ud0c0\ub0bc \uc218 \uc788\ub294 \ub370\uc774\ud130 \ubd84\uc11d \ubc0f \ud328\ud134 \uc2dd\ubcc4\uc744 \ud1b5\ud574 \ub2ec\uc131\ub429\ub2c8\ub2e4.<\/p>\n<p>\uc608\ub97c \ub4e4\uc5b4, IOC\uac00 \ud2b9\uc815 IP \uc8fc\uc18c\ub97c \uc545\uc758\uc801\uc778 \ud65c\ub3d9\uc758 \uc18c\uc2a4\ub85c \uc2dd\ubcc4\ud558\ub294 \uacbd\uc6b0 \ubcf4\uc548 \ub3c4\uad6c\ub294 \uc774 IP\uc758 \ud2b8\ub798\ud53d\uc744 \ucc28\ub2e8\ud558\uc5ec \ud574\ub2f9 \uc18c\uc2a4\ub85c\ubd80\ud130\uc758 \uc7a0\uc7ac\uc801 \uce68\ud574\ub97c \ubc29\uc9c0\ud558\ub3c4\ub85d \uad6c\uc131\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<h2>IOC(\uce68\ud574 \uc9c0\ud45c)\uc758 \uc8fc\uc694 \uae30\ub2a5<\/h2>\n<p>IOC\uc758 \uc8fc\uc694 \ud2b9\uc9d5\uc740 \ub2e4\uc74c\uacfc \uac19\uc2b5\ub2c8\ub2e4.<\/p>\n<ol>\n<li><strong>\uc801\uc2dc<\/strong>: IOC\ub294 \uc7a0\uc7ac\uc801\uc778 \ubcf4\uc548 \uc704\ud611\uc5d0 \ub300\ud574 \uc2e4\uc2dc\uac04 \ub610\ub294 \uac70\uc758 \uc2e4\uc2dc\uac04\uc5d0 \uac00\uae4c\uc6b4 \uacbd\uace0\ub97c \uc81c\uacf5\ud569\ub2c8\ub2e4.<\/li>\n<li><strong>\uc2e4\ud589 \uac00\ub2a5\uc131<\/strong>: \uac01 IOC\ub294 \uc704\ud611\uc744 \uc608\ubc29\ud558\uac70\ub098 \uc644\ud654\ud558\uae30 \uc704\ud574 \uc870\uce58\ub97c \ucde8\ud560 \uc218 \uc788\ub294 \ud2b9\uc815 \ub370\uc774\ud130\ub97c \uc81c\uacf5\ud569\ub2c8\ub2e4.<\/li>\n<li><strong>\ud2b9\uc131<\/strong>: IOC\ub294 \ud2b9\uc815 \uc545\uc131 \ucf54\ub4dc \ubcc0\uc885\uc774\ub098 \uc54c\ub824\uc9c4 \uc545\uc131 IP\uc640 \uac19\uc740 \ub9e4\uc6b0 \uad6c\uccb4\uc801\uc778 \uc704\ud611\uc744 \uac00\ub9ac\ud0a4\ub294 \uacbd\uc6b0\uac00 \ub9ce\uc2b5\ub2c8\ub2e4.<\/li>\n<li><strong>\uacf5\uc720\uc131<\/strong>: IOC\ub294 \uc77c\ubc18\uc801\uc73c\ub85c \uc0ac\uc774\ubc84 \ubcf4\uc548 \ucee4\ubba4\ub2c8\ud2f0\uc5d0\uc11c \uacf5\uc720\ub418\uc5b4 \ub2e4\ub978 \uc0ac\ub78c\ub4e4\uc774 \uc790\uc2e0\uc758 \ub124\ud2b8\uc6cc\ud06c\ub97c \ubcf4\ud638\ud560 \uc218 \uc788\ub3c4\ub85d \ub3d5\uc2b5\ub2c8\ub2e4.<\/li>\n<li><strong>\ud655\uc7a5\uc131<\/strong>: IOC\ub294 \ub2e4\uc591\ud55c \ud658\uacbd\uacfc \uc2dc\uc2a4\ud15c\uc5d0\uc11c \uc0ac\uc6a9\ud560 \uc218 \uc788\uc5b4 \uc704\ud611 \ud0d0\uc9c0\uc5d0 \ub300\ud55c \uad11\ubc94\uc704\ud55c \uc801\uc6a9 \ubc94\uc704\ub97c \uc81c\uacf5\ud569\ub2c8\ub2e4.<\/li>\n<\/ol>\n<h2>IOC(\uce68\ud574 \uc9c0\ud45c) \uc720\ud615<\/h2>\n<p>IOC\ub294 \ud06c\uac8c \uc138 \uac00\uc9c0 \uc720\ud615\uc73c\ub85c \ubd84\ub958\ub429\ub2c8\ub2e4.