æ¬æ¥ã®åºçç©ã¯ãããããSOCã®æãéèŠãªåŽé¢ãã€ãŸãæœåšçãªæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®èå¥ãšåæã«é¢é£ããã³ã³ãã³ããæ±ã£ãŠããŸãã ããã¯ãŸããSIEMã·ã¹ãã ã®çžé¢ã«ãŒã«ã®ã¢ãŒããã¯ãã£ã§ãããé¢é£ããã·ãŒãããã¬ã³ããã¹ã¯ãªãããã³ãã¯ã¿èšå®ã§ãã ãã®èšäºã§ã¯ãSIEMã·ã¹ãã ã®ã³ãã¯ã¿ãŒã䜿çšããã€ãã³ãã®åŠçããå§ãŸããçžé¢ã«ãŒã«ã§ã®ãããã®ã€ãã³ãã®äœ¿çšãšã€ã³ã·ãã³ãã®ãããªãã©ã€ããµã€ã¯ã«ã§çµãããåæãã°ã®åŠçæ¹æ³å šäœã«ã€ããŠèª¬æããŸãã
åã®èšäºã§è¿°ã¹ãããã«ãSOCã®äžå¿ã¯HPE ArcSight ESM SIEMã·ã¹ãã ã§ãã ãã®èšäºã§ã¯ã4幎以äžã«ãããé²åã®ããã®ãã®ãã©ãããã©ãŒã ã®æ¹åã«ã€ããŠèª¬æããèšå®ã®çŸåšã®ããŒãžã§ã³ã«ã€ããŠèª¬æããŸãã
ãŸã第äžã«ãæ¹åç¹ã¯æ¬¡ã®ã¢ã¯ãã£ããã£ãæé©åããããšã§ããã
- æ°ããã¯ã©ã€ã¢ã³ããæ¥ç¶ããã³ãã¯ã¿ãæ§æããæéãççž®ããŸãã
- ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã³ã¢ã¢ã¯ãã£ããã£ã®ãããã¡ã€ãªã³ã°ã
- 誀æ€ç¥ã®æ°ãæžãããŸãã
- èšé²ãããæœåšçãªã€ã³ã·ãã³ãã«ã€ããŠã®æ å ±å 容ãšé¡§å®¢ã¢ã©ãŒãã®å®å šæ§ãé«ããã
ãã¹ãŠã®SIEMã«ã¯ããœãŒã¹ããã®ã€ãã³ããæ¯èŒãããããå€ãèç©ããããšã«ãããåºå®ãããç°åžžïŒæœåšçãªã€ã³ã·ãã³ãïŒãã¯ã©ã€ã¢ã³ãã«éç¥ã§ããäžé£ã®å®çŸ©æžã¿ã«ãŒã«ããããã«äœ¿çšå¯èœãã§ãã ã§ã¯ããªããã®ã·ã¹ãã ã®é«äŸ¡ãªå®è£ ããã®æ§æãããã³ã€ã³ãã°ã¬ãŒã¿ãŒãšç§ãã¡èªèº«ã®ã¢ããªã¹ãã«ãããµããŒããå¿ èŠãªã®ã§ããããïŒ
ãã®è³ªåã«çããããã«ããœãŒã¹ããSIEMã«åé¡ãããã€ãã³ãã®ã©ã€ããµã€ã¯ã«ãã©ã®ããã«æ§æãããŠããããã«ãŒã«ããªã¬ãŒããã€ã³ã·ãã³ãã®äœæãšé¡§å®¢ãžã®éç¥ãŸã§ã®æ¹æ³ã説æããŸãã
ã€ãã³ãã®äž»ãªåŠçã¯ãSIEMã·ã¹ãã ã®ã³ãã¯ã¿ã§çºçããŸãã åŠçã«ã¯ããã£ã«ã¿ãªã³ã°ãåé¡ãåªå é äœä»ããéçŽãããã³æ£èŠåãå«ãŸããŸãã ã€ãã³ãã«ã¯ãããšãã°ãç°ãªãæ å ±ãå«ãè€æ°ã®ã€ãã³ããçµã¿åãããŠãè¿œå ã®ååŠçãè¡ãããšãã§ããŸãã
