次ã®èšäºã®ãªãªãŒã¹ã§å°ãé ããŸããã ããã«ããããããã圌女ã¯æºåãã§ããŠãããç§ãã¡ã®æ°ããã¢ããªã¹ããšèè -Alexei Pavlov- avpavlovã«ããèšäºãæ瀺ããããšæããŸãã
ãã®èšäºã§ã¯ãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒã®ãã©ã€ããã®æãéèŠãªåŽé¢ãã€ãŸãæ å ±ã»ãã¥ãªãã£ã«å¯Ÿããæ°ããªè åšã®ç¹å®ãšéçšåæã«ã€ããŠæ€èšããŸãã ã«ãŒã«ã®èšå®æ¹æ³ãããã³ã¢ãŠããœãŒã·ã³ã°JSOCç£èŠããã³å¯Ÿå¿ã»ã³ã¿ãŒã§ã®ã€ã³ã·ãã³ãã®èå¥ãšç»é²ã«ã€ããŠèª¬æããŸãã
以åã®èšäºã§JSOCã®ä»çµã¿ã«ã€ããŠèª¬æããŸããã
JSOCïŒè¥ããã·ã¢MSSPã®çµéš
JSOCïŒã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒã®å¯çšæ§ã枬å®ããæ¹æ³
圌ãã¯ããšããããJSOCã®äžæ žã¯HP ArcSight ESM SIEMã·ã¹ãã ã§ãããšè¿°ã¹ãŸããã ãã®èšäºã§ã¯ã誀æ€ç¥ã€ãã³ãã®æ°ãæ°ããã·ã¹ãã ãšSISã®éçšäžã®æ¥ç¶ãæžããããã«å®è£ ãããèšå®ãšæ¹åã®èª¬æã«éäžããã客æ§ã®æœåšçãªã€ã³ã·ãã³ããåæããããã»ã¹ã®é床ãšéææ§ãé«ããŸãã
ãã¹ãŠã®SIEMã«ã¯ããœãŒã¹ããã®ã€ãã³ããæ¯èŒããããšã«ãããã¯ã©ã€ã¢ã³ãã«è åšãéç¥ã§ããäºåå®çŸ©ãããçžé¢ã«ãŒã«ã®ã»ããããããã«äœ¿çšå¯èœãã«ãªã£ãŠããŸãã ã§ã¯ããªãããã®ã·ã¹ãã ã®é«äŸ¡ãªã»ããã¢ãããšãã€ã³ãã°ã¬ãŒã¿ãŒããã³åœç€Ÿã®ã¢ããªã¹ãã«ãããµããŒããå¿ èŠãªã®ã§ããããïŒ
ãã®è³ªåã«çããã«ã¯ããœãŒã¹ããJSOCã«åé¡ãããã€ãã³ãã®ã©ã€ããµã€ã¯ã«ãã©ã®ããã«æ§æãããŠããããã«ãŒã«ããªã¬ãŒããã€ã³ã·ãã³ãã®äœæãŸã§ã®æ¹æ³ãäŒããå¿ èŠããããŸãã
ã€ãã³ãã®äž»ãªåŠçã¯ãSIEMã·ã¹ãã ã®ã³ãã¯ã¿ã§çºçããŸãã åŠçã«ã¯ããã£ã«ã¿ãªã³ã°ãåé¡ãåªå é äœä»ããéçŽãããã³æ£èŠåãå«ãŸããŸãã 次ã«ãCEF圢åŒïŒCommon Event FormatïŒã®ã€ãã³ããHP ArcSightã·ã¹ãã ã®ã³ã¢ã«éä¿¡ãããããã§çžé¢ãšèŠèŠåãè¡ãããŸãã ãããã¯ãSIEMã®æšæºçãªã€ãã³ãã¡ã«ããºã ã§ãã JSOCã®äžç°ãšããŠãã€ã³ã·ãã³ããç£èŠãããšã³ãã·ã¹ãã ã«é¢ããæ å ±ãååŸããæ©èœãæ¡åŒµããããã«ãããããæçµæ±ºå®ããŸããã
