시스템 보안 · 취약점 › A. Linux 서버 보안 설정 · 12/50편 (전체 012/450)
학습 단계: 2단계 · 설정 및 점검
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 「실습 예시」이며, IP·계정·호스트명은 가상의 값입니다.
SSH 한도 설정은 연결 단계별로 자원을 제한합니다. 어느 단계에서 걸렸는지에 따라 로그 메시지가 달라지므로, 메시지로 공격 유형을 추정할 수 있습니다.
TCP 연결 ──→ [MaxStartups] 인증 전 동시 연결 수 제한
↓
인증 대기 ──→ [LoginGraceTime] 인증 완료까지 허용 시간
↓
인증 시도 ──→ [MaxAuthTries] 연결당 인증 시도 횟수
↓
로그인 후 ──→ [MaxSessions] 연결당 세션 수
──→ [ClientAliveInterval × CountMax] 무응답 세션 정리
| 설정 | 권장 예시 | 기본값(OpenSSH) |
|---|---|---|
MaxAuthTries | 3~4 | 6 |
LoginGraceTime | 30 | 120 |
MaxStartups | 10:30:60 | 10:30:100 |
MaxSessions | 2~4 | 10 |
ClientAliveInterval / ClientAliveCountMax | 300 / 2 | 0 / 3 |
MaxStartups 10:30:60은 "인증 전 연결이 10개를 넘으면 30% 확률로 거절을 시작해, 60개에서는 모두 거절"이라는 뜻입니다.
sudo tee /etc/ssh/sshd_config.d/06-limits.conf <<'EOF'
MaxAuthTries 3
LoginGraceTime 30
MaxStartups 10:30:60
MaxSessions 4
ClientAliveInterval 300
ClientAliveCountMax 2
EOF
sudo sshd -t && sudo systemctl reload sshd
sudo sshd -T | grep -E '^(maxauthtries|logingracetime|maxstartups|maxsessions|clientalive)'
# 테스트 클라이언트에서: 틀린 비밀번호를 연속 입력해 한도 초과 메시지 확인
maxauthtries 3
logingracetime 30
maxsessions 4
clientaliveinterval 300
clientalivecountmax 2
maxstartups 10:30:60
정상 운영에서 한도 초과 로그는 드물게, 산발적으로 나타납니다(비밀번호를 잊은 사용자 등).
$ sudo sshd -T | grep -E 'maxauthtries|logingracetime'
maxauthtries 50
logingracetime 600
한도를 크게 늘린 설정은 무차별 대입 준비 또는 자동화 도구 접속을 쉽게 하려는 변경일 수 있습니다. 설정 변경 시각과 이후 실패 로그 급증을 함께 봅니다.
한도별 대표 로그입니다(가상의 예시 로그).
Oct 1 07:10:02 rocky9-web01 sshd[7001]: error: maximum authentication attempts exceeded for invalid user oracle from 192.168.56.77 port 40210 ssh2 [preauth]
Oct 1 07:10:02 rocky9-web01 sshd[7001]: Disconnecting invalid user oracle 192.168.56.77 port 40210: Too many authentication failures [preauth]
Oct 1 07:10:09 rocky9-web01 sshd[1022]: drop connection #10 from [192.168.56.77]:40288 on [192.168.56.10]:22 past MaxStartups
Oct 1 07:12:40 rocky9-web01 sshd[7044]: Timeout before authentication for 192.168.56.78 port 51544
| 메시지 | 걸린 한도 | 의미 |
|---|---|---|
maximum authentication attempts exceeded | MaxAuthTries | 연결당 다수 비밀번호 시도 |
past MaxStartups | MaxStartups | 인증 전 연결 폭주(병렬 도구) |
Timeout before authentication | LoginGraceTime | 연결만 열고 인증하지 않음(배너 수집·점검 도구 가능) |
invalid user oracle처럼 존재하지 않는 흔한 계정명이 섞이면 사전(dictionary) 기반 자동화일 가능성이 높습니다.
past MaxStartups는 정상 사용에서 거의 나오지 않으므로 발생 즉시 출발지를 확인합니다.Wazuh 기본 룰셋에서 5710(존재하지 않는 사용자 로그인 시도), 5712(SSHD brute force, 빈도 기반)가 관련 룰입니다. 연결 폭주는 별도 룰로 보완합니다.
<rule id="100190" level="10">
<decoded_as>sshd</decoded_as>
<match>past MaxStartups</match>
<description>SSH 인증 전 연결 폭주(MaxStartups 초과)</description>
</rule>
Kibana 예시: rule.id : (5710 or 5712 or 100190) and data.srcip : "192.168.56.77"
| 설정 | 걸리는 단계 / 로그 |
|---|---|
| MaxStartups | 인증 전 동시 연결 / past MaxStartups |
| LoginGraceTime | 인증 대기 시간 / Timeout before authentication |
| MaxAuthTries | 연결당 시도 수 / maximum authentication attempts exceeded |
| ClientAlive* | 무응답 세션 정리 |
| 면접 포인트 | "로그 메시지로 어느 한도에 걸렸는지 → 공격 유형 추정" |
다음 편 013. Linux 서버 보안 — 불필요한 서비스 식별과 비활성화 에서는 서버에서 돌아가는 불필요한 서비스를 식별하고 비활성화하는 방법을 다룹니다.
이전 편: 011. Linux 서버 보안 — SSH 접근 제어 — AllowUsers·AllowGroups·Match
📚 시리즈 전체 보기: 시스템 보안 · 취약점