äœã«è³ããŸããïŒ éãŸãã¯ä»®æ³ïŒ
ã©ã®æé ã§ãããééããªãä»®æ³ãã·ã³äžã§ããèªãããšã«ãªããŸãã ç§ã®çãã¯ããééããªãéã®äžã«ãã§ãã äž¡æ¹ã®çããæ£ããã§ãã ãªãã§ïŒ
OSSIMã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšããã³ãã«ããããŠã€ã³ã¹ããŒã«ãããã€ã¡ãŒãžã®ãããã£ã¹ã¯ã«ã¯ããŒããŠã§ã¢ã«å¿ èŠãªãã©ã€ããŒãå«ãŸããŠããªãå¯èœæ§ããããããæåã®çãã¯æ£ããã§ãã ããã«ééããå Žåãããã¯ããªãã®åé¡ã«ãªããŸããããªãã¯èªåã§è§£æ±ºããå¿ èŠããããŸãã ä»®æ³ãã·ã³ã«ã€ã³ã¹ããŒã«ãããšãããã€ãã®æ±çšæ§ãæäŸãããåé¡ã¯çºçããŸããã ããã«ãæŽæ°åŸã«åé¡ãå床解決ããå¿ èŠããªããšããä¿èšŒã¯ãããŸããã ã¢ãã©ã€ã¢ã³ã¹ãšããŠè²©å£²ãããããã«å¿ããŠãµããŒããããå ¬åŒã®åçšãããŒããŠã§ã¢å®è£ ãããããŸãããããã§ã¯ãªãŒãã³ãœãŒã¹OSSIMã«æ³šç®ããããã§ãã¹ãŠã®ããŒããŠã§ã¢ã®åé¡ã¯ããªãã®åé¡ã§ãã
ãã€ããŒãã€ã¶ãŒã¯ãã¬ãŒããªã®ã§ã2çªç®ã®çãã¯æ£ããã§ãã ãŠãããŒãµã«ä»®æ³åã®æ¯æè ã¯ãå¿ èŠãªã ããã©ã³ãããã鳎ããããã©ã ããŠã§ãŒããã©ã°ãæã¡è² ããããšãã§ããŸããããã€ããŒãã€ã¶ãŒã¯ã²ã¹ãã·ã¹ãã ã®ããã©ãŒãã³ã¹ãå€§å¹ ã«äœäžãããŸãã éåžžãããã¯ç¡èŠã§ããŸãããOSSIMã¯é床ã倧奜ãã§ãã ãã®çµæã4ã³ã¢ã¢ãã ã16 GB DDR3ããã³128 GB SATA3 SSDãåãããã¢ã³ã¢ããã³ã³ãã¥ãŒã¿ãŒã«ãããHP dl380äžã®ä»®æ³ãã·ã³ã容æã«ãªããŸãã ç©çãã·ã³ãå¿ èŠãšãããããã¯ããã«å€ãã®ãªãœãŒã¹ãä»®æ³ãã·ã³ã«æäŸããå¿ èŠããããŸãã ãããŠãããã¯ãã£ãšè²»çšãããããŸãã ãã©ã€ããŒã«ã€ããŠã¯ãã€ã³ã¹ããŒã«äžã«ãå¿ èŠã«å¿ããŠãã©ã€ããŒä»ãã®USBãã©ãã·ã¥ãã©ã€ããæ¿å ¥ããããã«æ±ããããŸãã
éèŠã§ãã ã¢ã€ã¢ã³ãã·ã³ã§ã¯ãã€ã³ã¹ããŒã©ãŒã¯èµ·åå¯èœãªCDããã®ã¿èµ·åããŸãã ã€ã¡ãŒãžãUSBãã©ãã·ã¥ãã©ã€ãã«ã¢ããããŒããããšãOSSIMã¯ã€ã³ã¹ããŒã«ãããŸããããDebianãã€ã³ã¹ããŒã«ã§ããŸãã
ãšãŠãéèŠã§ãã åäœäžã®ã³ã³ãã¥ãŒã¿ãŒã«OSSIMãã2çªç®ã®ã·ã¹ãã ããšããŠã€ã³ã¹ããŒã«ããªãã§ãã ããã ã€ã³ã¹ããŒã©ãŒã¯ãèªåã裞ã®ãã·ã³ã«çœ®ãããŠãããšä¿¡ããŠãããããã£ã¹ã¯ãããŒãã£ã·ã§ã³åå²ããæ¹æ³ããšããã°ããã質åãããŸããã ãŸã第äžã«ãå°ããããšãªãã圌ã¯ããŒãã£ã·ã§ã³ããŒãã«ãäžæžããããã£ã¹ã¯ããã©ãŒãããããŸãã
OSSIMã®ã€ã³ã¹ããŒã«ã«ã¯ãã15åãããããŸããã ãã£ãšé·ãã æåŸã®æ®µéã§ã¯ãã€ã³ã¹ããŒã©ãŒãããªãŒãºãããã¹ãŠããªããªã£ããšèããããšããã§ããŸãã ã¡ãã£ãšåŸ ã£ãŠ 圌ã¯åããŠããŸãã
éèŠåºŠã®é«ãé ã«OSSIMã®æãéèŠãªãªãœãŒã¹
ãã£ã¹ã¯ãµãã·ã¹ãã ã®é床ã SSDãæ£ãã䜿çšããŠãã ããã ããªã¥ãŒã ã¯éèŠã§ã¯ãããŸããã 100GBã§ååã§ãã ããããé床ã¯éåžžã«éèŠã§ãã ããã«ã¯2ã€ã®çç±ããããŸãã ãŸããsyslogã«éä¿¡ãããOSSIMãã©ã°ã€ã³ã«ãã£ãŠèªã¿åãããããã¹ããã°ã 次ã«ãåããã·ã³ã§å®è¡ãããããŒã¿ããŒã¹ã SSDã¯ã·ã¹ãã ã®ããã©ãŒãã³ã¹ãåçã«æ¹åããŸãã
ããã»ããµã³ã¢ã®æ°ã åã³ã¢ã®ããã©ãŒãã³ã¹ã¯ããã®æ°ã»ã©éèŠã§ã¯ãããŸããã OSSIMã¯éåžžã«ç°¡åãªæäœãå®è¡ããŸãããäžåºŠã«å€ãã®æäœãããã䞊è¡ããŠå®è¡ã§ããŸãã ãŸãããåç¥ã®ããã«ããããã¯ãŒã¯IDSïŒSuricataïŒã«ãšã£ãŠãéèŠã§ãã
RAMã®éã ããã»ã©éèŠã§ã¯ãããŸããããããŒãžãã¡ã€ã«ã«äœãããã·ã¥ããªãæ¹ãè¯ãã§ãã
ãã°å ã®200äžã€ãã³ããšãå€èªäžèœãã€ã³ã¿ãŒãã§ã€ã¹äžã®10ãã©ãã€ãã®ãã©ãã£ãã¯ã®æ¯æ¥ã®ã¹ããªãŒã ã«åºã¥ãä»®æ³ãã·ã³ã«é©ããæ§æïŒ8ã³ã¢ã16 GBã ããããããã¯èäžåããã§ãã ãªãœãŒã¹ã¯çŒçã«é£ã¹ãããŸãã
ãã¡ãããã¹ã€ããã®ã¹ãã³ããŒããããããã¯ãŒã¯ã®ãã¹ãŠã®ãŽã£ã©ã³ããããŒã¢ãã£ããã®åæã®ããã«åéããããã©ãã£ãã¯ãã¹ããŒããå€èªäžèœãªã€ã³ã¿ãŒãã§ã€ã¹ã¯10Gbsã§ããå¿ èŠããããŸãã ãã以å€ã®å Žåã¯ãåã«ãã§ãŒã¯ããŸãã
