èŠããã«ãWindows Defender ATPã¯ããããã¯ãŒã¯äžã®ã»ãã¥ãªãã£ã®è åšãæ€åºãã調æ»ããè¡åãèµ·ããããã«äœ¿çšã§ããã»ãã¥ãªãã£ãµãŒãã¹ã§ãã ãã®ãµãŒãã¹ã¯ãWindows 10ã«çµã¿èŸŒãŸãããã¯ãããžãŒãšMicrosoftã¯ã©ãŠããµãŒãã¹ã®çµã¿åããã«åºã¥ããŠããŸãã ãã®ãããªæè¡ã«ã¯ä»¥äžãå«ãŸããŸãã
- ãã¹ãåäœã»ã³ãµãŒ ã ãããã®ã»ã³ãµãŒã¯Windows 10ã«çµã¿èŸŒãŸããŠããŸããåäœïŒããã»ã¹ãã¬ãžã¹ããªããã¡ã€ã«ããããã¯ãŒã¯ã®çžäºäœçšãªã©ïŒã«é¢ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ä¿¡å·ãåéããã³åŠçããATPãµãŒãã¹ã®ãã©ã€ããŒããªåé¢ã¯ã©ãŠãã€ã³ã¹ã¿ã³ã¹ã«ããŒã¿ãéä¿¡ããŸãã
- ã¯ã©ãŠãã»ãã¥ãªãã£åæ ã æ¬è³ªçã«ã¯ãè¡åä¿¡å·ãåæããŒã¿ã«å€æããŠè åšãç¹å®ããããšãå¯èœã«ããè åšãæé€ããããã®æšå¥šäºé ã«ã圹ç«ã¡ãŸãã
- è åšåæ ã ãã€ã¯ããœããã«ã¯ãå°é家ãšããŒã¿ã»ãã¥ãªãã£éšéãå¥ã ã«ãããããã«å ããŠãããŒãããŒããã®è åšã«é¢ããåæããŒã¿ã䜿çšãããŸãã ããã«ãããATPãµãŒãã¹ã¯æ»æã®æ段ãæè¡ãããã³æ¹æ³ãèå¥ã§ããŸãã åéãããŠããããŒã¿ã§é¢é£ããå åãæ€åºãããšãã«ãŠãŒã¶ãŒã«èŠåããŸãã
æŠç¥çã«ããããã®ãµãŒãã¹ã³ã³ããŒãã³ãã以äžã«ç€ºããŸãã
ãã¹ãæ¢çŽ¢æ©èœã«ããã詳现ãªã¢ã©ãŒããåä¿¡ããäŸµå ¥ã®æ§è³ªãšç¯å²ãææ¡ã§ããŸãã
Windows Defender ATPãµãŒãã¹ã¯ãããŸããŸãªWindowsã»ãã¥ãªãã£ãã¯ãããžãŒãšé£æºããŸãã
- Windows Defender
- ããã«ãŒ
- ããã€ã¹ã¬ãŒã
ãŸãããµãŒãããŒãã£ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšäžŠè¡ããŠåäœããããšãã§ããŸãã
Windows Defender Advanced Threat Protection Portalã®æŠèŠ
ATPããŒã¿ã«ã䜿çšããŠãè åšãç£èŠããŠå¯Ÿå¿ã§ããŸãã 次ã®ã¿ã¹ã¯ã解決ããŸãã
- ãã¹ãããã®ã¢ã©ãŒãã衚瀺ããœãŒããããã³åé¡ããŸãã
