ãµã€ããŒæ»æã¯ãããåºç¯ãã€é«åºŠã«ãªãã€ã€ãããŸãã 倧èŠæš¡ãªãµã€ããŒæ»æã®äž»ãªçç±ã®1ã€ã¯ãæé ãªäŸ¡æ Œã§ãã ããšãã°ã2015幎 10æã«çºè¡ããã2015幎ã®ãµã€ããŒç¯çœªèª¿æ»ã«é¢ããã¬ããŒãïŒ HPEãã¹ãã³ãµãŒã®Ponemon Instituteãå®æœããã°ããŒãã«èª¿æ»ã§ã¯ããã·ã¢ã§ã®ãµã€ããŒç¯çœªã®å¹³åè²»çšã¯100ã150ã«ãŒãã«ïŒãã«ïŒãšæšå®ãããŠããŸããèšç®é¢ã§ã¯ã2014幎ã®3.33ãã«ãã2015幎ã®2.37ãã«ã«æžå°ããŸããã
ãµã€ããŒæ»æã«å¯Ÿããä¿è·ã®å¹æãäžååã§ããäž»ãªåé¡ã®1ã€ã¯ãå€ãã®å Žåãæ»æã«å¯Ÿããä¿è·ãæçåãããŠããããã¹ãŠã®ãªã¹ã¯ãé©åã«èæ ®ãããŠããªãããšã§ãã çµéšã瀺ãããã«ãæ å ±ã»ãã¥ãªãã£è³éã®è³Œå ¥ã«å²ãåœãŠãããäºç®ã®çŽ80ïŒ ã¯ããããã¯ãŒã¯ãžã®äŸµå ¥ãé²ãããã®é²æ¢ããŒã«ã®ååŸãšå®è£ ã«è²»ããããŠããŸãã ãããè¡ãã«ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãIPSã·ã¹ãã ãããŸããŸãªã²ãŒããŠã§ã€ãœãªã¥ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ãããŸãã äŸµå ¥åŸãæ å ±ã»ãã¥ãªãã£ããŒã«ã«è²»ããããæ®ãã®20ïŒ ã¯ãæ»æè ã®è¡åããä¿è·ããããã«å¿ èŠã§ãã ISãµãŒãã¹ã®äž»ãªç®çã¯ããã¹ãŠã®æ®µéã§æ»æã«å¯Ÿããå šäœçã§çµ±åãããåäžãªé²åŸ¡ãæäŸããé²åŸ¡ã®å€±æãåé¿ããããšã§ãã
Hewlett Packard Enterpriseã¯ããµã€ããŒæ»æã«å¯Ÿãããã«ãã¬ãã«ã®ä¿è·ãæ§ç¯ããããããåŒãèµ·ããæ害ãæå°éã«æããããã«ãåœéçã«å®èšŒããããœãªã¥ãŒã·ã§ã³ãæäŸããŸãã éåžžã«å¹æçãªè£œåã«å ããŠãHPEã«ã¯ããã«ãŒæ»æããä¿è·ããããã®æ¹æ³è«ããããŸãã ãŠãŒã¶ãŒæ å ±ã·ã¹ãã ã®å æ¬çãªä¿è·ãåºç€ãšããŠäœæããããšã¯ãHPEããŒãããŒã®éèŠãªã¿ã¹ã¯ã§ãã
HPEãœãªã¥ãŒã·ã§ã³ããŒããã©ãªãªã¯ãæ»æè ã«ããæ»æã®æ®µéãäžå¿ã«æ§ç¯ãããŠããŸãã æåã®æ®µéã¯ã被害è ã«é¢ããæ å ±ã®åéã§ããçµç¹ã§äœ¿çšãããŠããIPã¢ãã¬ã¹ããã¹ããããŠãããµãŒãã¹ãä¿è·ãããŠããæ段ãªã©ã§ããæ»æã®2çªç®ã®æ®µéã¯ãæè¡çæ段ãšæ¹æ³ã䜿çšããŠå®è¡ã§ããäŸµå ¥ã§ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãããšãã°ããŠãŒã¶ãŒã«é»è©±ãããããããã£ãã·ã³ã°ã¡ãã»ãŒãžãéä¿¡ãããããŸãã æ»æã®3çªç®ã®æ®µéïŒæ»æè ã¯çµç¹ã®ãããã¯ãŒã¯ã«å ¥ããæå©ã«äœ¿çšã§ããããŒã¿ïŒã¢ã«ãŠã³ãã£ã³ã°ããŒã¿ããŒã¹ãã¯ã©ã€ã¢ã³ãããŒã¿ããŒã¹ãªã©ïŒãæ¢ããŠããŸããããã¯ãåã