![](https://habrastorage.org/files/84e/fcd/4c2/84efcd4c25754134ac0c72573a6b5f89.jpg)
ä»æ¥ã®ãã·ã¢ã®ããžãã¹ã®å€å žçãªã¢ãããŒã㯠ããã¡ã€ã¢ãŠã©ãŒã«ãã€ã³ã¹ããŒã«ããæšçåæ»æã®æåã®è©Šã¿ã®åŸãäŸµå ¥é²åŸ¡ã·ã¹ãã ãã€ã³ã¹ããŒã«ããããšã§ãã ãããŠå¹³åã«ç ãç¶ããŸãã å®éã«ã¯ãããã¯å€ããå°ãªããæ·±å»ãªè åšïŒããšãã°ã競åä»ç€Ÿããã®æ»æãæªæã®ãããŠãŒã¶ãŒããã®æ»æããŸãã¯å€åœã®ç£æ¥ã¹ãã€ã°ã«ãŒãããã®æšçæ»æïŒã«å¯ŸããŠãscriptdiddyã«å¯ŸããŠã®ã¿è¯å¥œãªã¬ãã«ã®ä¿è·ãæäŸããŸããå€å žçãªæ段ã«å ããŠãè¿œå ã®äœããå¿ èŠã§ãã
ãã·ã¢ã®æ°éäŒæ¥ã«å¯Ÿããå žåçãªæšçåæ»æã®ãããã¡ã€ã«ã«ã€ããŠã¯ãã§ã«æžããŠããŸãã 次ã«ãç¹ã«æ»æãã¯ãã«ã®0æ¥éãžã®ç§»è¡ãšé¢é£ããIDEã§ã®éçã³ãŒãã¢ãã©ã€ã¶ãŒã®å®è£ ã«é¢é£ããŠãè¿å¹Žãããåœã®é²è¡æŠç¥å šäœãã©ã®ããã«å€åããŠãããã«ã€ããŠèª¬æããŸãã
ããã«ããèåã®ããã€ãã®äŸ-ã€ã³ã¿ãŒãããããå®å šã«éé¢ããããããã¯ãŒã¯ãšéè¡ã®åšèŸºã§äœãèµ·ããããç¥ãããšãã§ããŸãã
éçº
éå»2幎éã§ã倧äŒæ¥åããœãªã¥ãŒã·ã§ã³ã®åžå Žã§ã¯ããªã匷ãåããå§ãŸã£ãŠããŸãã æåã¯ãDDoSããä¿è·ããããã®ããªãè¯ã掻åããããŸãã-ãã®çŽåŸãæ»æã¯å®ããªããŸããã äžèŠæš¡äŒæ¥ã¯ããªããµã€ãã«Webãµã€ããšãã£ãã·ã¥ãã¹ã¯ãåºèã«æã£ãŠããã®ãããšããåé¡ã«ã€ããŠITã«ç²ŸéããŠããŸãããã倧èŠæš¡ãªäŒæ¥ã¯éæšæºæ»æã«å¯Ÿããä¿è·ã«å¯Ÿããé²åŸ¡ãåæ§ç¯ããŠããŸããã æ瀺ãããè åšã®ã»ãšãã©ã¯ã0ãã€ãšãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®çµã¿åããã«ãã£ãŠå®çŸãããããšãæãåºãããŠãã ããã ãããã£ãŠãè«ççãªã¹ãããã¯ãäŒç€Ÿã®ãœãããŠã§ã¢éçºã®æ®µéã§ã³ãŒãã¢ãã©ã€ã¶ãŒãå°å ¥ããããšã§ããã
ã³ãããåã«ç¢ºèªãã
æãå¹æçãªæ段ã®1ã€ã¯ãéçã³ãŒãåæãªãã§ã¯ã³ããããè¡ããããåçåæãåæ ŒãããŸã§ããã«ãµãŒããŒã«ãªãªãŒã¹ã1ã€ãéä¿¡ãããªãããã«ããã»ã¹ãç·šæããããšã§ããã ããã«ããã®ãã€ããã¯ã¹ã¯ãç°ãªããµãŒããŒãç°ãªããããã¡ã€ã«ãæã€ãŠãŒã¶ãŒã®ãã·ã³ãªã©ã«çæ³çã«å¯Ÿå¿ããä»®æ³ãã·ã³ã®ããµã³ãããã¯ã¹ãã§å®è¡ãããŸãã ã€ãŸããã³ãŒãã¯çžäºäœçšã®ãã§ãŒã³å šäœãåããå®éã®ç°å¢ã§ãæºãåããŠããŸããã