Windowsãã·ã³ããOSSIMãµãŒããŒã管çããå Žåã¯ããããšWinSCPãå¿ èŠã§ãã ãŸãããŸãã¯ããªãã圌ãæããŠãããªãé ãã UbuntuãæèŒãããã·ã³ãããã©ã€ãããæ¹ã䟿å©ã§ãã å°ãªããšããã¹ã¯ãªããã§CRLFãšããŠè¡æ«ã誀ã£ãŠæžãããã©ãããæ¯å確èªããå¿ èŠã¯ãããŸããã
ã€ã³ã¹ããŒã«åŸããªã¢ãŒããã·ã³ããSSHçµç±ã§ãµãŒããŒã«æ¥ç¶ããããšã¯ã§ããŸããã Debian 8ã§ã¯ãsshdèšå®ã®ããã©ã«ããªãã·ã§ã³ã¯ãPermitRootLogin without-passwordãã§ããã `/ etc / ssh / ssh_config`ã§` PermitRootLogin yes`ã«å€æŽããå¿ èŠããããŸãã
ã¿ã€ã ãŸãŒã³
ãã1ã€ã®éèŠãªããšã¯ããã©ã°ã€ã³ã®ã¿ã€ã ãŸãŒã³ã®æ£ããæ§æã§ãã å®éããã¹ãŠã®ãã°ãœãŒã¹ãåãã¿ã€ã ãŸãŒã³ã«ããå Žåã§ããå¿ ãããåãçŸå°æéã䜿çšããŠããããã§ã¯ãããŸããã ããšãã°ãSystem Center Configuration Managerã¯ãUTCã§ããŒã¿ããŒã¹ã«æéãä¿åããã®ã劥åœã§ãããšèããŠããŸãã ãŸããããŒã¿ããŒã¹ããæ°ããã€ãã³ããèªã¿åããã©ã°ã€ã³ãæã£ãŠããå ŽåïŒãããŠãç§ã¯ãããæã£ãŠããŸãïŒããããã¯çŸå°æéã§èšé²ãããªãããšãèæ ®ããå¿ èŠããããŸãã
ãã©ã°ã€ã³ã®ã¿ã€ã ãŸãŒã³ã¯2ã€ã®å Žæã§èšå®ãããŸãïŒæåã«ããã¹ãŠã®ãã©ã°ã€ã³ã®ããã©ã«ãã®ã¿ã€ã ãŸãŒã³ã `/ etc / ossim / agent / config.cfg`ã«èšå®ããã次ã«ãåã ã®ãã©ã°ã€ã³ã®èšå®ãã¡ã€ã«ã§åå®çŸ©ã§ããŸãã ã¿ã€ã ãŸãŒã³ã®å®çŸ©ãšã¯ããã©ã°ã€ã³ãžã§ãã¬ãŒã¿ãŒã«ãããŒã¿ããã®ãããªã¿ã€ã ãŸãŒã³ããæ¥ãŠãããšæ³å®ããæéãæã ã®æéã«å€æãããããšãæå³ããŸãã ãã®å Žåããoursãã¯ãµãŒããŒã®çŸå°æéã§ãã å®éãæéã¯ããŒã¿ããŒã¹ã«UTCã§æžã蟌ãŸããŸããããããŒã«ã«ã·ã¹ãã ãã®ãªãã»ãããæžã蟌ãŸããå¥ã®ãã£ãŒã«ãããããŸãã
ç°ãªãã¿ã€ã ãŸãŒã³ã«åãã¿ã€ãã®2ã€ã®ãœãŒã¹ãããå Žåãèå³æ·±ãããšãå§ãŸããŸãã ããšãã°ãããŸããŸãªãã©ã³ãããcisco-asaã«ãŒã¿ãã°ãååŸããŸãã ãã®å Žåãç°ãªããã©ã¡ãŒã¿ãŒ `tzone =`ãæå®ããèšå®ãã¡ã€ã«ã§ãç°ãªããã©ã°ã€ã³ã§ããããåŠçããå¿ èŠããããŸãã ãã®ãã©ã¡ãŒã¿ãŒã¯ `[default]`ã»ã¯ã·ã§ã³ã§èšå®ãããŸãã ããªããããã¥ã¡ã³ãã§ãããèŠã€ããããªãã®ã§ãç§ã¯ããã«ã€ããŠæžããŠããŸããç§ã¯çç±ãç¥ããŸããã POSIX圢åŒïŒãtzone = Europe / Moscowãã
Windowsãã°ãåéããæè¯ã®æ¹æ³ã¯äœã§ããïŒ
ç§ã®çãïŒããã€ãã£ããããŒã«AlienVault HIDSãå¥åOSSECã ãã¡ãããããã«ã€ããŠç°¡åã«èª¬æããŸãã
çè«çã«ã¯ãå€ãã®ãšãŒãžã§ã³ãã®ããããã䜿çšããŠãWindowsã€ãã³ããã°ãsyslogã«éä¿¡ããããWMIã䜿çšãããã§ããŸãã OSSIMã«ã¯WMIã¯ã©ã€ã¢ã³ãããããWindowsãã°ãèªã¿åãããã®æšæºãã©ã°ã€ã³ããããŸãã SNAREãšãŒãžã§ã³ãçšã®æšæºãã©ã°ã€ã³ããããŸããããã·ã¢ã®Windowsãæ±ã£ãŠããå Žåãããã¯åœ¹ã«ç«ã¡ãŸããã åé¡ã¯ãSNAREããã·ã¢ã®Windowsããcp1251ãšã³ã³ãŒãã£ã³ã°ã§ããŒã¿ãéä¿¡ããSNAREã®æšæºããŒãµãŒãcp1252ã®äžã«èšè¿°ãããŠããããšã§ãã ã¬ã®ã¥ã©ãŒã·ãŒãºã³ãç·šéããå¿ èŠããããŸãã
ããããæãèå³æ·±ãããšã¯ããå€èšèªãã·ã¹ãã ãããã°ãåéãããšãã«å§ãŸããŸãã ããšãã°ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ãã·ã¢èªã®WindowsãããããµãŒããŒã«è±èªããããŸãã ãããŠä»ããããåæããæ¹æ³ã¯ïŒ ããã¯å®éããã¹ãŠã®SIEMã«å ±éã®åé¡ã§ãã 圌ãã¯ãããããŸããŸãªæ¹æ³ã§è§£æ±ºããŸãã ããšãã°ãArcSightã¯Windowsãã°ã®åéã«ããªãæŽç·Žãããã·ã¹ãã ã䜿çšããŠãããããã·ã¹ãã ã®ããŒã«ã©ã€ãºã«é¢ä¿ãªããè±èªã®ã¿ã§ãã°ãåéã§ããŸãã OSSECã¯éåžžã«åçŽãªææ³ã䜿çšããŸãã Windowsã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ãããšãè±èªã®Windowsãã°ã®æååã¡ãã»ãŒãžã®ããŒãã«ãå«ãcsvãã¡ã€ã«ããã®äœæ¥ãã£ã¬ã¯ããªã«æžã蟌ãŸããŸãã ãããã£ãŠãåæã«å¿ èŠãªã¡ãã»ãŒãžã®ãå¿ é éšåãã¯ãã·ã¹ãã ã®ããŒã«ã©ã€ãºã«é¢ä¿ãªããåžžã«1ã€ã®èšèªã§éä¿¡ãããŸãã ãããããããŒã¿ãã¯ãå ã®èšèªã§ãæ¥ãŸãã ãšãŠã䟿å©ã§ãã
