æªç¥ã®è åšããä¿è·ããããã®Panda Adaptive Defenseãã¡ããªãŒãœãªã¥ãŒã·ã§ã³ã®æ°ããããŒãžã§ã³2.4ã®äž»ãªé©æ°ã¯ãæ¢ç¥ã®æªç¥ã®æ»æãæ©æã«æ€åºããŠé»æ¢ã§ããæ°ããåçãªäžæ£å©çšæè¡ã§ãã
Adaptive Defenseãã¡ããªãŒã®ãœãªã¥ãŒã·ã§ã³ã®æ°ããããŒãžã§ã³2.4ã¯ã以äžã®æ¹åã«ãããŠãŒã¶ãŒãåã°ããŸãã
1.ãµã€ããŒæ»æã®ã©ã€ããµã€ã¯ã«ã®æªçšïŒææïŒæ®µéã§ã®æ€åº/ç·©å-åçãªäžæ£å©çšæè¡
2.ãã«ãŠã§ã¢ããã¡ã€ã«ã䜿çšããªãæ»æã®æ€åºãããã³ç®¡çã³ã³ãœãŒã«ã«ããç£èŠ
3.ãããã¯ãŒã¯å ã§æ»æãæ¡æ£ããããã«äœ¿çšãããã³ã³ãã¥ãŒã¿ãŒã®èå¥
4.éçšã¢ããªã±ãŒã·ã§ã³ãžã®çµ±åã®ããã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒã®ã¹ããŒã¿ã¹ã«é¢ãã詳现æ å ±ã®ãšã¯ã¹ããŒã
5.ããŒã«ã«SIEMã¯ã©ã€ã¢ã³ããœãªã¥ãŒã·ã§ã³ãšçµ±åããããã®æè»æ§ã®åäž
6.é«åºŠãªãšãã¹ããŒãåæïŒ1ã€ä»¥äžã®è åšã®ã©ã€ããµã€ã¯ã«ã«é¢ãã詳现æ å ±ããšã¯ã¹ããŒãããæ©èœãããã³ã³ãã³ãã©ã€ã³ãã©ã¡ãŒã¿ãŒã«é¢ããæ å ±ã衚瀺ããæ©èœïŒããŒãžã§ã³2.4.1ïŒ
ãããã®æ¹åç¹ãããã«è©³ããèŠãŠã¿ãŸãããã
ãµã€ããŒæ»æã®ã©ã€ããµã€ã¯ã«ã®æªçšïŒææïŒæ®µéã§ã®çµæã®æ€åºãšè»œæž-åçãªäžæ£å©çšãã¯ãããžãŒ
ãšã¯ã¹ããã€ããšã¯ãæ£åœãªãœãããŠã§ã¢ã®ãã°ãè匱æ§ãå©çšã§ããäžé£ã®ã³ãã³ãã§ãã çŸä»£ã®ãµã€ããŒç¯çœªè ã¯ãå®è¡å¯èœãã¡ã€ã«ãšéå®è¡å¯èœãã¡ã€ã«ïŒãŸãã¯ã¹ã¯ãªããã«åºã¥ããã¡ã€ã«ããŒã¹ã®æ»æïŒã䜿çšããŠãã¯ãŒã¯ã¹ããŒã·ã§ã³ããµãŒããŒã«ã€ã³ã¹ããŒã«ãããã·ã¹ãã ã«ã¢ã¯ã»ã¹ããæ»æãè¡ãããã«ã·ã¹ãã ãæªçšããŸãã
å žåçãªæ»æã·ããªãªã§ã¯ãããã«ãŒã¯æ£åœãªããã°ã©ã ãæäœããŠã³ãŒããå®è¡ããã»ãã¥ãªãã£ã·ã¹ãã ã«ããæ€åºãåé¿ããããšããŸãã ãã®åŸããã®ã³ãŒãã¯ãã«ãŠã§ã¢ãã€ãŸã æªæã®ããå®è¡å¯èœãã¡ã€ã«ããŸãã¯æ£åœãªã·ã¹ãã ãŠãŒãã£ãªãã£ã䜿çšããŠãå®è¡å¯èœãã¡ã€ã«ã䜿çšããã«æªæã®ããã¢ã¯ã·ã§ã³ãå®è¡ããŸãïŒãã«ãŠã§ã¢ãŸãã¯ãã¡ã€ã«ã¬ã¹æ»æã䜿çšããªãæ»æïŒã
åŸè ã®å Žåãããã³å¿ èŠãªã³ã³ãã¥ãŒã¿ãŒãå®å šã«å¶åŸ¡ããããã«ãããã«ãŒã¯ãœãããŠã§ã¢ã®è匱æ§ãæªçšãããšãã«å¯èœã«ãªãäžé£ã®ã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠããããŸãã ãã®ãããªã·ããªãªã§ã¯ãè匱æ§ãæªçšããããšããè©Šã¿ããããã¯ããããšã«ãããæ»æãå®å šã«åæ¢ã§ããŸãã