äŸïŒarpã¹ããŒãã£ã³ã°ã远跡ããããã®netscreenãžã¥ãããŒãã°ã«ã¯ãIPã¢ãã¬ã¹ãšMACã¢ãã¬ã¹ã«é¢ããæ å ±ãç°ãªãè¡ã«å«ãŸããŠããŸãã
iso.3.6.1.4.1.3224.17.1.3.1.2.274 = IpAddressïŒ192.168.30.94
iso.3.6.1.4.1.3224.17.1.3.1.2.275 = IpAddressïŒ172.16.9.231
iso.3.6.1.4.1.3224.17.1.3.1.2.276 = IpAddressïŒ172.16.9.232
iso.3.6.1.4.1.3224.17.1.3.1.3.274 =å è§ã¹ããªã³ã°ïŒAC 22 0B 74 91 4C
iso.3.6.1.4.1.3224.17.1.3.1.3.275 =å è§ã¹ããªã³ã°ïŒ20 CF 30 9A 17 11
iso.3.6.1.4.1.3224.17.1.3.1.3.276 =å è§ã¹ããªã³ã°ïŒ80 C1 6E 93 A0 56
ã³ãã¯ã¿ãäœæãããšããããã«ããŒãžããŠ1ã€ã®ã€ãã³ãã«ãã¹ãŠã®æ å ±ã衚瀺ã§ããŸãã ãã®å Žåã®ããŒãã£ãŒã«ãããŒãžã¯iso.3.6.1.4.1.3224.17.1.3.1ã*ã276ã§ãã
次ã«ãååŠçãããã€ãã³ãã¯HPE ArcSightã·ã¹ãã ã®ã³ã¢ã«éä¿¡ãããããã§åŠçãããŸãã Solar JSOCã®äžç°ãšããŠãã€ãã³ãåŠçã®ãã¹ãŠã®æ®µéã䜿çšããŠãã€ã³ã·ãã³ããç£èŠãããšã³ãã·ã¹ãã ã«é¢ããæ å ±ãååŸããæ©èœãæ¡åŒµããŸããã
ã³ãã¯ã¿èšå®
ã€ãã³ãã®ååŠçã®äžéšãšããŠããã£ãŒã«ããããã³ã°ãè¿œå ã®åé¡ãããã³ã³ãã¯ã¿äžã®ã€ãã³ãã®ãã£ã«ã¿ãªã³ã°ã«é¢é£ããæ©èœãæ倧éã«æŽ»çšããããšããŸãã
æ®å¿µãªããã1ç§ãããã®åŠçæžã¿ã€ãã³ãïŒEPSïŒã®æ°ãããã³åŸç¶ã®èšç®ãšåæã€ãã³ãã®åŠçã«é¢ããSIEMã·ã¹ãã ã®æ©èœã¯éãããŠããŸãã Solar JSOCã§ã¯ã1ã€ã®ArcSightã€ã³ã¹ããŒã«ã«å¯ŸããŠè€æ°ã®é¡§å®¢ãååšãããããããã®ã€ãã³ãã®ãããŒã¯éåžžã«å€ããªã£ãŠããŸãã èšé²ãããã€ã³ã·ãã³ãã®åèšç¯å²ã¯100ã150ã«éããŸããããã¯ãèšç®ãã·ãŒãã®èšå ¥ãã€ã³ã·ãã³ãã®çæãªã©ã«æ°çŸã®ã«ãŒã«ã䜿çšããããšãæå³ããŸãã åæã«ãã·ã¹ãã ã®å®å®æ§ãšã¢ã¯ãã£ããªãã£ã³ãã«ã§ã®ã€ãã³ãã®è¿ éãªæ€çŽ¢ã¯éåžžã«éèŠã§ãã
åŸã ã«ãäžèšã®æ¡ä»¶ãæºããããã«ãåŠçã®äžéšãã³ãã¯ã¿ã¬ãã«ã«ç§»åã§ããããšãããããŸããã