ãã£ã«ã¿ãªã³ã°ãšåé¡
SIEMã®äž»ãªæ©èœã®1ã€ã¯ãã³ãã¯ã¿ã§çºçããã€ãã³ãã®ãã£ã«ã¿ãªã³ã°ãšåé¡ã§ãã å¹³åçãªSIEMã·ã¹ãã ã§ã¯ã6000ã8000 EPSïŒ1ç§ãããã®ã€ãã³ãïŒã¯éåžžã®ã€ãã³ããããŒãšèŠãªãããŸããã50ã80ã®ãœãŒã¹ããã®ã€ãã³ãã¿ã€ãã®æ°ã¯æ°åã«ãªããŸãã ãã®ãããªå€§éã®æ å ±ãåŠçããããããã«ãã€ãã³ãã«ããŽãªãèæ¡ãããŸããã
ããŸããŸãªãã³ããŒã®æ©åšãã·ã¹ãã ã§ã¯ãåãã€ãã³ããç°ãªãæ¹æ³ã§åŒã°ããããšãå€ãããšã«æ³šæããŠãã ããã ããšãã°ãTCPæ¥ç¶å ã®ã»ãã·ã§ã³ã®éå§ã¯ãJuniperã§ã¯ãBuilt inbound TCP connectionããJuniperã§ã¯ãã»ãã·ã§ã³äœæããCheckpointã«ã¯æ¥ç¶ã®æåã«å¿ããŠãacceptããŸãã¯ãblockããšãã2ã€ã®ã€ãã³ãããããŸãã ãæ°ãããã³ããŒã®ãçžé¢ã«ãŒã«ã®å€æŽãé¿ããããã«ãããã€ã¹ãç»å Žãããšãã«ãå®è¡ãããã¢ã¯ã·ã§ã³ã決å®ããã€ãã³ãã®ã«ããŽãªãå°å ¥ãããŸããã
äŸïŒJuniper Firewallã€ãã³ã-ãã»ãã·ã§ã³éå§ã
ã«ããŽãªã®æå³ïŒ/æ å ±-ã¡ãã»ãŒãžã¿ã€ã-æ å ±
ã«ããŽãªããã€ã¹ã¿ã€ãïŒãã¡ã€ã¢ãŠã©ãŒã«-ãã¡ã€ã¢ãŠã©ãŒã«ããã®ã€ãã³ã
ã«ããŽãªã®åäœïŒ/ã¢ã¯ã»ã¹/éå§-ã»ãã·ã§ã³ãéã
ã«ããŽãªãŒçµæïŒ/æå-æå
ãããã£ãŠãçžé¢ã«ãŒã«ã§ãã¹ãŠã®ããã€ã¹ããã®æåããã¢ã¯ã»ã¹ã€ãã³ãã远跡ããå¿ èŠãããå Žåã¯ãåã«ã«ããŽãªåäœïŒ/ã¢ã¯ã»ã¹/éå§ãã«ããŽãªããã€ã¹ã¿ã€ãïŒãã¡ã€ã¢ãŠã©ãŒã«ãã«ããŽãªçµæïŒ/æåãæå®ããŸãã
JSOCå ã®æšæºçãªåé¡ã«å ããŠãã€ã³ã·ãã³ããçæããã«ãŒã«ãžã®å¯èœãªå€æŽãæå°éã«ããããã«ãè¿œå ã®åé¡ãå®è£ ããŸããã ãããã®ã«ãŒã«ã¯ããŸããŸãªã客æ§ã«æå¹ã§ããããã®ãã¡ã®1ã€ã®ãã©ã¡ãŒã¿ãŒãå€æŽãããšããã¹ãŠã®ãŠãŒã¶ãŒã«ãšã£ãŠãœãªã¥ãŒã·ã§ã³ãäžæçããã³/ãŸãã¯å®å šã«æ©èœããªããªãå¯èœæ§ããããŸãã