Adaptive Defenseããã³Adaptive Defense 360ââã«ã¯ãããã€ã¹ã¢ã¯ãã£ããã£ãç¶ç¶çã«ç£èŠããæ¢ç¥ããã³æªç¥ã®ïŒãŒããã€ïŒãšã¯ã¹ããã€ããèå¥ããããšã«ããããšã¯ã¹ããã€ãè©Šè¡ãé²æ¢ããæ°ããåçãªã¢ã³ããšã¯ã¹ããã€ããã¯ãããžãŒãå«ãŸããŠããŸãã
éçšïŒææïŒæ®µéã§æ»æãé»æ¢ããããšãéèŠãªã®ã¯ãªãã§ããïŒ
ãµã€ããŒæ»æã¯ãããŸããŸãªææ³ã䜿çšããŠã·ã¹ãã ã«äŸµå ¥ããæ¢åã®æ€åºã¡ã«ããºã ããã€ãã¹ããäžé£ã®ã¢ã¯ã·ã§ã³ã§æ§æãããŸãã
å€ãã®æªæã®ããæ»æã«ã¯ãæ£åœãªã¢ããªã±ãŒã·ã§ã³ã«èŠãããè匱æ§ã䜿çšããŠãã€ã³ã¹ããŒã«ãããã»ãã¥ãªãã£ã·ã¹ãã ããçããåŒãèµ·ããããšãªãå¿ èŠãªã¢ã¯ã·ã§ã³ãå®è¡ããããšãå«ãŸããŸãã ããã«ãŒã¯ãœãããŠã§ã¢ã®è匱æ§ãå©çšããŠãã·ã¹ãã å šäœãå±éºã«ããããŸãã ãã®çµæããã®ãããªè匱æ§ã«ãããæ»æè ã¯å¿ èŠãªããã€ã¹ã ãã§ãªãããããã¯ãŒã¯äžã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã«ãå®å šã«ã¢ã¯ã»ã¹ã§ããŸãã
Panda Adaptive Defenseã®ãããªé«åºŠãªä¿è·ã·ã¹ãã ã®ç®æšã¯ããã®äžé£ã®ã¢ã¯ã·ã§ã³ãç¹å®ããŠåæ¢ããæªæã®ããã³ãŒããã¢ããªã±ãŒã·ã§ã³ãã·ã¹ãã ãããã³ã¯ãŒã¯ã¹ããŒã·ã§ã³ããµãŒããŒãèµ·åããŠå±éºã«ããããªãããã«ããããšã§ãã
ãµã€ããŒæ»æãæ§æããã¢ã¯ã·ã§ã³ãŸãã¯ã¹ãããã¯ããµã€ããŒãã«ãã§ãŒã³ïŒCKCïŒãšåŒã°ããå¢çããã¿ãŒã²ããã¯ãŒã¯ã¹ããŒã·ã§ã³ããã³ãµãŒããŒãžã®æ¡åŒµããŒãžã§ã³ã¯ãã¢ããã³ã¹ãµã€ããŒãã«ãã§ãŒã³ãšåŒã°ããŸãã ãµã€ããŒãã«ãã§ãŒã³ã«ã€ããŠè©³ããç¥ãããå Žåã¯ãããã«ã€ããŠã®èšäºãèªãããšããå§ãããŸãã
å³ 1.æ¡åŒµãµã€ããŒãã«ãã§ãŒã³ãã¢ãã«åããŸãã ã¿ãŒã²ãããµãŒããŒããã³ããã€ã¹ã«ã¢ã¯ã»ã¹ããããã«èšèšãããã¢ã¯ã·ã§ã³ãããã³ããã«ãŒã«ããæäœ
æ¡åŒµãµã€ããŒãã«ãã§ãŒã³ã¢ãã«ã«ãããšãæ»æè ã¯ç®æšãéæããããã«ãã®ã¢ãã«ã®åãã§ãŒãºãæåããå¿ èŠããããŸãããã客æ§ã®ãããã¯ãŒã¯ã®é²åŸ¡è ãšããŠãããã«ãŒãã¢ã¯ã»ã¹ãååŸããåã«ã©ã®æ®µéã§ãæ»æãåæ¢ã§ããå¿ èŠããããŸã圌ã®ç ç²è ã®è³ç£ã«ã ãããã£ãŠãæ»æã®ã©ã€ããµã€ã¯ã«ã®ãããã段éã§ãè åšãå¯èœãªéãè¿ éã«é»æ¢ããããã«é©åãªæè¡ãé©çšããå¿ èŠããããŸãã