ããšãã°ããããã¯ãŒã¯æ©åšãå«ãããŸããŸãªã·ã¹ãã ã§èªèšŒã€ãã³ããçµ±äžããããã«äºåæ°žç¶åã«ãŒã«ã䜿çšãã代ããã«ãã³ãã¯ã¿ã®ããããã¡ã€ã«ã¬ãã«ã§ã«ããŽãªãå°å ¥ããŸãã
Ciscoã«ãŒã¿ãŒã®ããããã¡ã€ã«ã¯æ¬¡ã®ããã«ãªããŸãã
event.eventClassIdãset.event.deviceActionãset.categoryOutcomeãset.event.categoryDeââviceGroup
SEC_LOGINïŒLOGIN_SUCCESSããã°ã€ã³ãæåã/ JSOC /èªèšŒ
SEC_LOGINïŒLOGIN_FAILUREããã°ã€ã³ã倱æã/ JSOC /èªèšŒ
SYSïŒãã°ã¢ãŠãããã°ã¢ãŠããæåã/ JSOC /èªèšŒ
DNSãµãŒããŒããã®ã€ãã³ãã®ãããŒã¯éåžžæãé«ããã®ã®1ã€ã§ãããããã€ã³ãã©ã¹ãã©ã¯ãã£ãã¹ãã£ã³ããããã«å€éšãµãŒããŒã«ããã°ã¬ãŒã¢ãã¬ã¹ã®è§£æ±ºã®è©Šè¡ãæ£èŠè¡šçŸã䜿çšããŠè¿œè·¡ããããšã¯éåžžã«å°é£ãªã¿ã¹ã¯ã«ãªããŸãã ArcSightã¯ãDNSã䜿çšãã1500 EPSã®ã¹ããªãŒã ã§ãæ°åãæªããªãããããæ£èŠè¡šçŸãããããã¡ã€ã«ã«é 眮ãããã«ããŽãªãå²ãåœãŠãããŸãã
代ããã«
æžãïŒ
æ®ãã¯ãããããã¡ã€ã«å ã®æ£èŠè¡šçŸã«ãã£ãŠåãåºãããŸãã
ã€ãã³ããã£ã«ã¿ãªã³ã°ã®äœ¿çšã®é¡èãªäŸã¯ãDNSãµãŒããŒã«ãé¢é£ä»ããããŠããŸãã HPE ArcSight SmartConnectorã³ãã¯ã¿ãµãŒããŒã§ã¯ããã¹ãåãWindowsã³ãã¯ã¿ããã³ãããã¯ãŒã¯æ©åšã®ã¢ãã¬ã¹ã«è§£æ±ºã§ããŸãã ãããã£ãŠãã³ãã¯ã¿ãµãŒããŒããã®DNSã¯ãšãªã®æ°ã¯éåžžã«å€ããªãå¯èœæ§ããããããããã¹ãŠã®ã€ãã³ãã¯ã€ã³ã·ãã³ããèå¥ããããã«æããã«å¿ èŠã§ã¯ãªããããESMã®è² è·ãæžããããã«æ£åžžã«ãã£ã«ã¿ãªã³ã°ã§ããŸãã
åé¡ã䜿çšãã2çªç®ã®ãããã«éèŠãªçç±ã¯ãå€ãã®å ŽåãããŸããŸãªããã€ã¹ãã·ã¹ãã ãããã³ã¢ããªã±ãŒã·ã§ã³ãœãããŠã§ã¢ã䜿çšããããšã§ãã
ããšãã°ããã·ã¢ã®äŒæ¥ã§ã¯ããŸã人æ°ã®ãªãNetScreenã«æ¥ç¶ããå¿ èŠãããå Žåã¯ãããšãã°ã以äžã«é¢ãããã¹ãŠã®ã«ãŒã«ã§Solar JSOCã«èš±å¯ã€ãã³ããè¿œå ã§ããŸãã
- ãããã·ããã€ãã¹ããŠã€ã³ã¿ãŒãããã«çŽæ¥ã¢ã¯ã»ã¹ããŸãã
- ããŸããŸãªã¬ãã¥ããŒã·ã§ã³ããŒã¿ããŒã¹ã®ããŒãžã§ã³ã«å¿ãããæœåšçã«å±éºãªãã¹ããžã®ã¢ã¯ã»ã¹ã
