ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãã€ã³ããªãžã§ã³ããããã¯ãŒã¯æ©åšïŒç¹ã«ãCiscoã¹ã€ãããã«ãŒã¿ãŒããã¡ã€ã¢ãŠã©ãŒã«ïŒã«ãã£ãŠåéããããããã¯ãŒã¯ãã¬ã¡ããªãçžé¢ããã³åæããã¯ãŒã¯ã¹ããŒã·ã§ã³ããã³ãµãŒããŒã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããå¿ èŠããªããããããèŠæš¡ã®åæ£ãããã¯ãŒã¯ã«å¯Ÿå¿ã§ããŸãã

æ°ããæ»ææ€åºã¢ãããŒã
ãããã¯ãŒã¯ã¬ãã«ã§ã®æ»æã®åŸæ¥ã®æ€åºã«ã¯ãæ¢ç¥ã®æ»æã«å¯Ÿå¿ããç¹å®ã®ã·ã°ããã£ã»ããã®ãããã¯ãŒã¯ãã©ãã£ãã¯ã®åéãšåæãå«ãŸããŸãã ããã«ã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ã®æ¢ç¥ã®äžè¯ãã¿ãŒã³ãæ€åºããããšãããããã¯ãŒã¯ã®äž»èŠãšãªã¢ã«ã»ã³ãµãŒïŒIDS / IPSïŒãå¿ èŠã§ãã ããããããã€ãã®çç±ã«ããããã®ã¢ãããŒãã¯ä»ã§ã¯é¢ä¿ãããŸããããŸãããŒããã€æ»æãæªæã®ããã³ãŒããšããããããå¶åŸ¡ãã£ãã«ããã¹ã¯ããé«åºŠãªæ¹æ³ã«å¯ŸããŠã眲åã¯ç¡åã§ãã 第äºã«ãçŸä»£ã®æšçåæ»æïŒAPTïŒã¯ãã»ã³ãµãŒãåŸæ¥ã€ã³ã¹ããŒã«ãããŠããåŸæ¥ã®ãããã¯ãŒã¯å¢çããã€ãã¹ãããããã¯ãŒã¯å ããåäœããããšãã§ããŸãã ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒéã®ã€ã³ãã©ãããéä¿¡ã¯ãéåžžIDS / IPSã®ç¯å²å€ã§ãã ãã¹ãŠã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãå ã«å°çšã®ã»ã³ãµãŒãèšçœ®ããåã¯ãŒã¯ã¹ããŒã·ã§ã³ãç£èŠããããšã¯æè¡çã«å°é£ã§ããã財æ¿çã«ãé«äŸ¡ãªäœæ¥ã§ãã
æ¥çã¯çŽ10幎éããããã¯ãŒã¯ãã©ãã£ãã¯ã®åäœãšç°åžžãåæããŠæ»æãæ€åºããæ°ããã¢ãããŒããéçºããŠããŸããã èŠããã«ãè¡ååæã·ã¹ãã ã¯ããããã¯ãŒã¯çžäºäœçšãåæããããšã«ããããããã¯ãŒã¯äžã®ããã€ã¹ã®æ¢ç¥ã®ãæªãè¡åããæ€åºããŸãã ãã®åäœã®åºæ¬çãªäŸã¯ããããã¯ãŒã¯ãã¹ãã£ã³ããããå€æ°ã®TCPã»ãã·ã§ã³ãéãããšã§ãã
