
사이버 보안 인식 프레임워크 (CSAF)

CSAF(사이버 보안 인식 프레임워크, Cyber Security Awareness Framework) 는 개인, 조직 및 커뮤니티의 사이버 보안 인식과 이해를 향상시키기 위한 구조화된 접근 방식입니다. 이 프레임워크는 효과적인 사이버 보안 인식 프로그램 개발을 위한 지침을 제공하며, 인식 요구 평가, 교육 자료 제작, 훈련 및 시뮬레이션 수행, 커뮤니케이션 캠페인 구현, 인식 수준 측정 등 주요 영역을 다룹니다. 이 프레임워크를 채택함으로써 조직은 강력한 보안 문화를 조성하고, 사이버 위협을 탐지하고 대응하는 능력을 향상시키며, 공격 및 보안 침해와 관련된 위험을 완화할 수 있습니다.
---
config:
layout: elk
---
flowchart TD
kali_attack["Kalilinux Attack"]
kali_defense["Kalilinux Defense"]
kali_monitor["Kalilinux Monitor"]
subgraph Webserver["Webserver"]
dvwa["DVWA"]
dvwa_monitor["DVWA Monitor"]
wackopicko["Wackopicko"]
juiceshop["Juiceshop"]
end
subgraph Database["Database"]
mariadb["MariaDB"]
mongodb["MongoDB"]
end
subgraph Phishing["Phishing LAB"]
gophish["Gophish"]
phishing["Phishing WEB"]
mail_server["Mail Server"]
mitmproxy["Mitmproxy"]
end
subgraph Ransomware["Ransomware LAB"]
ransomware["Ransomware WEB"]
end
subgraph Breach["Breach LAB"]
caldera["Caldera"]
infection_monkey["Infection Monkey"]
end
subgraph Versioning["Versioning"]
gitea["Gitea"]
end
subgraph Monitor["SOC LAB"]
subgraph WAF["WAF"]
bunkerweb["BunkerWEB"]
modsecurity["Modsecurity"]
end
subgraph SIEM["SIEM"]
wazuh["Wazuh"]
splunk["Splunk"]
end
subgraph DFIR["DFIR"]
velociraptor["Velociraptor"]
end
end
dvwa -->|Connect| mariadb
dvwa -->|Sending Alert| wazuh
dvwa -->|Sending Log| splunk
dvwa_monitor -->|Connect| mariadb
dvwa_monitor -->|Sending Alert| wazuh
dvwa_monitor -->|Sending Log| splunk
wackopicko -->|Lateral Movement| juiceshop
wackopicko -->|Lateral Movement| dvwa
wackopicko -->|Lateral Movement| dvwa_monitor
gitea -->|Update Code| dvwa
gitea -->|Update Code| dvwa_monitor
caldera -->|Control| dvwa
caldera -->|Control| dvwa_monitor
infection_monkey -->|Connect| mongodb
velociraptor -->|Control| dvwa
velociraptor -->|Control| dvwa_monitor
bunkerweb -->|Protect| dvwa_monitor
bunkerweb -->|Protect| wackopicko
bunkerweb -->|Protect| juiceshop
modsecurity -->|Protect| dvwa_monitor
gophish -->|Sending Phishing| mail_server
phishing -->|Seding Data| mitmproxy
mail_server -->|Access| phishing
ransomware -->|Infection| kali_attack
ransomware -->|Infection| kali_defense
ransomware -->|Infection| kali_monitor
kali_attack -->|Attack| bunkerweb
kali_attack -->|Attack| modsecurity
kali_attack -->|Attack| wackopicko
kali_attack -->|Access| gophish
kali_attack -->|Collect Data| mitmproxy
kali_attack -->|Access| caldera
kali_attack -->|Access| infection_monkey
kali_defense -->|Patch Source Code| gitea
kali_defense -->|Control Rule| bunkerweb
kali_defense -->|Remote SSH| dvwa
kali_defense -->|Remote SSH| dvwa_monitor
kali_defense -->|Access| mail_server
kali_monitor -->|Monitor| splunk
kali_monitor -->|Monitor| wazuh
kali_monitor -->|Monitor| velociraptor
kali_monitor -->|Monitor| bunkerweb
kali_monitor -->|Access| mail_server
%% Styling
classDef attackStyle fill:#ff6b6b,stroke:#c92a2a,stroke-width:3px,color:#fff
classDef defenseStyle fill:#51cf66,stroke:#2f9e44,stroke-width:3px,color:#fff
