Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
sentinel-mcp — MCP, Gemini 2.0 Flash, Dynatrace observability 및 MongoDB를 사용하는 자율 AI 기반 사이버 방어 시스템. Google Cloud Hackathon 제출물. | Kitploit
도구/GitLabGitLab/reyjesusq/sentinel-mcp
Defensive ToolsCloud SecurityIntrusion DetectionIncident ResponseAI SecurityAnomaly Detection
GitLabreyjesusq/sentinel-mcp

sentinel-mcp

MCP, Gemini 2.0 Flash, Dynatrace observability 및 MongoDB를 사용하는 자율 AI 기반 사이버 방어 시스템. Google Cloud Hackathon 제출물.

저장소 보기
213개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

SentinelMCP — AI 기반 사이버 방어 시스템

Google Cloud Hackathon 제출작 — Google Cloud Agent Builder (Vertex AI Agent) 가 오케스트레이션하는 자동 위협 탐지 및 대응 시스템, Gemini 2.0 Flash, Model Context Protocol (MCP), Dynatrace 관찰 가능성 기반.

Agent Builder Gemini 2.0 Flash Dynatrace MongoDB MCP Protocol


문제점

보안 팀은 일반적인 사고에 대해 MTTD 30분 및 MTTR 4시간에 직면합니다. 인간 분석가가 공격을 탐지하고, 방화벽 규칙을 작성하고, 배포할 때쯤이면 피해는 이미 발생한 후입니다.

해결책

SentinelMCP는 Google Cloud Agent Builder 에이전트를 배포하여 MTTD를 <30초로, MTTR을 <30초로 단축합니다. 이 에이전트는 Dynatrace 이상 웹훅을 수신하고, Gemini 2.0 Flash를 통해 추론하며, MCP를 통해 실제 방어 도구를 호출하여 실시간 인프라에 조치를 취합니다(단순 알림이 아닌).

Dynatrace webhook  →  Agent Builder receives alert  →  Gemini reasons  →  MCP tools execute  →  Threat neutralized
       1 s                        2 s                      8 s                  15 s                  25 s total

결과: 이전에는 인간 분석가와 4시간이 필요했던 사고 생애 주기가 이제 30초 미만으로 자동 완료되며, MongoDB에 전체 감사 추적이, Jaeger에 분산 추적이 저장됩니다.


아키텍처

┌──────────────────────────────────────────────────────────────────────┐
│                         SANDBOX ENVIRONMENT                          │
│                                                                      │
│   ┌─────────────┐   100–1000 req/s   ┌──────────────────────────┐   │
│   │  attacker   │ ──────────────────►│    victim-service        │   │
│   │ (DDoS/SQLi) │                    │    port 8080             │   │
│   └─────────────┘                    │    /admin/* control API  │   │
│                                      └────────────┬─────────────┘   │
└───────────────────────────────────────────────────│──────────────────┘
                                                    │ metrics + anomaly webhook
                   ┌────────────────────────────────▼─────────────────┐
                   │         Dynatrace Mock  (anomaly engine)          │
                   │  Threat Risk Score → fires POST /alerts/simulate  │
                   └────────────────────────┬─────────────────────────┘
                                            │ webhook
          ┌─────────────────────────────────▼──────────────────────────┐
          │          Google Cloud Agent Builder  (Vertex AI Agent)      │
          │  ┌──────────────────────────────────────────────────────┐  │
          │  │  Gemini 2.0 Flash  ──  reasons over threat context   │  │
          │  │  Tool manifest  ──  dynamically fetched from MCP     │  │
          │  │  HITL gate  ──  halts if confidence < threshold      │  │
          │  └──────────────────────────────────────────────────────┘  │
          └──────────────┬─────────────────────────┬───────────────────┘
                         │ REST calls                │ audit write
         ┌───────────────▼──────┐      ┌────────────▼──────────┐
         │  MCP Server  :8001   │      │  MongoDB 7.0  Atlas   │
         │  11 real tools       │      │  incidents + traces   │
         └───────────┬──────────┘      └───────────────────────┘
                     │ acts on live infra
         ┌───────────▼──────────┐
         │  FastAPI  :8000      │
         │  victim-service :8080│
         └──────────────────────┘

                   ┌──────────────────────────────────────────────────┐
                   │              OBSERVABILITY STACK                  │
                   │  OTel Collector ──► Jaeger  (distributed traces)  │
                   │  Prometheus ──────────────► Grafana               │
                   └──────────────────────────────────────────────────┘

핵심 설계 원칙: 우아한 성능 저하 + 인간 개입 루프(HITL). Agent Builder 에이전트는 충분한 신뢰도로 결정을 내릴 수 없을 때 안전하게 중단하고 운영자에게 제어권을 넘깁니다 — 중요한 인프라에서 추측하지 않습니다.