ã®ä¿è·ããããããã¯ãŒã¯ã»ã°ã¡ã³ãã«äŸµå ¥ããããšããŠããããã§ãã 第4段éïŒæ»æè ã¯ä¿è·ãããã»ã°ã¡ã³ãã«å ¥ãããã«ãŠã§ã¢ãã³ã³ãã¥ãŒã¿ãŒãŸãã¯ãããã¯ãŒã¯ããã€ã¹ã«ã€ã³ã¹ããŒã«ããå¿ èŠãªããŒã¿ãååŸããããšããŸãïŒæå·åãããŠããå Žå-HPEã«ã¯ãã®ããŒã«ããããŸã-å ¥æã¯æ±ºããŠå®¹æã§ã¯ãããŸããïŒ ïŒ æåŸã®5çªç®ã®æ®µé-ããã«ãŒã«ãã£ãŠå¶åŸ¡ããããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã«ããŒã¿ãéä¿¡ããŠãããã«äœ¿çšããïŒããšãã°ã競åä»ç€Ÿã«è²©å£²ãããã被害è ã®è©å€ãæãªãããã«å ¬éããïŒã
HPEã«ã¯ãæ å ±ã»ãã¥ãªãã£ã®è åšãšåŸåãåæããã»ãã¥ãªãã£ç 究ãŠãããããããŸãã æ¯å¹ŽãHPE Security Researchã¯æ å ±ã»ãã¥ãªãã£ã¬ããŒããçºè¡ããŸãããã®ã¬ããŒãã«ã¯ã4ã€ã®åéã§æãé¢é£æ§ã®é«ãäž»èŠãªåŸåããªã¹ããããŠããŸãã
- ã€ã³ã·ãã³ãã®ç£èŠãšå¯Ÿå¿ïŒãŠãŒã¶ãŒã®è¡ååæãå«ãïŒ;
- ãœãããŠã§ã¢ãœãŒã¹ã³ãŒãã®åæã
- ãããã¯ãŒã¯ã»ãã¥ãªãã£ã
- æå·åã
ãããã®ååéã«ã€ããŠãæ å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãéçºããŠããéšéã§ããHewlett Packard Enterprise Securityã®ããŒããã©ãªãªã«ã¯ã察å¿ããåé¡ã®ã°ã«ãŒãã解決ããç¬èªã®è£œåããããŸãã åèšã§ãHPEããŒããã©ãªãªã«ã¯çŽ40åã®æ å ±ã»ãã¥ãªãã£è£œåãå«ãŸããŠããŸãã
HPE ArcSightãã¡ããªãŒã®ãœãªã¥ãŒã·ã§ã³ã«ã¯ã次ã®ã¿ã¹ã¯ãå®è¡ãããã¯ãããžãŒãå«ãŸããŠããŸãã
- æ°ããªæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«é¢ããã€ãã³ãã®åéãçµ±åãçžé¢-HPE ArcSight Enterprise Security Manager / Express / Logger;
- 350ãè¶ ããã€ãã³ããœãŒã¹ãšã®çµ±åãããã³ä»ã®ã·ã¹ãã ãæ¥ç¶ããããã®äŸ¿å©ãªSDK-HPE ArcSight Smart / FlexConnectors;
- å€æ°ã®æšæºçžé¢ã«ãŒã«ãšCompliance Insightããã±ãŒãžã䜿çšããè åšã®èª¿æ»ãšã¿ã€ã ãªãŒãªæ€åºã
- ããããã¿ã€ãã®ã€ãã³ãã®è¡ååæ-HPE ArcSight ThreatDetector;ãŠãŒã¶ãŒè¡åã®åæ-HPE ArcSight User Behavior Analyticsã«ããå éšäŸµå ¥è ã®ã¢ã¯ãã£ããã£ã®ç£èŠã
- HPE ArcSight Reputation Security Monitorãµãã¹ã¯ãªãã·ã§ã³ã¯ãäŒæ¥ãããã¯ãŒã¯ãžã®äŸµå ¥ãæ©å¯ããŒã¿ã®æŒããã®æ€åºãé²ãããã«ãçŸåšã®æ å ±ã»ãã¥ãªãã£ã®è åšã«é¢ããã¢ã©ãŒããåãåããŸãã