- æ€åºãããã€ã³ãžã±ãŒã¿ã«é¢é£ããè¿œå æ å ±ãæ€çŽ¢ããŸãã ãããã¯ãç¹å®ã®ãã¡ã€ã«ãŸãã¯IPã¢ãã¬ã¹ã«ããããšãã§ããŸãã
- ããŸããŸãªãµãŒãã¹èšå®ãå€æŽããŸãïŒã¿ã€ã ãŸãŒã³ãšã¢ã©ãŒãã«ãŒã«ã
ããŒã¿ã«ã€ã³ã¿ãŒãã§ã€ã¹ã«ã¯ã次ã®4ã€ã®ã¡ã€ã³ã¯ãŒã¯ã¹ããŒã¹ãå«ãŸããŸãã
- ïŒ1ïŒèšå®ãšãªã¢
- ïŒ2ïŒããã²ãŒã·ã§ã³ãšãªã¢
- ïŒ3ïŒã¡ã€ã³ããŒã¿ã«
- ïŒ4ïŒæ€çŽ¢
èšå®ã§ã¯ããã¹ãŠãéåžžã«æçœã§ãã
ããã²ãŒã·ã§ã³ããã«ã§ã次ã®ãããªãã¥ãŒ
- æ å ±ããã« ïŒåºæ¬æ å ±ã衚瀺ããããã·ã¥ããŒãèªäœïŒ;
- ã¢ã©ãŒããã¥ãŒ ïŒæ°èŠãé²è¡äžãèš±å¯ãªã©ïŒã
ãã³ã³ãã¥ãŒã¿ãŒãã»ã¯ã·ã§ã³ã«ã¯ãATPãµãŒãã¹ãä¿è·ããã³ã³ãã¥ãŒã¿ãŒã®ãªã¹ããšãããã«é¢ããæ å ±ã衚瀺ãããŸãã
åªå 床èšå®ã䜿çšãããšãé»åã¡ãŒã«éç¥ãŸãã¯ããŒã¿ã¹ãã¬ãŒãžããªã·ãŒïŒã€ãŸããããã³ãã«ä¿åãããããŒã¿ã®éïŒãæ§æã§ããŸãã
ãã¹ã管çã»ã¯ã·ã§ã³ã§ã ATPã䜿çšãããã·ã³ãæºåããããã®ããã±ãŒãžãããŠã³ããŒãã§ããŸãã
ATPãµãŒãã¹ã次ã®èŠåã䜿çšããŸãã
ã¢ã©ãŒã-é«åºŠãªæ»æãšçžé¢ããã¢ã¯ãã£ããã£ã«é¢ããã¡ãã»ãŒãžã
æ€åº-æ€åºããããã«ãŠã§ã¢ã®è åšã®å åã
ã¢ã¯ãã£ããªè åš-æ€åºæã«ã¢ã¯ãã£ãã«å®è¡ãããè åšã
解決æžã¿-è åšã¯ã³ã³ãã¥ãŒã¿ãŒããåé€ãããŸããã
æªè§£æ±º-è åšã¯ã³ã³ãã¥ãŒã¿ãŒããåé€ãããŠããŸããã
äžè¬ã«ãATPã䜿çšããŠã»ãã¥ãªãã£ããŒã«ã調æ»ããæ¹æ³ã¯ã次ã®æé ã«åããããšãã§ããŸãã
- ããã·ã¥ããŒããŸãã¯ã¢ã©ãŒããã¥ãŒã«ã¢ã©ãŒãã衚瀺ããŸãã
- 䟵害ïŒIOCïŒãŸãã¯æ»æïŒIOAïŒã®ææšã®åæã
- ã¢ã©ãŒããåäœãããã³ã³ã³ãã¥ãŒã¿ãŒã€ãã³ãã®ã¿ã€ã ã©ã€ã³ã®åæã
- ã¢ã©ãŒãã®ç®¡çãè åšãŸãã¯æœåšçãªãããã³ã°ã®ç解ãæ å ±ãåéããŠå¿ èŠãªãã®ãå€æããã¢ã©ãŒããåŠçããŸãã
Windows Defender Advanced Threat Protectionããã·ã¥ããŒãã衚瀺ãã