<\/p>\n<ol>\n<li>\n<p><strong>\uc6d0\uc790 IOC<\/strong>: \ub354 \uc774\uc0c1 \ubd84\ud574\ud560 \uc218 \uc5c6\ub294 \ub2e8\uc21c\ud558\uace0 \ubd84\ud560\ud560 \uc218 \uc5c6\ub294 IOC\uc785\ub2c8\ub2e4. \uc608\ub85c\ub294 IP \uc8fc\uc18c, \ub3c4\uba54\uc778 \uc774\ub984, URL \ub4f1\uc774 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<\/li>\n<li>\n<p><strong>\uacc4\uc0b0 IOC<\/strong>: \uc774\ud574\ud558\ub824\uba74 \ucc98\ub9ac \ub610\ub294 \uacc4\uc0b0\uc774 \ud544\uc694\ud55c \ub354 \ubcf5\uc7a1\ud55c IOC\uc785\ub2c8\ub2e4. \uc608\ub85c\ub294 \ud30c\uc77c \ud574\uc2dc \ub610\ub294 \uc774\uba54\uc77c \ucca8\ubd80 \ud30c\uc77c\uc774 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<\/li>\n<li>\n<p><strong>\ud589\ub3d9 IOC<\/strong>: \uc774\ub7ec\ud55c IOC\ub294 \uc704\ud611\uc774 \ub098\ud0c0\ub0b4\ub294 \ub3d9\uc791\uc744 \uae30\ubc18\uc73c\ub85c \uc2dd\ubcc4\ub429\ub2c8\ub2e4. \uc608\ub85c\ub294 \ub808\uc9c0\uc2a4\ud2b8\ub9ac \ud0a4 \ubcc0\uacbd, \ud30c\uc77c \uc218\uc815, \ub124\ud2b8\uc6cc\ud06c \ud2b8\ub798\ud53d \uc774\uc0c1 \ub4f1\uc774 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<\/li>\n<\/ol>\n<table>\n<thead>\n<tr>\n<th>IOC \uc720\ud615<\/th>\n<th>\uc608<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\uc6d0\uc790 IOC<\/td>\n<td>IP \uc8fc\uc18c, \ub3c4\uba54\uc778 \uc774\ub984, URL<\/td>\n<\/tr>\n<tr>\n<td>\uacc4\uc0b0 IOC<\/td>\n<td>\ud30c\uc77c \ud574\uc2dc, \uc774\uba54\uc77c \ucca8\ubd80<\/td>\n<\/tr>\n<tr>\n<td>\ud589\ub3d9 IOC<\/td>\n<td>\ub808\uc9c0\uc2a4\ud2b8\ub9ac \ud0a4 \ubcc0\uacbd, \ud30c\uc77c \uc218\uc815, \ub124\ud2b8\uc6cc\ud06c \ud2b8\ub798\ud53d \uc774\uc0c1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>IOC(\uce68\ud574 \uc9c0\ud45c) \uc0ac\uc6a9: \uacfc\uc81c \ubc0f \uc194\ub8e8\uc158<\/h2>\n<p>IOC\ub294 \uc704\ud611 \ud0d0\uc9c0 \ubc0f \uc644\ud654\uc5d0 \uc788\uc5b4 \uc911\uc694\ud55c \ub3c4\uad6c\uc774\uae30\ub294 \ud558\uc9c0\ub9cc \uacfc\uc81c\ub3c4 \uc788\uc2b5\ub2c8\ub2e4. \uc608\ub97c \ub4e4\uc5b4, \uc591\uc131 \ud65c\ub3d9\uc774 \uc2dd\ubcc4\ub41c IOC\uc640 \uc77c\uce58\ud558\ub294 \uacbd\uc6b0 IOC\ub294 \uc624\ud0d0\uc9c0\ub97c \uc0dd\uc131\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4. \ub610\ud55c IOC\uc758 \uc591\uc774 \ub108\ubb34 \ub9ce\uc544 \uad00\ub9ac \ubc0f \uc6b0\uc120\uc21c\uc704 \uc9c0\uc815\uc774 \uc5b4\ub824\uc6b8 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<p>\uc774\ub7ec\ud55c \uacfc\uc81c\ub97c \uadf9\ubcf5\ud558\uae30 \uc704\ud574 \uc0ac\uc774\ubc84 \ubcf4\uc548 \uc804\ubb38\uac00\ub294 \ub2e4\uc74c\uacfc \uac19\uc740 \uc194\ub8e8\uc158\uc744 \uc0ac\uc6a9\ud569\ub2c8\ub2e4.<\/p>\n<ol>\n<li><strong>\uc704\ud611 \uc778\ud154\ub9ac\uc804\uc2a4 \ud50c\ub7ab\ud3fc<\/strong>: \uc774\ub7ec\ud55c \ud50c\ub7ab\ud3fc\uc740 IOC\ub97c \uc218\uc9d1, \uad00\ub9ac \ubc0f \uc0c1\ud638 \uc5f0\uad00\uc2dc\ucf1c \ubcfc\ub968\uc744 \ubcf4\ub2e4 \uc27d\uac8c \ucc98\ub9ac\ud558\uace0 \uc624\ud0d0\uc744 \ubc29\uc9c0\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/li>\n<li><strong>\uc6b0\uc120\uc21c\uc704<\/strong>: \ubaa8\ub4e0 IOC\uac00 \ub3d9\uc77c\ud55c \uac83\uc740 \uc544\ub2d9\ub2c8\ub2e4. \uc77c\ubd80\ub294 \ub2e4\ub978 \uac83\ubcf4\ub2e4 \ub354 \ud070 \uc704\ud611\uc744 \uac00\ud569\ub2c8\ub2e4. \uc2ec\uac01\ub3c4\uc5d0 \ub530\ub77c IOC\uc758 \uc6b0\uc120\uc21c\uc704\ub97c \uc9c0\uc815\ud568\uc73c\ub85c\uc368 \uc0ac\uc774\ubc84 \ubcf4\uc548 \ud300\uc740 \uac00\uc7a5 \uc2ec\uac01\ud55c \uc704\ud611\uc5d0 \uba3c\uc800 \uc9d1\uc911\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/li>\n<\/ol>\n<h2>IOC(\uce68\ud574 \uc9c0\ud45c)\uc640 \uc720\uc0ac\ud55c \uac1c\ub150<\/h2>\n<table>\n<thead>\n<tr>\n<th>\uac1c\ub150<\/th>\n<th>\uc124\uba85<\/th>\n<th>IOC\uc640\uc758 \ube44\uad50<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\uacf5\uaca9 \uc9c0\ud45c(IOA)<\/td>\n<td>\uc77c\ubc18\uc801\uc774\uc9c0 \uc54a\uc740 \ub124\ud2b8\uc6cc\ud06c \ud504\ub85c\ud1a0\ucf5c\uacfc \uac19\uc740 \uc801\uadf9\uc801\uc778 \uacf5\uaca9\uc758 \uc9d5\ud6c4<\/td>\n<td>IOC\ub294 \uce68\ud574 \uc9d5\ud6c4\ub97c \uc2dd\ubcc4\ud558\ub294 \ubc18\uba74, IOA\ub294 \uc9c4\ud589 \uc911\uc778 \uacf5\uaca9\uc758 \uc9d5\ud6c4\ub97c \uc2dd\ubcc4\ud569\ub2c8\ub2e4.<\/td>\n<\/tr>\n<tr>\n<td>TTP(\uc804\uc220, \uae30\uc220 \ubc0f \uc808\ucc28)<\/td>\n<td>\uacf5\uaca9\uc744 \uacc4\ud68d, \uc2e4\ud589, \uad00\ub9ac\ud558\ub294 \ubc29\ubc95\uc744 \ud3ec\ud568\ud55c \uc704\ud611 \ud589\uc704\uc790\uc758 \ud589\ub3d9<\/td>\n<td>TTP\ub294 \uacf5\uaca9\uc5d0 \ub300\ud55c \ub354 \ub113\uc740 \uadf8\ub9bc\uc744 \uc81c\uacf5\ud558\ub294 \ubc18\uba74, IOC\ub294 \uacf5\uaca9\uc758 \ud2b9\uc815 \uc694\uc18c\uc5d0 \uc911\uc810\uc744 \ub461\ub2c8\ub2e4.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\uce68\ud574\uc9c0\ud45c(IOC) \uad00\ub828 \ubbf8\ub798 \uc804\ub9dd\uacfc \uae30\uc220<\/h2>\n<p>\uc0ac\uc774\ubc84 \ubcf4\uc548\uc774 \ubc1c\uc804\ud568\uc5d0 \ub530\ub77c IOC\uc758 \uac1c\ub150\uacfc \ud65c\uc6a9\ub3c4 \ubc1c\uc804\ud560 \uac83\uc785\ub2c8\ub2e4. \uace0\uae09 \uba38\uc2e0\ub7ec\ub2dd\uacfc AI \uc54c\uace0\ub9ac\uc998\uc740 IOC \ud0d0\uc9c0, \ubd84\uc11d, \ub300\uc751\uc744 \uac15\ud654\ud558\ub294 \ub370 \ud575\uc2ec\uc801\uc778 \uc5ed\ud560\uc744 \ud560 \uac83\uc73c\ub85c \uc608\uc0c1\ub429\ub2c8\ub2e4. \uc774\ub7ec\ud55c \uae30\uc220\uc740 \uc7a0\uc7ac\uc801\uc73c\ub85c \uc0c8\ub85c\uc6b4 \ud328\ud134, \uc0c1\uad00 \uad00\uacc4 \ubc0f IOC\ub97c \uc2dd\ubcc4\ud558\ub294 \ub370 \ub3c4\uc6c0\uc774 \ub418\uc5b4 \uc704\ud611 \ud0d0\uc9c0\ub97c \ubcf4\ub2e4 \uc0ac\uc804 \uc608\ubc29\uc801\uc774\uace0 \uc608\uce21 \uac00\ub2a5\ud558\uac8c \ub9cc\ub4ed\ub2c8\ub2e4.