- å±éãããHPE ArcSightã€ã³ãã©ã¹ãã©ã¯ãã£ã®éäžç®¡ç-HPE ArcSight Management Centerã
- ã€ã³ã·ãã³ã調æ»äžã®äººçããã³æéçãªãœãŒã¹ãšã®æŠã-HPE ArcSight Risk Insightã
ArcSightãã¡ããªã«ã¯ã12ãè¶ ããããŸããŸãªè£œåãå«ãŸããŠããŸãã 2007幎ãããã·ã¢ã§äœ¿çšãããŠããŸãã ArcSightãŠãŒã¶ãŒã¯ããã·ã¢ã®äžäœ100éè¡ã®çŽååãã»ãŒãã¹ãŠã®äž»èŠãªéä¿¡äŒç€Ÿãããã³äžäœ20ã®äž»èŠãªã€ãã³ãç£èŠããã³ã€ã³ã·ãã³ã管çã»ã³ã¿ãŒïŒSOCïŒã®çŽ15ã§ãã ArcSightã¯ãå€ãã®ãã·ã¢ã®ã·ãã¥ãšãŒã·ã§ã³ã»ã³ã¿ãŒã§ã䜿çšãããŠããŸãã
ããåœã«ã¯200人以äžã®ArcSightèªå®ã¹ãã·ã£ãªã¹ããããŸãïŒæªèªå®ããããã10å以äžïŒã ããã«ãèªå®ãã¬ãŒãã³ã°ã»ã³ã¿ãŒãšArcSightãå®è£ ããHPEããŒãããŒã®ãšã³ã·ã¹ãã ããããããšãã°ãSolar Securityã¯ArcSight補åãã¡ããªã䜿çšããŠé¡§å®¢ã«æ å ±ã»ãã¥ãªãã£ãµãŒãã¹ãæäŸããŠããŸãã
ãã®æ å ±æè¡ãã¯ãããžãã¡ããªã®äººæ°ã®ãã1ã€ã®éèŠãªçç±ã¯ãArcSight補åãã¡ããªã«ã¯å€æ°ã®é¡§å®¢çµç¹ã®çµéšãšãã®å°é家ã®çµéšãçµã¿èŸŒãŸããŠãããããArcSightãšé£æºããããšã§ãITããã³æ å ±ã»ãã¥ãªãã£ã®å°é家ãå°éçã¬ãã«ãå€§å¹ ã«åäžã§ããããšã§ãã
Hewlett Packard Enterprise Securityã¯ãArcSightã«å ããŠããœãŒã¹ã³ãŒãéçºã®æ®µéã§ã¢ããªã±ãŒã·ã§ã³ãå æ¬çã«ä¿è·ãã匷åãªãœãªã¥ãŒã·ã§ã³ãã¡ããªãŒããã®éçåæããã§ã«ã³ã³ãã€ã«ãããã¢ããªã±ãŒã·ã§ã³ïŒHPE FortifyïŒã®ä¿è·ã·ã¹ãã ã®æŽåæ§ã®åçåæãããã³äžé£ã®äŸµå ¥é²æ¢ããŒã«ïŒäŸµå ¥é²æ¢ïŒãæäŸããŸãã·ã¹ãã ãIPSïŒããã³ãããã¯ãŒã¯è åšä¿è·-HPE TippingPointãããã³ããŸããŸãªæå·åããŒã«ã
ãã®èšäºã§ã¯ãArcSightãã¡ããªã®3ã€ã®è£œåãEnterprise Security ManagerïŒESMïŒãDNS Malware AnalyticsïŒDMAïŒãããã³User Behavior AnalyticsïŒUBAïŒã«çŠç¹ãåœãŠãŸãã
HPE ArcSight Enterprise Security Manager
HPE ArcSight ESMã®æ©èœã¯ãåŸæ¥ã®ã»ãã¥ãªãã£æ å ±ããã³ã€ãã³ã管çïŒSIEMïŒã·ã¹ãã ãã¯ããã«è¶ ããŠããããã·ã¢ã§ã®ãã®è£œåã®äœ¿çšçµéšã瀺ãããã«ãå€ãã®ç°ãªãå®çšçãªåé¡ã解決ããããã«äœ¿çšã§ããŸãã ããšãã°ãéè¡ã·ã¹ãã ã®éèååŒãERPã·ã¹ãã ã®ããžãã¹ã·ããªãªã®ç£èŠãåäžã®ãšã³ã¿ãŒãã©ã€ãºç®¡çã³ã³ãœãŒã«ãžã®çµ±åãªã©ã«äœ¿çšã§ããŸããå€ãã®å ŽåãArcSight ESMã¯ãèŠå¶èŠä»¶ãžã®ã³ã³ãã©ã€ã¢ã³ã¹ã®ç¢ºä¿ãå«ããªã¹ã¯ç®¡çã¿ã¹ã¯ã§äœ¿çšãããŸãã