æãé£ããã®ã¯ãã¡ãããã¢ãã©ã€ã¶ãŒãšIDEã®çµ±åã§ãã ã¢ãã©ã€ã¶ãŒã®èŠåããã¹ãŠã¯ãªã¢ãããŸã§ããã以äžã®ã¹ãããã§ã¯ãªããé¢æ°ãäœæããŸããã åæã«ãå®å šãªå¹žçŠã®ããã«ãèŠåå¡ã¯äœãèµ·ãã£ããã®ãã°ãèŠãŠããã¹ãŠã®èŠåã圌ã«è€è£œãããŸãã ååãèšãããã«ã西æŽã§ã¯ãéåžžã®ã³ãŒããããã«æžãããã®éåžžã«å¹æçãªããŒã«ã§ããããšãå€æããŸããã
![](https://habrastorage.org/files/b71/396/739/b71396739af2478a8ab0cbf031a7785b.png)
ãœãªã¥ãŒã·ã§ã³ã®äŸã¯ãHP Fortify Software Security Centerã§ãã
ãµãŒãããŒãã£ã®ã³ãŒã
ãµãŒãããŒãã£ã®ã³ãŒããå®è£ ããå Žåã倧äŒæ¥ã®æ å ±ã»ãã¥ãªãã£äŒæ¥ã¯å€ãã®å Žåãéçã³ãŒãåæãèŠæ±ããŸãã ãªãŒãã³ãœãŒã¹ã«é¢ããŠã¯ãç¶æ³ã¯éåžžã«åçŽã§åçŽã§ãããã¢ãã©ã€ã¶ãŒãééããŠã100ãã1000ã®èŠåããæå¶ãããŸãã ã³ãŒããåçšã§ããã顧客ããµãã·ã¹ãã ã®ãœãŒã¹ã³ãŒããæäŸããæºåãã§ããŠããªãå Žåãããã«èå³æ·±ãå埩ãè¡ãããŸãã
ãœãŒã¹ã³ãŒããæäŸãããŠããªãããéçºè ã®ãªãã£ã¹ã§èªãããšãã§ããå ŽåãITéšéãšæ å ±ã»ãã¥ãªãã£éšéã®æ åœè ã¯ãéçã¢ãã©ã€ã¶ãŒãäžç·ã«å®è¡ããå Žæã«åãããŸãã ãšã«ããäžå¯èœãªå Žåã¯ãã³ãŒããæåŠããããããã»ã©é »ç¹ã§ã¯ãªããããã€ããã¯ã¹ã§åŒ·åãããããã«ãã¢ããããå²ãåœãŠãŸãã
èªååãããæ¹æ³ã«å ããŠãå€ãã®å Žåããã³ãã¹ã¿ãŒãæåŸ ãããŸããããã¯ãå°éæè²ãåããIB / ITéšéã®åŸæ¥å¡ããŸãã¯å€ãã®å ŽåãããŒãããŒäŒæ¥ã®ãµãŒãããŒãã£ã¹ãã·ã£ãªã¹ãã§ãã
å€ãã³ãŒã
ã¬ã¬ã·ã³ãŒãã«åé¡ãããã1996幎ãŸã§ãµãã·ã¹ãã çšã«ã³ã³ãã€ã«ãããŠããå ŽåïŒãã®ãããªå®éã®ã±ãŒã¹ããããŸããïŒããã¡ããããããæžãæããããšã¯éåžžã«å°é£ã§ãã ãã®å Žåãè匱æ§ã®æªçšã®çš®é¡ïŒå®éã«ã¯ãæªçšããã±ãŒãžã®çœ²åïŒã説æããã«ãŒã«ããã¡ã€ã¢ãŠã©ãŒã«ã«æžã蟌ãŸããŸãããŸãã¯ãäžéã·ã¹ãã ã®1ã€ïŒä»¥äžã«ã€ããŠïŒã«ãæçµã·ã¹ãã ã®éåžžã®ããã±ãŒãžã§ã¯ãªããã¹ãŠã®ã«ãããªããç»é²ãããŸãã äžçš®ã®DPIã§ãããè匱æ§ãéããããã«ããã€ã³ãã£ã³ã°ã¯ããé«ãã¬ãã«ã§ãã