ç°åžžåæã«ãããç¹å®ã®ããã€ã¹ãŸãã¯ããã€ã¹ã°ã«ãŒãã®ãéåžžã®ããã©ãã£ãã¯ãããã¡ã€ã«ããã®ãããã¯ãŒã¯ããã€ã¹ãã©ãã£ãã¯ã®å€§å¹ ãªéžè±ãæããã«ãªããŸãã ç°åžžã®åæã«ã¯ããéåžžã®ããã©ãã£ãã¯ãããã¡ã€ã«ãæ§ç¯ããã³æŽæ°ããããã®ãã¬ãŒãã³ã°ããã³çµ±èšåæã®å¯çšæ§ãå«ãŸããŸãã ç°åžžã®äŸãšããŠã¯ãç¹å®ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®éåžžã®1æ¥ãããã®ã¬ãŒããšæ¯èŒããå Žåã®ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ã€ã³ã¿ãŒããããã©ãã£ãã¯ã®çªç¶ã®å¢å ããã©ãã£ãã¯æ§é ã®å€æŽïŒæå·åSSLãã©ãã£ãã¯ã®å¢å ãªã©ïŒããããŸãã ã»ãšãã©ã®å Žåãæªãåäœãšç°åžžãæ€åºããã«ã¯ãäž»èŠãªãã©ãã£ãã¯ãã©ã¡ãŒã¿ïŒãã¬ã¡ããªïŒãåæããã ãã§ååã§ãããIPSã®ããã«åãã±ããã®å 容ãå³å¯ã«èª¿ã¹ãå¿ èŠã¯ãããŸããã

ãããã®ã¢ãããŒãã«ã¯ããããå©ç¹ãšå¶éããããŸãã

è¡åãšç°åžžã®åæã«ã¯å€ãã®å ±éç¹ããããå€ãã®å Žåããããã®ã¢ãããŒãã¯äžç·ã«äœ¿çšãããŸãã ãããã®ååã«åºã¥ããã»ãã¥ãªãã£ã·ã¹ãã ã¯ããããã¯ãŒã¯åäœç°åžžæ€åºïŒNBADïŒãšåŒã°ããŸãã NBADã·ã¹ãã ã¯ãè€éãªæ»æã®æ€åºã«é¢ããŠåŸæ¥ã®IDS / IPSã眮ãæãããã®ã§ã¯ãªããè£å®ãããã®ã§ãããäžç·ã«äœ¿çšã§ããããšã«æ³šæããŠãã ããã IDS / IPSã¯ããããã¯ãŒã¯ã®å¢çãšéèŠãªãã€ã³ãã®ä¿è·ã«éç¹ã眮ããŠããŸãã NBADã·ã¹ãã ã¯ããããã¯ãŒã¯å šäœã®æ·±ããã浞éãããããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ããã€ã¹ãšã»ãã¥ãªãã£ããã€ã¹ãããã¬ã¡ããªãŒãåéããŸãã
NetFlow-ã»ãã¥ãªãã£ã®ããã®è²Žéãªãã¬ã¡ããªãœãŒã¹
NetFlowãããã¯ãŒã¯ãããã³ã«ã¯ãã»ãã¥ãªãã£ã¿ã¹ã¯ã®åªããæ å ±æºã§ãã NetFlowã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ã®ç£èŠãš90幎代ã®ç£èŠã®ããã«ãã·ã¹ã³ã«ãã£ãŠåœåææ¡ãããŸããã NetFlowã¯ããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãééãããããã¯ãŒã¯ãããŒã«é¢ããçµ±èšãåéããŸããã ã¹ããªãŒã ã¯ãäžæ¹åã«ééããå ±éã®ãã©ã¡ãŒã¿ãŒãæã€ãã±ããã®ã»ããã§ãã
- éä¿¡å /å®å ã¢ãã¬ã¹
- UDPããã³TCPã®éä¿¡å /å®å ããŒãã
- ICMPã®ã¡ãã»ãŒãžã¿ã€ããšã³ãŒãã
- IPãããã³ã«çªå·
- ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹
- IPã¿ã€ããªããµãŒãã¹ã

éå»20幎ã«ããã£ãŠãNetFlowã¯IETFæšæºïŒIPFIXãããã³ã«ïŒãšããŠæšæºåãããå€ãã®ããŒãžã§ã³ãšæ¡åŒµæ©èœãåãåããŸããã NetFlowã¯ããã©ãã£ãã¯ã®æ§é ããã±ããã®ãµã€ãºãšç¹æ§ããã©ã°ã¡ã³ããŒã·ã§ã³ãªã©ã«é¢ãã詳现ãªçµ±èšæ å ±ãåéããããšãåŠã³ãŸããã ãããã¯ãŒã¯ããã€ã¹ã§DPIïŒãã£ãŒããã±ããåæïŒãæå¹ã«ãªã£ãŠããå Žåãã¢ããªã±ãŒã·ã§ã³æ å ±ãNetFlowã«è¿œå ã§ããŸãã ãããã£ãŠãNetFlowã䜿çšããŠã1000ãè¶ ããã¢ããªã±ãŒã·ã§ã³ãèå¥ããããšãã°ã80çªç®ã®ããŒãã§éåžžã®Webãã©ãã£ãã¯ãSkypeãŸãã¯P2Pãã¡ã€ã«å ±æãµãŒãã¹ããåºå¥ã§ããŸãã NetFlowçµ±èšæ å ±ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã®ããªã·ãŒãHTTP URLã³ã³ãã³ããããã³ãã®ä»ã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æ å ±ã䜿çšãããããŒã®ã³ã³ãã©ã€ã¢ã³ã¹ã«é¢ããæ å ±ã§è£å®ã§ããŸãã
NetFlowã®ãã1ã€ã®éãã¯ããã©ãã£ãã¯ã«ãã¬ããžã®å¹ ã§ãã NetFlowã¯ããã¹ãŠã®Ciscoã«ãŒã¿ãŒïŒISR G2ããã³ASRãå«ãïŒãCisco ASAãã¡ã€ã¢ãŠã©ãŒã«ãCatalyst 2960-Xã3560ã3750-Xã3850ã4500ã6500ãããã³Nexus 7000ã¹ã€ããã§ãµããŒããããŠããŸãã Cisco UCSããã¬ã¡ããªãµãŒããŒãã©ãã£ãã¯ãšä»®æ³ãã·ã³ãã©ãã£ãã¯ãåéã§ããŸãã NetFlowãšIPFIXã¯ãä»ã®å€ãã®ãã³ããŒããªãŒãã³ãœãŒã¹è£œåã§ããµããŒããããŠããŸãã
ãããã£ãŠãNetFlowãããã³ã«ã¯ãã¬ã¡ããªãåéããã¢ã¯ã»ã¹ã¬ãã«ãããŒã¿ã»ã³ã¿ãŒãããªã¢ãŒããã©ã³ãã«è³ããŸã§ããããã¯ãŒã¯ã®ãã¹ãŠã®éšåã«å¯Ÿããæ»æã®å¯èŠæ§ã確ä¿ã§ããŸãã å®éãNetFlowã§ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£æ©èœã®ã¿ã䜿çšããŠããœãããŠã§ã¢ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããããšãªããåã ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ããã³ãµãŒããŒã®ãåäœãã調ã¹ãããšãã§ããŸãã
