9. Security Considerations

์ด ์ ˆ์€ HTTP ์˜๋ฏธ์™€ ๊ด€๋ จ๋œ ์•Œ๋ ค์ง„ ๋ณด์•ˆ ์šฐ๋ ค ์‚ฌํ•ญ๊ณผ ์ธํ„ฐ๋„ท์„ ํ†ตํ•œ ์ •๋ณด ์ „์†ก์— ๋Œ€ํ•œ ๊ทธ๊ฒƒ์˜ ์‚ฌ์šฉ์„ ๊ฐœ๋ฐœ์ž, ์ •๋ณด ์ œ๊ณต์ž ๋ฐ ์‚ฌ์šฉ์ž์—๊ฒŒ ์•Œ๋ฆฌ๊ธฐ ์œ„ํ•œ ๊ฒƒ์ด๋‹ค. ๋ฉ”์‹œ์ง€ ๊ตฌ๋ฌธ, ๊ตฌ๋ฌธ ๋ถ„์„ ๋ฐ ๋ผ์šฐํŒ…๊ณผ ๊ด€๋ จ๋œ ๊ณ ๋ ค์‚ฌํ•ญ์€ [RFC7230]์˜ Section 9์— ์„ค๋ช…๋˜์–ด ์žˆ๋‹ค.

9.1. Attacks Based on File and Path Names

9.2. Attacks Based on Command, Code, or Query Injection

9.3. Disclosure of Personal Information

ํด๋ผ์ด์–ธํŠธ๋Š” ๋ฆฌ์†Œ์Šค(e.g., ์‚ฌ์šฉ์ž์˜ ์ด๋ฆ„, ์œ„์น˜, ๋ฉ”์ผ ์ฃผ์†Œ, ๋น„๋ฐ€๋ฒˆํ˜ธ, ์•”ํ˜ธํ™” ํ‚ค ๋“ฑ)์™€ ์‹œ๊ฐ„ ๊ฒฝ๊ณผ์— ๋”ฐ๋ฅธ ์‚ฌ์šฉ์ž์˜ ๊ฒ€์ƒ‰ ํ™œ๋™์— ๋Œ€ํ•œ ์ •๋ณด(e.g., ์ด๋ ฅ, ์ฑ…๊ฐˆํ”ผ ๋“ฑ)๋ฅผ ํฌํ•จํ•˜์—ฌ ์‚ฌ์šฉ์ž๊ฐ€ ์ œ๊ณตํ•œ ๋‘ ๊ฐ€์ง€ ์ •๋ณด๋ฅผ ํฌํ•จํ•˜์—ฌ ๋Œ€๋Ÿ‰์˜ ๊ฐœ์ธ ์ •๋ณด์— ์ข…์ข… ์ ‘๊ทผํ•œ๋‹ค. ๊ตฌํ˜„ ์‹œ ์˜๋„ํ•˜์ง€ ์•Š์€ ๊ฐœ์ธ์ •๋ณด์˜ ๊ณต๊ฐœ๋ฅผ ๋ฐฉ์ง€ํ•  ํ•„์š”๊ฐ€ ์žˆ๋‹ค.

9.4. Disclosure of Sensitive Information in URIs

URI๋Š” ๋ณด์•ˆ ๋ฆฌ์†Œ์Šค๋ฅผ ์‹๋ณ„ํ•˜๋”๋ผ๋„ ๋ณด์•ˆ์ด ์•„๋‹Œ ๊ณต์œ ๋  ์ˆ˜ ์žˆ๋„๋ก ๋˜์–ด ์žˆ๋‹ค. URI๋Š” ์ข…์ข… ๋””์Šคํ”Œ๋ ˆ์ด์— ํ‘œ์‹œ๋˜๊ณ , ํŽ˜์ด์ง€๊ฐ€ ์ธ์‡„๋  ๋•Œ ํ…œํ”Œ๋ฆฟ์— ์ถ”๊ฐ€๋˜๋ฉฐ, ๋ณดํ˜ธ๋˜์ง€ ์•Š๋Š” ๋‹ค์–‘ํ•œ ๋ถ๋งˆํฌ ๋ชฉ๋ก์— ์ €์žฅ๋œ๋‹ค. ๋”ฐ๋ผ์„œ ๋ฏผ๊ฐํ•˜๊ฑฐ๋‚˜ ๊ฐœ์ธ ์‹๋ณ„ ๊ฐ€๋Šฅํ•˜๊ฑฐ๋‚˜ ๊ณต๊ฐœํ•  ์œ„ํ—˜์ด ์žˆ๋Š” ์ •๋ณด๋ฅผ ๋ณดํ˜ธ๋˜์ง€ ์•Š๋Š” ๋‹ค์–‘ํ•œ ๋ถ๋งˆํฌ ๋ชฉ๋ก์— ํฌํ•จํ•˜๋Š” ๊ฒƒ์€ ํ˜„๋ช…ํ•˜์ง€ ๋ชปํ•˜๋‹ค.

