Skip to content

Latest commit

ย 

History

History
588 lines (374 loc) ยท 9.75 KB

Linux-full-stack12.md

File metadata and controls

588 lines (374 loc) ยท 9.75 KB

{ํ’€์Šคํƒ#12} ๋ฆฌ๋ˆ…์Šค(Linux) - ์‹ค๋ฌด์—์„œ ๊ผญ ํ•„์š”ํ•œ ๊ธฐ์ˆ  (1/2)

Linux (CentOS) ์‹ค๋ฌด์—์„œ ์œ ์šฉํ•œ ๊ธฐ์ˆ 

# sudo ๊ถŒํ•œ ๋ถ€์—ฌ

# ncloud ์„œ๋ฒ„

# ncloud alias ์ •๋ณด ํ™•์ธ
# cat .bashrc | grep ncloud
cat .profile | grep ncloud

# ncloud ์ง„์ž…
ncloud

# user ์ฒดํฌ
cat /etc/passwd

cat .bashrc

exit

# root๊ฐ€ ์•„๋‹ˆ๋ผ ding-co user๋กœ ์ ‘์†
ssh ding-co@mydealh -p 50000

whoami

# sudo ๊ถŒํ•œ ์ฒดํฌ
sudo bash

# ํ˜„์žฌ ๊ถŒํ•œ์ด ์—†์–ด์„œ read-only ์ƒํƒœ์ž„
vi /etc/hosts

hostname

# ๋‚˜๊ฐ”๋‹ค๊ฐ€ root ๊ถŒํ•œ์œผ๋กœ ๋‹ค์‹œ ์ ‘์†
ncloud

visudo

# ๊ฒ€์ƒ‰
/wheel

# ์ฃผ์„ ํ’€์–ด์ฃผ๊ธฐ
%wheel ALL=(ALL) NOPASSWD: ALL

# ding-co user์—๊ฒŒ sudo ๊ถŒํ•œ ์ฃผ๊ธฐ
usermod -aG wheel ding-co

# ๋‚˜๊ฐ”๋‹ค๊ฐ€ ding-co user๋กœ ๋‹ค์‹œ ์ ‘์†

sudo bash

# ๋งŒ์•ฝ ์•ˆ๋˜๋ฉด,
# ๋‚˜๊ฐ”๋‹ค ๋‹ค์‹œ ๋“ค์–ด์˜ค๊ธฐ
exit

hostname

ssh ding-co@mydealh -p 50000

hostname

# ์ด๋ฒˆ์—๋Š” ๋ฐ”๋กœ ๋“ค์–ด๊ฐ
sudo bash

whoami

exit

whoami

# ding-co

sudo vi /etc/hosts

# ์ˆ˜์ • ๊ฐ€๋Šฅ
# ๋งˆ์ง€๋ง‰์— ์ฃผ์„ ์ถ”๊ฐ€
# This is write sudo test

# ์ž˜ ์ €์žฅ๋จ ์ฒดํฌ
cat /etc/hosts

# ํŒ€ ํ”„๋กœ์ ํŠธ์‹œ,
# root ๊ถŒํ•œ ์ฃผ๋Š” ๊ฒƒ์€ ์•„๋‹ˆ๊ณ  ํŒŒ์ผ ๋“ฑ ์„ธํŒ…ํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ ์ฃผ๊ธฐ
  • ํŒŒ์ผ ์••์ถ•

    • legacy - gzip ๋งŽ์ด ์‚ฌ์šฉ
    • ์ตœ๊ทผ์—๋Š” xz (์••์ถ•๋ฅ  ๋†’์Œ), bzip2 ๋งŽ์ด ์‚ฌ์šฉ
# ncloud ์„œ๋ฒ„ (root)