å³ 1.äŸãšããŠINC_Password Change Neededã«ãŒã«ã䜿çšããã€ãã³ãã®åé¡
äŸãšããŠãã«ãŒã«ãINC_Password Change NeededããåŒçšããŸãããã ãã®äž»ãªã¿ã¹ã¯ã¯ãæå¹æéãåãããã¹ã¯ãŒããæã€ã¢ã«ãŠã³ãã§ã·ã¹ãã ã§èªèšŒãè¡ããããã©ãããéç¥ããããšã§ãã æéã¯äŒæ¥ã«ãŒã«ã«åŸã£ãŠèšç®ããã顧客ã«ãã£ãŠç°ãªããŸãã ãã®ã«ãŒã«ã¯ãããŸããŸãªãœãŒã¹ããã®ãã¹ãŠã®èªèšŒã€ãã³ããå«ãJSOCåé¡ãããã€ã¹ã€ãã³ãã«ããŽãªã¯/ JSOC / Authentication /ãã䜿çšããæšæºåé¡ãHP Arcsight-Category Outcome = / Successã-æåããæ¥ç¶ã€ãã³ãã䜿çšããŸãã
åºæ¬ã«ãŒã«ãšãããã¡ã€ã«ã«ãŒã«
ã·ã¹ãã ã®ã³ã¢ã«åé¡ãããç¹å®ã®ã¿ã€ãã®ã€ãã³ããåŠçããããã«ãç¹å¥ãªãããã¡ã€ãªã³ã°ãšåºæ¬çãªã«ãŒã«ãJSOCã«å°å ¥ãããŸããã ããŸããŸãªã¢ã¯ãã£ããã£ã®ãããã¡ã€ã«ã«ãŒã«ã¯ãæãéèŠãªåœ¹å²ã®1ã€ã§ãã ãããã¯ãã¢ã¯ãã£ããªã¹ãã«èšé²ããããã©ã€ããªããŒã¿ã圢æãããã®åŸãå¹³åãæ倧ãããã³å€åã®ã€ã³ãžã±ãŒã¿ãŒã®èšç®ã«äœ¿çšãããŸãã ãã®ãããªã«ãŒã«ã«ã¯ãèªèšŒããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãæ¯æ¥ã®ãã©ãã£ãã¯ãäž»èŠã·ã¹ãã ãžã®ã¢ã¯ã»ã¹çšã®IPã¢ãã¬ã¹ã®ãã¯ã€ããªã¹ããªã©ã®ããŒã¿ãå«ãŸããŸããéåžžã®ã¢ã¯ãã£ããã£ãããã¡ã€ã«ãå®äºããããéåžžã®ã¢ã¯ãã£ããã£ããã®éžè±ãèšé²ããã«ãŒã«ãäœæã§ããŸãã
åºæ¬çãªã«ãŒã«ãå¥ã®æ®µèœãšããŠåãäžããããšæããŸãã äžè¶³ããŠããæ å ±ãã€ãã³ãã«è¿œå ãã-ãã¡ã€ã¢ãŠã©ãŒã«ããã®ã€ãã³ãã®ãŠãŒã¶ãŒåã人äºã·ã¹ãã ããã®ã¢ã«ãŠã³ãææè æ å ±ãCMDBããã®ãã¹ãã®è¿œå 説æ-JSOCã«å®è£ ãããã€ã³ã·ãã³ããåæãã1ã€ã®ã€ãã³ãã§å¿ èŠãªãã¹ãŠã®æ å ±ãååŸããããã»ã¹ãé«éåããŸãã