ããã«ãOSSECãšãŒãžã§ã³ãã®æšæºãã©ã°ã€ã³ã¯éåžžã«ããæžãããŠããŸãã 圌ã¯ã€ãã³ããã¿ã€ãããšã«æ éã«è§£æããŸãã ãã°ãåéããããã«å¥ã®æ¹æ³ã䜿çšããå Žåãæ£ã§ã€ãã³ããæé ããã®ã«å€ãã®æ±ããããªããã°ãªããŸããã æåŸã«ãOSSECã¯åãªãããã°è»¢éãã§ã¯ãªããå®éã«ã¯ãã¹ãIDSã§ãããæªããã®ã§ããããŸããã ãã¬ã³ããã€ã¯ãã¯ããã®ãšã³ãžã³ããé«åºŠãªããŠã€ã«ã¹å¯Ÿçã«äœ¿çšããããšã«æ±ºããŸããã ã¯ããOSSECã¯ã³ã³ãããŒã«ã·ã§ãããšããŠä¿¡é Œã§ããŸãã éèŠãªã·ã¹ãã ã«ãšãŒãžã§ã³ããå®å šã«ã€ã³ã¹ããŒã«ã§ããŸãã
ãã®ä»ã ãŠãµã®ã¯è²Žéãªæ¯ç®ã§ããã ãã§ãªãã3ã4ããã°ã©ã ã®é£èã§ããããŸãã OSSECã¯ãã°ã³ã¬ã¯ã¿ãŒã§ã¯ãªããããèªäœãSIEMã§ãã OSSIMã§ã¯ãWindowsãã°ã¯ãŸã£ããéä¿¡ãããŸããããç¬èªã®alert.logã¯ãšãŒãžã§ã³ãããåä¿¡ããã€ãã³ãã®äºååŠçã«åºã¥ããŠåœ¢æãããŸãã ããã«ã¯ãããšãã°ãå¶åŸ¡ããããã¡ã€ã«ã®å€æŽã€ãã³ãããŸãã¯ãè€æ°ã®ãšã©ãŒãããã¬ãžã¹ããªå ã®ããŒã®ãã§ãã¯ãµã ã®è€æ°ã®å€æŽããªã©ã®éçŽã€ãã³ãããããŸãã åãªãã³ã¬ã¯ã¿ãŒããã䟿å©ã§ãã OSSECã¯ã€ã³ã¿ãŒãããäžã§éåžžã«åºãæ®åããŠãããWebãµãŒããŒãä¿è·ããããã«é »ç¹ã«äœ¿çšãããŠãããããã³ãã¥ããã£ã¯å€§ãã掻çºã§ãã
ãã¡ãããWindowsã®ãã°ãåéããä»ã®æ¹æ³ãè©Šãããšãã§ããŸãã ããã¯é¢çœãã§ãã
OSSECãšãŒãžã§ã³ãæ§æã«ã€ããŠã®äœã
Windowsãã·ã³ã§ã¯ããšãŒãžã§ã³ãã¯ããã©ã«ãã®æ§æãã¡ã€ã«ãšãšãã«ã€ã³ã¹ããŒã«ãããŸãã ãã®ãã¡ã€ã«ã¯æ¬¡ã®å Žæã«ãããŸãïŒ `/ usr / share / ossec-generator / installer / ossec.conf`ã OSSECã¯ããµãŒããŒããã®æ§æã®ããŠã³ããŒãããµããŒãããŠããŸãã ãã¡ã€ã« `/ var / ossec / etc / shared / agent.conf`ããã®ç®çã«äœ¿çšãããŸãã ããã©ã«ãã§ã¯ååšããŸããã ãã®ãã¡ã€ã«ã¯ãOSSIMã³ã³ãœãŒã«ã®Webã€ã³ã¿ãŒãã§ãŒã¹ããäœæã§ããŸãïŒç°å¢-æ€åº-ãšãŒãžã§ã³ã-agent.confïŒã ãŸãã¯ãããã¹ããšãã£ã¿ã§äœæããŸãã
ããŒã«ã«ãšãŒãžã§ã³ãèšå®ãã¡ã€ã«ãšããŒãžãããXML圢åŒã®èšå®ãã£ã¬ã¯ãã£ããå«ããå¿ èŠããããŸãã ããŸããŸãªãšãŒãžã§ã³ãã®ãã£ã¬ã¯ãã£ããããã¯ãããŒã¯ããŠãé©åãªãšãŒãžã§ã³ãã«ã®ã¿é©çšã§ããŸãã OSã¿ã€ãããšãŒãžã§ã³ãåããããã¡ã€ã«åã«ããããŒãã³ã°ãèš±å¯ãããŸãïŒããŒã«ã«ãšãŒãžã§ã³ãæ§æã§ã¯ããã®å Žåããããã¡ã€ã«ã®ååã瀺ãå¿ èŠããããŸãïŒã
<agent_config name="agent001|agent002|agent018">
</agent_config>
<agent_config os="Linux|FreeBSD">
</agent_config>
<agent_config os="Windows">
</agent_config>
<agent_config profile="web-server">
</agent_config>
ãã®ããã«ããŠããšãŒãžã§ã³ãã®æ§æãäžå çãã€åå¥ã«å€æŽã§ããŸãã ãããŒãžããšããçšèªã«ã¯æ確åãå¿ èŠã§ãã æ§æãã¡ã€ã«ã®ããŒã«ã«ã»ã¯ã·ã§ã³ããªãŒããŒã©ã€ãããããšã©ããªããŸããïŒ çè«ã§ã¯ãããŒã«ã«ãã¡ã€ã«ãæåã«èªã¿èŸŒãŸãã次ã«ãµãŒããŒãã¡ã€ã«ãèªã¿èŸŒãŸããæåŸã«èªã¿èŸŒãŸããã«ãŒã«ãæåŸã«èªã¿èŸŒãŸãã以åã®ãã¡ã€ã«ã¯ãã¹ãŠäžæžããããŸãã å®éã«ã¯ããã®ãããªæ§æãã©ã¡ãŒã¿ãŒã®äº€å·®ãè©Šããããšã¯ãããŸããã åã«å¿ èŠã¯ãããŸããã§ããã å¿ èŠã«å¿ããŠãæãããã«æ©èœããããšãé¡ã£ãŠããŸãã
ããäžã€ã®éèŠãªãã€ã³ãã ããŒã«ã«ãšãŒãžã§ã³ãæ§æã®ãã³ãã¬ãŒãã¯ããµãŒããŒãžã®æ¥ç¶æ¹æ³ã瀺ããŠããŸãã
<server-ip>172.17.2.10</server-ip>
<notify_time>120</notify_time>
<time-reconnect>240</time-reconnect>
ããªããããã§èŠãããšãã§ããããã«IPã¢ãã¬ã¹ã èè ããã®ãããªãã³ãã¬ãŒãã奜ãã çç±ã¯ããããŸããã FQDNãæå®ãããšããã®ã»ã¯ã·ã§ã³ã¯ç°ãªãããã«èŠããã¯ãã§ãã