ããŒãžã§ã³2.4ã«å«ãŸããåçãªæªçšé²æ¢æè¡ã¯ãæ£åœãªã¢ããªã±ãŒã·ã§ã³ãå±éºã«ããããŸã§æ»æãæ€åºããŠé®æããããã«èšèšãããŠããŸãã
Adaptive Defenseã®äžæ£å©çšæè¡ãšã¯äœã§ããïŒ
Adaptive Defenseã«ã¯ãPandaLabs PandaLabs Antivirus Labã®æ å ±ã»ãã¥ãªãã£å°é家ã«ãã£ãŠéçºãããæ°ããæªçšé²æ¢æè¡ãå«ãŸããŠããŸãã ãããã®æè¡ã¯ãPanda Securityã®ç¶ç¶çã«æŽæ°ãããç¥èïŒãã®æ å ±ã¯ãæ°çŸäžã®ããã€ã¹ã«ã€ã³ã¹ããŒã«ãããã»ã³ãµãŒãå«ãããŸããŸãªã»ã³ãµãŒãããªã¢ã«ã¿ã€ã ã§ååŸãããŸãïŒãããã³ããã»ã¹ãšãããŸããŸãªããã»ã¹éã®åå ãšçµæã®é¢ä¿ãç¶ç¶çã«åæãããšã³ãããã€ã¹äžã®ã¢ã¯ãã£ããã£ã®ç¶ç¶çãªç£èŠã«åºã¥ããŠããŸã
ãã®ãã¯ãããžãŒã®äž»ãªå©ç¹ïŒ
- ãšã¯ã¹ããã€ãããªã¢ã«ã¿ã€ã ã§ãããã¯ããããã®è¿œå ã®ä¿è·ã¬ã€ã€ãŒãæäŸããŸãã æªçšã«ããããã®ãã¯ãããžãŒã¯ãã³ã³ãã¥ãŒã¿ãŒã«ææããŠç€Ÿå ã®ä»ã®ããã€ã¹ã«åºããæªæã®ããã³ãŒãã®èµ·åãé²ããŸãã
- æ¢ç¥ãŸãã¯æªç¥ã®ïŒãŒããã€ïŒãšã¯ã¹ããã€ãã瀺ãå¯èœæ§ã®ããç°åžžãæ€çŽ¢ããããšã«ããã䟵害ãããããã»ã¹ã®å éšåäœãå¶åŸ¡ããŸãã
- æ»æã§äœ¿çšããããšã¯ã¹ããã€ãã«é¢ä¿ãªããè åšãæ€åºããŸãã Adaptive Defenseã¯ãããããçš®é¡ã®ãšã¯ã¹ããã€ããç¹ã«äžè¬çã«äœ¿çšãããã¢ããªã±ãŒã·ã§ã³ïŒJavaãAdobe ReaderãAdobeïŒã®Webãã©ãŠã¶ãŒïŒInternet ExplorerãFirefoxãChromeãOperaãªã©ïŒã®è匱æ§ãå©çšããæªç¥ã®ãšã¯ã¹ããã€ãïŒãŒããã€ïŒã«å¯Ÿããå¹æçãªä¿è·ãæäŸããŸãFlashãMicrosoft Officeããã«ãã¡ãã£ã¢ãã¬ãŒã€ãŒ...ïŒããã³ãµããŒããããŠããªããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒMicrosoft XPãªã©ïŒã
- ãšã³ããŠãŒã¶ãŒã«ç¶ç¶çãªä¿è·ãæäŸããã·ã¹ãã ã®åäœãé ãããŸããã
çŸåšåžè²©ãããŠããä»ã®ã»ãšãã©ã®è£œåãšã¯ç°ãªããAdaptive Defenseã¯æ¢ç¥ã®è匱æ§ã ãã§ãªããæãå±éºãªè åšã§ããæªç¥ã®è匱æ§ïŒãŒããã€ïŒãäžåããããšãã§ããŸãã ãããã£ãŠããœãªã¥ãŒã·ã§ã³ã¯ãã©ã€ããµã€ã¯ã«ã®ãããã段éã§ãšã¯ã¹ããã€ããã¯ããã¯ã䜿çšããæ»æã®æ€åºãšãããã¯ãå«ããå®è£ ã®ã³ã³ããã¹ãã§ã®ããããçš®é¡ã®ç°åžžãšç°åžžãªåäœã®æ€åºã«äž»ã«çŠç¹ãåœãŠãŠããŸãã