- ã¢ããªã±ãŒã·ã§ã³å±€ãããã³ã«ãªã©ã®ã¹ãã£ã³ã
ãŸããåé¡ãŸãã¯æ¢æã®ãã£ã«ã¿ãŒã䜿çšã§ããŸãã Solar JSOCã¯ãç°ãªãå Žåã«äž¡æ¹ã®æ¹æ³ã䜿çšããŸãã ãã®å ŽåãFirewall_Passãã£ã«ã¿ãŒã䜿çšããŸãã
äžèšã®äŸãããããããã«ãèŠä»¶ã«åã£ãŠããå Žåã¯æšæºã®ArcSightã«ããŽãªã䜿çšããŸãã
ã³ã³ãã³ãçžé¢ã«ãŒã«
Solar JSOCã®äžéšãšããŠããããŒã¹ãããã¡ã€ãªã³ã°ã€ã³ã·ãã³ãã«ãŒã«ããã³ãã«ãæ£åžžã«æ©èœãããšçµè«ä»ããŠããŸãã ããããã®ã¿ã€ããé çªã«è©³ããèŠãŠãããŸãããã
åºæ¬çãªã«ãŒã«
åºæ¬çãªã«ãŒã«ã¯ãæ¬ èœããŠããæ å ±ãã€ãã³ãã«è¿œå ããããã«äœ¿çšãããŸã-ãŠãŒã¶ãŒåã人äºã·ã¹ãã ããã®ã¢ã«ãŠã³ãææè æ å ±ãCMDBããã®ãã¹ãã®è¿œå 説æã ããã¯ãã¹ãŠSolar JSOCã«å®è£ ãããŠãããã€ã³ã·ãã³ããããè¿ éã«åæããéãããã€ãã³ãããŒã«ã§å¿ èŠãªãã¹ãŠã®æ å ±ãååŸããã®ã«åœ¹ç«ã¡ãŸãã ããã¯ãæåã®è¡ãåžžã«20åéSLAã«ãã£ãŠå²ãåœãŠãããé倧ãªã€ã³ã·ãã³ãã«å¯Ÿå¿ããåæã«éåžžã«é«å質ã§å®å šãªåæãè¡ãæ©äŒãæã€ããã«è¡ãããŸããã
ãããã¡ã€ã«ã«ãŒã«
ããŸããŸãªã¢ã¯ãã£ããã£ã®ãããã¡ã€ã«ã«ãŒã«ã¯ãæãéèŠãªåœ¹å²ã®1ã€ã§ãã ãããã¯ãã¢ã¯ãã£ããªã¹ãã«èšé²ããããã®åŸæ¬¡ã®ç¶æ³ã§äœ¿çšããããã©ã€ããªããŒã¿ã圢æããŸãã
- ã¢ã¯ãã£ããã£ã®ã¯ã€ãã¯ã¬ããã¹ãã¯ãã£ãæ€çŽ¢ã
ãããã®ãããã¡ã€ãªã³ã°ã«ãŒã«ã«ã¯ãããšãã°ãProfile_IA_Internet AccessïŒProxyïŒãå«ãŸããŸãã ãã®ã«ãŒã«ã¯ããããã·ãµãŒããŒãä»ãããµã€ããžã®ãã¹ãŠã®çŽ¹ä»ããªã¹ãã«æžã蟌ã¿ãŸãã ãã®ã·ãŒãã«ã¯æ¬¡ã®ãã£ãŒã«ããå«ãŸããŠããŸãã
ãã ããã·ãŒãã«ã¯300äžä»¶ã®ã¬ã³ãŒãã®å¶éããããããæ¯æ¥å€éã«ã¹ãã¬ãŒãžã¹ããŒã¹ã1æ¡å€ãåŸåã«ããŒã¿ãå ¥åããŸãã
ãã®ã·ãŒãã¯ãæšæºçãªã€ã³ã·ãã³ã調æ»ãšã1幎ãŸã§ã®é·æéã«ããã䟵害ã®ææšã®é¡åçæ€èšŒã®äž¡æ¹ã§äœ¿çšãããŸãã
- ãããã¡ã€ã«ã®äœæãšä¿®æ£ã