NetFlowã¯ãåŠçãããåãã±ãããèæ ®ã«å ¥ããŠããã¹ãŠã®ãã©ãã£ãã¯ã®è©³çŽ°ãªåæãæäŸã§ããŸãã ããã«ãããNetFlowã¯sFlowãªã©ã®é¡äŒŒã®ãããã³ã«ãšåºå¥ãããŸããsFlowã¯ãnçªç®ããšã®ãã±ãããåæããããšã§éçŽçµ±èšïŒãµã³ããªã³ã°ããããããŒïŒã®ã¿ãåéã§ããŸãã éçŽãããå®å šãªNetFlowã¯ãæ¬ã®åããŒãžãèªãã ãã泚ææ·±ãããŒãžãèªãã ãããããšãšæ¯èŒã§ããŸãã éçŽãããçµ±èšæ å ±ã¯ãã©ãã£ãã¯ã®æŠèŠã瀺ããŸãããã»ãã¥ãªãã£ã¿ã¹ã¯ã«ã¯ããŸãé©ããŠããŸããã Full NetFlowã¯ãã»ãã¥ãªãã£ã®èŠ³ç¹ãããããã¯ãŒã¯ã¢ã¯ãã£ããã£ã®å æ¬çãªæŠèŠãæäŸããŸãã
ã·ã¹ã³ã®ãµã€ããŒè åšé²æ¢ãœãªã¥ãŒã·ã§ã³
ã·ã¹ã³ã®ãµã€ããŒè åšé²åŸ¡ïŒCTDïŒé²åŸ¡ãœãªã¥ãŒã·ã§ã³ã®ããŒã¹ãšãªã£ãŠããã®ã¯ãNetFlowãããã³ã«ã§ãã ãœãªã¥ãŒã·ã§ã³ã¯ããã€ãã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸãã
- NetFlowãããã³ã«ããµããŒããããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ïŒã¹ã€ãããã«ãŒã¿ãŒããã¡ã€ã¢ãŠã©ãŒã«ïŒ
- Lancope StealthWatchãããã¯ãŒã¯ãã©ãã£ãã¯åæã·ã¹ãã ã
- ã³ã³ããã¹ãæ å ±ãè¿œå ãããªãã·ã§ã³ã®Cisco Identity Services EngineïŒISEïŒã
StealthWatchã¯ãã·ã¹ã³ãšååããŠLancopeã«ãã£ãŠéçºãããŠãããåžå Žã§æãå€ãNBADã·ã¹ãã ã®1ã€ã§ãã StealthWatchãšISEã¯ãããŒããŠã§ã¢ãšä»®æ³ããã€ã¹ã®äž¡æ¹ã®åœ¢åŒã§å©çšã§ããŸãã
Cyberââ Threat Defenseã®åæ段éã§ã¯ãçµç¹ã®ãããã¯ãŒã¯ãæ§æãããŸãŒã³ãèšè¿°ããå¿ èŠããããŸãã ãã®ãããªãŸãŒã³ã¯æ¬¡ã®ãšããã§ãã
- ããŒã«ã«ãšãªã¢ãããã¯ãŒã¯
- æ
- ç®çãŸãã¯å Žæããšã«çµã¿åããããã¯ãŒã¯ã¹ããŒã·ã§ã³ã
- å©çšå¯èœãªãµãŒãã¹ãã¢ããªã±ãŒã·ã§ã³ãªã©ã§ã°ã«ãŒãåããããµãŒããŒ
ãŸãŒã³ã¯äºãã«å ¥ãåã«ããããšãã§ããŸã-ããšãã°ãããŒã¿ã»ã³ã¿ãŒãŸãŒã³ã«ã¯ãã¢ããªã±ãŒã·ã§ã³ïŒWebãã¡ãŒã«ãµãŒããŒãDNSãµãŒããŒãERPïŒã®ãŸãŒã³ãå«ãŸããŸãã 次ã«ãWebãµãŒããŒã®ãŸãŒã³ã¯ãå€éšããã³å éšWebãµãŒããŒã®ãŸãŒã³ã«åå²ãããŸãã