å éšæ£æ©
éåžžã«å€§èŠæš¡ãªããžãã¹ã«ã¯å¥ã®ç¹åŸŽçãªåé¡ããããŸããç掻ã€ã³ãã©ã®å€åã®æ°ã¯ã倧èŠæš¡ãªéšéã§ãããããã¯ãŒã¯å ã®ãã¹ãŠã®åãã远跡ã§ããªãã»ã©ã§ãã ãããã£ãŠãåãéè¡ãå°å£²æ¥è ãããã³ä¿éºäŒç€Ÿã¯ãHP Webinspectãåèã®Positive Technologiesã®MaxPatrolãªã©ã®å°çšããŒã«ã䜿çšããŠããŸãã ãããã®ã·ã¹ãã ã䜿çšãããšãäœé»æµã·ã¹ãã ã®ãã€ã¯ãã³ã³ãããŒã©ãŒã«é©çšããããã®ãå«ããããŸããŸãªã€ã³ãã©ã¹ãã©ã¯ãã£ã³ã³ããŒãã³ãããã¹ãã§ããŸãã
ãã©ãã£ãã¯ãããã¡ã€ãªã³ã°ã·ã¹ãã ã¯éåžžã«äžè¬çã«ãªã£ãŠããŸãã åããŒããžã®åŒã³åºãã®å žåçãªãããã¡ã€ã«ã¯ãã¹ã€ããããã³ã«ãŒã¿ãŒããã®ããŒã¿ã«åºã¥ããŠæ§ç¯ããããŠãŒã¶ãŒãšãŠãŒã¶ãŒãåç §ããã·ã¹ãã ãšã®éã«çžé¢é¢ä¿ãæ§ç¯ãããŸãã çžäºäœçšãããªãã¯ã¹ãå€æããã©ã®ãµãŒãã¹ãã©ã®ãŠãŒã¶ãŒã«ãã©ãã£ãã¯ãçæãããã確èªã§ããŸãã ããããªéžè±ã¯èŠåå¡ãžã®éç¥ãšãã圢ã§ããããããæ·±å»ãªãã®ã¯ããã«ãããã¯ãããŸãã ãã«ãŠã§ã¢ããããã¯ãŒã¯ã«å ¥ããšãç¹åŸŽçãªè€æ°ã®ãã¬ãŒã¹ã衚瀺ãããéèŠãªãã®ã¯ãã¹ãŠãåçµãããããã°ã®åæãéå§ãããŸãã
ãã®å Žåãæ§æã¯ãITéšéã®åå ãªãã«ãã»ãã¥ãªãã£ã¬ãŒãèªèº«ãçŽæ¥GUIã®åœ¢ã§ãapplication-user-serverãã®åœ¢ã§è¡ããŸãã å¥åŠãªããšã«ãç§ã¯ç®¡çè ãå«ããã®ãããªã·ã¹ãã ã奜ãã§ã-Vkontakteã¢ããªã±ãŒã·ã§ã³ã垯åå ã®ãã©ãã£ãã¯ã®90ïŒ ãçæãå§ãããšãã®äŸãããã管çè ã¯ãããéåžžã«ç°¡åã«æ°ä»ããŸããã
ãããã¯ãŒã¯ç°åžžæ€çŽ¢ã·ã¹ãã ã®äŸã¯StealthWatchã§ãã
å æ¬çãªã»ãã¥ãªãã£åæã«ã¯éåžžã次ã®3ã€ã®æé ãå«ãŸããŸãã
- ãŠãŒã¶ãŒæš©éãªãã®ãã©ãã¯ããã¯ã¹ã¬ãã«ã§ã®åæ ãã€ãŸããåã«å€ã«åºãã ãããã¯ç¡æã®ããŒãã§ããããµãŒãã¹ããèŠãããã¹ãŠã®ãã®ã®åæã§ãããåéãããè匱æ§ã䜿çšããŠDMZãééããããšããŸãã ååãšããŠãæšæºã®ãã³ãã¹ãã
