시스템 보안 · 취약점 › A. Linux 서버 보안 설정 · 36/50편 (전체 036/450)
학습 단계: 2단계 · 설정 및 점검
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 「실습 예시」이며, IP·계정·호스트명은 가상의 값입니다.
커널 모듈은 실행 중인 커널에 기능을 추가하는 코드입니다. 커널 공간에서 동작하므로 모듈을 로드할 수 있다는 것은 시스템 전체를 통제할 수 있다는 뜻입니다. 커널 수준 루트킷이 모듈 형태로 동작하는 이유입니다.
모듈 로드 경로
사용자: modprobe usb-storage / insmod ./x.ko
↓ /etc/modprobe.d/*.conf 규칙 확인 (blacklist, install ... /bin/false)
커널: init_module / finit_module 시스템 콜 ← auditd 감시 지점(kmod 키)
↓ 서명 검증 (Secure Boot·서명 강제 시 미서명 모듈 거부)
로드 완료 → lsmod 에 표시 (단, 루트킷은 목록에서 자신을 숨길 수 있음)
| 명령·설정 | 용도 |
|---|---|
lsmod, modinfo 모듈 | 로드된 모듈, 파일 경로·서명 정보 |
modprobe -n -v usb-storage | 실제 로드 없이 동작 확인(차단 시 install /bin/false 표시) |
/etc/modprobe.d/*.conf | blacklist 모듈(자동 로드 방지) + install 모듈 /bin/false(수동 로드도 차단) |
cat /proc/sys/kernel/tainted | 0이 아니면 비정상 모듈 로드 등 흔적(비트 의미 확인) |
kernel.modules_disabled=1 | 이후 모든 모듈 로드 금지(재부팅 전 해제 불가, 신중히) |
mokutil --sb-state | Secure Boot 상태 |
# 1) USB 저장장치·미사용 파일시스템 차단
sudo tee /etc/modprobe.d/90-disable.conf <<'EOF'
blacklist usb-storage
install usb-storage /bin/false
install cramfs /bin/false
install udf /bin/false
EOF
modprobe -n -v usb-storage # install /bin/false 출력 확인
# 2) 현재 모듈 상태와 taint 확인
lsmod | head
cat /proc/sys/kernel/tainted
modinfo -F signer xfs 2>/dev/null # 배포판 서명자 확인
# 3) 모듈 로드 감사 규칙 (030편 kmod)
sudo auditctl -l | grep kmod
blacklist만 쓰면 의존성이나 수동 modprobe로 로드될 수 있으므로 install ... /bin/false를 함께 씁니다.
$ modprobe -n -v usb-storage
install /bin/false
$ cat /proc/sys/kernel/tainted
0
$ modinfo -F signer xfs
Rocky kernel signing key
taint 값이 0이고, 모듈 서명자가 배포판 키인 상태가 정상입니다. (서명자 문자열은 배포판·버전에 따라 다릅니다.)
$ cat /proc/sys/kernel/tainted
12288
$ sudo dmesg | grep -i taint
[ 8123.441] sysmon: loading out-of-tree module taints kernel.
[ 8123.442] sysmon: module verification failed: signature and/or required key missing - tainting kernel
$ lsmod | grep sysmon
$
dmesg에는 로드 기록이 있는데 lsmod에는 보이지 않음 → 자신을 목록에서 숨기는 커널 루트킷 의심모듈 로드와 USB 연결 흔적입니다(가상의 예시 로그).
type=SYSCALL msg=audit(1759737000.501:2901): arch=c000003e syscall=313 success=yes exit=0 a0=3 auid=1002 uid=0 comm="insmod" exe="/usr/bin/kmod" key="kmod"
Oct 1 04:20:00 rocky9-web01 kernel: sysmon: module verification failed: signature and/or required key missing - tainting kernel
Oct 1 04:31:15 rocky9-web01 kernel: usb 1-1: new high-speed USB device number 3 using ehci-pci
Oct 1 04:31:15 rocky9-web01 kernel: usb 1-1: New USB device found, idVendor=0781, idProduct=5567
| 관찰 | 해석 |
|---|---|
syscall=313 | finit_module(파일 디스크립터로 모듈 로드) |
comm="insmod" | 경로 지정 수동 로드(일반 운영에서는 드묾) |
signature ... missing | 미서명 모듈 |
| USB 장치 인식 후 mass storage 메시지 없음 | usb-storage 차단으로 저장장치로 마운트되지 않음 |
USB 연결 자체는 커널 로그에 남으므로, 차단 정책이 있어도 연결 시도 기록은 하이퍼바이저 접근 기록과 함께 확인합니다.
kmod 키 이벤트(특히 insmod, 비표준 경로 .ko)는 즉시 확인합니다.kernel/tainted 값을 기준선에 넣어 0이 아니게 변하면 Alert를 발생시킵니다.dmesg와 lsmod 결과가 다르면 커널 수준 은닉을 의심하고 상위 대응 절차로 올립니다.<group name="local,kmod,">
<rule id="100420" level="12">
<if_group>audit</if_group>
<field name="audit.key">kmod</field>
<description>커널 모듈 로드/언로드 시스템 콜</description>
</rule>
<rule id="100421" level="12">
<match>module verification failed</match>
<description>미서명 커널 모듈 로드(커널 taint)</description>
</rule>
</group>
패키지 업데이트(새 커널·드라이버)에서도 모듈 로드가 발생하므로, dnf/apt 로그와 시각을 비교해 정탐 여부를 판단합니다.
dmesg 모듈 메시지, kmod 감사 이벤트로 로드된 모듈과 사용자를 확인합니다.| 구분 | 핵심 내용 |
|---|---|
| 위험 | 커널 모듈 로드 = 시스템 전체 통제 가능 |
| 차단 | blacklist + install 모듈 /bin/false |
| 탐지 | init_module/finit_module(kmod 키), module verification failed |
| 은닉 단서 | dmesg에는 있고 lsmod에는 없음, tainted ≠ 0 |
| 면접 포인트 | "커널 루트킷 의심 시 서버 내부 도구 출력은 신뢰하지 않는다" |
다음 편 037. Linux 서버 보안 — 설정 드리프트(Drift)와 취약 설정 탐지 에서는 설정 점검 단계를 마치고, 시간이 지나며 무너지는 설정 드리프트와 취약 설정 탐지로 넘어갑니다.
이전 편: 035. Linux 서버 보안 — 코어 덤프 제한과 민감정보 보호
📚 시리즈 전체 보기: 시스템 보안 · 취약점