# nginx log๋กœ ์ด๋™
cd /var/log/nginx/

# ํŒŒ์ผ ์••์ถ•
gzip error.log

ll

# ํŒŒ์ผ ์••์ถ• ํ•ด์ œ
gzip -d error.log.gz

# ํŒŒ์ผ ํ•˜๋‚˜ ์••์ถ•ํ•ด์„œ ๋ณด๊ด€ํ• ๋•Œ gzip ๋งŽ์ด ์‚ฌ์šฉํ•จ

# ์šฉ๋Ÿ‰ ์ฒดํฌ
gzip error.log

ll

gzip -d error.log.gz

# xz (์••์ถ•๋ฅ  ๋” ์ข‹์Œ)

xz error.log

xz -d error.log.xz

# bizp2 ์„ค์น˜
yum install bzip2 -y

# bzip2๋กœ ์••์ถ•

bzip2 error.log

ll

bzip2 -d error.log.bz2

# ํ™•์žฅ์ž ๋ณด๊ณ  ์••์ถ• ํŒŒ์ผ ํ˜•์‹ ํ™•์ธ ๊ฐ€๋Šฅ

# ์œˆ๋„์šฐ์šฉ ์œ„ํ•ด zip
# ๋งŒ๋“ค_ํŒŒ์ผ๋ช… - ์••์ถ•ํ• _ํŒŒ์ผ๋ช… ์ˆœ์„œ

zip error.log.zip error.log

ll

# ์••์ถ• ํ•ด์ œ
unzip error.log.zip

n

# zip์€ ์ƒˆ๋กœ ์••์ถ•ํŒŒ์ผ ๋งŒ๋“ฆ (์›๋ณธ ํŒŒ์ผ ๋ณด์กดํ•˜๊ณ  ์ƒˆ๋กœ ๋งŒ๋“ฆ)

unzip error.log.zip

# rename
r
err2.log

ll

rm -f err2.log
ll

# ์‹ค๋ฌด์—์„œ tar ๊ฐ€์žฅ ๋งŽ์ด ์”€ (ํŒŒ์ผ ์—ฌ๋Ÿฌ๊ฐœ ๋ฌถ์œผ๋ฉด์„œ ์••์ถ•๊นŒ์ง€ ํ•จ)

# create vfz, tar๋กœ ๋ฌถ์–ด์„œ gz๋กœ ์••์ถ•
tar cvfz xxx.tar.gz *.log

ll

# home dir๋กœ ์˜ฎ๊น€
mv xxx.tar.gz ~/

# home dir
cd ~

# extract vfz (z ๋น ์ ธ์žˆ์œผ๋ฉด ๋ฌถ๋Š”๊ฑธ ํ’€๊ธฐ๋งŒ ํ•จ, z ๋ถ™์œผ๋ฉด gzip์œผ๋กœ ์••์ถ•๊นŒ์ง€)
# ๋งŒ์•ฝ z์ž๋ฆฌ์— J๋ฉด xz์œผ๋กœ ์••์ถ•, j๋ฉด bzip2๋กœ ์••์ถ• (tar๋กœ ๋ฌถ์–ด์„œ)
tar xvfz xxx.tar.gz

ll

ll *.log

rm -r *.log

# back ์œผ๋กœ ์ด๋™
cd -

rm error.log.zip
y

ll

# ๋น„๋ฒˆ ๊ฑธ๋ฉด์„œ ์••์ถ•
zip -P "x1234" error.zip error.log

unzip error.zip
x1234
# rename
r
xx

# zip์€ ํŒŒ์ผ ๊ทธ๋Œ€๋กœ ๋‚จ์•„์„œ ์ง€์ €๋ถ„ํ•จ -> ์ž˜ ์•ˆ์”€
  • ftp, sftp

    • ํŒŒ์ผ ์ฃผ๊ณ  ๋ฐ›๊ธฐ ์œ„ํ•จ
    • ftp (21) - ๋ณด์•ˆ์— ์ทจ์•ฝ
    • sftp (22) - SSH ๊ธฐ๋ฐ˜, ๋ณด์•ˆ์„ฑ ๊ฐ•ํ™”
      (ssh ๊ธฐ๋ฐ˜์ด๋ฏ€๋กœ sshd์— ํฌํ•จ๋˜์–ด ์žˆ์Œ)
    • samba - windows remote directory ์—ฐ๊ฒฐ
    • ownCloud (์˜คํ”ˆ ์†Œ์Šค ํด๋ผ์šฐ๋“œ) - dropbox ๊ตฌ์„ฑ ๊ฐ€๋Šฅ
      (mariadb, httpd, php, ๋“ฑ ์„ค์น˜ ํ•„์š”ํ•ด์„œ ์กฐ๊ธˆ ๋ฒˆ๊ฑฐ๋กœ์›€)
# sftp settings (ftp server)