ãããã¯ãŒã¯ãããæ£ç¢ºã«ãŸãŒã³ã«åå²ããããšããœãªã¥ãŒã·ã§ã³ã¯ãã¬ã¡ããªãŒãšããã€ã¹ã®åäœãããæ£ç¢ºã«åæã§ããããã«ãªããŸãã CTDã¯ãç¹å®ã®é åãžã®ããã€ã¹ã®å²ãåœãŠãšããã€ã¹ã®æææš©ãææ¡ã§ããŸãã ããšãã°ããµãŒããŒãWebãã©ãã£ãã¯ã®ãœãŒã¹ã§ããå Žåããã®ãµãŒããŒãWebãµãŒããŒã®ã°ã«ãŒãã«å²ãåœãŠãããšãææ¡ãããŸãã

次ã®ã¹ãããã§ã¯ãCTDã¯ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ããNetFlowãã¬ã¡ããªãåéãããŸãŒã³ããã³åã ã®ãããã¯ãŒã¯ããã€ã¹ã®ãããã¯ãŒã¯åäœãããã¡ã€ã«ãæ§ç¯ããŸãã æåã®èªå·±ãã¬ãŒãã³ã°ãšèª¿æŽã¯æåã®7æ¥éã§è¡ããã次ã®28æ¥éã§ãéåžžã®åäœã®ãããã¡ã€ã«ïŒããŒã¹ã©ã€ã³ïŒãäœæãããŸãã ãã©ãã£ãã¯æ§é ãåŸã ã«å€åãããšããããã¡ã€ã«ã¯èªåçã«é©å¿ããŸãã
ãã©ãã£ãã¯ãéåžžã®åäœãŸãã¯ãæªããåäœããå€§å¹ ã«éžè±ãããšãæœåšçãªã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®éç¥ãçºçããŸãã ã€ã³ã·ãã³ããç»é²ããå Žåãäž»èŠãªã€ã³ãžã±ãŒã¿ã¯æ°å€ã§ãïŒ
- æžå¿µææ°ïŒCIïŒ-ç¹å®ã®ãã¹ããç¡å¹ãŸãã¯ç°åžžãªã¢ã¯ãã£ããã£ã®åå ã§ããããšã瀺ãã€ã³ãžã±ãŒã¿ãŒã
- ã¿ãŒã²ããã€ã³ããã¯ã¹-ã¿ãŒã²ããã€ã³ããã¯ã¹ïŒTIïŒ-ãã¹ããæ»æãŸãã¯ç°åžžãªã¢ã¯ãã£ããã£ã®ã¿ãŒã²ããã«ãªãå¯èœæ§ãããããšã瀺ãã€ã³ãžã±ãŒã¿ã
- ãã¡ã€ã«å ±æã€ã³ããã¯ã¹ïŒFSIïŒ-æœåšçãªP2Pã¢ã¯ãã£ããã£ã远跡ããŸãã
ãããã®ã€ã³ããã¯ã¹ã¯ãå€æ°ã®ãã©ãã£ãã¯ãã©ã¡ãŒã¿ãèæ ®ããŠãCTDã«ãã£ãŠç£èŠããããã¹ãŠã®ãããã¯ãŒã¯ãã¹ãã«å¯ŸããŠèšç®ãããŸãã ã€ã³ããã¯ã¹ã䜿çšãããšããã®ç°åžžã®æ·±å»åºŠãšä¿¡é Œæ§ã«å¯Ÿãããã¹ãã®ç°åžžãªåäœãšã·ã¹ãã ã®ä¿¡é ŒåºŠã远跡ã§ããŸãã ã€ã³ããã¯ã¹ã䜿çšãããšãã€ã³ã·ãã³ã調æ»ã«åªå é äœãä»ããããšãã§ããŸãã ã€ã³ããã¯ã¹å€ãé«ãã»ã©ãã€ã³ã·ãã³ãã¯ããå±éºã«ãªããŸãã
人çã®äŸãæããŸãã ã©ã³ãã ãªéè¡äººããã¢ãã«ã鳎ãããŠãããäœæãšééãããšå ±åããå Žåãå¿é ããç¹å¥ãªçç±ã¯ãããŸããã ããããéè¡äººãåãããã«10çªç®ã®ãã¢ãããã¯ããå Žåãããã¯æžå¿µã®åå ã§ãã ãããã£ãŠãæžå¿µææ°ã¯10ã§ãã