- 管çè ãŸãã¯ç¹æš©ãŠãŒã¶ãŒã®ã¢ã«ãŠã³ãããç£æ»ããŸãã æ»æè ã¯äœããã®æ¹æ³ã§ïŒããšãã°ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã«ãã£ãŠïŒã¢ã¯ã»ã¹ããããªãã¯ããããã®ç¬éããæ»æãé²è¡ãããšæ³å®ãããŠããŸãã ãã®ç£æ»ã®äžç°ãšããŠããããã¯ãŒã¯å šäœã§ãã¢ãŒãè¡ãããŸãã èšå®ãæ§æãã¡ã€ã«ãã·ã¹ãã æŽæ°ã®æ£ç¢ºæ§ãåããã±ãŒãžãšãã¡ã€ã«ã®ãã§ãã¯ãµã ããã§ãã¯ããããœãããŠã§ã¢ããŒãžã§ã³ãšãã®æ¢ç¥ã®è匱æ§ãè©äŸ¡ãããŸãïŒããšãã°ããŠãŒã¶ãŒãã·ã³ã®Windowsãèªå®ãœãŒã¹ããæ£ããæŽæ°ãããããã«ïŒã ããã±ãŒãžã®äŸã¯RedCheckã§ãã
- 3çªç®ã®ã¢ãŒãã¯ãç¹å®ã®æšæºã®èŠä»¶ãžã®æºæ ã§ãã ããã¯ããã³ãã¬ãŒãïŒããšãã°ãã¯ã©ã¹ããšã«å人ããŒã¿ãåŠçããããã®ã¢ãã«ïŒã«åŸã£ãŠæ¡åŒµããããããã¯ãŒã¯ãã€ãã¹ã§ãã ç§ãã¡ã®ãã³ããŒã¯ãã·ã¢åãã«äºåèšå®ããããã³ãã¬ãŒããæã£ãŠããŸã-å€åœã®ãã³ãã¬ãŒãã¯ãéåžžãããããPCI DSSãè¶ ããããšã¯ã»ãšãã©ãããŸããã
ããã«ãã®ãããªç£æ»ã®äŸããããŸã ã ããããåé¡ãšã²ãŒã ãåéãèŠã€ãããã«ç§»ããŸãããã
å žåçãªåé¡
ååãšããŠã倧äŒæ¥ã®æ å ±ã»ãã¥ãªãã£ã®åé¡ã®ã»ãšãã©ã¯ããã¯ãæè¡ã¬ãã«ã§ã¯ãªããçµç¹ã¬ãã«ã§ã®ã家åºãã§ãã
- å€ãããŒããŠã§ã¢ãšãœãããŠã§ã¢ã å€ãã®å Žåã倧äŒæ¥ã§ã¯èªå®ãœãªã¥ãŒã·ã§ã³ãå¿ èŠã§ãããæ°è£œåã«é ãããšã£ãŠããŸãã å€ãã®äººã¯åã«æ°ãããœãããŠã§ã¢ãæ°ããã¯ãŒã«ãªããŒããŠã§ã¢ãå ¥ããäœè£ã¯ãããŸããããåé¡ã解決ããããã«æããã«æ¢ç¥ã®ç©Žãå¿ èŠãªæ©èœãæ¬ ããŠãããã®ã眮ããæŸèæãæã¡ãŸãã éè¡ãèªèšŒãããŠããã ãã®æ±ºå®ãäžãããšã¯çãããªããå®éãèŠå¶åœå±ã®èŠä»¶ãå®å šã«æºããããšãªãã1ã2ãæã®éãç¬èªã®ãªã¹ã¯ã§æ©èœããŸãã å¥ã®æ¹æ³ã¯ãæ å ±ã»ãã¥ãªãã£ã«éŠ¬ã»ã©ã®å€§ããã®ç©Žãéããããšã§ãããåæã«ããããã¹ãŠæšæºãšèŠä»¶ãæºããçŽã§èŠãããã«ããŠãã ããã
- çµæ-1ã€ã®ããã¯ã¹ããããã¯ãŒã¯å šäœãéããŸãã åé¡ã¯å€éšããå®å šã«æ£æ°ã§ã¯ãããŸããããå€ãã®å Žåãå°ããªéè¡ã®å éšãããã¯ãŒã¯å šäœã1ã€ã®ããã€ã¹ã«çœ®ãããŸããããã¯æèŠãã5幎é ããŠããŸããã蚌ææžã®äžã§æ©èœããŸãã ãã®ããŒããŠã§ã¢ãæ éãããšããã¹ãŠã解決çã«ãªããŸãã åœç¶ãææ°ã®ãœãªã¥ãŒã·ã§ã³ã¯ãµãã·ã¹ãã ã䞊ååŠçãåé·æ§ããã€ãã¹ã§ããŸãããçŸå®ã¯çæ³çãªãããã¯ãŒã¯ã¢ãŒããã¯ãã£ã¹ããŒã ãšã¯å°ãç°ãªããŸãã
