å®éã«äœãèµ·ãã£ããã«ã€ããŠã®ããã€ãã®èšèã 2014幎11æ21æ¥éææ¥ããœããŒã®å¹¹éšã¯ããœããŒã®ITã€ã³ãã©ã¹ãã©ã¯ãã£ãã倧èŠæš¡ãªçæãã確å®ã«åé¿ããããã«äžå®ã®éé¡ãæ¯æãããæ±ããæžç°¡ãåãåããŸããã ãã®æçŽã¯éèŠã§ã¯ãªããå€ãã®ãããŒãžã£ãŒã«ãšã£ãŠã¹ãã ã«ãªããŸãããã2014幎11æ24æ¥ããã§ã«æææ¥ã®æã«è·å Žã«å°çãããœããŒã®åŸæ¥å¡ã¯ã¢ãã¿ãŒã§æ¬¡ã®åçãèŠãŸããã
å瀟ã®ã³ã³ãã¥ãŒã¿ãŒããã³ITãµãŒãã¹ã®ã»ãšãã©ã¯æ©èœããŠããŸããã§ããã ããã€ãã®æ å ±æºã«ãããšãä»åŸæ°æ¥éããœããŒã®åŸæ¥å¡ã¯è·å Žã®ã³ã³ãã¥ãŒã¿ãŒã䜿çšããããã³ãšçŽã§äœæ¥ããŸããã ãã®æ»æã®éçšã§ïŒæ»æã®æœåšæ®µéã¯æ°ãæãã1幎ã«çºå±ãããšèããããŠããŸãïŒãæ°çŸäžãã«ã§ãœããŒããããŒã¿ãæŒããŸããïŒäžéšã®æšå®ã«ãããšãåèš100ãã©ãã€ãïŒã ãã®åŸãããã«ãŒã¯ãŸã å ¬éãããŠããªãããã€ãã®æ°ããæ ç»ãšãåŸæ¥å¡ã®å人ããŒã¿ãå«ã倧éã®æ©å¯æ å ±ãã¢ããããŒãããŸããã ããŸããŸãªæšå®ã«ãããšããã®æ»æã«ããããããã®çŽ¯ç©æ害é¡ã¯çŽ1åãã«ã§ããã
ããã¯ã©ã®ããã«èµ·ããããããŠæãéèŠãªã®ã¯ããªãã§ããïŒ
Sony Entertainmentã®æ»æã«é¢äžãããã«ãŠã§ã¢ã¯ã Destover TrojanãšåŒã°ããŸãã ããã¯ãããŒããã©ã€ãããããŒã¿ãåé€ããMBRãå¿ èŠãªæ¹æ³ã§äžæžãã§ããã¯ã€ããŒã¿ã€ãã®ãã«ãŠã§ã¢ã§ãã ããŸããŸãªã¯ã€ããŒã䜿çšãããã®ãããªæ»æã®æ³¢ã¯ã2012幎以éäžå€®ã¢ãžã¢ã§äžæããïŒãµãŠãžã¢ã©ã ã³ãžã®æ»æã30,000å°ãè¶ ããã³ã³ãã¥ãŒã¿ãŒã§ã®ããŒã¿ç Žå£ãã«ã¿ãªã©ã¹ã¬ã¹ãžã®æ»æãªã©ïŒããããŸã§ã®ãšãããœããŒãšã®æ³šç®ã®ç©èªã§çµãããŸããã
å°é家ã«ãããšãæ»æè ã¯æããã«ããã®ããã€ã®æšéŠ¬ããããã¯ãŒã¯å ã®ã³ã³ãã¥ãŒã¿ãŒã«é åžãå§ããåã«ãSony Entertainmentã®å éšãããã¯ãŒã¯ãžã®ãã«ã¢ã¯ã»ã¹ãååŸããŸããã äžã®å³ã«ç€ºãå€å žçãªæ»æã¹ããŒã ã«åŸã£ãŠè¡åããŸããã
æ»æã©ã€ããµã€ã¯ã«ïŒ
- 䟵å
¥ïŒæµžéïŒã¯ãããã«ãŒãä»åãœããŒãããã¯ãŒã¯ã«æåã«åå