ãµã€ããŒè åšé²åŸ¡ã«ãåãããšãåœãŠã¯ãŸããŸã-ã€ã³ããã¯ã¹ããããå€ãè¶ ããå Žåã察å¿ããã¢ã©ãŒã ãçæãããŸãã ã·ã¹ãã ã«ã¯ãã¢ã©ãŒã ãçæããããã®å€æ°ã®æšæºããªã·ãŒããããç¹å®ã®çµç¹ã®èŠ³ç¹ãã蚱容ã§ããªãã¢ã¯ãã£ããã£ãèšè¿°ããã«ã¹ã¿ã ããªã·ãŒãäœæããããšãã§ããŸãã
ã³ã³ããã¹ããè¿œå
ãœãªã¥ãŒã·ã§ã³ã®äœæ¥ã§ã¯ãã³ã³ããã¹ããéèŠã§ãã NetFlowãããã³ã«ã¯éåžžãIPã¢ãã¬ã¹ãšããŒãçªå·ã§åäœããŸãã ã³ã³ããã¹ããç¥ãããšã«ãããCyberââ Threat Defenseã¯ä»¥äžãç解ã§ããŸãã
- ãã®ãŠãŒã¶ãŒãŸãã¯ãã®IPã¢ãã¬ã¹ã®èåŸã«é ããŠãããŠãŒã¶ãŒãšããã€ã¹
- ãã®ããŒãã䜿çšããã¢ããªã±ãŒã·ã§ã³ã
- IPã¢ãã¬ã¹ãŸãã¯ãã¡ã€ã³åã®è©å€ãšãã€ã³ã¿ãŒããããã¹ããéæ³è¡çºïŒããšãã°ãããããããã®äœæ¥ïŒã§ä»¥åã«æ°ã¥ããããã©ããã
ãããã£ãŠãIPã¢ãã¬ã¹ãšããŒãã«é¢ãããã§ãŒã¹ã¬ã¹æ å ±ããè²ä»ããããŠãã³ã³ããã¹ããæäŸããããšãå¯èœã«ãªããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«ããæ£ç¢ºãã€å¹ççã«å¯Ÿå¿ã§ããããã«ãªããŸãã
ãŠãŒã¶ãŒããã³ããã€ã¹æ å ±ã¯ããããã¯ãŒã¯äžã®ããã€ã¹ã¿ã€ããšãŠãŒã¶ãŒåãèå¥ããã€ã³ããªãžã§ã³ãã¡ã«ããºã ãåããCisco Identity Services Engineãšã®CTDçµ±åãéããŠåéãããŸãã
ã€ã³ã¿ãŒããããã¹ãã®ã¬ãã¥ããŒã·ã§ã³ããŒã¿ã¯ãã¯ã©ãŠãããŒã¹ã®ã¬ãã¥ããŒã·ã§ã³ããŒã¿ããŒã¹ãããªã¢ã«ã¿ã€ã ã§ååŸãããŸãã ç¹ã«ãã®ããŒã¿ããŒã¹ã«ã¯ãã¢ã¯ãã£ããªããããããã³ã³ãããŒã«ã»ã³ã¿ãŒã«é¢ããåçãªæ å ±ãå«ãŸããŠããŸãã
ãããå€ã«éãããšãCTDã¯æå®ã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸãã ããšãã°ãç¹å®ã®ãã¹ãã®çãããã¢ã¯ãã£ããã£ããããã¯ããããã¹ã€ããããŒãããããã¯ãããããã³ãã³ãããã¡ã€ã¢ãŠã©ãŒã«ã«äžããŸãã ã³ãã³ãã¯èªåã¢ãŒããŸãã¯åèªåã¢ãŒãã§æå®ã§ããŸãïŒç®¡çè ã«ãã確èªåŸïŒã ã·ã¹ãã ã«ã¯ãããŸããŸãªãã³ããŒã®ã«ãŒã¿ãŒãšãã¡ã€ã¢ãŠã©ãŒã«çšã®ã¹ã¯ãªãããäºåã«ã€ã³ã¹ããŒã«ãããŠãããã«ã¹ã¿ã ã¹ã¯ãªãããäœæããããšãã§ããŸãã