ãã ããESMã¯ãããã«ãŒæ»æã®èå¥ãšæéãããã³ãããããã®çµæã®é²æ¢ãç®çãšããã·ã¹ãã ã§æããã䜿çšãããŸãã ãã®ãããªæªæã®ããã¢ã¯ã·ã§ã³ãåå ã§ãå€ãã®é害äºäŸãç¥ãããŠããŸãã ãããã®å€ãã¯ããŸãã€ã³ã¹ããŒã«ããããœãããŠã§ã¢ã®æªæã®ããã³ãŒããè匱æ§ããã§ãã¯ãã次ã«æ å ±ã·ã¹ãã å ã®ãœãããŠã§ã¢è£œåã®åäœãç¶ç¶çã«ç£èŠããããšã«ãããé¡èãªæ害ãåŒãèµ·ããåã«é²æ¢ãŸãã¯æå¶ã§ããŸãã æ·±å»ãªæªæã®ããã¢ã¯ã·ã§ã³ãéå§ãããåã«ãããã«ãŒãã·ã¹ãã ã«äŸµå ¥ããŠããããªãã®æéãçµéããå¯èœæ§ãããããšã¯åšç¥ã®äºå®ã§ãã ãããã£ãŠãPonemon InstituteïŒå³3ãåç §ïŒã«ãããšãæªæã®ããã³ãŒãã®äŸµå ¥ããæå¶ãŸã§ãæªæã®ããã€ã³ãµã€ããŒã®æŽ»åã®éå§ããæå¶ãŸã§ãå¹³åã§çŽ1ãæãçŽ2ãæããããŸãã ãã®éãESMã䜿çšããŠããã°ã©ã ã®åäœã®éžè±ã远跡ããã·ã¹ãã 管çè ã«éç¥ããããšãã§ããŸãã
ESMã¯ãæ å ±ã»ãã¥ãªãã£ã€ãã³ãã®ã³ã¬ã¯ã·ã§ã³ã ãã§ãªãããããã®ã€ãã³ãã®çžé¢é¢ä¿ã®åæãªã©ãä»ã®å€ãã®çš®é¡ã®åŠçãæäŸããŸãã ESMã¯ãæ å ±ã ãã§ãªãç©ççãªã»ãã¥ãªãã£ã¿ã¹ã¯ãèªååããããã®ãã©ãããã©ãŒã ãšèããããšãã§ããŸãïŒESMã¯ãæ å ±ã»ãã¥ãªãã£ã«çŽæ¥é¢é£ããªãITã€ãã³ããç£èŠãããããã«å¯ŸæããåŸæ¥ã®è åšãšããŒã«ã«é¢ããæ å ±ãåéããããã«äœ¿çšã§ããŸãã ããšãã°ãç£èŠãKPIæ å ±ã»ãã¥ãªãã£èšå®ãªã©ã劚ãããã®ã¯ãããŸããã察å¿ããããžãã¯ã補åã«çµã¿èŸŒãããšãã§ããŸãã ã¢ã³ããŠã€ã«ã¹ã·ã¹ãã ããæ å ±ãåéããå ŽåãäŒæ¥ã«ããã€ã®ã¿ã€ããå±éãããŠãããã¯é¢ä¿ãããŸããã ãŠã€ã«ã¹å¯Ÿç補åã®ç°çš®ç°å¢ã§ç¶æ³ãç£èŠããããšã劚ãããã®ã¯äœããããŸãããKPIã¯åäžã«è©äŸ¡ãããéžæããKPIã®ã³ã³ããã¹ãã§çŸåšã®ç¶æ³ã ãã§ãªããããšãã°1幎ãŸãã¯2幎åã«çºçããç¶æ³ãåæã§ããŸã-ããã¯ã KPIãã€ããã¯ã¹åæãšåŸååæã
ããã«ãESMã¯ãERPã·ã¹ãã ãªã©ã®ããžãã¹ã¢ããªã±ãŒã·ã§ã³ããã®æ å ±ãåæããããšã«ãããäžæ£è¡çºããä¿è·ããããã«äœ¿çšã§ããŸãã æ€åºããžãã¯ã圢åŒåã§ããå Žåããã®å ŽåãããããESMã«é 眮ããããšãå¯èœã§ãã