¥ããæ¹æ³ã«ã€ããŠã¯ç¹å®ãããŠããŸããïŒå°ãªããšãå
¬éãããŠããŸããïŒã 3ã€ã®ããŒãžã§ã³ãæåŸ
ãããŠããŸã-ã€ã³ãµã€ããŒãã«ããå€å
žçãªãã£ãã·ã³ã°ããŸãã¯ããã¯ãã¢ã®ãã®åŸã®çµç¹ã«ããWebãµãŒãã¹ã®è匱æ§ã®æªçšã æçµçã«ãããã«ãŒã¯ç®¡çè
æš©éã§Sonyãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸããã
- ç 究 -ããã«ããã«ãŒã¯ãSony Entertainmentã®ãããã¯ãŒã¯ãšITãªãœãŒã¹ã®ããããäœæããã¢ã«ãŠã³ãåãšç®¡çè
ãã¹ã¯ãŒããã¢ã¯ã»ã¹èšŒææžãªã©ãåãåããŸããã
- ãªãœãŒã¹ã®ãã£ãã㣠-ããã«ãŒã¯ãªãœãŒã¹ããããšãããã«ã¢ã¯ã»ã¹ããããã«å¿
èŠãªãã¹ãŠã®è³æ Œæ
å ±ãæã«å
¥ããŠãäŒç€Ÿã®ãªãœãŒã¹ã«ãã«ãŠã§ã¢ãå±éããåæã«ãœããŒã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãã貎éãªããŒã¿ãçã¿åã/åé€ãå§ããŸããã
- æå·ãšæ»æã®çµäº -ãã®æ®µéã§ããªãœãŒã¹ã«ã€ã³ã¹ããŒã«ãããã¯ã€ããŒã¯äŒç€Ÿã®ããŒããã©ã€ãäžã®ããŒã¿ãäžæžãããçè·¡ãæ¶ããŸããã
- åçå-ããã«ãŒã¯ããœããŒãšã³ã¿ãŒãã€ã¡ã³ãã®åœ¹å¡ã«èº«ä»£éãæäŸããŠãITã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç Žå£ãšæ©å¯æ
å ±ã®é瀺ãé²ãããšã«ãããæ»æãåçåããããšããŸããã æåŠåŸãããã«ãŒã¯çãŸããæ©å¯ããŒã¿ããããªãã¯ãããã¯ãŒã¯ã«æ¡æ£ãå§ããŸããã
質åã¯æªè§£æ±ºã®ãŸãŸã§ã-ãœããŒã®ãããªå€§èŠæš¡ã§æåãªäŒç€Ÿã§ãããåããŠèµ·ããã®ã¯ãªãã§ããïŒ å°é家ã«ãããšãSonyã®éèŠãªã»ãã¥ãªãã£åé¡ã®1ã€ã¯ãã»ãã¥ãªãã£ã·ã¹ãã ãäºåŸå¯Ÿå¿ããŒã¹ã§æ§ç¯ããããã®åŸã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç£æ»ã瀺ãããã«ãæœåšçãªè åšãæééãã«èªèããã³é²æ¢ãããªãã£ãããšã§ãã 3幎ã§3çªç®ã®æ³šç®ãéããããã¯ã¯ããœããŒããããã¯ãŒã¯ã»ãã¥ãªãã£æ§é ã®äœããå€æŽããæããã«ããã¢ã¯ãã£ããªåŠçãšè åšã®é²æ¢ã«çŠç¹ãåœãŠãå¿ èŠãããããšãæ確ã«è¿°ã¹ãŠããŸãã