<server-hostname>fqdn</server-hostname>
...
ãã ããããã¯è¡ãããŠããŸããã ããã¯ããµãŒããŒã®IPã¢ãã¬ã¹ãå€æŽãããšããã¹ãŠã®ãšãŒãžã§ã³ããèœã¡ãããšãæå³ããŸãã è¯ãèãã§ã¯ãããŸããã ãã¡ãããSIEMã¯IPã¢ãã¬ã¹ãå€æŽããããããªããã€ã¹ã§ã¯ãããŸããããã©ããããããäžå¿«ã§ãã ãã¡ããããã³ãã¬ãŒãã®ãã®ã»ã¯ã·ã§ã³ãå€æŽã§ããŸãããã»ãšãã©ã®å Žåã次ã®æŽæ°ã§ãã³ãã¬ãŒããåçæãããŸãã ãããåžžã«ç£èŠããå¿ èŠããããŸãã ã¢ãã¬ã¹ãå€æŽããç¿æ £ããªãã®ã§ããã®åé¡ã¯ç§ãæ©ãŸããŸããã
ãã¹ããšãŒãžã§ã³ãã®ã€ã³ã¹ããŒã«ã«é¢ããèæ ®äºé
Windowsã§ã¯ãèªåå±éãã¿ã³ã䜿çšããŠOSSIM Webã³ã³ãœãŒã«ãããšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããã®ãæã䟿å©ã§ãã ãã ããã¿ãŒã²ãããã¹ãïŒãŸãã¯ãã¡ã€ã³ïŒã®ããŒã«ã«ç®¡çè ã®è³æ Œæ å ±ãå¿ èŠã«ãªããŸãã ã°ã«ãŒãããªã·ãŒããã®ã€ã³ã¹ããŒã«ãŸãã¯SCCMã®äœ¿çšã¯éåžžã«å°é£ã§ãã å®éã«ã¯ãåã€ã³ã¹ããŒã«ãã¡ã€ã«ã¯ããµãŒããŒãšã®éä¿¡ãæå·åããããã®äžæã®ããŒãå«ããããç¹å®ã®ãã¹ãã«å¯ŸããŠåå¥ã§ãã PCI DSSã¬ãã«ã§ã®ãã®ãããªç§å¯ã æ²ãã¿ã
Linuxã®å ŽåããšãŒãžã§ã³ãã¬ã¹ãå¯èœã§ãããSSHãä»ãããã¹ãæ¥ç¶ã®ã»ããã¢ãããå¿ èŠã§ãã ç§ã®æèŠã§ã¯ãããã¯æªãèãã§ãã ç§ã¯ãšãŒãžã§ã³ãã眮ãããšã奜ã¿ãŸãã ãã®å Žåããçãããã¿ãŒã²ãããã·ã³ã«ãšãŒãžã§ã³ããã³ã³ãã€ã«ããŠå®å šã«æåã§ã€ã³ã¹ããŒã«ããŸãã ããŒãžã§ã³2.8.2ãå ¬åŒã«ãµããŒãããŸããããããŒãžã§ã³2.8.3ãåé¡ãªãæ©èœããŸãã å®éã«ã¯ãããšãã°Debianãªã©ãããŸããŸãªã·ã¹ãã çšã®ããã±ãŒãžããããŸãã 詳现ã¯ãã¡ããã芧ãã ããã
ããã¥ã¡ã³ããæ¢ãå Žæãšèªãã¹ããã®
Webã³ã³ãœãŒã«ã¡ãã¥ãŒã®ãµããŒããã¿ã³ãã¯ãªãã¯ããŠããªã³ã¯ãååŸããŸãã èªãå¿ èŠããããŸãïŒ
USM 5.xãã©ã°ã€ã³ç®¡çã¬ã€ã
çžé¢ãã£ã¬ã¯ãã£ããŸãã¯çžäºçžé¢ã«ãŒã«ã®ã«ã¹ã¿ãã€ãº
AlienVaultã§ã®äŸµå ¥æ€ç¥
ããªã·ãŒç®¡çã®åºç€
OTXã§USMããã³OSSIM 5.1ã䜿çšãã-AlienVault
è³ç£ãã°ã«ãŒãããããã¯ãŒã¯
ã·ã¹ãã ãšã©ãŒãèŠåãææ¡
SIEMãå¿ èŠãªçç±
誰ããç解ããŠããããã«èŠããŸãããããžãã¹ã«é¢ããŠã¯ãã»ãšãã©ã®å Žåã人ã ã¯SIEMã®ç®çãæ£ããç解ããŠããªãããšãããããŸãã ãŸã第äžã«ãããã¯ææžçã§ã¯ãããŸããã ãã»ãã¥ãªãã£ç®¡çã·ã¹ãã ãã§ããªãã®ã§ããã®èšäºã®ã¿ã€ãã«ã倱瀌ããŸãããæåã«å§ããããã§ã¯ãããŸããã å®éãããã¯ã»ãã¥ãªãã£äŸµå®³ã®æåãæ€åºããæ段ã§ãã ä¿è·ãæ§ç¯ããããã®æšæºçãªã¹ããŒã ã¯ãèµ·ããããæ»æïŒå®éã®è åšïŒãšãããã®å®è¡æ¹æ³ã®èå¥ããå§ãŸããŸãã 次ã«ãèãããããæ»æãã¯ãã«ãã«çœ®ãããæè¡çããã³çµç¹çãªé²åŸ¡æ段ãèæ¡ãããå®è£ ãããŸãã ãããŠãããããã¹ãŠã®åŸããã³ã³ãããŒã«ããèšå®ãããŸãããã®ç®çã¯ããã¹ãŠã®ä¿è·æ段ãæ©èœããªãããšã確èªããããšã§ãã ãŸããSIEMã¯ãã®ã¯ã©ã¹ã«å±ããŸãã
ããã¯ããªããç解ããå¿ èŠããããã®ã§ãã SIEMã¯ããã§ã«çºçããéåãæ€åºããããæè¡çããã³çµç¹çãªä¿è·æ段ãåé¿ããããã«èšèšãããŠããŸãã ããã¯ããããªç£èŠã·ã¹ãã ã®ãããªãã®ã§ãã ãŸãããããã®éåãæ€åºããå åãSIEMããããã®å åãèå¥ããæ¹æ³ãå¿ èŠãªæ å ±ãååŸããå Žæã決å®ããå¿ èŠããããŸãã SIEMã«è¡šç€ºãããªããããããŸãŒã³ãã¯ãããŸããã ç¶æ³ã¯æãäºæ³å€ã®å ŽåããããŸãã
OSSIMã¯ãåæã®ããã«çããããã±ãããpcap圢åŒã§ä¿åããŸãã ããã«ãããŸãïŒ
ããã¯äœã ã£ãïŒ