<\/p>\n<p>\ub354\uc6b1\uc774 \uc704\ud611\uc774 \ub354\uc6b1 \uc815\uad50\ud574\uc9d0\uc5d0 \ub530\ub77c \ud589\ub3d9 IOC\ub294 \ub354\uc6b1 \uc911\uc694\ud574\uc9c8 \uac83\uc785\ub2c8\ub2e4. \uc774\ub294 \uacf5\uaca9\uc790\uac00 \uc228\uae30\uae30\uac00 \ub354 \uc5b4\ub824\uc6b4 \uacbd\uc6b0\uac00 \ub9ce\uc73c\uba70 \uace0\uae09 \ub2e4\ub2e8\uacc4 \uacf5\uaca9\uc758 \uc9d5\ud6c4\ub97c \uc81c\uacf5\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<h2>\ud504\ub85d\uc2dc \uc11c\ubc84 \ubc0f \uce68\ud574 \uc9c0\ud45c(IOC)<\/h2>\n<p>\ud504\ub85d\uc2dc \uc11c\ubc84\ub294 IOC\uc640 \uad00\ub828\ud558\uc5ec \uc911\uc694\ud55c \uc5ed\ud560\uc744 \ud569\ub2c8\ub2e4. \uc774\ub97c \ud1b5\uacfc\ud558\ub294 \ud2b8\ub798\ud53d\uc744 \ubaa8\ub2c8\ud130\ub9c1\ud558\uace0 \ubd84\uc11d\ud568\uc73c\ub85c\uc368 \ud504\ub85d\uc2dc \uc11c\ubc84\ub294 \uc7a0\uc7ac\uc801\uc778 IOC\ub97c \uc2dd\ubcc4\ud558\uace0 \uc704\ud611\uc744 \uc608\ubc29\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4. \uc545\uc758\uc801\uc778 \ud65c\ub3d9\uc774 \ud2b9\uc815 IP \uc8fc\uc18c\uc5d0\uc11c \ubc1c\uc0dd\ud558\ub294 \uacbd\uc6b0 \ud504\ub85d\uc2dc \uc11c\ubc84\ub294 \ud574\ub2f9 \uc18c\uc2a4\uc758 \ud2b8\ub798\ud53d\uc744 \ucc28\ub2e8\ud558\uc5ec \uc7a0\uc7ac\uc801\uc778 \uc704\ud611\uc744 \uc644\ud654\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<p>\ub610\ud55c \ud504\ub85d\uc2dc \uc11c\ubc84\ub294 \ub124\ud2b8\uc6cc\ud06c \ud2b8\ub798\ud53d\uc744 \uc775\uba85\ud654\ud558\uc5ec \uc7a0\uc7ac\uc801\uc778 \uacf5\uaca9 \ud45c\uba74\uc744 \uc904\uc774\uace0 \uc0ac\uc774\ubc84 \ubc94\uc8c4\uc790\uac00 \ub124\ud2b8\uc6cc\ud06c \ub0b4\uc5d0\uc11c \uc7a0\uc7ac\uc801\uc778 \ub300\uc0c1\uc744 \uc2dd\ubcc4\ud558\ub294 \uac83\uc744 \ub354\uc6b1 \uc5b4\ub835\uac8c \ub9cc\ub4dc\ub294 \ub370 \ub3c4\uc6c0\uc774 \ub420 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n<h2>\uad00\ub828\ub41c \ub9c1\ud06c\ub4e4<\/h2>\n<ol>\n<li><a href=\"https:\/\/attack.mitre.org\/\" target=\"_new\" rel=\"noopener nofollow\">\ub9c8\uc774\ud130 ATT&amp;CK \ud504\ub808\uc784\uc6cc\ud06c<\/a><\/li>\n<li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Indicator_of_compromise\" target=\"_new\" rel=\"noopener nofollow\">IOC(\uce68\ud574 \uc9c0\ud45c) \u2013 Wikipedia<\/a><\/li>\n<li><a href=\"https:\/\/www.recordedfuture.com\/threat-intelligence-feeds\/\" target=\"_new\" rel=\"noopener nofollow\">\uc704\ud611 \uc778\ud154\ub9ac\uc804\uc2a4 \ud53c\ub4dc<\/a><\/li>\n<li><a href=\"https:\/\/www.sans.org\/course\/advanced-incident-response-threat-hunting-training\" target=\"_new\" rel=\"noopener nofollow\">SANS \ub514\uc9c0\ud138 \ud3ec\ub80c\uc2dd \ubc0f \uc0ac\uace0 \ub300\uc751<\/a><\/li>\n<li><a href=\"https:\/\/umbrella.cisco.com\/blog\/umbrella-investigate-blog\" target=\"_new\" rel=\"noopener nofollow\">\uce68\ud574 \uc9c0\ud45c\uc5d0 \ub300\ud55c Cisco \uac00\uc774\ub4dc<\/a><\/li>\n<\/ol>","protected":false},"featured_media":468615,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-477573","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Indicator of Compromise (IOC): An In-depth Guide<\/mark>","faq_items":[{"question":"What is an Indicator of Compromise (IOC)?","answer":"<p>An Indicator of Compromise (IOC) is an artifact observed on a network or in an operating system that strongly indicates a computer intrusion. These could be in the form of known malicious IP addresses, URLs, domain names, email addresses, file hashes, or even unique attributes of a malware, such as its behavior or code snippets.