ãã®çµæããã®ãœãªã¥ãŒã·ã§ã³ã¯ãä¿è·ãããããã€ã¹ã®ãŠãŒã¶ãŒã«æ°ä»ãããã«å®è¡ãããè匱æ§ã䜿çšããæ»æã®éåžžã«æ©ã段éã§ãæªçšãé»æ¢ããæ£åœãªã¢ããªã±ãŒã·ã§ã³ã®äŸµå®³ãé²ãããšãã§ããŸãã
é©å¿é²åŸ¡ã¢ã³ããšã¯ã¹ããã€ããã¯ãããžãŒã®äž»ãªæ©èœ
çŸåšåžå Žã§æäŸãããŠããã»ãšãã©ã®äžæ£å©çšãœãªã¥ãŒã·ã§ã³ã¯ããã¡ã€ã«ããã³/ãŸãã¯ãã®å®è¡ã³ã³ããã¹ãã®åœ¢æ åŠçåæããŸãã¯Windowsã§å©çšã§ããªãããŸããŸãªä¿è·æ©èœã®å°å ¥ã«äŸåããŠããŸãïŒASRãDEPãEAFãããã³æ¢ç¥ã®è匱æ§ã®ç¹å®ã®æ€åºïŒäžè¬çãªè匱æ§ãšé²åºãCVEïŒã
ãã ãããããã®ææ³ã¯ãæ¢ç¥ããã³æªç¥ã®è匱æ§ã®ãããã§ããšã³ããªãã€ã³ãããäœæããæ»æãé»æ¢ããã»ã©å¹æçã§ã¯ãããŸããã
ããããã¹ãŠã®èŠå ãèæ ®ããŠãAdaptive Defense補åãã¡ããªãŒã«çŸåšå®è£ ãããŠããäžæ£å©çšæè¡ã®äž»ãªéãã匷調ããŸãã
- ãã®ã°ããŒãã«ãªæ§è³ªïŒæ¢ç¥ããã³æªç¥ã®ïŒãŒããã€ïŒè匱æ§ã®ãšã¯ã¹ããã€ããæ€åºããŸãã
- åžå Žã«ããä»ã®ã»ãšãã©ã®ãœãªã¥ãŒã·ã§ã³ãšã¯ç°ãªããPandaã®æ°ããäžæ£å©çšæè¡ã¯ãWindowsã·ã¹ãã ã®ã»ãã¥ãªãã£ããŒã«ãä¿®æ£ããããã ãã«èšèšããããã®ã§ã¯ãããŸããã ããã¯ãããã€ã¹ã§å®è¡ãããŠãããã¹ãŠã®ããã»ã¹ã®ç¶ç¶çãªç£èŠãšã人工ç¥èœã¢ã«ãŽãªãºã ã䜿çšããŠåéãããããŒã¿ã®ã¯ã©ãŠãããŒã¹ã®çžé¢ã«åºã¥ããŠããŸãã ããã«ãããæ»æã®æ¹åãšè匱æ§ã®æªçšã®ã³ã³ããã¹ããèªåçã«åæã§ããŸãã
- æ°ããäžæ£å©çšæè¡ã§ããAdaptive Defenseã®æå¹æ§ã¯ã次ã®ã³ã³ããŒãã³ãã®æ³šææ·±ãåæã«ãããã®ã§ãã
- ã¯ãŒã¯ã¹ããŒã·ã§ã³ããã³ãµãŒããŒã§ã®æªçšé²æ¢ä¿è·ãé«åºŠãªä¿è·ãšå®å šã«çµ±åãããŠããŸãã æŽæ°ãè¿œå ã®åŠçæ©èœã¯å¿ èŠãããŸããã ä¿è·ã¢ãã«ã¯ããšã³ãããã€ã¹ã§å®è¡ãããŠããããã»ã¹ããã³ã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠå®è¡ããããã¹ãŠã®ã¢ã¯ã·ã§ã³ã®ç£èŠã«åºã¥ããŠããŸãã
- ã¯ã©ãŠãç°å¢ã§å®è¡ãããå°çšã®æ©æ¢°åŠç¿ã¢ã«ãŽãªãºã ã ãããã®ã¢ã«ãŽãªãºã ã¯ãããŒãžããµãŒãã¹ã®äžå¯æ¬ ãªéšåã§ããããããšã¯ã¹ããã€ãæ»æã«äœ¿çšãããæ°ããã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ãé«åºŠãªãã€ãã¹æè¡ã«åžžã«é©åããŠããŸãã