ããããããã¯ãã®ãããªãã®ã§ããã ãããªãã£ã¹ã§ã¯ãITå°é家ãTomcatã¢ããªã±ãŒã·ã§ã³ãµãŒããŒç°å¢ã§å転ããŠããããçš®ã®ãã®ããã¹ãããŸããã ãã¡ãããåºäŒã£ãæåã®ãµãŒããŒã«ãã®ãã®ãã€ã³ã¹ããŒã«ããã³ã³ãœãŒã«ã®å ¥ãå£ã«ç©ºã®ãã¹ã¯ãŒããæ®ããŸããã ãã¹ãããŠå¿ããŠããŸã£ãã æåã®ãµãŒããŒã¯ã¿ãŒããã«ãµãŒãã¹ãµãŒããŒã§ããããšãå€æããŸããã ãããŠããåãã®ãšãããtomcatã¯ã·ã¹ãã ã¢ã«ãŠã³ãã§åäœããŸããã éªæªãªããã«ãŒãã£ãã·ã³ã°ãåŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒã«ããã€ã®æšéŠ¬ãæ»ã蟌ãŸãããããã¯ãŒã¯äžã§æçšãªãã®ã調ã¹ãŸããã ãã®å¿ããããWebãµãŒããŒãèŠã€ããŠåãã§ããã ã³ã³ãœãŒã«ã³ãã³ãããµããŒãããããã«ã©ã€ãã©ãªã泚ããŸããã ãã®ã©ã€ãã©ãªããã¹ããããã®ç¬éãåçã«ç€ºãããŠããŸãã net userã³ãã³ããå®è¡ãããsuricataãhttp-responceã®åºåã®å 容ãèŠãŠããŒã€ã³ã°ãåºããŸããã 圌ããã©ããªçš®é¡ã®ãŽããæŽçããŠããéãéªæªãªããã«ãŒã¯ãã§ã«ããã«ããããã«æŒã蟌ã¿ããŠãŒã¶ãŒãã¹ã¯ãŒããåéãå§ããŸããã幞ããªããšã«ããããã¯ãã¹ãŠã¿ãŒããã«ãµãŒããŒã«è¡ããŸãã
ç¶æ³ã¯éåžžã«éèŠã§ãã 人ã ã¯åžžã«ééããç¯ããŸãã ITå°é家ã ãã§ãªããããã«ãŒãã
ãŸãã¯ãããã«ç°¡åãªè©±ããããŸãã ããã¯ãå®å šã«æ°ããã¢ã©ãŒã ããŒãžã§ãã
ããã¯ãããããOTXãã«ã¹ã§ãã 詳现ã¯æ¬¡ã®ãšããã§ãã
ããã¯äœã ã£ãïŒ
ãããŠãããã¯åŸæ¥å¡ã®1人ã®ãã©ãŠã¶ã§ãããbankir.ruã®ãã©ãŒã©ã ã¹ã¬ããã®1ã€ãèŠãŠãURL owqkq.ne1t3v8.topã«æ¥ãã§è¡ããŸãããããã¯Angler Exploit Toolkitã䜿çšããé§è»ããŒãžã®1ã€ã§ãã ãŸãèå³æ·±ã話ã
ãããããŸãŒã³ããåé¿ããã«ã¯ããŸããããã¯ãŒã¯äžã®ãã¹ãŠã®ãã¹ãã«HIDSãšãŒãžã§ã³ãïŒOSSECïŒãé 眮ããå¿ èŠããããŸãã 次ã«ãå éšãããã¯ãŒã¯äžã®ãã¹ãŠã®ãã©ãã£ãã¯ã®ãå€èªäžèœããªOSSIMã€ã³ã¿ãŒãã§ã€ã¹ãžã®éä¿¡ãæ§æããŠãNIDSïŒSuricataïŒã«ãã£ãŠåŠçãããããã«ããŸãã å°ãªããšããã¹ãŠã®DMZããŒãã®OpenVASã¹ãã£ããŒã§å®æçãªè匱æ§ã¹ãã£ã³ãæ§æããŠå®è¡ããããšãäžå¯æ¬ ã§ãã ããã¯éèŠã§ãã 芳å¯ã«ãããšãéåžžã«å°ããªäŒç€Ÿã§ããæ¯æ¥20ã50ã®æµã¹ãã£ããŒãééããŠããŸãã ããªãã圌ããããåã«è匱æ§ãçºèŠãããªãã°ãããã¯ããè¯ãã§ãããã ç§ã¯èªåŒµã§ã¯ãªãããã 軜èŠããŠããŸãã 以äžã¯ãæ¥å ±ã®å®éã®ã¹ããããã§ãã
2016:02:18 - 2016:02:19
IP
2016-02-18 09:22:46 180.97.106.37 Nanjing Malicious Host
2016-02-18 09:38:37 216.218.206.123 Fremont Malicious Host
2016-02-18 09:52:57 85.25.214.226 Germany Scanning Host
2016-02-18 10:08:11 146.185.250.105 Saint Petersburg Malicious Host
2016-02-18 10:22:54 178.62.14.193 London Malicious Host
2016-02-18 10:23:24 94.102.49.79 Netherlands Malicious Host
2016-02-18 10:47:52 195.88.209.6 Moscow Malicious Host
2016-02-18 10:53:29 222.186.34.177 Nanjing Malicious Host
2016-02-18 11:07:48 71.6.135.131 San Diego Malicious Host
2016-02-18 11:58:17 193.105.134.220 Sweden Malicious Host
2016-02-18 11:58:51 62.210.206.219 France Malicious Host
2016-02-18 12:28:13 193.109.69.150 Russia Malicious Host
2016-02-18 12:43:40 216.218.206.96 Fremont Malicious Host
2016-02-18 13:08:50 209.126.124.67 St Louis Malicious Host
2016-02-18 13:53:19 178.33.17.241 France Malicious Host
2016-02-18 14:23:52 198.20.70.114 Chicago Malicious Host
2016-02-18 14:32:49 104.219.238.10 Rye Malicious Host Scanning Host
2016-02-18 14:38:38 198.23.112.119 Dallas Scanning Host
2016-02-18 15:02:58 198.20.69.98 Chicago Malicious Host
2016-02-18 15:03:29 64.125.239.136 United States Malicious Host
2016-02-18 15:28:35 162.248.74.2 Clarks Summit Malicious Host
2016-02-18 15:43:36 222.174.5.28 Jinan Malicious Host