- ãŸãã¯å¥ã®ãªãã·ã§ã³ã äžè¬ã«ãå¿ èŠãªãã®ã¯ãã¹ãŠãããŸãã ãããã DLPãšã¢ã³ããããã¯ã¢ã¯ãã£ãåã§ãããã¢ã³ããããã·ã°ããã£ããŒã¿ããŒã¹ã®æŽæ°ã®åé¡ïŒæŽæ°ãçŠæ¢ãããŠããŸãïŒããã©ã€ããŒã®åé¡ïŒç¶æ³ããããŸãã-èªå®æ©åšãã€ã³ã¹ããŒã«ããŸããããRAIDã¢ã¬ã€ã«é©åããŸããã§ãã-幞ããªããšã«ãæ°ããèªå®ããŒãžã§ã³ãæ°æ¥ã§ãªãªãŒã¹ãããŸããïŒ ïŒ
- ããŒãã³ãŒãã ããã€ã¹ããšã«ç°ãªãçš®é¡ã®ãã©ãã£ãã¯ãå¿ èŠã§ãããæ°ããããŒããŠã§ã¢ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããå Žåãçã¿ã䌎ãé·æéã®åæ¥ç¶ãé »ç¹ã«è¡ãããŸãã ãã®ããã1ã€ã®ä¿è·å€ã®ãã¹ãã¯æ°é±éç¶ãå ŽåããããŸãã å®éã«ã¯ããã£ã³ãã«ã¬ãã«ã§äœæ¥ã§ããææ°ã®ãœãªã¥ãŒã·ã§ã³ãçšæããã°ååã§ãã ããã«ãããããšãã°ããã¡ã€ã¢ãŠã©ãŒã«ã®åãŸãã¯åŸã«ãã®ãã£ãã«ã®äžã«IPSãé 眮ã§ããŸãïŒããã©ãŒãã³ã¹ã«å€§ãã圱é¿ããŸãïŒã
![](https://habrastorage.org/files/361/e75/46a/361e7546a4534c05a4f95802f92ace84.png)
ã®ã¬ã¢ã³GigaVUE-HC2
- ä¿è·äžã®ãã®ä»ã®éã å®éã®ãšãããããã¯åé¡ã§ã¯ãããŸãããåŸåã¯ãã»ãšãã©ã®ãã³ããŒããã¹ãŠã®å¢çãœãªã¥ãŒã·ã§ã³ã1ã€ã®UTMããã€ã¹ã«é©åãããšããçµè«ã«éãããšããããšã§ãã å®éãåãœãªã¥ãŒã·ã§ã³ã¯ããã©ãã¯ããã¯ã¹ãã®åœ¢åŒã®PACã§ãã ææ°ã®ãªãã·ã§ã³ã¯åãx86ã¢ãŒããã¯ãã£ã§ããã2幎ããšã«ããŒããŠã§ã¢ãå»æ£ããããšãªãæ©èœãæŽæ°ããæ©èœã§ãã ããšãã°ãå éšã«ãã§ã«ãã¡ã€ã¢ãŠã©ãŒã«ãã¹ããªãŒãã³ã°ãŠã€ã«ã¹å¯Ÿçãã¢ã³ããããã·ã¹ãã ãªã©ãããããã€ã¹ããããŸãã åæã«ãå®å šã«èªèšŒãããŠãããéã®éšåã¯x86ãã·ã³ã§æ§æããããœãããŠã§ã¢ã¬ãã«ã§ä»®æ³ãœãããŠã§ã¢ãã¬ãŒãã«åå²ãããŠããŸãã å¿ èŠã«å¿ããŠããœãããŠã§ã¢ãããã«é ä¿¡ãããã©ã€ã»ã³ã¹æãæ¯æãããŸã-ãããŠãæ°ããæ¹æ³ã§è±ç©ãç¶ããŸãã