è¿å¹Žã®ãœããŒã®äºäŸããã®ä»ã®ãããã³ã°ãããŒã¿æŒæŽ©ã®äºäŸã¯ãæ°ããªè åšã«å¯Ÿæããããã«ãäŒæ¥ã¯åŸæ¥ã®ã»ãã¥ãªãã£æè¡ã®æ¢åã®æ¬ ç¹ãæé€ãã次äžä»£ãããã¯ãŒã¯ã»ãã¥ãªãã£ããŒã«ã«æè³ããå¿ èŠãããããšãèªä¿¡ãæã£ãŠç¢ºèªããŠããŸãã ããšãã°ã次äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ïŒNGFWïŒã¯ãäž»ã«ãåŸæ¥ã®ã¹ããŒããã«FWãhttpãã©ãã£ãã¯ãªã©ã®ã¢ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ã®è åšãæ€åºã§ããªãããšã«å¯Ÿå¿ããããã«äœæãããŸããã ããã«ãNGFWã®éèŠãªæ©èœã¯ããã©ãã£ãã¯ãèå¥ããŠç¹å®ã®ãŠãŒã¶ãŒã«é¢é£ä»ããæ©èœã§ãã
GARTNERã¯NGFWã次ã®ããã«å®çŸ©ããŸãïŒæ¬¡äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ïŒNGFWïŒã¯ãçµã¿èŸŒã¿ã®äŸµå ¥é²æ¢ã·ã¹ãã ãã€ã³ããªãžã§ã³ããªåŠçãå«ããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ãã©ãã£ãã¯ãæ€æ»ããã³ãããã¯ããæ©èœãåããããã£ãŒããã±ããã€ã³ã¹ãã¯ã·ã§ã³ïŒããŒã/ãããã³ã«ãè¶ ããŠïŒãå®è¡ããããã€ã¹ã§ãå€éšã·ã¹ãã ãšã®çµ±åã«åºã¥ããã©ãã£ãã¯ã åæã«ãNGFWã¯ã1ã€ã®ãœãªã¥ãŒã·ã§ã³ã§IPSãšçµ±åãããŠããªãéåžžã®ãã¡ã€ã¢ãŠã©ãŒã«ãå«ããéé¢ãããäŸµå ¥é²æ¢ã·ã¹ãã ïŒIPSïŒãŸãã¯IPSãšæ··åããªãã§ãã ããã ãã®å®çŸ©ãç°¡åã«ãŸãšãããšã NGFWã¯ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ãã©ãã£ãã¯å¶åŸ¡ãçµ±åãããäŸµå ¥æ€ç¥ã·ã¹ãã ãããã³ãã©ãã£ãã¯ãŠãŒã¶ãŒIDã®èå¥ãåããããã€ã¹ã§ãã
äžéšã§ã¯ãNGFWã³ã³ã»ããã®åºçŸã«ãããdeja vuãå¹æãçºçããNGFWãšUTMïŒUnified Threat ManagementïŒã³ã³ã»ããã«ã¯é¡äŒŒæ§ããããæè¿ã§ã¯äžè¬çã§ãã ãããã¯éåžžã«ãã䌌ãã¢ãããŒãã§ããã1ã€ã®ããã€ã¹ã§åæã«è€æ°ã®ã¿ã€ãã®è åšã«å¯Ÿããä¿è·ãå¹æçã«çµã¿åãããããšããŸãã ãã ãããããã®ããã€ã¹ã¯ã©ã¹ãäžæã«åé¢ããåŸæ¥ã®ã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ïŒä»¥äžãåã«FWïŒããåé¢ã§ããããã«ãã倧ããªéãããããŸãã 以äžã®è¡šã¯ãFWãUTMãNGFWãªã©ã®ããã€ã¹ã®äž»ãªãã©ã¡ãŒã¿ãŒãšäœçœ®ããŸãšãããã®ã§ãã