2016-02-18 15:57:42 66.240.236.119 San Diego Malicious Host
2016-02-18 16:13:09 74.82.47.45 Fremont Malicious Host
2016-02-18 16:13:44 64.125.239.92 United States Malicious Host
2016-02-18 17:07:57 142.54.162.74 Kansas City Malicious Host
2016-02-18 17:22:41 64.125.239.107 United States Malicious Host
2016-02-18 17:58:54 23.239.66.99 United States Malicious Host
2016-02-18 18:07:50 61.216.2.14 Taiwan Malicious Host
2016-02-18 18:08:03 198.20.69.74 Chicago Malicious Host
2016-02-18 18:08:18 141.212.122.84 Ann Arbor Malicious Host
2016-02-18 18:08:18 141.212.122.81 Ann Arbor Malicious Host
2016-02-18 19:52:53 185.94.111.1 Russia Malicious Host
2016-02-18 19:58:27 162.244.35.24 United States Malicious Host
2016-02-18 20:23:00 162.244.35.22 United States Malicious Host
2016-02-18 20:23:37 89.248.160.192 Netherlands Malicious Host
2016-02-18 20:43:55 222.174.5.17 Jinan Malicious Host
2016-02-18 21:23:55 185.130.5.201 Republic of Lithuania Malicious Host
2016-02-18 21:47:39 92.60.184.34 Ukraine Scanning Host
2016-02-18 22:33:48 209.126.102.181 St Louis Malicious Host
2016-02-18 22:57:37 71.6.167.142 San Diego Malicious Host
2016-02-18 23:13:37 212.83.148.78 France Malicious Host
2016-02-19 00:07:54 185.130.5.240 Republic of Lithuania Scanning Host
2016-02-19 00:48:22 64.125.239.224 United States Malicious Host
2016-02-19 01:13:11 66.240.192.138 San Diego Malicious Host Scanning Host
2016-02-19 02:33:05 198.204.234.74 Kansas City Scanning Host Malicious Host
2016-02-19 02:57:03 104.243.223.8 Tampa Malicious Host
2016-02-19 02:58:02 198.20.99.130 Netherlands Malicious Host
2016-02-19 03:27:43 162.244.35.25 United States Malicious Host
2016-02-19 03:28:13 89.163.251.200 Germany Malicious Host
2016-02-19 04:28:25 71.6.165.200 San Diego Malicious Host
2016-02-19 04:52:08 93.174.93.181 Netherlands Malicious Host
2016-02-19 04:58:24 184.105.247.238 Fremont Malicious Host
2016-02-19 05:23:07 192.162.101.79 Russia Malicious Host
2016-02-19 05:23:20 64.125.239.112 United States Malicious Host
2016-02-19 06:12:43 188.138.1.218 Germany Malicious Host Scanning Host
2016-02-19 06:12:44 74.82.47.55 Fremont Malicious Host
2016-02-19 06:43:55 209.239.123.106 St Louis Malicious Host
2016-02-19 07:13:45 185.56.28.67 Netherlands Malicious Host
2016-02-19 08:13:09 184.105.247.228 Fremont Malicious Host
2016-02-19 08:28:51 184.105.139.72 Fremont Malicious Host
ãããŠãããã¯ã³ãã¥ããã£ã«ç¥ãããŠããæªåœ¹ã«é¢é£ããéšåã®ã¿ã§ãããã¬ããŒãã«ã¯æªç¥ã®æªåœ¹ã®ãªã¹ããå«ãå¥ã®éšåããããŸãã ãã¡ããããããã®ã»ãšãã©ã¯ããŸãããã·ã¥ããŸããã äŸïŒãã®ããã«ïŒããã¯åãã¬ããŒãããã®åãæãã§ãïŒïŒ
Netflow 180.97.106.37 : Nanjing : Malicious Host
2016-02-18 09:22:46.585 0.000 ICMP 91.111.111.9:0 180.97.106.37:3.0 1 56 1