- åç©åã·ã¹ãã ã®é«åºŠãªçµ±åã ç¹°ãè¿ããŸãããåã®æ®µèœã®çµæã§ãã ããŸããŸãªäžé©åã«ãããã³ã°ãããã¢ã€ãã³ã®å€ãã¯ãIBã·ã¹ãã ã®ããéšåããå¥ã®éšåã«ããŒã¿ã転éããåé¡ã§ãã ããšãã°ãIPSãã¢ã³ãããããããã·ã¹ãã ã«æ確ã«æ¥ç¶ãããŠããããšã¯é·ãéæšæºã§ããã ããã¯ããã¹ãŠã®éè¡ã®å Žåãšã¯ã»ã©é ãããšã§ããããããããçµ±åã¡ã«ããºã ãå®è¡ããã®ãé£ããããäžèšã®ããã«ãã¬ãŒããåããããŒããŠã§ã¢ã1ã€ããªãããã§ãã ã¡ãªã¿ã«ãææ°ã®äžä»£ã¯ãåãPCI DSSã®æ§æã«æºæ ããŠãããã©ãããã¹ãã£ã³ããããã«ããè³ãåå²ãããæ¹æ³ãç¥ã£ãŠããŸãã 以åã¯ãããã¯å¥ã®å€éšã·ã¹ãã ã«ãã£ãŠè¡ãããŠããŸããã
- æšæºã«æºæ ããããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®åæã§ã¯ããã·ã¢ã®çŸå®ã¯èæ ®ãããŸããã ãããç°¡çŽ åããããã«ãPCI DSSã³ã³ãã©ã€ã¢ã³ã¹ãæ€èšŒããããã®ã¯ããŒã©ãŒãŠãŒãã£ãªãã£ã®å®ç§ãªã»ãããçšæããŸãã ãããã決å®ã®ããäžéšã®ã¿ããNoã152-FZã å人ããŒã¿ã«ã€ã㊠ããè¡ãããšãã§ããŸã ã ããšãã°ãåœå ã®MaxPatrolã¯ãã«ã¯ãªã€ã«ãããªã«ã¹ã¯ããã±ã«ãVympelcomãã¬ã¹ããã ãªã©ã§ãè¿œãããããã ãã§ã¯ãããŸããã
- çªç¶ã®å€åã ããã¯äžè¬ã«åæªãè¶ ããŠããŸãããèµ·ãããŸãã äžè¬çãªã±ãŒã¹-ITã¹ãã·ã£ãªã¹ããäœããå®è¡ããã€ã³ãã©ã¹ãã©ã¯ãã£ã¬ãã«ã§æ°ããã«ãŒã«ãèšå®ããŸããããã¯ãã»ãã¥ãªãã£ã¬ãŒãã1ã2ãæã§çªç¶æ€åºããŸãïŒå€ãã®å Žåãèªåã§ã¯ãªãããã³ãããã°ããã³ãã¹ãããŸãã¯å®éã®æ»æãèŠã€ããããã®ããã°ã©ã ïŒã ãããã圌ã¯çãéã¶ããšãæé ããŸãã ããšãã°ãçµ±åã®1ã€ã§ãéãè±ç©ãµãŒããŒã®å°å ¥ã1é±éã¹ããŒãã¢ããããªããã°ãªããªãã£ãç¶æ³ããããŸããã å®è£ äžã«ã顧客ã®ITãããã³ã®è©³çŽ°ããã¹ãŠç¥ããã«ãç¹å®ã®ã¿ã€ãã®ãã©ãã£ãã¯ãçŽæ¥èªå°ããããšãèš±å¯ãããŸããã ãããŠã圌ãã¯æåã«ã€ããŠå ±åããã ããã«å¿ããŠãèŠåå¡ã¯å éšèª¿æ»ãéå§ããŸããããã®çµæãç§ãã¡ã¯ã»ãšãã©åžœåãæã«ããŸããã ãã®ãããITã¹ãã·ã£ãªã¹ãããããã¯ãŒã¯ã«äœããå®è£ ãããšãã«ã·ã¹ãã ãã€ã³ã¹ããŒã«ããã®ã¯æ£ããããšã§ãããã«ãŒã«ã¯ã»ãã¥ãªãã£ã¬ãŒãã«ãã£ãŠç¢ºèªããããŸã§æŽæ°ãããŸããã åé¡ã¯ãã©ãã£ãã¯ã®èš±å¯ã§ã¯ãªããæ å ±ã»ãã¥ãªãã£éšéãééãããããååã¯ããŒãã¹ãåãåãããšã«ãªããŸãã