<\/p>"},{"question":"Who first introduced the concept of Indicator of Compromise (IOC)?","answer":"<p>The concept of Indicator of Compromise (IOC) was first introduced by the information security firm Mandiant around 2013 as part of their cyber threat intelligence operations.<\/p>"},{"question":"What are the key features of an Indicator of Compromise (IOC)?","answer":"<p>The key features of an IOC include timeliness, actionability, specificity, shareability, and scalability. These characteristics make IOCs a powerful tool for early threat detection and response in cybersecurity.<\/p>"},{"question":"How are Indicators of Compromise (IOCs) classified?","answer":"<p>IOCs are typically classified into three types: Atomic IOCs (like IP addresses, domain names, URLs), Computational IOCs (like file hashes or email attachments), and Behavioral IOCs (like registry key changes, file modification, or network traffic anomalies).<\/p>"},{"question":"What challenges are associated with the use of IOCs and how can they be mitigated?","answer":"<p>While IOCs are a critical tool in threat detection, they can generate false positives and can be challenging to manage due to their volume. To mitigate these challenges, cybersecurity professionals employ threat intelligence platforms and prioritize IOCs based on their severity.<\/p>"},{"question":"What is the future perspective of IOCs in cybersecurity?","answer":"<p>As cybersecurity evolves, advanced machine learning and AI algorithms are expected to enhance IOC detection, analysis, and response. Behavioral IOCs, which provide indications of advanced, multi-stage attacks, will become increasingly important.<\/p>"},{"question":"How are proxy servers associated with IOCs?","answer":"<p>Proxy servers can monitor and analyze traffic to identify potential IOCs and prevent threats. They can block traffic from malicious sources, mitigating potential threats. Additionally, they can help anonymize network traffic, reducing the potential attack surface.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/kr\/wp-json\/wp\/v2\/wiki\/477573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/kr\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/kr\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/kr\/wp-json\/wp\/v2\/wiki\/477573\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/kr\/wp-json\/wp\/v2\/media\/468615"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/kr\/wp-json\/wp\/v2\/media?parent=477573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}