2016-02-18 09:22:46.586 0.000 TCP 180.97.106.37:46024 91.111.111.9:3128 1 40 1
2016-02-18 20:32:23.247 0.000 TCP 180.97.106.37:37254 91.111.111.101:22 1 40 1
2016-02-18 20:43:38.783 0.000 TCP 180.97.106.37:45840 91.111.111.25:22 1 40 1
2016-02-18 20:43:38.783 0.000 ICMP 91.111.111.25:0 180.97.106.37:3.0 3 204 1
2016-02-18 22:07:25.502 0.000 TCP 180.97.106.37:54895 91.111.111.36:22 2 80 1
2016-02-18 22:41:06.739 0.000 TCP 91.111.111.13:22 180.97.106.37:48365 1 40 1
2016-02-18 23:16:01.974 0.996 TCP 180.97.106.37:13302 91.111.111.32:80 10 539 1
2016-02-18 23:16:01.975 0.679 TCP 91.111.111.32:80 180.97.106.37:13302 7 3048 1
2016-02-18 23:20:07.473 0.000 TCP 180.97.106.37:43667 91.111.111.9:22 2 80 1
2016-02-18 23:20:07.473 0.000 ICMP 91.111.111.9:0 180.97.106.37:3.0 1 56 1
2016-02-19 05:50:52.757 12.217 TCP 91.111.111.44:80 180.97.106.37:53461 5 260 1
ããããéåžžã«éªéãªæ§æ ŒããããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ãã°ãå¿ èŠã«ãªããŸãã ããã¯ãã©ã®ãªãã£ã¹ã§ãæå°å€ã§ãã ãããŠãå éšã®ãã®ããããŸããDBMSããã³åã ã®ããžãã¹ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãã°ãWebãµãŒããŒãã°ãªã©ã§ãã ãªã© å¿ èŠãªãã®ããã¹ãŠåéã§ããŸãã ãã°ã解æããããã®æšæºãã©ã°ã€ã³ããªãå Žåã¯ãç¬èªã®ãã©ã°ã€ã³ãäœæããã®ã¯éåžžã«ç°¡åã§ãã çå®ã¯ç°¡åã§ãã æåã®ãã©ã°ã€ã³ãéçºããã®ã«æ°æ¥ãããããŸããã ãããŠã2çªç®ã®éçºã«ã¯æ°æéããããŸãã
ããšãã°ãçµç¹ã®ã»ãã¥ãªãã£å¯Ÿçã®éåãç£èŠããå Žåããªãã£ã¹ã§ã¯ãæ å ±ã»ãã¥ãªãã£ãµãŒãã¹ã®æ¿èªãªãã«éçšç°å¢ã®æ§æãå€æŽããããšã¯çŠæ¢ãããŠããŸãã OSSECã¯ãæ§æã®å€æŽã«ã€ããŠå£sã鳎ãããåæããããã©ããã確èªã§ããŸãã æãèå³æ·±ãéšåã¯ã誰ããã®å€æŽãè¡ã£ãŠããªãããšãå€æãããšãã«å§ãŸããŸãã
ã©ã®å¶åŸ¡ã«ãŒã«ãé©çšãã¹ããã«ã€ããŠæ£ç¢ºã«ã¢ããã€ã¹ããã€ããã¯ãããŸããã åæã«ã¯ç¬èªã®äŒçµ±ããããŸãã ã質åãããå Žåã¯ããåãåãããã ããã
éèŠã§ãã AlienVault OSSIMã¯ãå€å žçãªæå³ã§ã®SIEMã ãã§ã¯ãããŸããã ããã¯ããã¹ãIDSããããã¯ãŒã¯IDSãã¯ã€ã€ã¬ã¹IDSãVolnurability ScanerãNetFlow Collectorãå«ãæ¬æ£å šäœã§ãã ã€ãŸããäŒæ¥ã®ãããã¯ãŒã¯ã®ãããªç£èŠãæŽçããããã®å®å šãªå€å žçãªãã³ã³ãããŒã«ãã®ã»ããã§ãã
ãã©ãã«ãšå°æ
äœãããããããšæãããå Žåã¯ããã°ã確èªããŠãã ããã ã©ãïŒ
OSSECãã°ãšãšã©ãŒïŒ
`/var/ossec/logs/ossec.log`-ããã«OSSECãšã©ãŒã衚瀺ãããŸãã æãäžè¬çãªééãã¯ããšãŒãžã§ã³ããšã®éä¿¡ã倱ãããããšã§ããããã¯ããããã¯ãŒã¯äžã§èŽåœçãªéä¿¡é害ãçºçããå ŽåããŸãã¯ãšãŒãžã§ã³ããåã€ã³ã¹ããŒã«ããåŸã«çºçããŸãã ãŸãã§ããããšãŒãžã§ã³ãã®æ°ãå€ãå Žåãããã»ã©çããããšã§ã¯ãããŸããã ãšãŒãžã§ã³ããã¢ã¯ãã£ãã§ãªãããšãã³ã³ãœãŒã«ã§ç¢ºèªããã³ã³ãã¥ãŒã¿ãŒã®é»æºãå ¥ã£ãŠããããšãããã£ãŠããå Žåã¯ãããã«ããŸãã ãã°ã§ã¯ããšã©ãŒã¯ãERRORïŒDuplicated counter for 'agent-name'ãã®ããã«ãªããŸãã åçŽã«æé€ãããŸãã Webã³ã³ãœãŒã«ïŒç°å¢-æ€åº-ãšãŒãžã§ã³ãïŒãŸãã¯ãã¡ã€ã« `/ var / ossec / etc / client.keys`ã§ããã®ååã®ãšãŒãžã§ã³ããæ¢ãããã®çªå·ïŒå·Šç«¯ã®åã®çªå·ïŒã確èªããŸãã 次ã«ã `/ var / ossec / queue / rids`ãã£ã¬ã¯ããªã«ç§»åãããã®äžã®ãã¡ã€ã«-ãšãŒãžã§ã³ãçªå·ãåé€ããŸãã SSHããµãŒããŒã³ã³ãœãŒã«ã«ç§»åããã³ãã³ãã©ã€ã³ãçµäºããŠã `/ etc / init.d / ossec restart`ãå®è¡ããŸãã ãã¹ãŠã®ãã®ã æ£çŽãªãšãããOSSECã§ä»ã®ãšã©ãŒãèŠãããšã¯ãããŸããã