- ä¿¡é Œã§ããªããœãŒã¹ã åšåº«ã¬ãã«ã®å€ãã®äŒæ¥ç°å¢ã§ã¯ããšã³ããŠãŒã¶ãŒã®ããã€ã¹ããŠã€ã«ã¹ã®è åšã«ãããããååã®ãµãŒã«ã¹ã§ãããšããäºå®ã«ãã°ãã°åé¡ããããŸãã ããšãã°ãä¿éºä»£çåºãå Žæã«æ è¡ããã«ã¡ã©ã§è»ã®ãžãã¿ãæ®åœ±ãããã®åŸã家ã«å°çããããæ·±å»ãªæ害ãæ±ããŠåçãè²·ãç©ã«éãããããéä¿¡ããããšã¯äžã€ã®ããšã§ãã å¥ã®ããšã¯ãåçãäŒæ¥ã¢ããªã±ãŒã·ã§ã³ããïŒèšŒææžã®äžã§ïŒå®å šãªãã£ãã«ãçµç±ããŠãäžæ£ãªããã€ã¹ããéä¿¡ãããå Žåã§ãã ããŒã¿ã®å€§ããã¯ä¿¡é Œã§ããŸãã ããæ·±å»ãªã±ãŒã¹ã¯ããŠã€ã«ã¹ã®çµæãšããŠããªã¢ãŒãã®åŸæ¥å¡ãæ»æè ãžã®ãã¹ãŠã®ã¢ã¯ã»ã¹æš©ãååŸããäŒæ¥ã®1ã€ã§ã®VPNä¿¡é Œã®æ¥æ¿ãªäœäžã§ãã VPNã¢ã¯ã»ã¹çšã®å®å šã§ä¿¡é Œã§ããç°å¢ãæäŸãããã©ãŠã¶ã§ä»®æ³JAVAã¢ãã¬ããã䜿çšããŠåé¡ã解決ããŸããã
ä¿è·å€ãäŸ
â¢NG FWã¯ã©ã¹ã·ã¹ãã ïŒCheck PointãStonesoftãHP Tipping PointïŒã
â¢æœåšçã«å±éºãªãã¡ã€ã«ãæ€åºããã·ã¹ãã ïŒãµã³ãããã¯ã¹ïŒïŒCheck PointãMcAfeeãFireEyeïŒã
â¢Webã¢ããªã±ãŒã·ã§ã³ïŒWAFïŒçšã®ç¹å¥ãªä¿è·ããŒã«ïŒImperva SecureSphere WAFãRadware AppWallãFortinet FortiwebïŒã
â¢æ å ±ã»ãã¥ãªãã£ããã€ã¹ïŒGigamon GigaVUE-HC2ïŒãæ¥ç¶ããããã®ã€ã³ããªãžã§ã³ãã»ã³ã¿ãŒïŒByPassããŒãïŒã
â¢ãããã¯ãŒã¯ãã©ãã£ãã¯ã®ç°åžžãæ€åºããã·ã¹ãã ïŒStealthWatchãRSA NetWitnessãSolera NetworksïŒã
â¢ã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ã®åæïŒMaxPatrolãHP WebinspectïŒ
â¢ã³ãŒãã»ãã¥ãªãã£ç£æ»ïŒHP Fortifyãããžã¿ã«ã»ãã¥ãªãã£ERPScan CheckCodeãIBM AppScan SourceïŒã
â¢DDoSä¿è·ã·ã¹ãã ïŒããŒããŠã§ã¢-ã©ããŠã§ã¢DefensePROãARBOR PRAVAILããã§ãã¯ãã€ã³ãDDoSãããã¯ã¿ãŒããµãŒãã¹-ã«ã¹ãã«ã¹ããŒDDoSé²æ¢ãQRATOR HLLïŒã
ãã¶ãŒãã®äŸ
èªå®ãããã¯ãŒã¯