# ์™ธ๋ถ€ ์—…์ฒด์— ๋ณ„๋„ ๊ณ„์ • ์ƒ์„ฑ

whoami

# false (๋กœ๊ทธ์ธ ์ž์ฒด ๋ชปํ•˜๊ฒŒ ๋งŒ๋“ฆ)
useradd -s /bin/false ftpuser

cat /etc/passwd

# ํŒจ์Šค์›Œ๋“œ ์„ค์ • (์™ธ๋ถ€์—…์ฒด์—๊ฒŒ ์ค˜์•ผ ํ•จ)
passwd ftpuser
# ์•”ํ˜ธ
seniorcoding

vi /etc/ssh/sshd_config

# Subsystem sftp /usr/libexec/openssh/sftp-server
  Subsystem sftp internal-sftp

systemctl restart sshd

# ํ˜„์žฌ ์‹œ๊ฐ„์œผ๋กœ ์ž˜ ๋œธ
ps -ef | grep sshd

# -------
# ์‚ฌ์šฉํ•˜๋Š” ์ชฝ

# ์œˆ๋„์šฐ - ์•Œftp ๋“ฑ ์—ฌ๋Ÿฌ ํ”„๋กœ๊ทธ๋žจ ๋งŽ์Œ

# SFTP ์—ฐ๊ฒฐ ์„ค์ •
# Server ssh ์ ‘์†์šฉ ip, username, password, port(50000 -> 22), utf8 ์„ค์ •
# -------

cd ~ftpuser
ll

# ftpuser home
pwd

# ํ•œ๊ธ€ ๊นจ์ง€๋Š”์ง€ check
echo "This is ftp ํ…Œ์ŠคํŠธ" > ftptest.txt

# --
# ์‚ฌ์šฉํ•˜๋Š” ์ชฝ
# ์ƒˆ๋กœ๊ณ ์นจ ํ•ด์„œ ํŒŒ์ผ ์ฒดํฌ -> ํ•œ๊ธ€ ์•ˆ๊นจ์ง (์ธ์ฝ”๋”ฉ ์ž˜ ๋งž์ถ”๋ฉด ๋จ)
# drag & drop ํŒŒ์ผ ์ด๋™
# --