ãããã£ãŠãUTMãšNGFWã¯ãããŸããŸãªã¿ã€ãã®ã¿ã¹ã¯ã解決ããããã«èšèšãããããŸããŸãªã¯ã©ã¹ã®æ©åšã§ãã GARTNERãäºæž¬ããããã«ããããã¯ãŒã¯ä¿è·ãæäŸããåŸæ¥ã®ããã€ã¹ã®æéã¯ãããããæ°ããã¿ã€ãã®ããã€ã¹ã§ããNGFWã«çœ®ãæããããšã«åŸã ã«è²»ããããŠããŸãã
2013幎ãHPã¯HP TippingPoint次äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ïŒNGFWïŒã®ãªãªãŒã¹ãçºè¡šããŸããã HP NGFWã¯ãäžèšã®æŠå¿µã«åºã¥ããŠæ§ç¯ããããœãªã¥ãŒã·ã§ã³ã®ãããã¯ãŒã¯å¹çãä¿¡é Œæ§ãããã³ã¹ã±ãŒã©ããªãã£ã«é¢ããææ°ã®èŠä»¶ãèæ ®ããŠããããã¯ãŒã¯ã»ãã¥ãªãã£ã®èŠ³ç¹ããããŸããŸãªèŠæš¡ã®äŒæ¥ã®ããŒãºãæºããããã«èšèšãããŠããŸãã NGFWã¯NGIPSãã©ãããã©ãŒã ã«å®è£ ããã7ãã€ã³ïŒ99.99999ïŒ ã®çšŒåæéïŒã®ä¿¡é Œæ§ã§ãããã¯ãŒã¯ã¢ããªã±ãŒã·ã§ã³ãèå¥ããã³å¶åŸ¡ã§ãããããè€éãªãããã¯ãŒã¯ã®è åšã®å®è£ ã«ããäŒæ¥ã®æœåšçãªãªã¹ã¯ã軜æžã§ããŸãã ããã«ãHP TippingPoint補åïŒNGIPSãªã©ïŒãæ¢ã«ã€ã³ã¹ããŒã«ããŠãããŠãŒã¶ãŒããå€æ°ã®NGFWãå±éããäºå®ã®ãŠãŒã¶ãŒã«ãšã£ãŠããã®ãããªäŒæ¥ã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£ã管çããããã«ã»ãã¥ãªãã£ç®¡çã·ã¹ãã ïŒSMSïŒã«åºã¥ããåäžã®éäžã³ã³ãœãŒã«ã䜿çšãããšäŸ¿å©ã§ãã
HP NGFWãœãªã¥ãŒã·ã§ã³ã®æ³šç®ãã¹ãæ©èœã¯ãããŸããŸãªã¡ãŒã«ãŒã®ãœãããŠã§ã¢ã®è匱æ§ãæ€çŽ¢ããããããã«ããŒããé¢é£ã¢ããããŒãããªãªãŒã¹ããæ§é ïŒDVLabsïŒãHPã«ååšããããšã§ãã ä»æ¥ã®DVLabsã®ä»äºã«é¢ããç°¡åãªçµ±èšïŒ
- 8,200+ã®ããã«äœ¿çšå¯èœãªãã£ã«ã¿ãŒ
- é±ã«çŽ20åã®æ°ãããã£ã«ã¿ãŒ
- 12çªç®ã®ãã£ã«ã¿ãŒã¯ãã¹ãŠZero Dayãã£ã«ã¿ãŒã§ã
- 2014幎ã«ãªãªãŒã¹ããã379åã®ãŒããã€ãã£ã«ã¿ãŒ
- 50æ¥éã®ãŒããã€ãã£ã«ã¿ãŒã䜿çšããè匱æ§ã®äºåã®ã«ãã¬ããž
