검색 상세

역할 맥락 기반 클라우드 자격증명 탈취 탐지 연구

초록/요약

클라우드 컴퓨팅의 확산과 함께 AWS(Amazon Web Services) 환경에서의 보안 위협이 증가하 고 있다. 특히 EC2 인스턴스의 메타데이터 서비스 버전 1(IMDSv1)은 인증 없이 HTTP GET 요청만으로 접근 가능한 구조적 특성을 가지며, SSRF(Server-Side Request Forgery) 공격과 결합될 경우 IAM 임시 자격증명 탈취 및 클라우드 자원 정찰, 데이터 접근 등으로 확장될 수 있다. 탈취된 자격증명은 정상 사용자와 유사한 AWS API 호출 형태로 사용되기 때문에 기존의 단일 Signal 기반 탐지 방식만으로는 효과적인 식별에 한계가 존재한다. 본 연구는 AWS 3-Tier 아키텍처 기반 실험 환경을 구축하고, IMDSv1 오설정을 악용한 SSRF 공격 시나리오를 실험적으로 재현하였다. 실험은 기본 공격(그룹 A) 외에도 UserAgent 위변조 (그룹 B), Tor 기반 IP 우회(그룹 C), UserAgent 및 IP 동시 위변조(그룹 D)를 포함하도록 설 계하여, sourceIPAddress 및 UserAgent 기반 단일 Signal 탐지의 구조적 한계를 검증하였다. 실험 결과 단일 탐지 방식은 위변조 및 NAT·Tor 환경에서 탐지 효율이 크게 저하되었으며, 특 히 UserAgent 기반 탐지는 위변조 시 탐지율이 현저히 감소하는 한계를 보였다. 이에 본 연구는 공격 목적 달성을 위해 공통적으로 발생하는 Cloud API 행위를 기반으로 네 가지 탐지 규칙(R1: UserAgent 이상, R2: Source IP 이상, R3: 열거 시퀀스 일치, R4: 역할 맥락 위반)을 정의하고, 가중치 합산 기반의 RiskScore 복합 탐지 모델을 제안하였다. 특히 R4 는 특정 역할명을 직접 탐지하는 방식이 아니라, 워크로드 역할의 정상 기능 범위를 벗어난 IAM 및 RDS 관련 고위험 API 호출을 역할 맥락 위반(Role Context Violation)으로 정의함으 로써 역할 기반 행위 탐지의 일반화 가능성을 고려하였다. 제안한 모델은 AWS 관리형 역할 제외 및 외부 공인 IP 조건 등을 포함한 탐지 규칙 기반으로 설계되었으며, 총 60,208건의 CloudTrail 로그 데이터(정상 60,019건, 공격 189건)를 이용하여 성능을 평가하였다. 평가 결과 단일 탐지 규칙은 각각 낮은 재현율 또는 오탐 문제를 보였으나, 제안한 복합 탐지 모델은 Precision 100%, Recall 66.7%, FPR 0.0%, F1-score 80.0%를 기 록하였다. 특히 UserAgent 위변조 및 Tor 기반 IP 우회 환경에서도 역할 맥락 위반(R4) 기반 탐지는 모든 공격 그룹에서 안정적인 탐지 결과를 보였다. 이는 IP 및 UserAgent와 같은 위변 조 가능한 단일 Signal보다 공격 목적 종속적 행위 기반 복합 탐지가 클라우드 자격증명 탈취 공격 탐지에 효과적일 수 있음을 시사한다. 다만 본 연구의 결과는 특정 역할 기반 실험 환경과 제한된 워크로드를 기준으로 수행되었으며, 실제 운영 환경에서는 역할별 정상 API 호출 패턴 과 자동화 작업 특성에 따라 탐지 성능이 달라질 수 있다. 핵심어 : AWS, IMDSv1, SSRF, CloudTrail, IAM 역할 맥락 위반, 복합 탐지, Splunk SPL, RiskScore 행위 기반 탐지