# ftp ํ”„๋กœ๊ทธ๋žจ ์—†์„ ๋•Œ
# docker server

hostname

sftp -P 50000 ftpuser@<์„œ๋ฒ„์ ‘์†IP>
seniorcoding
ls

# ftp ๋ช…๋ น์–ด ์ฒดํฌ
help

# home์˜ ftp user (์„œ๋ฒ„์˜ pwd)
pwd

# local(client)์˜ pwd (ํŒŒ์ผ ๊ฐ€์ ธ์˜ฌ ๊ณณ)
lpwd

# server ls
ls

# local์˜ ls
lls

# ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ
get ftptest.txt

lls

# ์—…๋กœ๋“œ
put test.txt

# ํด๋ผ์šฐ๋“œ ์„œ๋ฒ„ ---
mkdir ttt
ll

echo "ttt" > ttt/ttt.txt
# ํด๋ผ์šฐ๋“œ ์„œ๋ฒ„ ----


# ํด๋” ์ „์ฒด๋ฅผ ๊ฐ€์ ธ์˜ค๊ธฐ (-r : directory)
get -r ttt

lls

# ํด๋” ์—…๋กœ๋“œ

put -r <ํ˜„์žฌ ๋กœ์ปฌ์— ์กด์žฌํ•˜๋Š” ํด๋”๋ช…>

# -- ftp user๋Š” ๋‹ค๋ฅธ user์— ๋“ค์–ด๊ฐ€์ง€ ๋ชปํ•จ (ftp ํ”„๋กœ๊ทธ๋žจ์—์„œ)

# bye / quit
# ftp ๋Š๊ธฐ
bye

# ๋ถˆํ•„์š” ํŒŒ์ผ ์ œ๊ฑฐ
rm -rf ttt
  • ์ง€๋‚œ log ํŒŒ์ผ ์ •๋ฆฌ

    • ์˜ค๋ž˜๋œ log ํŒŒ์ผ ์‚ญ์ œ
# ๊ฐœ๋ฐœ ์„œ๋ฒ„

cd /var/log/nginx
ll

# ์ด๋ฏธ ์••์ถ•์€ ๋˜์–ด ์žˆ์–ด์„œ ๋ฌถ๊ธฐ๋งŒ ํ•จ
tar cvf err.tar error.log*

ll

# ๋ฌถ์€ ํŒŒ์ผ์„ ncloud ์„œ๋ฒ„๋กœ ์˜ฎ๊ธฐ๊ธฐ

# --- ncloud ์„œ๋ฒ„์—์„œ ์šฐ์„  /var/log/nginx ์— tmp dir ์ƒ์„ฑ
# ncloud ์„œ๋ฒ„
mkdir tmp
ll

pwd

cd tmp
pwd
 --- ncloud ์„œ๋ฒ„

# --- ๊ฐœ๋ฐœ ์„œ๋ฒ„
# user๋กœ ์ค˜๋„ ์ƒ๊ด€์—†์Œ
rsync -avz err.tar root@<์„œ๋ฒ„-์ ‘์†์šฉ-ip>:/var/log/nginx/tmp/ -e "ssh -p 50000"
# ncloud ์„œ๋ฒ„ ์•”ํ˜ธ ์ž…๋ ฅ
# --- ๊ฐœ๋ฐœ ์„œ๋ฒ„

# --- ncloud ์„œ๋ฒ„
pwd

ll

# tar ํ’€๊ธฐ
tar xvf err.tar

ll err.tar

# ftpuser home dir๋กœ ์ด๋™
mv err.tar ~ftpuser/
# --- ncloud ์„œ๋ฒ„

# --- ๊ฐœ๋ฐœ ์„œ๋ฒ„
sftp -P 50000 ftpuser@<์„œ๋ฒ„-์ ‘์†์šฉ-ip>
seniorcoding

ls

get err.tar
# --- ๊ฐœ๋ฐœ ์„œ๋ฒ„

# ์˜ค๋ž˜๋œ log ํŒŒ์ผ ์ง€์šฐ๊ธฐ

# --- ncloud ์„œ๋ฒ„
find . -name "*.gz"

# word count ์ธ๋ฐ line ๋‹จ์œ„๋กœ ๋ณด์—ฌ์คŒ
find . -name "*.gz" | wc -l

# 60์ผ ์ง€๋‚œ ๊ฒƒ๋“ค๋งŒ ๋ณด์—ฌ์คŒ
find . -name "*.gz" -mtime +60

# 60์ผ ์ง€๋‚œ ๋กœ๊ทธ ํŒŒ์ผ ์‚ญ์ œ
find . -name "*.gz" -mtime +60 -delete

ll

find . -name "*.gz" | wc -l

# ๋งค๋ฒˆ ์ž‘์—… ํ•˜๊ธฐ ๋ฒˆ๊ฑฐ๋กœ์›Œ์„œ crontab์— ๊ฑธ๋ฉด ๋จ

pwd

# bin ํด๋”์— ์‹คํ–‰ํŒŒ์ผ๋“ค ๋ชจ์—ฌ ์žˆ์Œ
mkdir ~/bin

vi ~/bin/rmoldlogs.sh

#!/bin/bash
cd /var/log/nginx/tmp
find . -name "*.gz" -mtime +30 -delete

:wq

chmod +x ~/bin/rmoldlogs.sh

# crontab์—๋Š” full ๊ฒฝ๋กœ๊ฐ€ ๋“ค์–ด๊ฐ€์•ผ ํ•จ
crontab -e

# ์•„๋ž˜์— ๋‚ด์šฉ ์ถ”๊ฐ€
* * * * * /root/bin/rmoldlogs.sh 2>&1

:wq

ll | wc -l

# *๋Š” ํŠน์ˆ˜๊ธฐํ˜ธ์ด๋ฏ€๋กœ "" ๋ถ™์ด๊ฑฐ๋‚˜ ์—ญ์Šฌ๋ž˜์‹œ ๋ถ™์ด๋ฉด ๋จ
find . -name \*.gz -mtime +30

# ์ž˜ ์ง€์›Œ์ง
# --- ncloud ์„œ๋ฒ„

crontab -e

# ์‹œ๊ฐ„ ์ˆ˜์ •
0 1 * * *

:wq

!vi

# ๋‚ด์šฉ ์ˆ˜์ •

#!/bin/bash
cd /var/log/nginx
find . -name "*" -mtime +30 -delete

:wq

ps -ef | grep atd

# atd๋Š” ์ผํšŒ์„ฑ

at -l

# ์‹œ๊ฐ„ ์ง€์ •
at -f /root/bin/rmoldlogs.sh 00:00

date

# ํ…Œ์ŠคํŠธ์šฉ
!vi

#!/bin/bash
#cd /var/log/nginx
cd /var/log/nginx/tmp

find . -name "*" -mtime +10 -delete

:wq

date

at -l

date

ll

# ๋‹ค์‹œ ์ˆ˜์ •
!vi

#!/bin/bash
cd /var/log/nginx
#cd /var/log/nginx/tmp

find . -name "*" -mtime +30 -delete

:wq

crontab -l

at -l

# sort, uniq
# ๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ๋‚ด ์›น ์„œ๋ฒ„์— DDOS ๋‚ ๋ฆฐ๋‹ค๊ณ  ๊ฐ€์ •
# ๋ˆ„๊ฐ€ ์–ด๋ทฐ์ง• ํ•˜๋Š”์ง€ ๊ทธ ์‚ฌ๋žŒ ip ์ฐพ์•„๋ณด๊ธฐ

