설명
Azure SQL의 위협 탐지는 의심스러운 로그인이나 SQL Injection 같은 이상 활동에 대한 보안 경고를 제공합니다. 감사 로그를 저장하는 것만으로 위협 탐지가 활성화되는 것은 아닙니다.
잠재적 영향
위협 탐지가 꺼져 있으면 자동 보안 경고를 활용하지 못해 의심스러운 활동에 대한 대응이 늦어질 수 있습니다.
해결 방법
데이터베이스의 위협 탐지 정책을 활성화하고 Defender for SQL 설정과 알림 수신 경로를 확인하세요. 조사에 필요한 감사 로그도 함께 보관하세요.
예시
현재 AzureRM 리소스로 감사 기록을 유지하면서 위협 탐지를 켜는 예시입니다. 예시의 6일 보존 기간은 설명용이며 실제 요구 사항에 맞게 조정하세요.
변경 전
hcl
resource "azurerm_mssql_database" "example" {
name = "myexamplesqldatabase"
server_id = azurerm_mssql_server.example.id
threat_detection_policy {
state = "Disabled"
}
}
resource "azurerm_mssql_database_extended_auditing_policy" "example" {
database_id = azurerm_mssql_database.example.id
blob_storage_endpoint = azurerm_storage_account.example.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.example.primary_access_key
storage_account_access_key_is_secondary = false
retention_in_days = 6
}
변경 후
hcl
resource "azurerm_mssql_database" "example" {
name = "myexamplesqldatabase"
server_id = azurerm_mssql_server.example.id
threat_detection_policy {
state = "Enabled"
}
}
resource "azurerm_mssql_database_extended_auditing_policy" "example" {
database_id = azurerm_mssql_database.example.id
blob_storage_endpoint = azurerm_storage_account.example.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.example.primary_access_key
storage_account_access_key_is_secondary = false
retention_in_days = 6
}