åºæ¬çãªã«ãŒã«ã®äœ¿çšã®é¡èãªäŸã¯ããCISCO_VPN_User Session Startedãã§ãã ãã®ã«ãŒã«ã«ãããVPNãä»ããŠæ¥ç¶ããŠããåŸæ¥å¡ã®IPã¢ãã¬ã¹ããŠãŒã¶ãŒåã«é¢é£ä»ããããšãã§ããŸãïŒãã®æ å ±ã¯ãCisco ASAããã®ããŸããŸãªã€ãã³ãã«ãããŸãïŒã
å³ 2.åºæ¬çãªã«ãŒã«èšå®ã®äŸ
çžé¢ã«ãŒã«ãäœæããã³æ§æãã
ç°åžžãªã¢ã¯ãã£ããã£ãèšé²ããã«ã¯ãããã€ãã®ãªãã·ã§ã³ããããŸãã
- ãœãŒã¹ããã®ç¹å®ã®ã€ãã³ãçš
- ç¹å®ã®æéã«ããããœãŒã¹ããã®ããã€ãã®é£ç¶ããã€ãã³ãã
- ç¹å®ã®æéã«1ã€ã®ã¿ã€ãã®ã€ãã³ãã®ãããå€ã«éãããšã
- åç §ïŒãŸãã¯å¹³åïŒå€ããã®ã€ã³ãžã±ãŒã¿ãŒã®åå·®ã
åãªãã·ã§ã³ãããã«è©³ããåæããŸãããã
çžé¢ã«ãŒã«ã䜿çšããæãç°¡åãªæ¹æ³ã¯ããœãŒã¹ããã®åäžã€ãã³ãã®çºçæã«ããªã¬ãŒããããšã§ãã ããã¯ãæ§ææžã¿ã®SPIãšçµã¿åãããŠSIEMã·ã¹ãã ã䜿çšããå Žåã«å¹æçã§ãã
ç£èŠå¯Ÿè±¡ãµãŒããŒã§éèŠãªãµãŒãã¹ãåæ¢ãããšãINC_Critical Service Stoppedã«ãŒã«ãããªã¬ãŒãããŸãã ãã®ã€ãã³ãã¯ãæªæã®ãããŠãŒã¶ãŒãŸãã¯ãã«ãŠã§ã¢ã®ã¢ã¯ãã£ããã£ã瀺ããŠããå¯èœæ§ããããŸãã ããããäŒæ¥ã«å¯Ÿããã»ãšãã©ã®æšçåæ»æãšå éšã€ã³ã·ãã³ãã¯ãåäžã®ã€ãã³ãã§ç¹å®ããããšã¯ã§ããŸããã
å³ 3.ãœãŒã¹ããã®åäžã®ã€ãã³ãã§ããªã¬ãŒããã«ãŒã«ã®äŸ
2çªç®ã®æ¹æ³-äžå®æéã«ãããè€æ°ã®é£ç¶ããã€ãã³ãã®çžé¢ã«ãŒã«ã®ããªã¬ãŒ-çæ³çã«ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã»ãã¥ãªãã£ã«é©åããŸãã
ããã¢ã«ãŠã³ãã§ã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ãã°ã€ã³ããŠãããå¥ã®ã¢ã«ãŠã³ãïŒãŸãã¯VPNãšæ å ±ã·ã¹ãã ã䜿çšããåãã·ããªãªïŒã§ã¿ãŒã²ããã·ã¹ãã ã«ãã°ãªã³ãããšããããã®ã¢ã«ãŠã³ããçé£ãããå¯èœæ§ããããŸãã ãã®ãããªæœåšçãªè åšã¯ãç¹ã«ç®¡çè ã®æ¥åžžæ¥åïŒãã¡ã€ã³ïŒa.andronovãããŒã¿ããŒã¹ïŒoracle_adminïŒã§äžè¬çã§ãããå€æ°ã®èª€æ€ç¥ãåŒãèµ·ããããããã¯ã€ããªã¹ããšè¿œå ã®ãããã¡ã€ãªã³ã°ãäœæããå¿ èŠããããŸãã
