설명
GCP에서 감사 로그 설정이 바뀌면 어떤 활동을 기록할지도 달라집니다. 감사 설정 변경을 추적하는 로그 메트릭과 알림이 없으면 중요한 감사 범위가 줄어들어도 운영자가 늦게 알 수 있습니다.
잠재적 영향
- 감사 설정을 약화시키는 변경을 제때 발견하지 못할 수 있습니다.
- 사고 조사에 필요한 활동 기록이 부족해질 수 있습니다.
해결 방법
- 실제 감사 로그를 확인해
SetIamPolicy와auditConfigDeltas등 감사 설정 변경을 포함하는 필터를 구성하세요. - 로그 메트릭을 참조하는 알림 조건과
notification_channels를 설정하세요. 정상적인 시험 변경으로 로그 수신, 메트릭과 알림을 확인하고 수집 지연도 고려하세요.
예시
설정 일부를 비교하는 예제입니다. 변경 전 알림 구성은 불완전합니다. 변경 후 var.audit_monitored_resource_type에는 해당 메트릭에 실제 존재하는 모니터링 리소스 유형을 지정하고, 통지 채널과 프로젝트는 별도로 준비하세요. 평가 구간은 로그 수집 지연과 운영 요구에 맞게 조정하세요.
변경 전
hcl
resource "google_logging_metric" "audit_config_change" {
name = "audit_config_change"
description = "Detects changes to audit configurations via SetIamPolicy"
filter = "protoPayload.methodName=\"wrong_method\" AND protoPayload.serviceData.policyDelta.auditConfigDeltas:*"
}
resource "google_monitoring_alert_policy" "audit_config_alert" {
display_name = "Audit Config Change Alert"
combiner = "OR"
conditions {
display_name = "Audit Config Change Condition"
condition_threshold {
filter = "resource.type=\"gce_instance\" AND metric.type=\"logging.googleapis.com/user/audit_config_change\""
}
}
}
변경 후
hcl
resource "google_logging_metric" "audit_config_change" {
name = "audit_config_change"
description = "Detects changes to audit configurations via SetIamPolicy"
filter = "protoPayload.methodName=\"SetIamPolicy\" AND protoPayload.serviceData.policyDelta.auditConfigDeltas:*"
}
resource "google_monitoring_alert_policy" "audit_config_alert" {
display_name = "Audit Config Change Alert"
combiner = "OR"
notification_channels = [google_monitoring_notification_channel.security_ops.name]
conditions {
display_name = "Matching audit events"
condition_threshold {
filter = "metric.type=\"logging.googleapis.com/user/${google_logging_metric.audit_config_change.name}\" AND resource.type=\"${var.audit_monitored_resource_type}\""
comparison = "COMPARISON_GT"
threshold_value = 0
duration = "0s"
aggregations {
alignment_period = "600s"
per_series_aligner = "ALIGN_SUM"
}
}
}
}
설명:
- 변경 전: 메서드 필터가 잘못되어 의도한 변경이 메트릭에 포함되지 않을 수 있으며 알림 조건도 불완전합니다.
- 변경 후: 변경 필터와 메트릭 임계값 조건, 통지 채널을 연결합니다. 실제 이벤트 형식과 수신 여부를 확인하세요.