ç§ãã¡ã¯äœããä¿è·ããŠããŸã
Cyberââ Threat Defenseã¯ãããŸããŸãªã»ãã¥ãªãã£ã·ããªãªã§äœ¿çšããŠãããå€æ§ãªæ»æããä¿è·ã§ããŸãã
ç¹ã«ãCTDã¯ãæ å ±ã»ãã¥ãªãã£ã«åœ±é¿ãäžãã次ã®çš®é¡ã®æ»æãšç°åžžãæ€åºãããããã¯ããã®ã«åœ¹ç«ã¡ãŸãã
- æªæã®ããã³ãŒãã®é åžãšãŠã€ã«ã¹ã®çºçã
- ãããããã掻å
- DDoSæ»æ
- ãããã¯ãŒã¯ã€ã³ããªãžã§ã³ã¹
- ãªãœãŒã¹ãžã®äžæ£ã¢ã¯ã»ã¹ã®è©Šã¿ã
- äžæ£ããŒã¿ã®èç©ã
- ããŒã¿æŒæŽ©ã®è©Šã¿
- çŠæ¢ãããŠããã¢ããªã±ãŒã·ã§ã³ïŒP2PãIPãã¬ãã©ããŒãªã©ïŒã®äœ¿çšã
- ãµãŒãã¹ïŒWebãµã€ããªã©ïŒã®äžæ£ãªã€ã³ã¹ããŒã«ã
- ã¢ã¯ã»ã¹ããªã·ãŒã®éåãšITUæ§æã®ã®ã£ããã®èå¥ã

CTDã¯ãæ å ±ã»ãã¥ãªãã£ãç£æ»ããããã®åªããããŒã«ã§ãããããã¡ã€ã¢ãŠã©ãŒã«ãIPSãããã³ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãã»ããã¢ãããããšãã«ããããã¯ãŒã¯ãèšç»ã©ããã«åäœãããã©ããã確èªã§ããŸãã
ãããŠãã¡ãããCyberââ Threat Defenseã¯ããµã€ããŒã€ã³ã·ãã³ãã®èª¿æ»ãæ¯æŽããæªæã®ããã³ãŒããšæ»æãã¯ãã«ã®ååžã調æ»ã§ããŸãã ãã¹ãŠã®ãããã¯ãŒã¯ãããŒãšã»ãã·ã§ã³ã«é¢ããæ å ±ãä¿åããããããéå»ã®ããæç¹ã§èª°ãšã©ã®ããã«çããããã¹ãã察話ããããç¥ãããšãå¯èœã«ãªããŸãã
ã»ã³ã»ãŒã·ã§ãã«ãªOpenSSL HeartBleedè匱æ§ãäŸãšããŠäœ¿çšããŠãCyberââ Threat Defenseã®åäœã¡ã«ããºã ãèŠãŠã¿ãŸãããã
HearBleadã®æ€åºã®é£ããã¯ãæ»æè ãè匱æ§ãæ£ããæªçšããå ŽåãWebãµãŒããŒã®ãã°ã«æªçšã®çè·¡ãæ®ã£ãŠããªãããšã§ããã SSLæå·åã§ã¯ãèŠæ±ã³ã³ãã³ããšçœ²åã«ãã£ãŠéåžžã®ãã©ã³ã¶ã¯ã·ã§ã³ãšæªæã®ãããã©ã³ã¶ã¯ã·ã§ã³ãåºå¥ããããšãé£ãããªããŸãã ãããã£ãŠããã®è匱æ§ãæªçšããããšããè©Šã¿ãç¹å®ããã«ã¯ãSSLèŠæ±ãšWebãµãŒããŒå¿çã®ãµã€ãºã®ç¹æ§ã«äŸåããå¿ èŠããããŸãã
ãã¹ãã·ã¹ãã ã§HeartBleedã®è匱æ§ãæªçšããããšããã·ã¹ãã ã¬ããŒããèŠããšããããã®ãã©ã³ã¶ã¯ã·ã§ã³ã®2ã€ã®æ©èœã«æ°ã¥ãã§ãããã