- é«åºŠãªãšã¯ã¹ããã€ããã¯ããã¯ã®æ€åºã«ç¹åããè åšãã³ã¿ãŒã®å°éããŒã ã管çãããããŒãžããµãŒãã¹ã
Panda Adaptive Defenseã§ã®æ°ããäžæ£å©çšæè¡ã®çŽ¹ä»
æªçšé²æ¢æè¡ã®èšå®ã åäœã¢ãŒã
ããŒãžã§ã³2.4以éã§ã¯ãWebããŒã¹ã®ç®¡çã³ã³ãœãŒã«ã䜿çšããŠãã»ãã¥ãªãã£ãããã¡ã€ã«ã®ã¬ãã«ã§ãã®ãã¯ãããžãŒãæ§æã§ããŸãã æªçšé²æ¢æè¡ã¯ãé«åºŠãªä¿è·ãå«ãä»ã®é©å¿åé²è¡ã»ãã¥ãªãã£ã¢ãžã¥ãŒã«ãšã¯ç¬ç«ããŠãªã³ãšãªããåãæ¿ããããŸãã
æ°ããããŒãžã§ã³ã§ã¯ããã®ãã¯ãããžãŒã¯ããã©ã«ãã§ç¡å¹ã«ãªã£ãŠããŸãããäŒæ¥ãããã¯ãŒã¯ãä¿è·ããããã«æ§æããããã¹ãŠã®ã»ãã¥ãªãã£ãããã¡ã€ã«ã§æå¹ã«ããããšã匷ããå§ãããŸãã
å³ 2.ã»ãã¥ãªãã£ãããã¡ã€ã«ã§ã®äžæ£å©çšæè¡ã®èšå®
ç£æ»ã¢ãŒãïŒã³ã³ãœãŒã«æ€åºéç¥ã®ã¿
ãã®åäœã¢ãŒãã§ã¯ãAdaptive Defenseã¯ãšã¯ã¹ããã€ãã䜿çšããããšããè©Šã¿ãæ€åºããå Žåãã¢ã¯ã·ã§ã³ãå®è¡ããŸããã ãœãªã¥ãŒã·ã§ã³ã¯ãWebããŒã¹ã®ç®¡çã³ã³ãœãŒã«ã§ã€ãã³ããç»é²ããçµ±åAdvanced Reporting ToolïŒARTïŒSIEMã·ã¹ãã ã«é¢é£æ å ±ã衚瀺ããã ãã§ãªããSIEMFeederãµãŒãã¹ã®äžéšãšããŠãµãŒãããŒãã£ã®SIEMã·ã¹ãã ã«ãã°ãéä¿¡ããŸãã
ãããã¯ã¢ãŒãïŒæ€åºã«ã€ããŠã³ã³ãœãŒã«ã«éç¥ãããããã«å¯ŸããŠã¢ã¯ã·ã§ã³ãå®è¡ããŸã
ãã®æäœã¢ãŒãã§ã¯ãAdaptive Defenseã¯ç®¡çã³ã³ãœãŒã«ãšé»åã¡ãŒã«ãä»ããŠç®¡çè ã«ãšã¯ã¹ããã€ãã®äœ¿çšã®è©Šã¿ãéç¥ããã ãã§ãªãã䟵害ãããã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒã§å¿ èŠãªã¢ã¯ã·ã§ã³ãå®è¡ãããšã³ããŠãŒã¶ãŒã®ä»å ¥ãªãã«æ»æããããã¯ããŸã ã
ããã«ããããããã ã»ãšãã©ã®ãšã¯ã¹ããã€ãã¯ã䟵害ãããã¢ããªã±ãŒã·ã§ã³ã®ã¡ã¢ãªã«ãåç¶ããããããå€ãã®å Žåãããã»ã¹ãå®äºããŠã¡ã¢ãªãã¯ãªã¢ããå¿ èŠããããŸãã
ãã®ãããªç¶æ³ã§ã䟵害ãããããã»ã¹ãéèŠãªã·ã¹ãã ããã»ã¹ã§ããå Žåãæ»æãåæ¢ããã«ã¯ãå¿ èŠãªã³ã³ãã¥ãŒã¿ãŒã®åèµ·åãå¿ èŠã«ãªãå ŽåããããŸãã
ã¢ã¯ã·ã§ã³ãå¿ èŠãªå Žåã®äŸµå®³ãããã³ã³ãã¥ãŒã¿ãŒãŠãŒã¶ãŒã®éç¥