9.5. Disclosure of Fragment after Redirects

9.6. Disclosure of Product Information

User-Agent(Section 5.5.3), Via([RFC7230]์˜ Section 5.7.1), Server(Section 7.4.2) ํ—ค ๋” ํ•„๋“œ๋Š” ์ข…์ข… ๊ฐ ๋ฐœ์‹ ์ž์˜ ์†Œํ”„ํŠธ์›จ์–ด ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๊ณต๊ฐœํ•œ๋‹ค. ์ด๋ก ์ ์œผ๋กœ, ์ด๊ฒƒ์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์•Œ๋ ค์ง„ ๋ณด์•ˆ ๊ตฌ๋ฉ์„ ๋” ์‰ฝ๊ฒŒ ์ด์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•œ๋‹ค. ์‹ค์ œ๋กœ, ๊ณต๊ฒฉ์ž๋Š” ์‚ฌ์šฉ ์ค‘์ธ ๋ช…๋ฐฑํ•œ ์†Œํ”„ํŠธ์›จ์–ด ๋ฒ„์ „์— ์ƒ๊ด€์—†์ด ๋ชจ๋“  ์ž ์žฌ์  ๊ตฌ๋ฉ์„ ์‹œ๋„ํ•˜๋Š” ๊ฒฝํ–ฅ์ด ์žˆ๋‹ค.

9.7. Browser Fingerprinting

๋ธŒ๋ผ์šฐ์ € ์ง€๋ฌธ ์ฑ„์ทจ๋Š” ๊ณ ์œ ํ•œ ํŠน์„ฑ ์ง‘ํ•ฉ์„ ํ†ตํ•ด ์‹œ๊ฐ„์— ๋”ฐ๋ผ ํŠน์ • ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ๋ฅผ ์‹๋ณ„ํ•˜๊ธฐ ์œ„ํ•œ ๊ธฐ๋ฒ• ์ง‘ํ•ฉ์ด๋‹ค. ์ด๋Ÿฌํ•œ ํŠน์„ฑ์€ TCP ๋™์ž‘, ๊ธฐ๋Šฅ ๊ธฐ๋Šฅ ๋ฐ ์Šคํฌ๋ฆฝํŒ… ํ™˜๊ฒฝ๊ณผ ๊ด€๋ จ๋œ ์ •๋ณด๋ฅผ ํฌํ•จํ•  ์ˆ˜ ์žˆ์ง€๋งŒ, ์—ฌ๊ธฐ์„œ๋Š” HTTP๋ฅผ ํ†ตํ•ด ์ „๋‹ฌ๋  ์ˆ˜ ์žˆ๋Š” ๊ณ ์œ ํ•œ ํŠน์„ฑ์˜ ์ง‘ํ•ฉ์ด๋‹ค. ์ง€๋ฌธ ๊ฐ์‹์€ ์‚ฌ์šฉ์ž๊ฐ€ ๋‹ค๋ฅธ ํ˜•ํƒœ์˜ ๋ฐ์ดํ„ฐ ์ˆ˜์ง‘(e.g., cookies)์— ๋Œ€ํ•ด ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋Š” ํ•ด๋‹น ์ œ์–ด ์žฅ์น˜ ์—†์ด ์‹œ๊ฐ„ ๊ฒฝ๊ณผ์— ๋”ฐ๋ฅธ ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ์˜ ํ–‰๋™์„ ์ถ”์ ํ•  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ฐœ์ธ ์ •๋ณด ๋ณดํ˜ธ ๋ฌธ์ œ๋กœ ๊ฐ„์ฃผ๋œ๋‹ค.

Last updated