ããšãã°ãéèŠãªãã¹ãã®èªèšŒãŸãã¯ãããã¯ãŒã¯ãããã¡ã€ã«ã ãã®ãããªãããã¡ã€ã«ã®åéã«ã¯1ã2é±éããããŸãããã®åŸããããã¡ã€ã«ãã¢ã³ããŒããããŠã¯ã©ã€ã¢ã³ãã«éä¿¡ãããŸãã ãããã¡ã€ã«ã®èª¿æŽãšä¿®æ£ãè¡ãããåŸãã€ã³ã·ãã³ãã«ãŒã«ãèšå®ãããŸãã æå®ããããã©ã¡ãŒã¿ãŒã«åŸã£ãŠãããã¡ã€ã«ã«è©²åœããªãã¢ã¯ãã£ããã£ãåºçŸãããšããã®ã«ãŒã«ãããªã¬ãŒãããã€ã³ã·ãã³ããæåã®è¡ã§è§£æãããã¯ã©ã€ã¢ã³ãã«éç¥ãããŸãã
ã¹ããŒã¿ã¹ãå€æŽããããã«ãæ§æãã¡ã€ã«ã䜿çšããŸãã
ã¹ããŒã¿ã¹ãInProgressã®å Žåããããã¡ã€ã«ãåéãããã¹ããŒã¿ã¹ãFinishedã®å Žåãã€ã³ã·ãã³ãã«ãŒã«ãæ©èœãå§ããŸãã
- å¹³åãæ倧ãå€åææšã®èšç®ã
ããŠã€ã«ã¹æŽ»åã®ç°åžžãªçµ±èšããšããã«ãŒã«ã¯ããã®ååã«åºã¥ããŠããŸãã ã¯ã©ã€ã¢ã³ãã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãŠã€ã«ã¹ææã«é¢ããäžå®æéã®çµ±èšãèæ ®ããæ»æãæšçãšãªãæªæã®ããã¢ã¯ã·ã§ã³ã瀺ãå¯èœæ§ããããããããããã®æ¥ãæ¥å¢ããå Žåãç°åžžãã¯ã©ã€ã¢ã³ãã«éç¥ããŸãã
ã€ã³ã·ãã³ãã«ãŒã«
Solar JSOCã§ã¯ã次ã®çš®é¡ã®ç°åžžã¢ã¯ãã£ããã£ãã°ã䜿çšããŸãã
- ãœãŒã¹ããã®åäžã®ã€ãã³ãã
- éžæããæéã®1ã€ãŸãã¯è€æ°ã®ãœãŒã¹ããã®è€æ°ã®é£ç¶ããã€ãã³ãã®å Žåã
- ç¹å®ã®æéã®å¥ã®ã€ãã³ãã®éå§ã§ã¯ãªãã1ã€ã®éå§æã
- 1ã€ã®ã¿ã€ãã®ã€ãã³ãã®ãããå€ã«éãããšã
- åºæºå€ãŸãã¯å¹³åå€ããã®çµ±èšææšã®åå·®ã«ããã
- å¥ã«ã䟵害ã®ææšã®ãã§ãã¯ããããŸãã
åãªãã·ã§ã³ã«ã€ããŠè©³ããèŠãŠã¿ãŸãããã
çžé¢ã«ãŒã«ã䜿çšããæãç°¡åãªæ¹æ³ã¯ããœãŒã¹ããåäžã®ã€ãã³ããçºçãããšãã«èµ·åããããšã§ãã ããã¯ãæ§ææžã¿ã®SPIãšçµã¿åãããŠSIEMã·ã¹ãã ã䜿çšããå Žåã«å¹æçã§ãã å€ãã®äŒæ¥ã¯ãã®ããã«å¶éãããŠããŸãã
æãåçŽãªã€ã³ã·ãã³ãã®1ã€ã¯ããã¹ãäžã®éèŠãªãã¡ã€ã«ã®å€æŽã§ãã
ã«ãŒã«ã¯ãç¡æ¡ä»¶ã«/ etc / hostsãã¡ã€ã«ãããã³ã¢ã¯ãã£ããªã¹ãã§æå®ãããã¯ã©ã€ã¢ã³ããšåæãããã¹ãŠã®éèŠãªãã¡ã€ã«ãæ€çŽ¢ããŸãã
æéã«ãããè€æ°ã®ã€ãã³ãã®çžé¢ã«ãŒã«ã®äžè²«ããããªã¬ãŒã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã»ãã¥ãªãã£ã«çæ³çã«é©åããŸãã