ESMã§å€§éã®ããŒã¿ãä¿åããã³åŠçããã«ã¯ãHPE Vertica DBMSãã©ãããã©ãŒã ã䜿çšããŠãã»ãã¥ãªãã£ã¢ããªã¹ããäœæããæ€çŽ¢ã¯ãšãªã®å®è¡ãå€§å¹ ã«å éã§ããŸãã ArcSightãšVerticaã®çµ±åã¯ãæ å ±ã»ãã¥ãªãã£ã€ãã³ãã®ç£èŠã ãã§ãªããããšãã°Verticaã«ããŒã¿ãä¿åããããžãã¹ããã»ã¹ã®ã€ãã³ãã®è¿œè·¡ãç¹ã«äžæ£è¡çºã®é²æ¢ã«ã䜿çšã§ããŸãã ã·ã¹ãã çµ±åçšã®ç¹å¥ãªã³ãã¯ã¿ããããŸãã
HPE ArcSight DNS Malware Analytics
9æãæ¯å¹Žéå¬ãããHPE ProtectäŒè°ã§ããããã¯ãŒã¯ãã©ãã£ãã¯ãç£èŠããããã§çºçããDNSãã¡ã€ã³ããŒã ã·ã¹ãã èŠæ±ãåæããããã«èšèšãããæ°ããçµ±åããŒããŠã§ã¢ããã³ãœãããŠã§ã¢ãœãªã¥ãŒã·ã§ã³-HPE ArcSight DMAãçºè¡šãããŸããã ã¯ãŒã¯ã¹ããŒã·ã§ã³ãã¢ãã€ã«ã¬ãžã§ãããªã©ãæªæã®ããã³ãŒãããããã¯ãŒã¯ããŠãŒã¶ãŒããã€ã¹ã«ææãããµãŒããŒãè¿ éãã€æ£ç¢ºã«æ€åºããDNSãã©ãã£ãã¯ãåæããŠããµãŒããŒããããã¯ãŒã¯æ©åšããããã¯ãŒã¯ã«æ¥ç¶ãããããã€ã¹éã移åãããäžè¯ããã±ããããªã¢ã«ã¿ã€ã ã§æ€åºããŸãã ããã«ãããäŒæ¥ã¯ãããŸã§æªç¥ã®æ°ããè åšããè¿ éã«é²åŸ¡ããããšãã§ããŸããããã¯ãããžãã¹ã¢ããªã±ãŒã·ã§ã³ãã·ã¹ãã ãããã³ããŒã¿ã«æ倧ã®ãªã¹ã¯ããããããããéèŠã§ãã DMAã䜿çšãããšããŠãŒã¶ãŒã¯ãDNSã·ã¹ãã ãã°ãã倧éã®ããŒã¿ãåæããããã®è¿œå äœæ¥ã«ãããSIEMã·ã¹ãã ã«éè² è·ããããããšãªãè åšãèå¥ã§ããŸãã
DMAã®æ žå¿-äžèŠãè¡šé¢äžã«ããããã«èŠããã¢ã€ãã¢-ã¯ãHP Labsã®ã»ãã¥ãªãã£å°é家ã®1人ã«ãã£ãŠè¡šçŸãããŸããïŒDNSã¯ãã³ã³ãã¥ãŒã¿ãŒãããã¯ãŒã¯ã«å¯Ÿããã»ãŒãã¹ãŠã®æ»æã§äœ¿çšãããŸãïŒç¹ã«ãæ¥ç¶ã転éãä¿èšŒããããã«ïŒã³ãã³ããŸãã¯æ»æè ã«ãã£ãŠéä¿¡ããããã³ããªã³ã°ããŒã¿ïŒãããã³DNSã¯ãšãªãèªèããããã«ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã«æãããšãããã«ãŒæ»æã«é¢é£ããå¯èœæ§ã®ãããã®ãèå¥ã§ããŸãã
ãã®ãããªã·ã¹ãã ã®å®éšã¢ãã«ã¯ãHP Labsã§äœæããã365,000人ã®HPããã³HPEåŸæ¥å¡ã®ããã€ã¹ããæ å ±ã»ãã¥ãªãã£ã€ãã³ãã«é¢ããæ å ±ãåéããã³åæããã«ãªãã©ã«ãã¢å·ã®æ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ã管çã»ã³ã¿ãŒã§ããHP SOCã«å±éãããŸããã 1幎以äžã®æ £ããé転ã®éçšã§ãã·ã¹ãã ããã¬ãŒãã³ã°ãããå¿ èŠãªæç床ã«éããåŸãç¬ç«ãã補å-DMAãšããŠåžå Žã«æå ¥ãããŸããã ãã³ãã¬ãŒããšåæããŒã¹ã¯HPEããååŸãããŸãã