- 10ïŒ ã¢ããªã±ãŒã·ã§ã³ãã£ã«ã¿ãŒ
- æšå¥šèšå®ã§ã¯ããã£ã«ã¿ãŒã®40ïŒ ãããã©ã«ãã§å®è¡ãããŠããŸãã
- 3,000人ã®ç 究è ãHP Security Research Zero Dayã«åå
å€éšã®å°é家ã«ãããã£ã«ã¿ãŒéçºãžã®åå ã«ãããçã«é«å質ã®ãã£ã«ã¿ãŒãéçºã§ããŸãã æ ¹æ¬åå ã«çŠç¹ãåœãŠãããšã«ããããã®ãã£ã«ã¿ãŒã䜿çšãããšãäºåå®çŸ©ããããã³ãã¬ãŒãæ»æãéããŠæŒããè åšãç¹å®ã§ããŸãã ããã«ããã£ã«ã¿ãŒã¯ããã®äœ¿çšããœãªã¥ãŒã·ã§ã³ã®å šäœçãªããã©ãŒãã³ã¹ã«æå°éã®åœ±é¿ãäžããããã«æ§ç¯ãããŠããŸãã
ã¢ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ã®åŠçã«é¢ããŠãHP TippingPoint NGFWã¯ãã¢ããªã±ãŒã·ã§ã³ã¿ã€ãã®ã¬ãã«ãšããŸããŸãªãµãã¿ã€ãã®ã¬ãã«ã®äž¡æ¹ã§ãã©ãã£ãã¯ãå¶åŸ¡ã§ããŸãã åæã«ãHPã¯äŒæ¥ç°å¢ã«é¢é£ããäž»èŠãªããžãã¹ã¢ããªã±ãŒã·ã§ã³ã«çŠç¹ãåœãŠãŠããŸãã 以äžã®ã°ã©ãã¯ããã®ããªã·ãŒãææãäžããŠããããšã瀺ããŠããŸããHPã¯ãã®åéã®ãªãŒããŒã§ãã
ãŒããã€ã€ãã·ã¢ããïŒZDIïŒããã°ã©ã ã«ã€ããŠããããäœã§ããããªããããéèŠã§ãããã«ã€ããŠããã€ãã®èšèãèšã£ãŠã¿ãŸãããã ãŒããã€ã§ã¯ããšã¯ã¹ããã€ãã¯ãµãã©ã€ã€ã«ãŸã ç¥ãããŠããªããœãããŠã§ã¢ã®è匱æ§ã§ããããµãã©ã€ã€ããããèªèããŠä¿®æ£ããããšããåã«ããã«ãŒã«ãã£ãŠæªçšãããå¯èœæ§ã®ããã»ãã¥ãªãã£ããŒã«ã§ãã è匱æ§ãæªçšããè©Šã¿ã¯ç°ãªãããã«ãŠã§ã¢/ã¹ãã€ãŠã§ã¢ãã€ã³ãã©ã¹ãã©ã¯ãã£ã«å°å ¥ããè©Šã¿ããŠãŒã¶ãŒæ å ±ãžã®ã¢ã¯ã»ã¹ã®è©Šã¿ãªã©ãå«ãŸããŸãã è匱æ§ãç¥ããããšããã«ãæ»æè ãšéçºè ã®éã§ç«¶äºãå§ãŸããŸããæ»æè ãšéçºè ã¯ã察å¿ãããœãããŠã§ã¢ãããè¿ éã«ãªãªãŒã¹ããŸãã ãããŠããã®ã¬ãŒã¹ã®ããã«ãŒã¯ãããŸããŸãªçç±ã§åã€ããšããããããŸãïŒéçºäŒç€Ÿã®æ £æ§ããŠãŒã¶ãŒãé©åãªããããããã«ã€ã³ã¹ããŒã«ããªããªã©ïŒã ZDIããã°ã©ã ã«ãããHPã¯ãã®ã¬ãŒã¹ã§äž»å°æš©ãæ¡ããæ»æè ãè匱æ§ãçºèŠããŠå®è£ ããåã«è匱æ§ãæ€åºããŠè§£æ±ºããããç©æ¥µçã«è¡åããããšããŸãã èšäºã®åé ã§èª¬æããSonyã®äºäŸãæãåºããŠãZDIã䜿çšããããšã§äŒæ¥ã®ç©æ¥µçãªé²è¡æŠç¥ãå®è£ ããã®ã«éåžžã«åœ¹ç«ã€å¯èœæ§ããããããããææ°ã®æ»æããã®ãããªå£æ» çãªçµæããããããªãããšã瀺åããŸãã