æ å ±ããã«ã®ããŒã¿ãåæããããšã§ATPã®äœ¿çšãéå§ããããããã詳现ã«æ€èšããŸãã ã¢ã©ãŒããšã³ã³ãã¥ãŒã¿ãŒã«é¢ããããŒã¿ã䜿çšãããšããããã¯ãŒã¯äžã®çãããã¢ã¯ãã£ããã£ã®äºå®ãå Žæãããã³æéããã°ãã確ç«ã§ããŸããããã«ãããç¶æ³ãç解ããããã«å¿ èŠãªã³ã³ããã¹ããæäŸãããŸãã ã€ãã³ãã®æŠèŠãããã«è¡šç€ºãããã³ã³ãã¥ãŒã¿ãŒäžã®éèŠãªã€ãã³ããŸãã¯åäœãç¹å®ããã®ã«åœ¹ç«ã¡ãŸãã ãŸããã€ãã³ãããã³ã€ã³ãžã±ãŒã¿ã«é¢ãã詳现æ å ±ãäžäœã¬ãã«ã§éãããšãã§ããŸãã ã¢ã¯ãã£ãã¿ã€ã«ã¯ãã»ãã¥ãªãã£ã·ã¹ãã ã®å šäœçãªç¶æ ãè©äŸ¡ããããã®èŠèŠçãªæããããæäŸããŸãã ãã®ãããªã¿ã€ã«ãã¯ãªãã¯ãããšã察å¿ããã³ã³ããŒãã³ãã®è©³çŽ°ãã¥ãŒãéããŸãã
ATPãµãŒãã¹ã¢ã©ãŒã
[ ATPã¢ã©ãŒã ]ã¿ã€ã«ãã¯ãªãã¯ãããšãéå»30æ¥éã®ãããã¯ãŒã¯äžã®ã¢ã¯ãã£ããªATPãµãŒãã¹ã¢ã©ãŒãã®ç·æ°ã衚瀺ãããŸãã ã¢ã©ãŒãã¯ãæ°èŠãšå®è¡äžã®2ã€ã®ã°ã«ãŒãã«åããããŸãã
åã°ã«ãŒãã«ã¯ãé倧床ã¬ãã«ããšã«ãµãã«ããŽãªããããŸãã ããããã®å åŽã®æ°åãã¯ãªãã¯ãããšã察å¿ããã«ããŽãªã®ãã¥ãŒãã¥ãŒã衚瀺ã§ããŸãã
å±éºã«ãããããŠããã³ã³ãã¥ãŒã¿ãŒ
ãã®ã¿ã€ã«ã«ã¯ãæãã¢ã¯ãã£ããªã¢ã©ãŒããæã€ã³ã³ãã¥ãŒã¿ãŒã®ãªã¹ãã衚瀺ãããŸãã åã³ã³ãã¥ãŒã¿ãŒã®ã¢ã©ãŒãã®ç·æ°ã¯ãã³ã³ãã¥ãŒã¿ãŒåã®æšªã«ããåã§ç€ºãããŠããŸãã ã¿ã€ã«ã®å察åŽã«ã¯ãé倧床ã¬ãã«å¥ã«ã°ã«ãŒãåãããã¢ã©ãŒãã®æ°ããããŸãã æãè²ã®ã»ããå±éºã§ãããæããè²ã®ã»ããå°ãªããšæšæž¬ããããšã¯é£ãããããŸããã
[ ã¹ããŒã¿ã¹]ã¿ã€ã«ã«ã¯ããµãŒãã¹ãã¢ã¯ãã£ããã©ãããåé¡ããããã©ãããããã³éå»30æ¥éã«ãµãŒãã¹ã«ã¬ããŒããéä¿¡ããã³ã³ãã¥ãŒã¿ãŒã®æ°ã«é¢ããæ å ±ãå«ãŸããŸãã
[ ã³ã³ãã¥ãŒã¿ãŒã¬ããŒã]ã¿ã€ã«ã«ã¯ãæ¥ããšã«ã¢ã©ãŒããéä¿¡ããã³ã³ãã¥ãŒã¿ãŒã®æ°ã瀺ããã¹ãã°ã©ã ãå«ãŸããŠããŸãã ãã¹ãã°ã©ã ã®åã ã®åã«ã«ãŒãœã«ãåããããšãç¹å®ã®æ¥ã«ã¢ã©ãŒããéä¿¡ããã³ã³ãã¥ãŒã¿ãŒã®æ£ç¢ºãªæ°ã確èªã§ããŸãã