`/ var / ossec / logs / alerts / alerts.log`ã¯ãOSSECããšãŒãžã§ã³ãããåãã ã€ãã³ããåéãããã°ã§ããããã¯ãOSSIMãOSSECã®ãã©ã°ã€ã³ã§ã€ãã³ããèªã¿åããåŠçããå Žæã§ãã ããã§ãäœãããã«è¡ããã©ã®ããã«èŠããããèŠãããšãã§ããŸãã
åŸæ¥ã® `/ var / log`ã«ããæ®ãã®ãã°ã¯ã` / var / log / alienvault / agent / agent.log`ãšåãå Žæã«ããã `agent_error.log`ã«ãããŸãã ç¬èªã®ãã©ã°ã€ã³ããããã°ãããšãã«äŸ¿å©ã§ãã äœæ¥ã·ã¹ãã ã§ã¯ããagent.logãã®ãµã€ãºã¯ã®ã¬ãã€ãåäœã§ããããšã«æ³šæããŠãã ããã
OSSIMã®åäœã«é倧ãªãšã©ãŒãèŠãããšã¯ãããŸããã ã·ã¹ãã ã®æ¬¡ã®æŽæ°åŸãå®æçãªããã¯ã¢ãããæ©èœããªããªããŸããã ãã¡ã€ã«ã®1ã€ã«æš©éã誀ã£ãŠå²ãåœãŠãããšãå€æããŸããã ããã¯ç¿æ¥ãæåéãä¿®æ£ãããŸããã ãã®ãããªåé¡ã«é¢ããæ å ±ã¯ãã³ãã¥ããã£ãã©ãŒã©ã ã§éå¬ãããŸãã ããäžåºŠã次ã®æŽæ°åŸã次ã®æŽæ°ãæ©èœããªããªããŸããã ä»åã¯ã4æéåã«æçš¿ãããæŽæ°ã«ãã°ãå«ãŸããŠããããã®æ¹æ³ã§ä¿®æ£ããå¿ èŠããããšããéç¥ãæ¥ãŸããããä¿®æ£ãããæŽæ°ã¯ãã®ãããªææã«æçš¿ãããŸããã ã¡ãªã¿ã«ãæšæºçãªæ段ïŒWebãŸãã¯sshã³ã³ãœãŒã«ããïŒã«ããæŽæ°ãã¯ã©ãã·ã¥ããŠæ©èœããªãå Žåã¯ãã³ãã³ãã§æŽæ°ãå®è¡ã§ããŸãã
apt-get update
apt-get upgrade
ãµãŒããŒã³ã³ãœãŒã«ããã
ãããããããç§ãèšãããã£ãããšã®ãã¹ãŠã§ãã ãããŠæãéèŠãªããšã§ãã ããã¯ãªãŒãã³ãœãŒã¹ã§ãã ããªããæããã®ã¯äœã§ããPythonã¯ããªããšäžç·ã§ãã ãããŠãããªãã圌ãšäžç·ã«ããããªãå Žåã¯ãåçšç-PythonãèŠãŠãã ããã ãããŠããã§æåŸã®è³ªåã«è¡ããŸãã
ãªãŒãã³ãœãŒã¹ããšã³ã¿ãŒãã©ã€ãºãïŒ
ç§ã®çãã¯ãäŒç€Ÿã®ããŒãºã«åãããŠSIEMãå¿ èŠãªå Žåã¯ããšã³ã¿ãŒãã©ã€ãºã§ãã ãã¡ãããäŒæ¥ãç¬èªã®SIEMã®éçºãç®æããŠããªãå ŽåããªãŒãã³ãœãŒã¹ããŒãžã§ã³ããšã³ã¿ãŒãã©ã€ãºã¬ãã«ã«ããããã®ååãªäººçããã³æè¡çãªãœãŒã¹ã¯ãããŸããã ãããããããããªãã®ããžãã¹ã§ã¯ãªãå Žåãããªãèªèº«ã®äžè©±ãããŠãã ããã æ®å¿µãªããããšã³ã¿ãŒãã©ã€ãºSIEMã¯éåžžã«é«äŸ¡ã§ãã ããããéåžžã«é«äŸ¡ãªã®ã¯ãç°åžžãªçžé¢ãµãŒããŒãšã³ãžã³ãããããã§ã¯ãªããã€ãã³ãçžé¢ã«ãŒã«ã©ã€ãã©ãªã®äœæãè€éãªæ»æã®ãã·ã°ããã£ãã®åæãšãããã®æ€åºæ¹æ³ãããã³ãããã®ã¡ãœããã®ãããã°ã«å€å€§ãªæè³ãããããã§ãã ããã¯ãèªåã§ã¯ã§ããªãä»äºã§ãã ããã§ã¯åçšè£œåã®å©ç¹ã«ã€ããŠã¯èª¬æããŸããããããã®å©ç¹ã¯æããã§ãããè°è«ãã䟡å€ã¯ãããŸããã
ã§ã¯ããªããã®ãªãŒãã³ãœãŒã¹ã«æéãç¡é§ã«ããŠããã®ã§ããããïŒ ãŸã第äžã«ãç§ã¯åœŒã奜ãã§ãã ãã®ãããªãã¹ãŠã®ãªãŒãã³ãœãŒã¹ãããžã§ã¯ãã®äžã§ãããã¯æåããŠããŸãã 第äºã«ãAlienVaultã®Webãµã€ãã¯ãã誰ã§ãã»ãã¥ãªãã£ã«ã¢ã¯ã»ã¹ã§ããããã«ãããããšèšã£ãŠããŸãã ããèãã ã ãµããŒãããŸãã ããŸãã«ãå€ãã®äŒæ¥ã¯ããã®ã¯ã©ã¹ã®åçšè£œåãè³Œå ¥ããäœè£ããããŸããã sysadminã®ããªãŒã©ã³ãµãŒã倧å¢ããããšã¯ç¥ã£ãŠããŸããå°ããªäŒç€Ÿã«ãµãŒãã¹ãæäŸããŠãããšããŸãããã 圌ãããã®ããã«èŠããããšã¯çã«ããªã£ãŠããŸãã åé ã§ããã³ã³ãã¥ãŒã¿ãŒã«ã€ããŠèšåããã®ã¯ãäœã®æå³ããããŸããã Little SIEMã¯éåžžã«çŸå®çãªãã®ã§ãã
ãšã³ã¿ãŒãã©ã€ãº-ãšã³ã¿ãŒãã©ã€ãºãããã³ã³ãã¥ããã£-ã³ãã¥ããã£ã åå°-蟲æ°ãå·¥å Ž-åŽåè ããé-éè¡å¡ã ããã¹ãŠã®äººã«å¹žçŠãããããŠãã¹ãŠã®äººã«ååãïŒA.ãšB. Strugatskyããå芳è ã®ãã¯ããã¯ãïŒã
䜿çšããããœãŒã¹ïŒ
https://www.alienvault.com/documentation
https://alienvault.ru/open-threat-exchange/
http://ossec.github.io/docs/
http://suricata-ids.org/docs/