çŸä»£ã®äŒæ¥ã®ITã€ã³ãã©ã¹ãã©ã¯ãã£ã¯æ¥ã
è€éåããŠããŸãã å€ãã®ã·ã¹ãã ã¯ãã»ãã¥ãªãã£ã«å¯Ÿããå®éã®è
åšããã³æœåšçãªè
åšãå«ããåŠçããã³åæãå¿
èŠãªå€§éã®æ
å ±ãçæããŸãã 12人ãŸãã¯2人ã®ç®¡çè
ãéãããšãã§ããŸãããå€ãã®ãœãŒã¹ããããŒã¿ãåéããŠåæããäŒæ¥ã®ITã€ã³ãã©ã¹ãã©ã¯ãã£ã§èµ·ãããããªã¹ã¯ãšè匱æ§ãå ±åã§ããSIEMã·ã¹ãã ãã€ã³ã¹ããŒã«ããæ¹ãã¯ããã«å®äŸ¡ã§å¹ççã§ãã ããã«ãè©æ¬ºãæ
å ±çé£ããã®ä»ã®äºä»¶ã«é¢é£ãããµã€ããŒç¯çœªã®é²æ¢ã«ã圹ç«ã¡ãŸãã
Gartnerã®åææ©é¢ã«ãããšãæ°å¹Žéãã°ããŒãã«ãªSIEMåžå Žã§è°è«ã®äœå°ã®ãªããªãŒããŒã®1人ã¯ãHewlett Packard Enterpriseã®ArcSightã§ããã ããšããšç±³åœã®æ³å·è¡æ©é¢ã®ããŒãºã®ããã«éçºããããã®è£œåã¯ãåæ¥äŒæ¥ã«ãã䜿çšãåŸã«èš±å¯ãããŸããã ArcSight瀟ã¯2000幎ã«èšç«ããã2010幎ã«HPã«è²·åãããŸãããHPã¯ArcSightãœãªã¥ãŒã·ã§ã³ã®éçºã«åŸäºããŠãããç±³åœããšãŒãããããã®ä»ã®åœã®åžå Žã§æšé²ããŠããŸãã ãã·ã¢ã§ã¯ã2007幎ã«ç»å ŽããŸããã ãã以æ¥ãã·ã¹ãã ãå®è£
ããããã®çŽ400ã®ãããžã§ã¯ããå®è£
ãããFSTECã¯æè¿ãæªå®£èšã®æ©èœããªãããšãä¿èšŒããNDV 4蚌ææžãæäŸããŸããã ã€ãŸããArcSightã¯ãå人ããŒã¿ã®ä¿è·ãšåœå®¶æ©å¯ãå«ãŸãªãAISã®ä¿è·ã®ããã®ãããžã§ã¯ãã§äœ¿çšã§ããããã«ãªããŸããã æ
å ±ã»ãã¥ãªãã£ã®åéã§ã®ã€ãã³ãã®åéãåæãèŠèŠåã«é¢ããHPE ArcSightã®æ©èœã¯ããã·ã¢ã®çµç¹ã«ããç¥ãããŠããŸããããã«ããã®ãœãªã¥ãŒã·ã§ã³ãäžå¿ã«ãã·ã¹ãã ã€ã³ãã°ã¬ãŒã¿ãŒã®åºç¯ãªããŒãããŒãããã¯ãŒã¯ãé·ãé圢æãããArcSightå®è£
ãããžã§ã¯ããæ£åžžã«å®è£
ããŠããŸãã
HPã®åŸç¶ã§ããHewlett Packard Enterpriseã¯ãArcSightã®éçºãç¶ããæ¢åã®ã³ã³ããŒãã³ããæ¹åããæ°ããã³ã³ããŒãã³ããéçºããŠããŸãã æ°æ©èœã®1ã€ã§ããArcSight User Behavior Analyticsã¯ããŠãŒã¶ãŒã®è¡åã®åæã«åºã¥ããŠç°åžžãæ€åºããArcSightã®åºæ¬æ©èœã§ããåŸæ¥ã®çžé¢é¢ä¿ãè£å®ããŸãã åŸæ¥ã®çžé¢ã¡ã«ããºã ã¯ãç°åžžãªãŠãŒã¶ãŒã¢ã¯ã·ã§ã³ãä¿®æ£ããã«ãŒã«ã«åºã¥ããŠæ©èœããŸãã ã€ã³ã·ãã³ããæ€åºããããšãIS管çè