ã¢ã¯ãã£ããªãã«ãŠã§ã¢ãæ€åºãããã³ã³ãã¥ãŒã¿ãŒ
ã¢ã¯ãã£ããªãã«ãŠã§ã¢ãæ€åºãããã³ã³ãã¥ãŒã¿ãŒã¿ã€ã«ã¯ããšã³ããã€ã³ãã§Windows Defenderã䜿çšãããŠããå Žåã«ã®ã¿è¡šç€ºãããŸãã ã¢ã¯ãã£ããªãã«ãŠã§ã¢ãšã¯ãæ€åºæã«ã¢ã¯ãã£ãã«å®è¡ãããŠããè åšã®ããšã§ãã ååã«ã«ãŒãœã«ãåããããšãæ€åºãããã¢ã¯ãã£ããªãã«ãŠã§ã¢ã®æ°ãšãéå»30æ¥éã«å°ãªããšã1ã€ã®ã¢ã¯ãã£ããªãã«ãŠã§ã¢ãæ€åºããããã¹ãã®æ°ã確èªã§ããŸãã
ãã®ã¹ããŒã ã«ã¯ã5ã€ã®ã«ããŽãªã®ãã«ãŠã§ã¢ãå«ãŸããŠããŸãã
- ãã¹ã¯ãŒãçé£ããã°ã©ã -è³æ Œæ å ±ãçãããšãç®çãšããè åšã
- æmailã¯ãã³ã³ãã¥ãŒã¿ãŒãŸãã¯ãã¡ã€ã«ãžã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ããããã¯ããã¢ã¯ã»ã¹ãå埩ããããã«éã匷èŠããããšãç®çãšããè åšã§ãã
- ãšã¯ã¹ããã€ã -ãœãããŠã§ã¢ã®è匱æ§ã䜿çšããŠã³ã³ãã¥ãŒã¿ãŒã«ææããè åšã
- è åš -ãã¹ã¯ãŒããçãããã®ããã°ã©ã ãè è¿«ããã°ã©ã ãããã³ãšã¯ã¹ããã€ãã®ã«ããŽãªã«å±ããªããã®ä»ã®ãã¹ãŠã®è åšã ãã®ã«ããŽãªã«ã¯ãããã€ã®æšéŠ¬ãã¯ãŒã ãããã¯ãã¢ïŒããã¯ãã¢ïŒããã³ãŠã€ã«ã¹ãå«ãŸããŸãã
- äœé倧床 -ãã©ãŠã¶ãŒã®ä¿®é£Ÿåãªã©ãã¢ããŠã§ã¢ãæœåšçã«æãŸãããªãããã°ã©ã ãå«ãã äœé倧床ã®è åšã
ãã«ãŠã§ã¢ããããã¯ãŒã¯äžã§å®è¡ãããŠããå¯èœæ§ãéåžžã«é«ãããã£ã¹ã¯ã«ããŒã«ã«ã«ä¿åãããŠããã ãã§ã¯ãªãå Žåãè åšã¯ã¢ã¯ãã£ãã§ãããšèŠãªãããŸãã
ãããã®ã«ããŽãªã®ãããããã¯ãªãã¯ãããšã ã³ã³ãã¥ãŒã¿ãã¥ãŒã«ç§»åãã察å¿ããã«ããŽãªã®ããŒã¿ããã£ã«ã¿ãªã³ã°ãããŸãã ããã«ãããã©ã®ã³ã³ãã¥ãŒã¿ãŒãã¢ã¯ãã£ããªãã«ãŠã§ã¢ãæ€åºããããåã³ã³ãã¥ãŒã¿ãŒã«ç»é²ãããŠããè åšã®æ°ã«é¢ãã詳现æ å ±ãååŸã§ããŸãã
Advanced Threat Protectionã¢ã©ãŒããã¥ãŒã®è¡šç€ºãšæŽç