å³ 4.è€æ°ã®ãœãŒã¹ããäžé£ã®ã€ãã³ããããªã¬ãŒããã«ãŒã«ã®äŸ
å³ 5.ã€ã³ã·ãã³ããå€éšããã®ãªãœãŒã¹ãžã®äžæ£ã¢ã¯ã»ã¹ãã«é¢ããã€ãã³ãã®ãããã³ã°ã®äŸ
ã«ãŒã«ãæ§æãã3çªç®ã®æ¹æ³ã¯ãããŸããŸãªã¹ãã£ã³ããã«ãŒããã©ãŒã¹ãæµè¡ãããã³DDoSã®æ€åºã«æé©ã§ãã
å€æ°ã®ãã°ã€ã³è©Šè¡ã®å€±æã¯ããã«ãŒããã©ãŒã¹æ»æã瀺ããŠããå¯èœæ§ããããŸãã BF_INC_SSH_Dictionaryæ»æã«ãŒã«ã¯ãUnixã·ã¹ãã ã§20åã®ãã°ã€ã³è©Šè¡ã®å€±æã远跡ããããã«æ§æãããŠããŸãã
å³ 6. 1ã€ã®ã¿ã€ãã®ç¹å®ã®æ°ã®ã€ãã³ãã«å¯ŸããŠããªã¬ãŒããã«ãŒã«ã®äŸ
ç°åžžãªæŽ»åãèšé²ããæãè€éã§åæã«å¹æçãã€æ®éçãªæ¹æ³ã¯ããããã¡ã€ã«ã®äœ¿çšã§ãã
äŸãšããŠã¯ãçžé¢ã«ãŒã«INC_AV_Virus Anomaly ActivityããããŸããããã¯ãäžå®æéã®å¹³åã¢ã³ããŠã€ã«ã¹å¿ççïŒãããã¡ã€ã«ã«åºã¥ããŠèšç®ïŒã®è¶ éãç£èŠããŸãã
å³ 7.å¹³åãè¶ ããã«ãŒã«ãããªã¬ãŒããäŸ
JSOCãéçºããŠãçžé¢ã«ãŒã«ãäœæããããã®æ¬¡ã®æšå¥šäºé ã®åºç€ãšãªãç¹å®ã®æèšãåŠã³ãŸããã
- ãããã¡ã€ãªã³ã°ã䜿çšããå¿ èŠããããŸãã 1人ã®ã¯ã©ã€ã¢ã³ãã«ãšã£ãŠã¯ããã¹ãã§TORã䜿çšããããšã¯å®å šã«æ£åžžãªå Žåããããå¥ã®ã¯ã©ã€ã¢ã³ãã«ãšã£ãŠã¯ãåŸæ¥å¡ã解éããçŽæ¥çãªæ¹æ³ã§ãã äžéšã®äººã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£å šäœã§äœæ¥ã§ããä¿¡é Œã§ãã管çè ã®ã¿ã«VPNã¢ã¯ã»ã¹ãèš±å¯ããä»ã®äººã¯åŸæ¥å¡ã®ååã«ã¢ã¯ã»ã¹ã§ããŸãããã¹ããŒã·ã§ã³ã§ã®ã¿äœæ¥ããŸãã ãããåæã«ãäŒç€Ÿã®åŸæ¥å¡ã®å€§å€æ°ã¯æ¯æ¥åãã·ããªãªã§äœæ¥ããŠããããããããã¡ã€ã«ãäœæããã®ã¯ç°¡åã§ãããããã£ãŠãç°åžžã¯ç°¡åã«ç»é²ã§ããŸãã ãããã£ãŠãJSOCã§ã¯çµ±äžãããã«ãŒã«ã䜿çšããŸããããããã®ãã©ã¡ãŒã¿ãŒããªã¹ãããã£ã«ã¿ãŒã¯ã¯ã©ã€ã¢ã³ãããšã«åå¥ã§ãã