1ã€ã®ã¢ã«ãŠã³ãã§ã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ãã°ã€ã³ããŠãããå¥ã®ã¢ã«ãŠã³ãïŒãŸãã¯VPNãšæ å ±ã·ã¹ãã ã䜿çšããåãã·ããªãªïŒã§ã¿ãŒã²ããã·ã¹ãã ã«ãã°ãªã³ãããšããããã®ã¢ã«ãŠã³ãã®çé£ã®å¯èœæ§ã瀺ãããŸãã ãã®ãããªæœåšçãªè åšã¯ãç¹ã«ç®¡çè ã®æ¥åžžæ¥åïŒãã¡ã€ã³ïŒa.andronovãããŒã¿ããŒã¹ïŒoracle_adminïŒã§äžè¬çã§ãããå€æ°ã®èª€æ€ç¥ãåŒãèµ·ããããããã¯ã€ããªã¹ãã®äœæãšè¿œå ã®ãããã¡ã€ãªã³ã°ãå¿ èŠã§ãã
次ã«ãVPNããŒã«ããäžæ£ãªãããã¯ãŒã¯ã»ã°ã¡ã³ããžã®ã¢ã¯ã»ã¹ãããªã¬ãŒããäŸã瀺ããŸãã
次ã«ããŠã€ã«ã¹æ€åºã€ãã³ããšããã®é€å»/修埩/æ€ç«ã®ã€ãã³ãã®ãã®åŸã®äžåšãæ€åºããããã«æ§æããã3çªç®ã®ã¿ã€ãã®ã€ã³ã·ãã³ãã«ãŒã«ã®äŸã瀺ããŸãã
ã«ãŒã«ãæ§æãã4çªç®ã®æ¹æ³ã¯ãããŸããŸãªã¹ãã£ã³ããã«ãŒããã©ãŒã¹ãæµè¡ãªã©ãèå¥ããã®ã«æé©ã§ãã
ãã¹ãŠã®ã·ã¹ãã ã«å ±éãããã«ãŒããã©ãŒã¹ã«ãŒã«ã¯ãäžèšã®ãã¹ãŠã®æ¹æ³ã®çé«ã§ãã ãœãŒã¹ãèšå®ãããšãã¯ãåžžã«åé¡ã«ããããã¡ã€ã«ã䜿çšããããããããã¯å€±æãã°ãªã³ãã£ã«ã¿ãŒã«è©²åœããã·ãŒãã«æžã蟌ãŸããã«ãŠã³ããããåºæ¬çãªã«ãŒã«ããããæ§æã·ãŒãã¯ããŸããŸãªé¡§å®¢ã®ãããå€ãèšå®ããããã«åå¥ã«äœ¿çšãããŸããã¯ãªãã£ã«ã«ããã³éã¯ãªãã£ã«ã«ãŠãŒã¶ãŒã 1人ã®ãŠãŒã¶ãŒã®æåã®è¡ãåãã¿ã€ãã®ã€ã³ã·ãã³ãã§ãã£ã±ãã«ãªããªãããã«ãäŸå€ãšåæ¢ãªã¹ããæäŸãããŸãã
å¹³åçãªææšããã®åå·®ã¯ãDDoSæ»æããŠã€ã«ã¹ã®çºçãäŒæ¥ãããã¯ãŒã¯ããã®æ å ±æŒãããããã³ãã®ä»ã®å€ããæ€åºããã·ããªãªã§äœ¿çšãããŸãã
äŸãšããŠã¯ãçžé¢ã«ãŒã«INC_AV_Virus Anomaly ActivityããããŸããããã¯ãç¹å®ã®æéã«ãããå¹³åçãªãŠã€ã«ã¹å¯Ÿçå¿ççïŒãããã¡ã€ã«ã«åºã¥ããŠèšç®ïŒã®è¶ éãç£èŠããŸãã
劥åã®ææšã®æ€èšŒã«é¢ããŠã¯ããããã®ç¹ã«é¢ããŠå šç¯å²ã®äœæ¥ãè¡ãããŠããããããããã¯å¥ã®æ®µèœãšããŠåŒ·èª¿ãããã¹ãã§ãïŒ
- ææšã®é¡åçæ€èšŒ;
- ã€ã³ãžã±ãŒã¿ã¯ãå°æ¥ã®æ€åºã®ããã«ç¹å¥ãªã·ãŒãã«å ¥åãããŸãã