ãã®ããã°ã©ã ã¯ãæ å ±ã»ãã¥ãªãã£ç 究ã®ç¯å²ãå€§å¹ ã«æ¡å€§ããéåžå Žã«äŸµå ¥ããè匱æ§ã®æ°ãå€§å¹ ã«åæžããŸããã ZDIããã°ã©ã ã®çµæãHPã¯ä»¥äžã®å³ã«ç€ºãããã«ãäž»èŠãªè匱æ§ã¬ããŒã¿ãŒãšããŠèªèãããŠããŸãã
HP NGFW補åã«ã€ããŠããå°ãèªãã§ãã ããã çŸåšãŸã§ã«ãäž»ã«ããã©ãŒãã³ã¹ãç°ãªã5ã€ã®ç°ãªãããã€ã¹ã¢ãã«ã販売ãããŠããŸãã 次ã®è¡šã«ãç°¡åãªä»æ§ãšæšå¥šãããçšéã®ããã€ã¹ã瀺ããŸãã
æ¯åº/å°èŠæš¡ãããã¯ãŒã¯ | äŒæ¥ãããã¯ãŒã¯ | ããŒã¿ã»ã³ã¿ãŒ |
HP NGFW S1050F | HP NGFW S3010F / S3020F | HP NGFW S8005F / S8010F |
1RU
| 2RU
| 2RU
|
500 Mbps
| 1-2 Gbps
| 5-10 Gbps
|
1ç§ããã1äžã®æ°ããæ¥ç¶
| 1ç§ããã20Kã®æ°ããæ¥ç¶
| 1ç§ããã5äžã®æ°ããæ¥ç¶
|
25äžåã®ç«¶åååç©
| 500K / 1Mã®ç«¶åååç©
| 10M / 20Mã®ç«¶åååç©
|
NGFWã®äž»èŠãªæ©èœçç¹åŸŽã以äžã«èŠçŽããŸãã
- ã€ã³ã¹ããŒã«ãèšå®ã管çãç°¡åïŒ
- æ°åã§ã€ã³ã¹ããŒã«ã
- æšå¥šãããIPSèšå®ã䜿çšããŠãèšå®ããŠå¿ãããã
- çŽæçãªWebããŒã¹ã®ã€ã³ã¿ãŒãã§ã€ã¹ã
- SMSã䜿çšããéäžç®¡çïŒ
- 1ã€ã®ã³ã³ãœãŒã«ã§NGFWãšIPSã管çããŸãã
- IPSããã³NGFWããªã·ãŒã®åå©çšã
- è¿ éã§äŸ¿å©ãªã¬ããŒãã
- 䟿å©ãªã€ãã³ãåæã
- RBACããŒã¹ã®ã¢ã¯ã»ã¹ã
- 8,000以äžã®å®çŸ©æžã¿ãã£ã«ã¿ãŒ
- å®è£
ãããæ»æã§ã¯ãªããè匱æ§ã«çŠç¹ãåœãŠã
- ã»ãã¥ãªãã£ç 究ãžã®å€§èŠæš¡ãªæè³ã
- çµã¿èŸŒã¿ã®é«ä¿¡é Œæ§ïŒ7ãã€ã³ïŒIPS
- ããªã·ãŒã®ãµã€ãºã¯ããã©ãŒãã³ã¹ã«å€§ãã圱é¿ããŸãã
- ãã©ãŒã«ããã¬ã©ã³ã¹ïŒã¢ã¯ãã£ã/ããã·ãã¢ãŒãã§ã®äœæ¥ã®ãµããŒãïŒ
ç¶ããŠãããŠããããšãã