補åã®é¡§å®¢ã¯ããããã¯ãŒã¯ã¢ã¯ãã£ããã£ã®èŠèŠåãããç»åã衚瀺ããç¹ã«çãããã¢ã¯ãã£ããã£ã®ããã³ã³ããŒãã³ããèå¥ããWebã€ã³ã¿ãŒãã§ãŒã¹ãèªç±ã«åãåããŸãã å®éããèµ€ããã¿ã³ãã®æŠå¿µãå®è£ ããŠããããããŠãŒã¶ãŒåŽã§ã»ãšãã©åŽåããããããšãªãããã«ãŒã®æ»æãæ€åºã§ããŸããæ»æãæéããããšã¯ã§ããŸãããéå§ã远跡ããããšã¯ã§ããŸããã
éåžžã«éèŠãªç¹æ§ã¯ã補åã®ã¹ã±ãŒã©ããªãã£ã§ãã HPE SOCã§ã¯ãæ¯æ¥çŽ200åã®DNSã¯ãšãªãåŠçãããŸããããã¯ã倧èŠæš¡ãªéä¿¡äŒç€Ÿã®ãã©ãã£ãã¯ã«å¹æµãããã©ãã£ãã¯ã§ãããéåžžã«é«ãã¹ã±ãŒã©ããªãã£ã瀺ããŠããŸãã
HPE ArcSightãŠãŒã¶ãŒè¡ååæ
åŸæ¥ã®SIEMã·ã¹ãã ã䜿çšããå Žåãæ å ±ã»ãã¥ãªãã£ã®å°é家ã¯éåžžã次ã®ããã«è¡åããŸããæ¢ç¥ã®ã€ã³ã·ãã³ãã®å åãåãåããçžé¢ã«ãŒã«ã®ããžãã¯ã®åœ¢åŒã§ããããé 眮ãããããã®ã«ãŒã«ã«åŸã£ãŠããŒã¿ãããŒãç£èŠããŸãã ã€ã³ã·ãã³ãã®å åãæ€åºããããšã矩å管çè ã®ã¢ã©ãŒããŸãã¯éç¥ãããªã¬ãŒããããã®åŸã€ã³ã·ãã³ãåŠçãæåãŸãã¯èªåã§éå§ãããŸãã ãã®ææ³ïŒç¹ã«äžè¬çãªãã®ããïŒã¯ãç¹ã«æªæã®ããã¢ã¯ãã£ããã£ã®å åãäºåã«ç¹å®ã§ããªãå Žåã«ãåžžã«é©çšã§ãããšã¯éããŸããã
HPE ArcSight UBAã§èŠå®ãããŠããã¢ãããŒãã¯ãå察æ¹åãžã®åããæå³ããŸãããŠãŒã¶ãŒã¢ã«ãŠã³ãã¯ããã®å žåçãªåäœã®ãã¿ãŒã³ãå«ãã¢ã«ãŠã³ããšç£æ»ã€ãã³ãã«åºã¥ããŠæ§ç¯ããããã®åŸãã€ãã³ãã®ç£èŠäžã«ãã¢ããªã±ãŒã·ã§ã³ãšããŒã¿ãæäœãããšãã«éå®åã®ãŠãŒã¶ãŒåäœãæããã«ãªããŸãã
2015幎4æã«ãªãªãŒã¹ãããUBA補åã䜿çšãããšãããŒã¿ããŒã¹ããã¡ã€ã«ãã£ã¬ã¯ããªãžã®ã¢ã¯ã»ã¹ããªã ãŒããã«ã¡ãã£ã¢ã®æäœãäŒæ¥æ å ±ã·ã¹ãã ã®æäœïŒèª²éãæ¯æããããã¥ã¡ã³ããããŒãå人ããŒã¿ã®æäœïŒãªã©ããŠãŒã¶ãŒã¢ã¯ãã£ããã£ã«é¢é£ããã€ãã³ããåæã§ããŸããããã«ãåä¿¡ããã€ãã³ãã«åºã¥ããŠã¢ã¯ãã£ããã£ããããã¡ã€ãªã³ã°ããããã®æ¢è£œã®æ°åŠã¢ãã«ã«åºã¥ãUBAã¯ãåãã¿ã€ãã®ã€ãã³ãã®ã°ã«ãŒãåïŒãã¢ã°ã«ãŒãåæïŒãç°åžžã®çºèŠïŒç°åžžæ€åºïŒã決å®ãå¯èœã«ããŸã ãŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ïŒããŒã¹ã©ã€ã³ãããã¡ã€ã«ïŒã®ãããã¡ã€ã«ã¯ãã€ãã³ãïŒã€ãã³ãåžå°ïŒã®åºçŸé »åºŠã決å®ããŸãã æ°åŠã¢ãã«ã®çµæãISã¿ã¹ã¯ã«é©çšããããšã§ãUBAã¯ã€ã³ãµã€ããŒã®èå¥ãç¹æš©ãŠãŒã¶ãŒã®å¶åŸ¡ãäŒæ¥ã·ã¹ãã ã§ã®ç°åžžãªã¢ã¯ãã£ããã£ã®æ€åºïŒãç ã£ãŠããã¢ã«ãŠã³ãããVIPã¯ã©ã€ã¢ã³ãã«ãŒããžã®ã¢ã¯ã»ã¹ã®æ€åºãªã©ïŒãå¯èœã«ããŸãã