- æéããã€ãšã䟵害ã®ææšã®é¢é£æ§ãèŠçŽãããŸãã
æåã®æ®µèœã«ã¯ããŠã§ããµã€ãã®èšªåãããã»ã¹ã®éå§ãã€ã³ãã©ã¹ãã©ã¯ãã£ã§èµ·åãããå®è¡å¯èœãã¡ã€ã«ã®md5åèšãç¹æ®ãªã»ãã¥ãªãã£ããŒã«ãŸãã¯äžéšããåãåã£ããŠã€ã«ã¹å¯Ÿçãã³ããŒã
2çªç®ãš3çªç®ã®æ®µèœã¯å¯æ¥ã«é¢é£ããŠããŸãã ãã®å Žåãã¬ãã¥ãŒã¯ãéãé »åºŠãããã³äœæŠãè»äºçã§ãã£ãããšã®ç¢ºèªã«å¿ããŠå®æœãããŸãã å€æ°ã®èª€æ€ç¥ãšæŠéäžè¶³ã®å Žåãã€ã³ãžã±ãŒã¿ã¯äžå®æéåŸã«åé€ãããŸãã
Solar JSOCãéçºããŠããµãŒãã¹ã®æäŸã®åºç€ãšãªãç¹å®ã®æèšãåŠã³ãŸããã
- ã«ã¹ã¿ããŒã€ã³ã¿ã©ã¯ã·ã§ã³ãšãã£ãŒãããã¯ã¯ãã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒã®éçšã«ãããéèŠãªèŠçŽ ã§ãã ããã«ããã顧客å
ã®ããã»ã¹ãããããç解ã§ããŸããã€ãŸããããŸããŸãªã€ã³ã·ãã³ãã«ãŒã«ã®äŸå€ãªã¹ããäœæãã誀æ€ç¥ã®æ°ãæ°åæžããããšãã§ããŸãã ããã¯ã©ã€ã¢ã³ãã§ã¯ãã¹ãã§TORã䜿çšããããšã¯å®å
šã«æ£åžžãªå Žåããããå¥ã®ã¯ã©ã€ã¢ã³ãã§ã¯åŸæ¥å¡ã解éããçŽæ¥çãªæ¹æ³ã§ãã äžéšã®äººã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœã§äœæ¥ã§ããä¿¡é Œã§ãã管çè
ã®ã¿ã«VPNã¢ã¯ã»ã¹ãèš±å¯ããä»ã®äººã¯åŸæ¥å¡ã®ååã«ã¢ã¯ã»ã¹ã§ããŸããã圌ãã¯ã¹ããŒã·ã§ã³ã§ã®ã¿äœæ¥ããŸãã
- ãããã¡ã€ã«ã®ã³ã¬ã¯ã·ã§ã³ã äŒç€Ÿã®åŸæ¥å¡ã®å€§å€æ°ã¯æ¯æ¥åãã·ããªãªã§åããŠããŸãã ãããã¡ã€ã«ããã®ã¯ç°¡åã§ãããããã£ãŠãç°åžžã¯ç°¡åã«ç¹å®ã§ããŸãã ãããã£ãŠãSolar JSOCã§ã¯çµ±äžãããã«ãŒã«ã䜿çšããŸããããããã®ãã©ã¡ãŒã¿ãŒããªã¹ãããã£ã«ã¿ãŒã¯ã¯ã©ã€ã¢ã³ãããšã«åå¥ã§ãã
- è€éãªã«ãŒã«ã¯æ©èœããŸãã ã çžé¢ã«ãŒã«ã«é¢ä¿ããæ確åæ¡ä»¶ãšéå§ã€ãã³ãã®æ°ãå€ãã»ã©ããã®ãããªã·ããªãªããã¹ãŠã®é¡§å®¢ã«å¯ŸããŠç®±ããå€ããå¯èœæ§ãäœããªããŸãã äŸå€ã®ã¬ãã«ã§è¡ãã«ã¯ãæ®éçãªã«ãŒã«ãšã埮調æŽããè¡ãå¿
èŠããããŸãã
- SIEMã¯ãã®ã¿ã¹ã¯ã®ã¿ã解決ããå¿