䟵害ãããã³ã³ãã¥ãŒã¿ãŒã®ãŠãŒã¶ãŒã¯ãæ£åœãªã¢ããªã±ãŒã·ã§ã³ã®æå³ããªãåæ¢ãã·ã¹ãã ã®åèµ·åã®éã«ééããå¯èœæ§ãããããã管çè ã«ããšã³ããŠãŒã¶ãŒã䟵害ãããããã»ã¹ãèªçºçã«åæ¢ãããã³ã³ãã¥ãŒã¿ãŒãåèµ·åãããã§ãããªãã·ã§ã³ãæäŸããŸãã ãã®ã¢ãããŒãã«ãããããšãã°ããŠãŒã¶ãŒãã¡ã€ã«ãžã®å€æŽãäºåã«ä¿åã§ããŸãã
å³ 3.ãšã¯ã¹ããã€ããæ€åºãããŸãã;䟵害ãããããã°ã©ã ãã·ã£ããããŠã³ããå¿ èŠããããŸã
å³ 4.ãšã¯ã¹ããã€ããæ€åºããããããã³ã³ãã¥ãŒã¿ãŒã®åèµ·åãå¿ èŠã§ãã ãã®éç¥ã¯ããšã³ãããã€ã¹ãåèµ·åããããŸã§å®æçã«è¡šç€ºãããŸãã
ãã ãã䟵害ãããããã»ã¹ãæ€åºãããŠããå®äºããããã³ã³ãã¥ãŒã¿ãŒãåèµ·åããããŸã§ãæªçšã³ãŒãã¯ã¡ã¢ãªã«ããŒãããããŸãŸã§ãæªæã®ããã³ãŒããå®è¡ããããšããããšã«æ³šæããŠãã ããã ãã®æœåšçã«å±éºãªç¶æ³ããŠãŒã¶ãŒã«æãåºãããããã«ãããŒã«ã«ã³ã³ãœãŒã«ã«ã¯ã䟵害ãããã¢ããªã±ãŒã·ã§ã³ãã·ã£ããããŠã³ãããã³ã³ãã¥ãŒã¿ãŒãåèµ·åãããããŠãŒã¶ãŒã«ä¿ãèŠåã衚瀺ãããŸãã
管çã³ã³ãœãŒã«ã§ã®ãšã¯ã¹ããã€ãæ€åºã®ç£èŠ
Adaptive Defense WebããŒã¹ã®ç®¡çã³ã³ãœãŒã«ã¯ã以äžã®æ¹æ³ã§ãšã¯ã¹ããã€ãæ€åºãéç¥ããŸãã
ãã¢ã¯ãã£ããã£ãããããã¯ããŸãã ããã«ãå®è¡äžããã³ãã¹ãæžã¿ã®ãã¹ãŠã®ããã°ã©ã ã®åé¡ã
æ€åºããããšã¯ã¹ããã€ãã®æ°ã¯ããã«ãŠã§ã¢ããã³ãšã¯ã¹ããã€ããšããŠåé¡ãããããã°ã©ã ã®ç·æ°ã«è¿œå ãããŸãã
å³ 5.ããã«ãå®è¡äžããã³ãã¹ãæžã¿ã®ãã¹ãŠã®ããã°ã©ã ã®åé¡ã
ãã¢ã¯ãã£ããã£ãããããã¯ããŸãã æªæã®ããã¢ããªã±ãŒã·ã§ã³ãšãšã¯ã¹ããã€ãããã«
æ€åºããããšã¯ã¹ããã€ãã¯ãæªæã®ããã¢ããªã±ãŒã·ã§ã³ãšãšã¯ã¹ããã€ãããã«ã®ã³ã³ãããŒã«ã³ã³ãœãŒã«ã«ãªã¢ã«ã¿ã€ã ã§è¡šç€ºãããŸãã
å³ 6.ããã«ãæªæã®ããããã°ã©ã ãšãšã¯ã¹ããã€ãã
æ€åºããããšã¯ã¹ããã€ãã®è©³çŽ°ïŒ
[æªæã®ããããã°ã©ã ãšãšã¯ã¹ããã€ã]ããã«ãã¯ãªãã¯ãããšãæ€åºããããã«ãŠã§ã¢ãšãšã¯ã¹ããã€ãã®ãªã¹ããå«ãããŒãžã«ç§»åããŸãã ããšã¯ã¹ããã€ããã¿ãã«åãæ¿ãããšã次ã®æ å ±ã衚瀺ãããŸãã
- ã³ã³ãã¥ãŒã¿ãŒå
- 䟵害ãããããã°ã©ã ãžã®é
- ãšã¯ã¹ããã€ãã«é¢é£ããŠå®è¡ãããã¢ã¯ã·ã§ã³ã ãã®åã®æå³ã¯æ¬¡ã®ãšããã§ãã
o 管çè ã«ããèš±å¯ïŒ ãç£æ»ãã¢ãŒãã
o ãããã¯ïŒèªåïŒïŒ ããããã¯ãã¢ãŒãã ãã®ãšã¯ã¹ããã€ãã¯ããŠãŒã¶ãŒã®ä»å ¥ãªãã§ããã«ãããã¯ãããŸããã