ã«éç¥ããããæå®ãããæäœãèªåçã«å®è¡ããŸãïŒã¹ã¯ãªããã®å®è¡ããŠãŒã¶ãŒã®ãããã¯ãªã©ãããã«å ããŠãUser Behavior Analyticsåäœã¡ã«ããºã ã¯ãã¹ããŒã ãšæ©èœã管çè
ã«ãŸã ç¥ãããŠããªãã€ã³ã·ãã³ããå ±åããŸãã
ãŠãŒã¶ãŒè¡ååæãéçºããéãèªå·±åŠç¿ã®ååããŠãŒã¶ãŒã®æ¥åžžã®è¡åã«äœ¿çšãããŸããã å°æ¥ãéåžžã®åäœã®ãããã¡ã€ã«ã«é©åããªãã¢ã¯ãã£ããã£ã¯ãèšç®ããããªã¹ã¯ã®ã¬ãã«ã«åŸã£ãŠçããããã®ãšããŠèšé²ãããŸãã ãã®åäœã®äŸãšããŠã¯ãéåžžã®æ¥ã«12é以äžã®ã¡ãŒã«ãéä¿¡ããçªç¶100ãŸãã¯1000ã®ã¡ãã»ãŒãžãéä¿¡ãããŠãŒã¶ãŒã®éåžžã®ã¢ã¯ã·ã§ã³ã®å€æŽããããŸãã ãŠãŒã¶ãŒè¡ååæã§ã¯ããŠãŒã¶ãŒããšã«åã
ã®è¡åãããã¡ã€ã«ãèªåçã«çæããããŠãŒã¶ãŒããããè¶
ãããšãã·ã¹ãã ã¯é©åãªä¿¡å·ãéä¿¡ããŸãã ãã®ã¢ãããŒãã«ãããIS管çè
ã®äœæ¥ãç°¡çŽ åãããéèŠãªã€ã³ã·ãã³ããã€ãã³ãã«ã®ã¿å¯Ÿå¿ã§ããããã«ãªããŸãã
HPE ArcSightãã©ãããã©ãŒã ã®å¥ã®æ°ãããœãªã¥ãŒã·ã§ã³ã¯ãDNS Malware Analyticsã§ãã DNSãã©ãã£ãã¯ãåæããITã€ã³ãã©ã¹ãã©ã¯ãã£ã®å®å
šãªå¯èŠæ§ãæäŸããŸããããã«ãããæ»æè
ã«æªçšãããåã§ãã£ãŠããããã¯ãŒã¯ã®è匱æ§ãç¹å®ã§ããŸãã æªæã®ããã¢ã¯ãã£ããã£ãæ€åºããç®çã§DNSãã©ãã£ãã¯ãåæãããšããèãã¯ã4幎åã«HP Labsã®ç 究éšéã§å§ãŸãã1幎åã®éããã®å°é家ã«ãã£ãŠäœæããããœãªã¥ãŒã·ã§ã³ã¯HPã§ãã¹ããããæ»æè
ã®å¶åŸ¡äžã«ããææãã·ã³ãæ€çŽ¢ããŠããŸãã è€éãªç°çš®ãããã¯ãŒã¯ãšèšå€§ãªæ°ã®åŸæ¥å¡-HPE ArcSight DNS Malware Analyticsã¯ããã®ãããªå°é£ãªæ¡ä»¶ã§ã®ãã£ãŒã«ããã¹ãã«åæ ŒããŸããã
çŸåšããã®ãœãªã¥ãŒã·ã§ã³ã¯ãã·ã¢ã®ã客æ§ã«ãå©çšããã ããŸãã ãã®åäœã®åçã¯æ¬¡ã®ãšããã§ããææãããã·ã³ã¯ãäŒæ¥ãããã¯ãŒã¯ã®å€éšã«äœããããŠã³ããŒããŸãã¯è»¢éããããšããŠããŸãã ãããã®ã¢ã¯ã·ã§ã³ã¯åŠå®çãªåäœã®ãããã¡ã€ã«ãããªã¬ãŒããæ
å ±ã»ãã¥ãªãã£ç®¡çè
ã¯ç¹å®ã®ã³ã³ãã¥ãŒã¿ãŒã«ææããæªæã®ããããã€ã®æšéŠ¬ã®ã¿ã€ããªã©ãäœãèµ·ãã£ãŠããããéç¥ãããŸãã ã·ã¹ãã ã¯DNSãã©ãã£ãã¯ã®ã¿ãåæãããããä»»æã®ãããã¯ãŒã¯ãšç°¡åã«çµ±åã§ããé«äŸ¡ãªãããã¯ãŒã¯æ©åšã賌å
¥ããå¿