èŠããããŸãã SIEMã·ã¹ãã ã«Zabbixã¿ã¹ã¯ãŸãã¯DDoSæ€åºãœãªã¥ãŒã·ã§ã³ã匷å¶çã«è§£æ±ºãããå¿
èŠã¯ãããŸããã åŸè
ã¯ãã·ã¹ãã ã®ãªãœãŒã¹ããé£ãå°œãããã ãã§ãªãããã®DDoSãé²ãã®ã«åœ¹ç«ã¡ãŸããã
åæã«ãSIEMã·ã¹ãã ãã©ã®ããã«é©åã«æ§æããŠãã誀æ€åºã€ãã³ããåžžã«ååšããããšã«æ³šæããŠãã ããã ããã§ãªãå ŽåãSIEMã¯æ»ãã§ããŸãã ãããã誀æ€ç¥ãç°ãªããŸãã å€éã«ããããããŒãžã£ãŒã®ãã¹ã¯ãŒãããªã»ããããããšã¯ãèªå® ã§ä»äºããããšããäºæãã¬æ±ºå®ãšãã¹ã¯ãŒããæãåºããªãããšãããã³æ»æè ã®è¡åã®äž¡æ¹ã«ãã£ãŠèª¬æã§ããŸãã ããããææ°æè¡ã§èª€æ€ç¥ãçºçããçŸåšãéåžžã®äŸå€ãšããŠã€ã³ã·ãã³ãã«ãŒã«ã«è¿œå ãããŠããªãç¶æ³ããããŸãã ãã®ãããå®éã®ã€ã³ã·ãã³ããç¹å®ã§ããè³æ Œã®ããã¢ãã¿ãªã³ã°ãšã³ãžãã¢ãé 眮ããããšãéèŠã§ãã å°é家ã¯ãæ å ±ã»ãã¥ãªãã£ã«é¢ããäžé£ã®ç¥èãæã¡ãèµ·ããããæ»æã®ãã¯ãã«ãäºæž¬ããã€ãã³ããåæããããã®æçµçãªã·ã¹ãã ãç¥ã£ãŠããå¿ èŠããããŸãã
ãããã«
çµè«ãšããŠãç§ã¯äŒç€Ÿã§èªåã®SOCãçµç¹ããããã®æšå¥šäºé ãèŠçŽããããšæããŸãã
- SOCã®æãéèŠãªèŠçŽ ã¯SIEMã·ã¹ãã ã§ããéžæã®åé¡ã¯ãµã€ã¯ã«ã®æåã®èšäºã§èª¬æããŸããããæãéèŠãªç¹ã¯ããžãã¹ããã³ã€ã³ãã©ã¹ãã©ã¯ãã£æ©èœã®èŠä»¶ãžã®ã«ã¹ã¿ãã€ãºã§ãã
- çžé¢ã«ãŒã«ãäœæããŠããŸããŸãªæ»æã·ããªãªãšæ»æè
ã®æŽ»åãæ€åºããäœæ¥ã¯ã絶ãéãªãè
åšã®çºå±ã«é¢é£ããŠçµããããšã®ãªãèšå€§ãªäœæ¥å±€ã§ãã ãã®ããã瀟å
ã¹ã¿ããã«è³æ Œã®ããã¢ããªã¹ããå¿
èŠã§ãã
- ç£èŠãšã³ãžãã¢ã®æåã®è¡ã¯ãæ å ±ã»ãã¥ãªãã£éšéã«åºã¥ããŠåœ¢æãããå¿ èŠããããŸãã ã¹ãã·ã£ãªã¹ãã¯ã誀æ€ç¥ãšå®éã®ã€ã³ã·ãã³ããåºå¥ããã€ãã³ãã®åºæ¬çãªåæãå®æœã§ããå¿ èŠããããŸãã ããã«ã¯ãæ å ±ã»ãã¥ãªãã£ã®åéã®ã¹ãã«ãšãèããããæ»æãã¯ãã«ã®ç解ãå¿ èŠã§ãã
ãã®èšäºã§ã¯ãã€ã³ã·ãã³ãã®ç»é²ãæåã®è¡ã«ããåŠçã誀æ€ç¥ã®ãã£ã«ã¿ãªã³ã°åºæºãã¯ã©ã€ã¢ã³ããžã®éç¥ããã³è¿œå 調æ»ã®å®æœã®åé¡ã«å¯ŸåŠããŸããã§ããã ããã¯ãã·ãªãŒãºã®æ¬¡ã®èšäºã®äž»é¡ã«ãªããŸãã