# ncloud ์„œ๋ฒ„

# nginx ํด๋”์ธ์ง€ ์ฒดํฌ
pwd

ll

tail -10 access.log

clear

# ์ฒซ๋ฒˆ์งธ ์—ด ์ฒดํฌ
cat access.log | awk '{print $1}'

# ๊ฐ ip๋ณ„๋กœ count๊ฐ€ ๋‚˜์˜ด
cat access.log | awk '{print $1}' | uniq -c

# ip ์ˆœ์„œ๋Œ€๋กœ sort + uniq
cat access.log | awk '{print $1}' | sort | uniq -c

# reverse sort (descending)
cat access.log | awk '{print $1}' | sort | uniq -c | sort -r

# ํ•œ์นธ ๋„์›€
cat access.log | cut -d" " -f1 | sort | uniq -c

# url๊นŒ์ง€ ๋‚˜์˜ด
cat access.log | cut -d" " -f1,7 | sort | uniq -c

# cut์€ ์ด๋Ÿฐ ํŒŒ์ผ๋“ค ๋ณผ ๋•Œ ์ข‹์Œ
cat /etc/passwd

# delimiter๋Š” :
# ์ฒซ๋ฒˆ์งธ ์—ด๊ณผ 7๋ฒˆ์จฐ ์ฃผ์„ธ์š”
cat /etc/passwd | cut -d: -f1,7
  • Name Server - DNS (resolv.conf)
# ๊ณต์ธ ip ๋‚˜์˜ด
nslookup ding-co.topician.com

# ํด๋ผ์šฐ๋“œ ํ”Œ๋žซํผ์˜ ๋„ค์ž„์„œ๋ฒ„
cat /etc/resolv.conf

# ๊ฐ€๋” ๋‹ค๋ฅธ ๋„ค์ž„ ์„œ๋ฒ„ ์ผ๋Š”๋ฐ ๋Š๋ ค์ง -> ๋„๋ฉ”์ธ ์ฐพ๋Š” ๊ฒƒ์ด ๋Š๋ ค์„œ ๊ทธ๋Ÿผ
# ์ž์‹ ํ•œํ…Œ ๊ฐ€์žฅ ๊ฐ€๊นŒ์šด ๋„ค์ž„์„œ๋ฒ„ ๊ฑธ๋ฉด ๋จ
# ํ˜„์žฌ๋Š” NCloud๊ฐ€ ๊ฑธ๋ ค ์žˆ์Œ

# ๊ธฐ๋ณธ DNS ์„œ๋ฒ„ ์ฃฝ์œผ๋ฉด ๋ณด์กฐ DNS ์„œ๋ฒ„๊ฐ€ ์•Œ๋ ค์คŒ
  • ๊ฐ์ข… ์„œ๋ฒ„ monitoring ๋„๊ตฌ (vmstat, sar, netstat)

  • NFS ๊ตฌ์„ฑ

    • Network File System
    • ๊ฐœ๋ฐœ ์„œ๋ฒ„๊ฐ€ 2๋Œ€ ์ด์ƒ ๋˜์—ˆ์„ ๋•Œ ํŒŒ์ผ ๊ณต์œ ์‹œ ํ•„์š”
    • ๊ฐœ๋ฐœ ์„œ๋ฒ„ - ์‹ค ์„œ๋ฒ„ ์—ฐ๋™/๋ฐฑ์—… ํ•  ๋•Œ๋„ ํ•„์š”

[Note]