èŠã¯ãããŸããã ååãšããŠãåŸæ¥ã®ä¿è·æ段ã¯ãããã¯ãŒã¯å¢çïŒDMZïŒãä¿è·ããŸãããã©ãããããã§äœæ¥ããåŸæ¥å¡ã¯ã©ãïŒèªå®
ã空枯ãã«ãã§ãªã©ïŒã§ãäœæ¥ã§ããããããã¹ãŠã®ææãã©ãã£ãã¯ããããè¶
ããããã§ã¯ãããŸããã ã DNSãã©ãã£ãã¯ã®åæã«ããããã®ãããªææããããã€ã¹ããäŒæ¥ãããã¯ãŒã¯ãç¹å®ããŠä¿è·ã§ããŸãã æåŸã«ãDNSãã©ãã£ãã¯ãéçŽããã®ãç°¡åã§ãããã©ãã£ãã¯ã®ã³ããŒãç¹å®ã®å Žæã«éäžããããã«ã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§æããã ãã§ãã HPEã¯ãDNSãã©ãã£ãã¯ã®ææã瀺ã眲åã®æ£ããæäœãšæŽæ°ãä¿èšŒããŸãã
HPE ArcSightéçºè
ã¯ãææ°ã®åžå Žååãšé¡§å®¢ã®å¥œã¿ã®å€åã远跡ããŸãã æ¯å¹Žãç±³åœã¯ArcSightãŠãŒã¶ãŒã®äžçäŒè°ãéå¬ããããã§æ°ããæ©èœã®å®è£
ã®èŠæãè°è«ãããšãšãã«ãæ°ããã¢ãžã¥ãŒã«ãšæ©èœãçºè¡šããŠããŸãã ãã®ãããªãŠãŒã¶ãŒäŒè°ã¯ãåãèŠåã§ã¢ã¹ã¯ã¯ã§éå¬ãããŸãã ã¬ããŒãã®éžæã§ç¹ã«éèŠãªã®ã¯ãArcSightã®å©ããåããŠãæ
å ±ã»ãã¥ãªãã£ã®åéã§è€éãªã¿ã¹ã¯ãéèŠãªã¿ã¹ã¯ã解決ããããšãå¯èœãªå®è£
ãããžã§ã¯ãã§ãã
HPE ArcSightã®æ°ããã³ã³ããŒãã³ãã«ã€ããŠèª¬æããããšã«å ããŠããœãªã¥ãŒã·ã§ã³ã®éèŠãªãæ±ããæãåºããããšæããŸãã ãŸãããããã»ãã¥ãªãã£ããŒã¿ãã©ãããã©ãŒã ã§ããããã¯ãã€ãã³ãã®åéãšåé¡ãããã³ã€ãã³ãã®ä¿åãšã¢ãŒã«ã€ããè¡ãäžé£ã®æ©èœã§ãã ãã®è£œåã«ã¯ããªã¢ãŒãã€ãã³ãåéãå®è¡ããã³ãã¯ã¿ãšãšãã«ãã¹ãã¬ãŒãžãå®æçãªæ€çŽ¢ãšåæãæäŸãããã¬ãŒãããã³ã³ãã¯ã¿ãæŽæ°ããã€ãã³ãåéãšç£èŠã®ããã®ã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœãããã¯ã¢ããããç¡æã®Management Centerãå«ãŸããŠããŸãã ãã®ãããªæ©èœã¯ããªã¢ã«ã¿ã€ã ã§ã¯ãªãã1é±éã1ãæãªã©ã®ã¬ããŒãã®åœ¢åŒã§ISã€ã³ã·ãã³ãã«é¢ããæ
å ±ãåä¿¡ããå¿
èŠãããã客æ§ã«é©ããŠããŸããSecurityData Platformã¯ãåŠçãããããŒã¿ã®éã«é¢ããŠã©ã€ã»ã³ã¹ãããŠããŸãã çŸåšãSecurity Data Platformãæ§æããã³ãã¯ã¿ã¯ãã€ãã³ãã¡ãŒã«ãŒãšããŠããŸããŸãªã¡ãŒã«ãŒã®350ãè¶
ããããŸããŸãªæ
å ±ã·ã¹ãã ããµããŒãããŠããŸãããç¡æã®SDKã®å©ããåããŠã顧客ãããŒãããŒã¯ä»»æã®ã·ã¹ãã çšã®ã³ãã¯ã¿ãç¬èªã«äœæã§ããŸãã SDPã¢ãžã¥ãŒã«ã¯æ¬æ Œçãªè£œåã§ãããããè¿œå ã®æ©èœãå¿