éèŠãªã®ã¯ãUBAã䜿çšãããšããŠãŒã¶ãŒããŠãŒã¶ãŒã®äœæ¥ç°å¢ãè·è²¬ãããã³ãã®ä»ã®å±æ§ã«é¢ããæ å ±ã§ã»ãã¥ãªãã£ã€ãã³ããè£å®ã§ããããšã§ãã ã€ãã³ãã«IPã¢ãã¬ã¹ã®ã¿ãå«ãŸããŠããå Žåã§ããUBAã䜿çšããŠããã®ã€ãã³ãã«é¢é£ä»ããããŠããå®éã®ãŠãŒã¶ãŒåãç¹å®ã§ããŸãã ãããã£ãŠãUBAã䜿çšãããšãçŸåšã®ãã¹ãŠã®å±æ§ïŒéçšããã³è§£éã®æ¥ä»ãäœçœ®ããŠããããå°åãªã©ïŒããã³äŒæ¥ã·ã¹ãã ã®ã¢ã«ãŠã³ããèªåçã«ãµããŒããããããŠãããŒãµã«ããŠãŒã¶ãŒã«ãŒããäœæã§ããŸãã
ãã®æ å ±ã«åºã¥ããŠãããŸããŸãªISã€ã³ã·ãã³ããæ€åºããŠãããšãã°ååã®ã¢ã¯ãã£ããã£ãšã¯å€§å¹ ã«ç°ãªããŠãŒã¶ãŒã®ã¢ã¯ãã£ããã£ãæ€åºã§ããŸãã ããšãã°ãéè¡ã®ãªãã¬ãŒã¿ãŒã¯ã1æ¥ãããå¹³å20ã®ã¯ã©ã€ã¢ã³ããéããŸãã ãã ãããªãã¬ãŒã¿ãŒã®1人ã200ã®ã¯ã©ã€ã¢ã³ãã®ããã¥ã¡ã³ããéããŸããã ãã®ãããªéå žåçãªãŠãŒã¶ãŒã®è¡åã¯ãäœãèµ·ãã£ãŠããã®ããèããååãªçç±ã§ãã ãã®ç¹å®ã®ãªãã¬ãŒã¿ãŒãä»ã®ãªãã¬ãŒã¿ãŒã®10åã®ããã¥ã¡ã³ããå¿ èŠãšããã®ã¯ãªãã§ããïŒ ãã¶ãã圌ã®äžåžã¯åœŒã«ããã€ãã®å žåçãªä»äºãåŸãã®ã§ããããïŒ ãŸãã¯ããã®ãªãã¬ãŒã¿ãŒã¯ç æ°ã®ãã¹ã®è² æ ãå²ãåœãŠãããŸãããïŒ ãŸãã¯ã解éã®æºåãšããŠããªãã¬ãŒã¿ãŒã¯éè¡ã®é¡§å®¢ã«é¢ããæ å ±ãèªåã®ééæ¥è ã«ã³ããŒãå§ããŸãããïŒãŸãã¯é»è©±ã§åçãæ®ããŸãããïŒïŒ æçµçãªçµè«ã¯ãå éšèª¿æ»ãè¡ãããšã§äœæã§ããŸãã
å¥ã®äŸïŒéè¡ãŸãã¯éä¿¡äºæ¥è ã®è£œåã®1ã€ã§è¡ããããã©ã³ã¶ã¯ã·ã§ã³ã®éããèšç®ãããæéïŒæéãææ¥ãæãæãé±æ«ãªã©ïŒã§é垞芳å¯ãããå€ãè¶ ããŠãã-ããã¯ããã®ã¢ã¯ãã£ããã£ãé ãããŠãããã©ãããèããæ©äŒã§ãããã«ãŒãŸãã¯ã€ã³ãµã€ããŒè©æ¬ºåž«ã
ã©ã¡ãã®å ŽåããUBAã¯éå žåçãªãŠãŒã¶ãŒã®è¡åã䜿çšããããšãéèŠã§ãããŸãã¯ããŠãŒã¶ãŒããããç¹å®ããããã調ã¹ãããšãã§ããŸãã
ãã¡ããããŠãŒã¶ãŒãšããã°ã©ã ã®åäœã远跡ãããã€ããã¯ã¹ãè©äŸ¡ããŠããããã®äžéšã®éå®åçãªåäœãèå¥ããããšãã§ããç£èŠããŒã«ã¯ã以åã«å®è¡ã§ããã¯ãã§ãã UBAã®å©ç¹ã¯ããã®ããŒã«ã«ããã¯ããã«ç°¡åã«ãªã£ãããšã§ãã ããšãã°ãåŸæ¥ã®SIEMããŒã«ã§ãŠãŒã¶ãŒã®è¡åãåæããæ©èœãå®è£ ããããšãããšãå€ãã®èŠå¶ãšè·åå 容ã調æ»ããå¿ èŠããããŸããããå€ãã®å ŽåãåŸæ¥å¡ãè·åå 