ãŸããã¯ã©ã€ã¢ã³ãã®èŠæ±ãšå¿çã®ãµã€ãºã®æ¯çã¯çŽ4.8ïŒ ã§ãã 第äºã«ãHeartBleedãæšçãšããæ»æã¯ãé·å¯¿åœã®ã»ãã·ã§ã³ãäœæããå¯èœæ§ããããŸãã åHeartbleedãã©ã³ã¶ã¯ã·ã§ã³ã¯ãæ»æãããWebãµãŒããŒã®å°ããªã¡ã¢ãªã®å 容ã§æ»æè ãè¿ããŸãã é¢å¿ã®ããæ å ±ïŒãã©ã€ããŒãSSLããŒãŸãã¯ãã¹ã¯ãŒãïŒãååŸããããã«ãæ»æè ã¯ãã©ã³ã¶ã¯ã·ã§ã³ãäœåºŠãç¹°ãè¿ãå¿ èŠãããããŠãŒã¶ãŒã»ãã·ã§ã³ã¯æåŸã®æ°æéã«ãªããŸãã CTDã«ã¯ããã®ãããªé·æéã®ã»ãã·ã§ã³ãæ€åºããããã®ã¡ã«ããºã ãçµã¿èŸŒãŸããŠããŸãïŒSuspect Long FlowïŒã
ãããã£ãŠãCTDã䜿çšããŠãçãããWebãã©ã³ã¶ã¯ã·ã§ã³ãèå¥ã§ããŸãã NetFlowãããã¯ãŒã¯ãã¬ã¡ããªã¯éåžžæ°ãæéä¿åããããããè匱æ§ãå ¬åŒã«å ¬éãããåã«éå»ã«çºçããæ»æãèŠã€ããããšãå¯èœã§ãã æãéèŠãªã®ã¯ããã®ãããªæ»æãæ€åºããããã«çœ²åãæŽæ°ããå¿ èŠããªãããœãªã¥ãŒã·ã§ã³ã¯è匱æ§ãŸãã¯ãšã¯ã¹ããã€ãã®åºçŸããããŒããæ¥ããæ»æãèŠã€ããããšãã§ããããšã§ãã

NetFlowã¯ã€ã³ã·ãã³ãæ å ±ã®åªããæ å ±æºã§ãããããã ãã§ã¯ãããŸããã Cisco Cyberââ Threat Defenseã®éçºã¯ãè¿œå æ å ±ãœãŒã¹ïŒãããã¯ãŒã¯IPS SourceFireãCisco Advanced Malware Protectionãé»åã¡ãŒã«ããã³Webã³ã³ãã³ããã£ã«ã¿ãªã³ã°ã·ã¹ãã ãã¯ã©ãŠãã€ã³ããªãžã§ã³ã¹ïŒã®ãœãªã¥ãŒã·ã§ã³ãžã®çµ±åã«åãã£ãŠããŸãã åºç¯ãªåŠçãšé«åºŠãªåŠçããã³çžé¢æè¡ã«ãããå€åããè åšã®ç¶æ³ã«ããæ£ç¢ºãã€è¿ éã«å¯Ÿå¿ã§ããããã«ãªããŸãã èšäºã®ãµã€ãºãéãããŠãããããCyberââ Threat Defenseã®ã»ãã¥ãªãã£æ©èœã®ã¿ã«æ³šç®ããŸããã å®éãCTDãœãªã¥ãŒã·ã§ã³ã¯ãIT管çè ããŠãŒã¶ãŒã®ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ãç£èŠãããããã¯ãŒã¯ãªãœãŒã¹ã®äœ¿çšãç£èŠããã¢ããªã±ãŒã·ã§ã³ãšQoSã®åäœãåæããã®ã«ãéåžžã«åœ¹ç«ã¡ãŸãã 詳现ã«ã€ããŠã¯ã次ã®èšäºãã芧ãã ããã
ãœãªã¥ãŒã·ã§ã³ã«é¢ãã詳现æ å ±ã¯ãã·ã¹ã³ã®Webãµã€ãã§å ¥æã§ããŸãã