classDef monitorStyle fill:#748ffc,stroke:#4c6ef5,stroke-width:3px,color:#fff
classDef webserverStyle fill:#ffa94d,stroke:#fd7e14,stroke-width:2px,color:#fff
classDef databaseStyle fill:#868e96,stroke:#495057,stroke-width:2px,color:#fff
classDef phishingStyle fill:#ffd43b,stroke:#fab005,stroke-width:2px,color:#333
classDef ransomwareStyle fill:#fa5252,stroke:#e03131,stroke-width:3px,color:#fff
classDef breachStyle fill:#e64980,stroke:#c2255c,stroke-width:2px,color:#fff
classDef versioningStyle fill:#74c0fc,stroke:#339af0,stroke-width:2px,color:#fff
classDef wafStyle fill:#20c997,stroke:#0ca678,stroke-width:2px,color:#fff
classDef siemStyle fill:#845ef7,stroke:#7048e8,stroke-width:2px,color:#fff
classDef dfirStyle fill:#5c7cfa,stroke:#4263eb,stroke-width:2px,color:#fff
%% Apply styles
class kali_attack attackStyle
class kali_defense defenseStyle
class kali_monitor monitorStyle
class dvwa,dvwa_monitor,wackopicko,juiceshop webserverStyle
class mariadb,mongodb databaseStyle
class gophish,phishing,mail_server,mitmproxy phishingStyle
class ransomware ransomwareStyle
class caldera,infection_monkey breachStyle
class gitea versioningStyle
class bunkerweb,modsecurity wafStyle
class wazuh,splunk siemStyle
class velociraptor dfirStyle
%% Link Styling (Arrows)
linkStyle 0,1,2,3,4,5 stroke:#868e96,stroke-width:2px
linkStyle 6,7,8 stroke:#e64980,stroke-width:2px
linkStyle 9,10 stroke:#74c0fc,stroke-width:2px
linkStyle 11,12 stroke:#e64980,stroke-width:2px
linkStyle 13 stroke:#868e96,stroke-width:2px
linkStyle 14,15 stroke:#5c7cfa,stroke-width:2px
linkStyle 16,17,18 stroke:#20c997,stroke-width:2px
linkStyle 19 stroke:#20c997,stroke-width:2px
linkStyle 20 stroke:#fab005,stroke-width:2px
linkStyle 21 stroke:#fab005,stroke-width:2px
linkStyle 22 stroke:#fab005,stroke-width:2px
linkStyle 23,24,25 stroke:#fa5252,stroke-width:3px
linkStyle 26,27,28,29,30,31,32 stroke:#ff6b6b,stroke-width:2px
linkStyle 33,34,35,36,37 stroke:#51cf66,stroke-width:2px
linkStyle 38,39,40,41,42 stroke:#748ffc,stroke-width:2px
%% Subgraph Styling
style Webserver fill:#fff4e6,stroke:#fd7e14,stroke-width:3px,color:#000
style Database fill:#e9ecef,stroke:#495057,stroke-width:3px,color:#000
style Phishing fill:#fff9db,stroke:#fab005,stroke-width:3px,color:#000
style Ransomware fill:#ffe3e3,stroke:#e03131,stroke-width:3px,color:#000
style Breach fill:#ffdeeb,stroke:#c2255c,stroke-width:3px,color:#000
style Versioning fill:#e7f5ff,stroke:#339af0,stroke-width:3px,color:#000
style Monitor fill:#f3f0ff,stroke:#7048e8,stroke-width:4px,color:#000
style WAF fill:#d3f9e8,stroke:#0ca678,stroke-width:2px,color:#000
style SIEM fill:#e5dbff,stroke:#7048e8,stroke-width:2px,color:#000
style DFIR fill:#dbe4ff,stroke:#4263eb,stroke-width:2px,color:#000
리포지토리 클론
git clone https://github.com/csalab-id/csaf.git
프로젝트 디렉터리로 이동
cd csaf
Docker 이미지 가져오기
docker compose --profile=all pull
Wazuh SSL 인증서 생성
docker compose -f generate-certs.yml run --rm generator
Docker Compose용 로컬 환경 파일 생성:
cp .env.example .env
필요에 따라 .env 파일의 값을 업데이트하거나 아래의 셸 내보내기를 사용하세요.