more

초록/요약

Cloud computing adoption has significantly increased the security threats faced in Amazon Web Services (AWS) environments. In particular, the Amazon Elastic Compute Cloud (EC2) Instance Metadata Service Version 1 (IMDSv1) possesses a structural characteristic that allows access through simple HTTP GET requests without authentication. When combined with Server-Side Request Forgery (SSRF) attacks, this weakness can lead to the theft of IAM temporary credentials, cloud resource reconnaissance, and unauthorized data access. Because stolen credentials are typically used through AWS API calls that closely resemble legitimate user behavior, conventional detection approaches based on a single signal have limitations in effectively identifying such attacks. This study constructed an AWS-based three-tier architecture and experimentally reproduced an SSRF attack scenario exploiting IMDSv1 misconfiguration. In addition to a baseline attack scenario (Group A), the experiments included User-Agent spoofing (Group B), Tor-based IP evasion (Group C), and simultaneous User-Agent and IP spoofing (Group D) to evaluate the structural limitations of single-signal detection methods based on source IP addresses and User-Agent information. The results demonstrated that the effectiveness of single-signal detection significantly decreased under spoofing and NAT/Tor environments. In particular, User-Agent-based detection exhibited a substantial decline in detection performance when the User-Agent was manipulated. To address these limitations, this study defined four detection rules based on cloud API activities commonly observed during credential theft attacks: R1 (User-Agent Anomaly), R2 (Source IP Anomaly), R3 (Enumeration Sequence Match), and R4 (Role Context Violation). A composite detection model based on weighted RiskScore aggregation was then proposed. Unlike approaches that directly identify specific role names, R4 defines high-risk IAM and RDS API activities that exceed the normal functional scope of workload roles as Role Context Violations, thereby considering the generalizability of role-based behavioral detection across different cloud environments. The proposed model was designed using rule-based detection criteria, including the exclusion of AWS-managed roles and external public IP conditions. Its performance was evaluated using 60,208 CloudTrail log events, consisting of 60,019 benign events and 189 attack events. While individual detection rules exhibited either low recall or false-positive issues, the proposed composite detection model achieved a Precision of 100%, Recall of 66.7%, False Positive Rate (FPR) of 0.0%, and F1-score of 80.0%. Notably, Role Context Violation (R4)-based detection consistently identified attacks across all attack groups, including User-Agent spoofing and Tor-based IP evasion scenarios. These findings suggest that behavior-based composite detection methods, which focus on attack objectives rather than easily manipulated signals such as IP addresses and User-Agent strings, can provide a more effective approach for detecting cloud credential theft attacks. However, the results of this study were obtained in a role-specific experimental environment with limited workloads. In real-world cloud environments, detection performance may vary depending on role-specific API usage patterns and automated operational processes. Keywords : Cloud Security, AWS, IMDSv1, SSRF, Credential Theft, CloudTrail, Role Context Violation, Risk-Based Detection, Threat Detection, Cloud Misconfiguration.

more

목차

제1장 서론 1
제1절 연구 배경 및 목적 1
1. 클라우드 전환 가속화와 보안 환경의 구조적 변화 1
2. SSRF와 클라우드 메타데이터 서비스의 위험 관계 1
제2절 오설정(Misconfiguration)의 심각성 2
제3절 연구 목표 및 기여 3
제2장 관련 연구 5
제1절 IMDSv1과 SSRF의 결합 위협 5
1. AWS 인스턴스 메타데이터 서비스 5
2. 위험 행위자의 IMDSv1 악용 사례 5
제2절 실제 침해 사례 : Capital One(2019) 6
제3절 기존 탐지 방법 및 한계 7
제3장 실험 환경 구축 10
제1절 AWS 인프라 구성 10
제2절 취약 설정 구성 11
제3절 로그 수집 구조 12
제4장 공격 시나리오 분석 13
제1절 실험 그룹 설계 13
제2절 단계별 공격 행위 13
1. SSRF 익스플로잇 및 IMDSv1 접근 13
2. 자격증명 설정 및 신원 확인 14
3. 클라우드 리소스 열거 및 데이터 탈취 14
제3절 공격 행위별 로그 발생 구조 14
제5장 CloudTrail 로그 분석 15
제1절 분석 방법론 및 데이터셋 구성 15
1. 분석 환경 및 필드 구성 15
2. 트래픽 레이블링 기준 15
3. 탐지 성능 지표 정의 16
제2절 단일 Signal 탐지의 한계 실증 16
1. SourceIPAddress 단독 탐지의 한계 16
2. UserAgent 단독 탐지의 한계 17
제3절 공격 단계별 로그 매핑 17
제4절 탐지 Feature 도출 18
1. R1 – UserAgent 이상 18
2. R2 – Source IP 이상 18
3. R3 열거 시퀀스 일치 18
4. R4 역할 맥락 위반 18
제6장 복합 탐지 모델 제안 19
제1절 계층적 방어 프레임워크 19
제2절 RiskScore 기반 복합 탐지 모델 19
제3절 가중치 설정 근거 19
제4절 Splunk SPL 구현 21
1. R1 – UserAgent 기반 탐지 21
2. R2 – 자격 증명 확인 탐지 21
3. R3 – 열거 시퀀스 탐지 21
4. R4 – 역할 맥락 위반 탐지 22
5. R5 – 복합 탐지 – RiskScore 22
제5절 성능평가 23
1. 5회차 누적 탐지 성능 23
2. 공격 그룹별 탐지율 25
3. 회차별 성능 추이 25
제6절 각 탐지 규칙의 한계 26
1. R1의 한계 26
2. R2의 한계 26
3. R3의 한계 26
4. R4의 한계 27
5. R5(복합 탐지)의 설계 의도 및 필요성 27
제7절 예방 및 피해 최소화 27
제7장 결론 및 향후 연구 29
참고문헌 30
Abstract 31

more