容ãå³å¯ã«éµå®ããŠããããã§ã¯ãªãã -第äºã«ãèŠåã¯ãååãšããŠãããŸãã«ã詳现ã§ã¯ãªããèŠåã®åªå é äœãšåŒ·èª¿ã®é 眮ã¯éåžžèŠãããšãã§ããŸããïŒç¹ã«ã決å®ããããšã¯äžå¯èœã§ãïŒ AKã¯ããããé£åããæ å ±ã·ã¹ãã ã®èŠ³ç¹ãããçµç¹å ã®åŸæ¥å¡ã®äž»ãªæŽ»åãïŒã®ããã«ãªããŸãã UBAã䜿çšãããšãäœçœ®ãšãžã§ãã°ã«ãŒãããšã«åé¡ããŠãŠãŒã¶ãŒã®è¡åãããã¡ã€ã«ãäœæããäŒç€Ÿã®æ å ±ã·ã¹ãã ã«åæ ããããŠãŒã¶ãŒã®è¡åã«é¢é£ããã€ãã³ããç£èŠå¯Ÿè±¡ãã©ã¡ãŒã¿ãŒã®ãªã¹ãã«å«ããŠãéåžžã®è¡åããã®éžè±ã远跡ã§ããŸãã éèŠãªããšã¯ããã®ããã«ããŠãå éšãŠãŒã¶ãŒã ãã§ãªãå€éšãŠãŒã¶ãŒãå¶åŸ¡ã§ããããšã§ã-ããšãã°ããªã¢ãŒããã³ãã³ã°ãµãŒãã¹ã®ãããã³ã°ã·ã¹ãã ããã°ãããããã³ã°ããããéä¿¡äŒç€Ÿã®ã¯ã©ã€ã¢ã³ããã¢ã«ãŠã³ãã«éæ³ã«æ¥ç¶ãããã§ããŸãã
ãã ããååãšããŠãæ倧ã®æ倱ã¯ã€ã³ãµã€ããŒãµã€ããŒç¯çœªè ã®è¡åã«é¢é£ããŠãããã€ã³ãµã€ããŒã®å°äœãé«ãã»ã©ã圌ã®è¡åãéããŠããå€ãã®æ害ãäžããå¯èœæ§ããããŸãã çŸåšãHPEã¯ãäž»èŠãªERPãCRMãSCMã·ã¹ãã ã®éçºè ãšååããŠãã€ã³ãµã€ããŒä¿è·ã·ã¹ãã ãéçºããå ¬çå°äœãæ±è·ãè©æ¬ºãçµæžã¹ãã€ãªã©ã®æªçšã®ãªã¹ã¯ãäœæžããŠããŸããããã«ãHPEã¯ãã€ã³ââãµã€ããŒä¿è·ã·ã¹ãã ã®æ§ç¯çµéšãããŒãããŒãšåãã§å ±æããŠããŸãããŸããŸãªç£æ¥ããã³ã»ã¯ã¿ãŒã®çµç¹ã
* * *
HPE ArcSight ESMãDMA UBA補åã¯ãäŒæ¥ããã®ããŒãããŒãããã³é¡§å®¢ãåãããªã¹ã¯ãå€§å¹ ã«æå°éã«æããããšãã§ãããšã³ã¿ãŒãã©ã€ãºã·ã¹ãã ãšããŒã¿ã®ã»ãã¥ãªãã£ãå€§å¹ ã«åäžãããŸãã æãéèŠãªããšã¯ãçããã掻åãã¿ã€ã ãªãŒã«ç¹å®ããITã·ã¹ãã ã®ã®ã£ãããèŠã€ããããšã«ãããæªç¥ã®è åšããªã¹ã¯ã«ããæ害ãé²ãã®ã«åœ¹ç«ã¡ãŸãã ãããã®è£œåã¯ãã¹ãŠãæ å ±ã»ãã¥ãªãã£ã®åéã§ã®æè¿ã®èª²é¡ã«å¿ããŠç»å ŽããHPEã®ã客æ§ãããžãã¹ã®ç©ããã§å®å šãªéå¶ã確ä¿ããã®ã«åœ¹ç«ã¡ãŸãã
252瀟ã§æ€åºãããæ»æã®çš®é¡ïŒ
åºå žïŒPonemon Instituteãã2015幎ã®ãµã€ããŒç¯çœªèª¿æ»ïŒã°ããŒãã«ãã2015幎10æ
ãµã€ããŒæ»æã«ãããããçµæãšããŠå¹Žéã«çºçããå¹³å被害é¡ïŒ
åºå žïŒPonemon Instituteãã2015幎ã®ãµã€ããŒç¯çœªèª¿æ»ïŒã°ããŒãã«ãã2015幎10æ
æå¶åã®æ»æã®å¹³åæéïŒæ¥æ°ïŒïŒ
åºå žïŒPonemon Instituteãã2015幎ã®ãµã€ããŒç¯çœªèª¿æ»ïŒã°ããŒãã«ãã2015幎10æ