Docker Compose를 실행하기 전에 설정하세요 (기본값은 docker-compose.yml에서 가져옴):
예시:
export ATTACK_PASS=ChangeMePlease
export DEFENSE_PASS=ChangeMePlease
export MONITOR_PASS=ChangeMePlease
export SPLUNK_PASS=ChangeMePlease
export VELOX_PASS=ChangeMePlease
export GOPHISH_PASS=ChangeMePlease
export MAIL_PASS=ChangeMePlease
export PHISHING_URL=https://example.com/
export PHISHING_TITLE="Example Login"
export PHISHING_FAVICON=https://example.com/favicon.ico
export BIND_ADDR=127.0.0.1
모든 컨테이너 시작
docker compose --profile=all up -d
다음 프로필을 사용하여 특정 실험실을 실행할 수 있습니다:
예:
docker compose --profile=attackdefenselab up -d
attack.lab (VNC on 6080), defense.lab (7080), monitor.lab (8080).dvwa.lab, wackopicko.lab, juiceshop.lab, gitea.lab.mail.server.lab (iRedMail), gophish.lab, phishing.lab.infectionmonkey.lab, mongodb.lab, caldera.lab.ransomware.lab.attackpassword / defensepassword / monitorpassword (env로 재정의 가능).csalab / giteapassword.GOPHISH_PASS의 관리자 비밀번호.[email protected] / mailpassword.admin / splunkpassword.admin / veloxpassword.admin / SecretPassword.docker compose down -v 명령으로 컨테이너와 볼륨을 제거합니다.docker compose --profile=all up -ddocker compose --profile=<profile> up -ddocker compose downdocker compose psdocker compose logs -f <service>docker compose -f generate-certs.yml run --rm generator를 실행하세요.BIND_ADDR=127.0.0.1을 설정하세요.docker compose down -v를 사용하여 영구 데이터를 완전히 삭제하세요..env를 통해 모든 기본 비밀번호를 변경하세요.BIND_ADDR=127.0.0.1을 사용하여 SOCKS5나 SSH를 통해 접근하는 것이 좋습니다.

노출된 포트는 SOCKS5 프록시, SSH 클라이언트 또는 HTTP 클라이언트를 사용하여 접근할 수 있습니다. 최상의 경험을 위해 적절한 방법을 선택하세요.
이 Docker Compose 애플리케이션은 MIT 라이선스 하에 배포됩니다. 자세한 내용은 LICENSE 파일을 참조하세요.
이 프로젝트는 교육 및 실험실 용도로만 제공됩니다. 강화 및 독립적인 보안 검증 없이 제공된 서비스를 인터넷이나 프로덕션 환경에 직접 노출하지 마십시오. 이 프로젝트를 배포하거나 사용할 때 해당 법률, 규정 및 조직 정책을 준수할 책임은 전적으로 사용자에게 있습니다.
wazuh-manager.labwazuh-indexer.labwazuh-dashboard.labsplunk.labvelociraptor.labbunkerweb.lab 리버스 프록시/WAF (DVWA, Juice Shop, WackoPicko용). 설정 UI: https://bunkerweb.lab/setup. 별칭: dvwa-bunkerweb.lab, juiceshop-bunkerweb.lab, wackopicko-bunkerweb.lab.