라이브 데모 — Google Cloud Run

세 가지 서비스가 모두 Google Cloud Run에 배포되어 실행 중입니다.

서비스URL
커맨드 센터(대시보드)https://sentinel-api-62d3d66zda-uc.a.run.app/dashboard
Swagger API 문서https://sentinel-api-62d3d66zda-uc.a.run.app/docs
상태 확인https://sentinel-api-62d3d66zda-uc.a.run.app/health
MCP 도구 카탈로그https://sentinel-mcp-62d3d66zda-uc.a.run.app/mcp/tools
Victim 서비스https://victim-service-62d3d66zda-uc.a.run.app

프로덕션 환경에 라이브 공격 실행:

.\attack.production.ps1 status   # verify all services healthy
.\attack.production.ps1 ddos     # DDoS — Gemini blocks IPs + rate limit
.\attack.production.ps1 sql      # SQL Injection — Gemini activates WAF
.\attack.production.ps1 brute    # Brute Force — Gemini blocks source IPs
.\attack.production.ps1 stop     # reset defenses

공격자 컨테이너는 로컬에서 실행되며 Cloud Run victim-service를 HTTPS로 대상으로 합니다. Command Center 대시보드에서 탐지 → 추론 → 무력화 사이클을 실시간으로 확인하세요.


Google Cloud Agent Builder 사용 방법

Google Cloud Agent Builder (Vertex AI ReasoningEngine) 는 SentinelMCP의 중앙 오케스트레이터입니다. 구현은 sentinel_mcp/agent/agent_builder.py에 있습니다.

SentinelAgent는 vertexai.preview.reasoning_engines.Queryable을 상속받습니다. 이는 공식 Agent Builder 프로그래매틱 인터페이스이며, 로컬에서 실행하거나 단일 명령으로 관리형 Agent Builder 서비스에 배포할 수 있습니다.

책임구현
웹훅 수신SentinelAgent.query(incident=...) — 모든 Dynatrace 알림에 대해 Agent Builder가 호출
도구 선언set_up()에서 Vertex AI FunctionDeclaration 객체로 등록된 6개의 MCP 도구
추론Gemini 2.0 Flash가 위협 컨텍스트 + 도구 카탈로그를 읽고 최소 도구를 선택하여 자동 호출
HITL 게이트Gemini가 도구 호출을 반환하지 않으면(신뢰도 < 임계값) escalate_to_humans=True를 내보냄
감사모든 도구 호출이 MongoDB Atlas에 기록되고 OTel 스팬으로 Jaeger에 내보내짐

핵심 코드 — sentinel_mcp/agent/agent_builder.py:

class SentinelAgent(reasoning_engines.Queryable):

    def set_up(self):
        # MCP tools as Vertex AI FunctionDeclarations — Gemini selects at runtime
        mcp_tools = Tool(function_declarations=[
            FunctionDeclaration(name="block_ip_address", ...),
            FunctionDeclaration(name="activate_waf", ...),
            FunctionDeclaration(name="rate_limit_requests", ...),
            FunctionDeclaration(name="scale_service", ...),
            FunctionDeclaration(name="collect_forensic_logs", ...),
            FunctionDeclaration(name="analyze_attack_pattern", ...),
        ])
        self._model = GenerativeModel("gemini-2.0-flash-001", tools=[mcp_tools])
        self._chat = self._model.start_chat()

    def query(self, *, incident: dict) -> dict:
        # Entry point — Agent Builder calls this for every Dynatrace webhook
        response = self._chat.send_message(threat_prompt(incident))
        tool_calls = [{"name": p.function_call.name, "args": dict(p.function_call.args)}
                      for p in response.candidates[0].content.parts if p.function_call]
        return {"engine": "agent_builder", "tool_calls": tool_calls, ...}

Google Cloud Agent Builder에 배포:

# Test locally (no GCP needed with google_ai_studio backend)
python scripts/deploy_agent_builder.py --test-only

# Deploy to managed Agent Builder endpoint
python scripts/deploy_agent_builder.py --project my-gcp-project

Agent Builder를 활성 백엔드로 설정:

# .env
GEMINI_BACKEND=agent_builder
GOOGLE_CLOUD_PROJECT=my-gcp-project
VERTEX_LOCATION=us-central1

Dynatrace 및 MCP 사용 방법

Dynatrace

SentinelMCP는 세 가지 계층에서 Dynatrace 관찰 가능성을 통합합니다.

  1. OpenTelemetry 파이프라인 — sentinel-otel-collector는 FastAPI 코어에서 스팬과 메트릭을 수집하여 Dynatrace Mock 엔드포인트(OTLP/HTTP :14318)로 전달합니다. 모든 사고, 도구 실행, LLM 호출은 전체 상관 ID와 함께 종단 간 추적됩니다.
도구 다운로드