Windows Defender ATPãµãŒãã¹ã¢ã©ãŒãã¯ãå®æçãªæ¯æ¥ã®ã¿ã¹ã¯ãéããŠç®¡çã§ããŸãã ã¢ã©ãŒãã¯ãçŸåšã®ã¹ããŒã¿ã¹ã«åŸã£ãŠãã¥ãŒã«å ¥ããããŸãããã©ã«ãã§ã¯ããã¥ãŒå ã®ã¢ã©ãŒãã¯ææ°ã®ãã®ããå€ããã®ã®é ã«ãœãŒããããŸã次ã®è¡šãšã¹ã¯ãªãŒã³ã·ã§ããã¯ã ã¢ã©ãŒããã¥ãŒã®äž»ãªé åã瀺ããŠããŸãã
éžæãããšãªã¢ | ãšãªã¢å | 説æ |
---|---|---|
ïŒ1ïŒ | ã¢ã©ãŒããã¥ãŒ | æ°èŠ ã å®è¡äžããŸãã¯èš±å¯ãããã¢ã©ãŒãã®è¡šç€ºãéžæããŸã |
ïŒ2ïŒ | ã¢ã©ãŒã | åã¢ã©ãŒãã«ã¯æ¬¡ã®ããŒã¿ãå«ãŸããŸãã
ã¢ã©ãŒããã¯ãªãã¯ãããšãè åšã«é¢ããè¿œå æ å ±ã衚瀺ãããã¿ã€ã ã©ã€ã³ã¯ã¢ã©ãŒããäœæãããæ¥ä»ã«ç§»åããŸãã |
ïŒ3ïŒ | 䞊ã¹æ¿ããšèŠåãã£ã«ã¿ãŒ | ã¢ã©ãŒãã¯ã次ã®ãã©ã¡ãŒã¿ãŒã§ãœãŒãã§ããŸãã
ããã«ã衚瀺ãããã¢ã©ãŒãã¯ããã©ã¡ãŒã¿ã§ãã£ã«ã¿ãªã³ã°ã§ããŸãã
|
ç¹å®ã®åºæºã«åºã¥ããŠå¿ èŠãªã¢ã©ãŒããèå¥ããããã«ãã¢ã©ãŒããã¥ãŒããã£ã«ã¿ãªã³ã°ããã³ãœãŒãïŒèŠçŽïŒã§ããŸãã ããã«ã¯ã次ã®3ã€ã®ã¡ã«ããºã ã䜿çšã§ããŸãã
- [䞊ã¹æ¿ã]ãã£ãŒã«ãã®ããããããŠã³ã¡ãã¥ãŒã䜿çšããŠã次ã®ããããã®ãã©ã¡ãŒã¿ãŒãéžæããŠãã¥ãŒã䞊ã¹æ¿ããŸãã
- ææ° -ãšã³ããã€ã³ãã«æåŸã«è¡šç€ºãããæ¥ä»ã§ã¢ã©ãŒãããœãŒãããŸãã
- ãã¥ãŒæé - ãã¥ãŒå ã®æéã®é·ãã§ã¢ã©ãŒãããœãŒãããŸãã
- é倧床 -é倧床ã¬ãã«ã§ãœãŒãããŸãã
- ã¢ã©ãŒããé倧床ã¬ãã«ã§ãã£ã«ã¿ãªã³ã°ããã«ã¯ã[ ãã£ã«ã¿ãŒ ]ãã£ãŒã«ãã®ããããããŠã³ã¡ãã¥ãŒã§1ã€ä»¥äžã®ãã©ã°ãèšå®ã§ããŸãã
- é«ïŒèµ€ïŒïŒéåžžãæç¶çãªé«åºŠãªè åšïŒAPTïŒã«é¢é£ããè åšã ãã®ãããªã¢ã©ãŒãã¯ããã¹ãã«åŒãèµ·ããããå¯èœæ§ã®ããæå·ã®æ·±å»ãã«ããé«ããªã¹ã¯ã瀺ããŸãã
- äžïŒãªã¬ã³ãžïŒïŒã¬ãžã¹ããªã®ç°åžžãªå€æŽãçããããã¡ã€ã«ã®å®è¡ãæ»æã®ããŸããŸãªæ®µéã«å žåçãªåäœãªã©ããŸãã«ããçºçããªãè åšã