äž»èŠãªæ¿åºéšéã®1ã€ã§ãæ©å¯æ å ±ãåŠçããããã«èšèšããããèªå®ããããããã¯ãŒã¯ã»ã°ã¡ã³ãã®ã»ãã¥ãªãã£ãè©äŸ¡ããããšã決å®ãããŸããã ç¹ã«ããã®ã»ã°ã¡ã³ãã®ãŠãŒã¶ãŒã¯ã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãå³ããçŠæ¢ãããŠããŸããã ãããèŠã€ããŸããïŒ
- USBã¢ãã ã®æ¥ç¶ã®çè·¡ã
- ã©ãããããã®1å°ãå€éšããã³ãããªãã¯ãããã¯ãŒã¯ã«åæã«æ¥ç¶ãããŸããã
- ã¡ãã»ã³ãžã£ãŒãšã²ãŒã ããããããããŸããã
äžè¬çã«ãæ¬éšã®æŠéæ©ãåºäŒãç³»ãµã€ãã«åº§ã£ãŠãããšããããªãã¯ããããè»éã§ãã®ãããªå€ç«ãããããã¯ãŒã¯ãèŠãŸããã ããã§ã¯ãç¶æ³ã¯ããæ·±å»ã§ããã
åæ¥éè¡ã®ãããã¯ãŒã¯å¢ç
å¢çã»ãã¥ãªãã£ãè©äŸ¡ããå¿ èŠããããŸããã éåžžããã®ãããªäœæ¥ã¯äŸµå ¥ãã¹ãã®äžéšãšããŠå®è¡ãããŸããããã®å Žåã顧客ã¯å éšããèªåã§ã§ããããšã確èªããããšã«é¢å¿ããããŸããã ãã®ãããå€éšéæŠè£ å°åž¯ã®ãµãŒããŒãšéä¿¡æ©åšã¯ãç£æ»ã¢ãŒããšã³ã³ãã©ã€ã¢ã³ã¹ã¢ãŒãã§MaxPatrolã·ã¹ãã ã«ãã£ãŠã¹ãã£ã³ãããåŸãã¬ããŒããåæããŸããã ç§ãæåã«ç®ãåŒããã®ã¯ããã€ãã®ããã«ãå€ããœãããŠã§ã¢ãŸãã¯ã»ãã¥ãªãã£æŽæ°ããã°ã©ã ã®æ¬ åŠïŒOSã®å€ãããŒãžã§ã³ãã»ãšãã©ã®ãµãŒããŒã«ãããããªãããšãªã©ïŒã«é¢é£ããç¹å®ã®æ°ã®è匱æ§ã§ããããããã¯ææªã§ã¯ãããŸããïŒãããã®è匱æ§ã®ã»ãšãã©ããã«ãŒãå©çšã§ãããšã¯ã¹ããã€ãã¯ãããŸããã ããããé©ãããããŸããã å¢çã«ãŒã¿ãŒã®ãã¢ã«ã¯ACLããããŸããã§ããïŒå€æããããããŠãããéã®éä¿¡ã®åé¡ã蚺æãããšãã«äžæçã«ç¡å¹ã«ãªããé»æºãå ¥ããã®ãå¿ããŠããŸããïŒã 倧èŠæš¡ãªã€ã³ã¿ãŒãããã§ã¯ãæŠéDBMSã¯å€èŠã«èŠããŸããã SSHã®ä»£ããã«ãå€ãã®ããŒãã§TELNETã䜿çšãããŸããã å€ãã®ããã«ãµãŒããŒã§ã¯ãæ§æåŸã«RDPèšå®ã¯å€æŽãããŸããã§ããïŒRDPãã©ãã£ãã¯ã¯æšæºããŒã§éããããŸããïŒã äŒç€Ÿã§åãå§ãããšãããããã©ã«ãã®ãã¹ã¯ãŒããå€æŽããªãã£ãããŒããŒãããŸããã 幞ããªããšã«ã圌ãã¯ãã®å€éšã«æ°ä»ãæéãæã£ãŠããªãã£ãã®ã§ãITéšéã§ã»ãšãã©ç ç²è ãªãã§ãã¹ãŠãçŽ æ©ãéããããšãã§ããŸããã
PSããªãã®è³ªåãã³ã¡ã³ãçšã§ã¯ãªãå Žåãç§ã®ã¡ãŒã«ã¯PLutsik@croc.ruã§ãã