èŠãšããªãäŒæ¥ã¯ããã ããååŸããŸãã
ArcSightã®ãã1ã€ã®åºæ¬ã³ã³ããŒãã³ãã§ããEnterprise Security Managerã¯ãæ
å ±ã»ãã¥ãªãã£ã€ãã³ãããªã¢ã«ã¿ã€ã ã§ç£èŠããŸãã ãã®ã³ã³ããŒãã³ãã¯ãã€ã³ã·ãã³ããžã®å³æ察å¿ãå¿
èŠãªäººã«å¿
èŠã§ãã 1ç§ãããã«åŠçãããã€ãã³ãã®æ°ã«åºã¥ããŠãEnterprise Security Managerã«ãã£ãŠã©ã€ã»ã³ã¹ãããŸãã ã©ã€ã»ã³ã¹ã®æå°ãããå€ã¯ã1ç§ããã250ã€ãã³ãã§ãã æ¯èŒã®ããã«ãHewlett Packard Enterpriseã¯1ç§ããã40ã5äžã®ã€ãã³ããåŠçããããšã«æ³šæããŠãã ããã ESMå
ã«ã¯ãäºåã«ããã°ã©ã ããã眲åã§ã¯ãªãããŠãŒã¶ãŒãŸãã¯ã¢ããªã±ãŒã·ã§ã³ã®ç°åžžãªåäœãšç¹°ãè¿ãã®ã¢ã¯ãã£ããã£ã®åæã«åºã¥ããŠè
åšãæ€åºããThreat Detectorã¢ãžã¥ãŒã«ããããŸãã äžå°äŒæ¥ã®ä»£è¡šè
åãã«ãArcSight ESM Expressã®ç¹å¥çãæäŸãããŠããŸãããããå®å
šã«ç¬ç«ãã補åã§ãã ã倧èŠæš¡ãªãESMãšã¯ç°ãªããŸããããããããããšãã°ãã§ãŒã«ãªãŒããŒã¯ã©ã¹ã¿ãŒã®ãµããŒããªã©ãããã€ãã®æ©èœããªãå Žåã®ã¿ã§ãã
æåŸã«ãã€ã³ã¿ã©ã¯ãã£ããªè
åšãã¬ããžããŒã¹ã§ããArcSight Threat Centralã§ã¯ãããããæ€åºããã³æé€ããæ¹æ³ã«é¢ããæ
å ±ãå
±æã§ããŸããMarketPlaceã«ã¯ãæ€åºãããè
åšïŒã»ãã¥ãªãã£ããã±ãŒãžïŒããã³è¿œå ã¢ããªã±ãŒã·ã§ã³ã®ã«ãŒã«ãšå
åãå«ãŸããŸãã HPEéçºè
ã¯ãäŒç€Ÿã®ããŒãããŒããã®ãããªã»ãã¥ãªãã£ããã±ãŒãžã®äœæãšè¿œå ã®ã¢ããªã±ãŒã·ã§ã³ã®äœæã«åå ããããšãæãã§ããŸãã
ãã¡ãããæ
å ±ã»ãã¥ãªãã£ã®åéã«ãããå€éšããã³å
éšã®åé¡ã¯ãã¹ãŠãäž»ã«äººçèŠå ã«ãã£ãŠåŒãèµ·ããããŸãã ããã«ãããã¯æªæã®ããè¡çºã§ã¯ãªããåçŽãªäžæ³šæãšèŠåãèŠå¶ã®æ æ
¢ã§ããå¯èœæ§ããããŸãã å€ãã®å Žåãæ
å ±ã»ãã¥ãªãã£éšéã®åŸæ¥å¡ã¯ãç·æ¥äºæ
ãçºçãããŸã§å°ããªäºä»¶ã«ããŸã泚æãæã£ãŠããŸããã åæã«ãHPE ArcSightãªã©ã®SIEMãœãªã¥ãŒã·ã§ã³ã¯ãäžæ¹ã§ã¯ç¶æ³ãå¶åŸ¡ãç¶ããã®ã«åœ¹ç«ã¡ãä»æ¹ã§ã¯ããããã«æ³šæãæããªããšæ²æšãªçµæã«ã€ãªããå¯èœæ§ã®ããæœåšçãªåé¡ã«ã€ããŠã¿ã€ã ãªãŒã«éç¥ããŸãã