- äœïŒé»è²ïŒïŒäžè¬çãªãã«ãŠã§ã¢ããããã³ã°ããŒã«ã«é¢é£ããè
åšã§ãè€éããå¢ãè
åšã瀺ããŠããŸããã
- ãã¥ãŒã®è¡šç€ºéšåã¯ãæ¥ä»ç¯å²ãã£ãŒã«ãã®ããããããŠã³ã¡ãã¥ãŒã䜿çšããŠãããŸããŸãªæå®æéã«ãã£ãŠå¶éã§ããŸãïŒããã©ã«ãå€ã¯6ãæã§ã ïŒã
ãœãŒãé ãå€æŽããã«ã¯ïŒããšãã°ãææ°ã®ã¢ã©ãŒãã§ã¯ãªãæãå€ãã¢ã©ãŒããæåã«è¡šç€ºããïŒããœãŒãé ã¢ã€ã³ã³ãã¯ãªãã¯ããŸãã
Windows Defender Advanced Threat Protectionã¢ã©ãŒãåæ
åæãéå§ãã詳现æ å ±ãååŸããã«ã¯ãä»»æã®ãã¥ãŒã®éç¥ãã¯ãªãã¯ããå¿ èŠããããŸãã
ã¢ã©ãŒãã®è©³çŽ°ã«ã¯æ¬¡ã®ãã®ãå«ãŸããŸãã
- ã¢ã©ãŒããæåŸã«äœæãããæ¥ä»ãšæå»ã
- ã¢ã©ãŒãã®èª¬æã
- æšå¥šãããã¢ã¯ã·ã§ã³ã
- ã€ã³ã·ãã³ããã«ãŠã³ãããŸãã
- ã¢ã©ãŒãã®äœæã«ã€ãªãã£ãã€ã³ãžã±ãŒã¿ãŒã
æ»æè ãŸãã¯ãµããžã§ã¯ãã®ã¢ã¯ã·ã§ã³ãšé¢é£ä»ããããŠããã¢ã©ãŒãã®å Žåããµããžã§ã¯ãã®ååãä»ããè²ä»ãã®ã¿ã€ã«ã衚瀺ãããŸãã
ãµããžã§ã¯ãã®ååãã¯ãªãã¯ãããšããµããžã§ã¯ãã®ç°¡åãªæŠèŠã圌ã®èå³ãç®æšã«é¢ããæ å ±ãæŠè¡ãæ¹æ³ãæé ãäžçäžã®åœŒã®æŽ»åã«é¢ããæ å ±ãªã©ã圌ã®è åšåæãããã¡ã€ã«ãèŠãããšãã§ããŸãã æšå¥šãããå¿çã¢ã¯ã·ã§ã³ã®ã»ããã衚瀺ãããŸãã
ã€ã³ã·ãã³ãã°ã©ãã«ã¯ãã¢ã©ãŒãã®å Žæããã®äœæã«ã€ãªãã£ãã€ãã³ããããã³ã€ãã³ãã®åœ±é¿ãåããä»ã®ã³ã³ãã¥ãŒã¿ãŒã®èŠèŠçè¡šçŸãå«ãŸããŸãã ãã®ã°ã©ãã¯ããœãŒã¹ã³ã³ãã¥ãŒã¿ãŒã§ã®ã¢ã©ãŒãã®å¹æãšããã®ã€ãã³ããä»ã®ã³ã³ãã¥ãŒã¿ãŒã§ã®ã¢ã©ãŒãã«ã©ã®ããã«åœ±é¿ãããã瀺ããŠããŸãã
ã€ã³ã·ãã³ãã°ã©ãã®åãã¯ãªãã¯ããŠãããŒããå±éããã¢ã©ãŒãã«é¢é£ä»ããããŠããã€ãã³ããŸãã¯ãã¡ã€ã«ã衚瀺ã§ããŸãã
Windows Defenderã®ATPãµãŒãã¹ã¯Windows 10 Enterpriseã®ã³ã¢ã«çµã¿èŸŒãŸããŠããããããã®äœæ¥ã¯ç¡æã§è©äŸ¡ã§ããŸãã