  • DNS; ๋„๋ฉ”์ธ ๊ฐ€์ง€๊ณ  ๋ผ์šฐํ„ฐ ๊ฑฐ์ณ์„œ ๋„ค์ž„์„œ๋ฒ„ ์ฐพ์•„๊ฐ
    ์ฐพ์€ ๋„ค์ž„์„œ๋ฒ„ํ•œํ…Œ ๊ฐ€์„œ IP ์ฃผ์†Œ ํ™•์ธํ•˜๊ณ  ์›น์„œ๋ฒ„๋กœ ๊ฐ€์„œ
    ์›น์„œ๋ฒ„์˜ ip์ฃผ์†Œ๋ฅผ ๊ฐ€์ง€๊ณ  html ๋‚ด๋ ค์คŒ (๋ธŒ๋ผ์šฐ์ €์—)
  • .com์ด ๋„ค์ž„์„œ๋ฒ„์˜ ๊ฐ€์žฅ ์ƒ์œ„ ๋ ˆ์ด์–ด (๊ฐ€์žฅ ๋จผ์ € ์ฐพ์Œ)
  • httpd (apache)

[Q&A]

  • DDOS ๊ฐ™์€ ํ•ดํ‚น ๊ณต๊ฒฉ์— ๋Œ€ํ•œ ๊ณต๊ฒฉ์ž์˜ ip ์ฃผ์†Œ๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด์„œ uniq, sort ๋“ฑ ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•˜์—ฌ
    ip ์ฃผ์†Œ๋ฅผ ์ถ”์ ํ•˜์‹ ๋‹ค๊ณ  ํ•˜์…จ๋Š”๋ฐ, ํ•˜์ง€๋งŒ ๊ณต๊ฒฉ์ž๊ฐ€ ๋‹จ์ˆœํžˆ ์ž์‹ ์˜ ip ์ฃผ์†Œ๋ฅผ ๊ทธ๋Œ€๋กœ ๋…ธ์ถœํ•ด์„œ
    ๋ณด๋‚ผ ๋ฆฌ๋Š” ์ ˆ๋Œ€๋กœ ์—†๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. IP spoofing ๊ฐ™์€ ๊ธฐ๋ฒ•์„ ํ†ตํ•ด์„œ source address๋ฅผ ์œ„์กฐํ•˜์—ฌ
    ๋ณด๋‚ด๋ฉด ๊ทธ์— ๋Œ€ํ•œ ip ์ฃผ์†Œ๋ฅผ ์—ญ์ถ”์ ํ•˜๋Š” ๊ฒƒ์ด ์–ด๋ ต๋‹ค๊ณ  ์ƒ๊ฐ๋˜๋Š”๋ฐ
    ๋งŒ์•ฝ ์ด์— ๋Œ€ํ•ด์„œ ์‹ค๋ฌด์—์„œ ์‹ค์ œ๋กœ DDOS์™€ ๊ฐ™์€ ํ•ดํ‚น ๋ฐฉ์ง€๋ฅผ ์œ„ํ•ด ์–ด๋– ํ•œ ๋ฐฉ๋ฒ•์„ ์ฃผ๋กœ ํ™œ์šฉํ•˜๊ฑฐ๋‚˜
    ์‚ฌ๋ก€ ๊ฐ™์€ ๊ฒƒ์ด ์žˆ๋Š”์ง€ ์•Œ ์ˆ˜ ์žˆ์„๊นŒ์š”?

    => DDOS ๊ฐ™์€ ๊ฒฝ์šฐ VPN์ด๋‚˜ IP Spoofing๊ฐ™์€ ๊ฑธ ์“ฐ๋ฉด ๋งŽ์ด ๋Š๋ ค์ง
    DDOS์˜ ์ƒ๋ช…์€ ๋‹จ์‹œ๊ฐ„ ๋‚ด์— ๋งŽ์€ ์š”์ฒญ์„ ๋ณด๋‚ด์•ผ ํ•จ
    ์‹ค๋ฌด์—์„œ๋Š” uniq, sort ๋ณด๋‹ค L4, L7 ๊ฐ™์€ ๋„คํŠธ์› ์žฅ๋น„์—์„œ DDOS๋ฅผ ๋จผ์ € ์ฐจ๋‹จํ•จ
    ํŠน์ • ์–ด๋ทฐ์ง• ํŒจํ„ด ๋“ฑ์„ ์ฐจ๋‹จํ•˜๋„๋ก ์„ค์ •ํ•ด ๋†“๊ธฐ ๋•Œ๋ฌธ์— ์„œ๋ฒ„๊นŒ์ง€ ๋ชป ๋“ค์–ด์˜ด
    ์กฐ๊ทธ๋งŒ ์„œ๋น„์Šค๋Š” L4๋‚˜ L7์ด ๋น„์‹ธ๊ธฐ ๋•Œ๋ฌธ์— ๋Œ€๋ถ€๋ถ„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Œ

Reference