- è€éãªã«ãŒã«ã¯æ©èœããŸããã誀æ€ç¥ã®æ°ãæå°éã«æããããã«ã«ãŒã«ãããªã¬ãŒããããã®æ¡ä»¶ã10åç©ã¿äžãããšãããªã¬ãŒã®å¯èœæ§ã¯äœããªããéèŠãªäœããèŠèœãšããªã¹ã¯ãé«ããªããŸãã
- SIEMã¯ãã®ã¿ã¹ã¯ã®ã¿ã解決ããå¿ èŠããããŸãã ãããã®ç®çã«ç¹åãããœãªã¥ãŒã·ã§ã³ãååšããå Žåããã®äžã«ãã¹ãŠãããããããããšããå¿ èŠã¯ãããŸããã ããšãã°ãå€éšIPã¢ãã¬ã¹ã1å以å ã«å€éšãªãœãŒã¹ãžã®æ¥ç¶ã1000以äžè©Šè¡ããããšããå Žåã«æ©èœããã«ãŒã«ãæ§æããŸãã äžèŠãªäœæ¥ã§SIEMãããŒãããããšãªããIPSã§ãã®ã«ãŒã«ãèšå®ããæ¹ãã¯ããã«ç°¡åã§ãã
åæã«ã泚æãããã®ã¯ãSIEMã·ã¹ãã ãã©ãã»ã©é©åã«æ§æãããŠããŠããFalse Positiveã€ãã³ãã¯åžžã«ååšãããšããããšã§ãã ããã§ãªãå ŽåãSIEMã¯æ»ãã§ããŸãã ãã®ãããå®éã®ã€ã³ã·ãã³ããç¹å®ã§ããè³æ Œã®ããã¢ãã¿ãªã³ã°ãšã³ãžãã¢ãé 眮ããããšãéèŠã§ãã ã¹ãã·ã£ãªã¹ãã¯ãæ å ±ã»ãã¥ãªãã£ã«é¢ããäžé£ã®ç¥èãèµ·ããããæ»æã®ãããã¡ã€ã«ãæã¡ãã€ãã³ããåæããããã®æçµçãªã·ã¹ãã ãç¥ã£ãŠããå¿ èŠããããŸãã
ãããã«
æåŸã®èšèãšããŠã瀟å ã§SOCãçµç¹ããããã®æšå¥šäºé ãèŠçŽããããšæããŸãã
- SOCã®æãéèŠãªéšåã¯SIEMã·ã¹ãã ã§ããéžæã®åé¡ã¯ãµã€ã¯ã«ã®æåã®èšäºã§èª¬æããŸããããæãéèŠãªç¹ã¯ããžãã¹ããã³ã€ã³ãã©ã¹ãã©ã¯ãã£æ©èœã®èŠä»¶ãžã®ã«ã¹ã¿ãã€ãºã§ãã
- çžé¢ã«ãŒã«ãäœæããŠããŸããŸãªæ»æã·ããªãªãšæ»æè ã®æŽ»åãæ€åºããäœæ¥ã¯ã絶ãéãªãè åšã®çºå±ã«é¢é£ããŠçµããããšã®ãªãèšå€§ãªäœæ¥å±€ã§ãã ãã®ãããè³æ Œã®ããã¢ããªã¹ããå¿ èŠã§ãã
- ç£èŠãšã³ãžãã¢ã®æåã®è¡ã¯ãæ å ±ã»ãã¥ãªãã£éšéã«åºã¥ããŠåœ¢æãããå¿ èŠããããŸãã ã¹ãã·ã£ãªã¹ãã¯ã誀æ€ç¥å¿çãå®éã®ã€ã³ã·ãã³ããšåºå¥ããã€ãã³ãã®åºæ¬çãªåæãå®æœã§ããå¿ èŠããããŸãã ããã«ã¯ãæ å ±ã»ãã¥ãªãã£ã®åéã®ã¹ãã«ãšãèããããæ»æãã¯ãã«ã®ç解ãå¿ èŠã§ãã