> For the complete documentation index, see [llms.txt](https://op.skill.or.kr/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://op.skill.or.kr/cloud-work/cloud/system-security-checker-os-was.md).

# System Security Checker 서비스 \[OS/WAS 취약점 진단]

## 1. System Security Checker 서비스

> 서버의 운영체제와 WAS의 보안 설정을 점검

{% hint style="info" %}
:thumbsup: **WIKI 먼저 읽어 보기**&#x20;

​[System Security Checker 란 무엇인가?](/wiki/wiki/ncloud-naver-cloud/system-security-checker-os-was.md)
{% endhint %}

### 1.1 OS/WAS 점검 서비스&#x20;

<table><thead><tr><th width="176">분류</th><th>설명</th></tr></thead><tbody><tr><td>OS</td><td>Linux<br>Windows</td></tr><tr><td>WAS</td><td><p>Apache(httpd) 2.4.x</p><p>Tomcat 8.5 기준 </p><p>Nginx 1.x</p></td></tr></tbody></table>

## 2. 점검 방법&#x20;

> 1. 점검 할 서버에 접속&#x20;
>    * root 권한 필요
> 2. 패키지 다운로드&#x20;
>    * wget <http://ossc.ncloud.com:10080/download/ncp\\_secuagent.tar.gz>
> 3. 해당 파일 압축 해제
>    * tar xvzf ncp\_secuagent.tar.gz&#x20;
> 4. ROOT 권한으로 ncp\_secuagent 실행&#x20;
>
>    ***\*. ncp\_secuagent 실행 할 때 필요한 패키지를 서버에 설치 후 진행 됨. (방화벽 Open 필요)***
>
>    * OS 실행 : ./ncp\_secuagent
>    * nginx 실행 : ./ncp\_secuagent -p nginx
>    * apache 실행 : ./ncp\_secuagent -p apache
>    * tomcat 실행 : ./ncp\_secuagent -p tomcat
>      * [x] 여러개의 tomcat 을 사용 하고 있을 때 pid 값이 상위인 것만 점검 함.&#x20;
>      * [x] 여러개의 tomcat 일 경우 tomcat 하나씩 진단 수행 함.
> 5. ncp\_secuagent 옵션&#x20;
>    * -h : 도움말 표시(--help)
>    * -v : 에이전트의 버전 표시(--version)
>    * -d : 터미널에 디버그를 위한 정보 표시(--debug)
>    * -t 숫자 : 입력한 시간 내에 점검이 종료되지 않을 경우 강제 종료, 1초 단위로 설정 가능(--timeout, 기본값: 60초)
>    * -p 설정값 : 다음 설정값을 입력하여 점검 대상 및 항목 설정(--project)
>      * [x] finance: 금융보안원 전자금융기반시설 기준으로 Linux 보안 설정을 점검
>      * [x] apache, tomcat, nginx: Apache, Tomcat 또는 Nginx의 보안 설정을 점검
> 6. 5분 안에 점검이 종료되며 아래와 같이 표시됨.
>    * <예시> Linux 점검이 정상적으로 종료된 경우
>
>      ```
>      [Project : linux] => Success
>      ```
> 7. nCloud 콘솔 > System Security Checker > OS security Checker or WAS Security Chekcer 에서 확인 가능&#x20;
> 8. 최초 진단에서 취약점이 존재 할 경우 서버에서 취약점 제거 후 4번 항목을 다시 진행 하면 재진단이 수행 됨.&#x20;
>    * 최초 진단 후 30일 이내 동일한 서버 진단 시 재진단 1회까지는 별도 비용이 발생 되지 않음.

<figure><img src="/files/mJJMDVPDMnaZ91h0Puxv" alt=""><figcaption><p>OS Security Checker 점검 현황 화면 </p></figcaption></figure>

<figure><img src="/files/VxlzHp6giGuYGvDcf4BH" alt=""><figcaption><p>WAS Security Checker 점검 현황 화면 </p></figcaption></figure>

## 3. 점검 현황 및 보고서&#x20;

### 3.1 OS Security Checker&#x20;

#### 3.1.1  점검 내역&#x20;

<figure><img src="/files/OPbJiBOpI8x2a476yWAS" alt=""><figcaption><p>OS Security Checker 점검 현황 화면 </p></figcaption></figure>

#### 3.1.2 점검 보고서&#x20;

> 해당 보고서는 Execl/PDF 로 저장 할 수 있다.&#x20;

<figure><img src="/files/hsVbKqyCmSeHjv04uVP0" alt=""><figcaption><p>결과 보고서 화면 </p></figcaption></figure>

### 3.2 WAS Security Checker&#x20;

#### 3.2.1 점검 내역&#x20;

<figure><img src="/files/W0asehPR4PkawykHp0FC" alt=""><figcaption><p>WAS Security Checker 점검 현황 화면 </p></figcaption></figure>

#### 3.4 점검 보고서&#x20;

> 해당 보고서는 Execl/PDF 로 저장 할 수 있다.&#x20;

<figure><img src="/files/cps7CX9uKv3cNjWdnToG" alt=""><figcaption><p>결과 보고서 화면 </p></figcaption></figure>

&#x20;               [![](https://ads-partners.coupang.com/banners/768697?subId=\&traceId=V0-301-f5c692db558def48-I768697\&w=300\&h=250)](https://link.coupang.com/a/bvPl62) [![](https://ads-partners.coupang.com/banners/45962?subId=\&traceId=V0-301-879dd1202e5c73b2-I45962\&w=300\&h=250)](https://link.coupang.com/a/bvPlik)

{% embed url="<https://doc.skill.or.kr>" %}
NHN Cloud 정보 사이트
{% endembed %}

{% embed url="<https://ssv.skill.or.kr>" %}
취약점 진단 분석 평가 방법 사이트
{% endembed %}

{% embed url="<https://sul.skill.or.kr>" %}
보안 업데이트 정보 사이트
{% endembed %}