o ããã»ã¹ã®å®äºåŸã«ãããã¯ïŒ ããããã¯ãã¢ãŒãã ãŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ãçµäºããåŸããšã¯ã¹ããã€ãã¯ç¡å¹åãããŸããã
o ãŠãŒã¶ãŒã«ããèš±å¯ã ããããã¯ãã¢ãŒãã ãŠãŒã¶ãŒã¯ã¢ããªã±ãŒã·ã§ã³ãå®äºããããã«æ±ããããŸãããããŸã å®äºããŠããŸããã§ããã
o çºèŠãããŸããã åèµ·åãåŸ ã£ãŠããŸãã ããããã¯ãã¢ãŒãã ãã®ã¢ã¯ã·ã§ã³ã¯ã次ã®ç¶æ³ã§è¡šç€ºãããŸãã
-æªçšããããã¯ããŠä¿®æ£ããããã«ã·ã¹ãã ãåèµ·åããå¿ èŠãããå Žå ã·ã¹ãã ããã»ã¹ã«åœ±é¿ããŸãã
-䟵害ãããã¢ããªã±ãŒã·ã§ã³ãã·ã£ããããŠã³ããããã«ãŠãŒã¶ãŒã«æ±ããããããäžå®æéåŸã«ãããããªãã£ãå Žåã ã³ã³ãã¥ãŒã¿ãŒã®ç¶æ ãå€ãããã·ã¹ãã ãåèµ·åããå¿ èŠããããŸãã
- ãªã¹ã¯ã ãšã¯ã¹ããã€ããããã«ãããã¯ãããªãã£ãå Žåãããªã¹ã¯ãåã¯ããšã¯ã¹ããã€ããçºèŠãããŠãããããã¯ããããŸã§ïŒå®éã«ãããã¯ãããå ŽåïŒãã³ã³ãã¥ãŒã¿ãŒããªã¹ã¯ã«ãããããŠããããšã瀺ããŸãã
- çºèŠæ¥ã
å³ 7.ãã«ãŠã§ã¢ãšãšã¯ã¹ããã€ãã¢ã©ãŒã
éç¥ã®è©³çŽ°ã«ã¯ãæ»æã®å°é家åæã«å¿ èŠãªè¿œå æ å ±ãå«ãŸããŸããæ»æã®ã©ã€ããµã€ã¯ã«ãšãæ»æãåæ¢ãããŸã§ïŒæ»æãåæ¢ããå ŽåïŒã®é²åã詳ãã説æããã¢ã¯ãã£ããã£ã¹ã±ãžã¥ãŒã«ãããã³æ»æãæ€åºããããŸã§ã®URLãžã®ã¢ã¯ã»ã¹ ãããã®ã¢ãã¬ã¹ã®äžéšããã®æ»æã«é¢é£ä»ããããŠããå¯èœæ§ãé«ããªããŸãã
å³ 8.ã¢ã¯ã»ã¹ããURLãå«ããšã¯ã¹ããã€ãã®è©³çŽ°
çºèŠããããŸã§ãã©ã€ããµã€ã¯ã«ãæªçšãã
å³ 9.æéã®ãã€ããã¯ã¹ã§ã©ã€ããµã€ã¯ã«ã掻çšãã
ãšã¯ã¹ããã€ãããŒãã£ã·ã§ã³ã®å®çŸ©æžã¿ãã£ã«ã¿ãŒã䜿çšãããšãç¹å®ã®ã³ã³ãã¥ãŒã¿ãŒã䟵害ãããã¢ããªã±ãŒã·ã§ã³ãªã©ãæ€çŽ¢ã§ããŸããæªæã®ããããã°ã©ã ãæãŸãããªãããã°ã©ã ããããã¯ããããªããžã§ã¯ããå«ãããŒãã£ã·ã§ã³ã®å®çŸ©æžã¿ãã£ã«ã¿ãŒãšãŸã£ããåãæ¹æ³ã§ãã
äºåèšå®ãããã¬ããŒã
管çã¬ããŒããé«åºŠãªç®¡çã¬ããŒããè åšã¬ããŒãã«ã¯ãçºèŠããããšã¯ã¹ããã€ãã«é¢ããæ å ±ãå«ãŸããŸãã
ã¡ãŒã«ã¢ã©ãŒã
ãŸãããã«ãŠã§ã¢ãæ€åºããããšãã«é»åã¡ãŒã«éç¥ãéä¿¡ãããªãã·ã§ã³ãæå¹ã«ãªã£ãŠããå Žåããããã¯ãŒã¯ç®¡çè ãŸãã¯æ å ±ã»ãã¥ãªãã£ãµãŒãã¹ã®è²¬ä»»è ã¯ãæªçšãæ€åºããçŽåŸã«é»åã¡ãŒã«ããã°ããåä¿¡ã§ããŸãã
å³ 10.ãªã¢ã«ã¿ã€ã ã®ã¡ãŒã«éç¥èšå®ã
ãšã¯ã¹ããã€ãçºèŠã¢ã©ãŒããå«ã
å³ 11. Internet Explorerã«ãã䟵害ãããçºèŠããããšã¯ã¹ããã€ãã®é»åã¡ãŒã«éç¥ã ãšã³ããŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ãã·ã£ããããŠã³ããªãã£ãããããªã¹ã¯ã¹ããŒã¿ã¹ãé«ã
Advanced Reporting Toolã§å©çšå¯èœãªæ å ±
ã¯ã©ã€ã¢ã³ãã®ãããã¯ãŒã¯ã®è匱æ§ãæªçšããããšãããã³ã«ããã«ãŠã§ã¢ãŸãã¯PUPæ€åºã®å Žåãšåæ§ã«Advanced Reporting ToolïŒARTïŒã«éç¥ãããŸãããã®å Žåã®ã¿ããExploitããšããå€ãAlertTypeåã«è¡šç€ºãããŸãã
å³ 12.ãšã¯ã¹ããã€ãæ€åºéç¥ããŒãã«
ãããã£ãŠããã®ã¿ã€ãã®æ€åºã®å Žåããããã¯ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«è¡šç€ºãããŸãã
å³ 13.ãšã¯ã¹ããã€ãæ å ±ãå«ãã»ãã¥ãªãã£ã€ã³ã·ãã³ã
ã¯ã©ã€ã¢ã³ãSIEMãœãªã¥ãŒã·ã§ã³ã§å©çšå¯èœãªæ å ±
ãµãŒãããŒãã£ã®SIEMã·ã¹ãã ãäŒæ¥ã«å®è£ ãããŠããå Žåã䜿çšãããŠãããã¯ãããžãŒã«é¢ä¿ãªããè匱æ§ãæªçšããè©Šã¿ã®åæ€åºã«é¢ããæ å ±ã¯ãç¹å®ã®éç¥ã®åœ¢åŒã§ãã®SIEMãœãªã¥ãŒã·ã§ã³ã«äŒéãããŸãã ããã¯ããã«ãŠã§ã¢ããã³PUPæ€åºã®å Žåãšåãæ¹æ³ã§å®è£ ãããŸãããã®å Žåã®ã¿ããã®ãããªéç¥ã¯ããšã¯ã¹ããã€ããã€ãã³ãã¿ã€ãã§éä¿¡ãããŸãã
ãã¡ã€ã«ã¬ã¹ããã³éãã«ãŠã§ã¢æ»æã®æ€åº
æªæã®ããããã°ã©ã ã䜿çšããªãæ»æã¯ãéå®è¡å¯èœãã¡ã€ã«ã®äœ¿çšãChromeãFirefoxãInternet ExplorerãMicrosoft OfficeïŒWordãExcelãªã©ïŒãJava VMãAdobe補åãªã©ã®æ£åœãªã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ã«åºã¥ããŠããŸãã æ»æããããŠãŒã¶ãŒããã¯ããªã©ã§ãã¡ã€ã«ãéããšãã¡ã¢ãªå ã®ã³ãŒãã®é åžãšå®è¡ãéããŠã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒãå±éºã«ããããŸãã éå®è¡å¯èœãã¡ã€ã«ã䜿çšããæ»æã¯ãæ£åœãªã¢ããªã±ãŒã·ã§ã³ã®ã¡ã¢ãªã¹ã¿ãã¯ãæäœããæªæã®ããå®è¡å¯èœãã¡ã€ã«ãããŠã³ããŒãããã«ç®æšãéæããŸãã
ããã«å ããŠããã¡ã€ã«ã¬ã¹ãŸãã¯ãã¹ã¯ãªããåãæ»æã¯ãã¹ã¯ãªããèšèªïŒJavaãPowerShellãªã©ïŒã§èšè¿°ãããäžé£ã®ã³ãã³ãã«åºã¥ããŠããŸãã ãããã®æªæã®ããã¹ã¯ãªããã¯ããã¡ã€ã«ããã£ã¹ã¯ã«æžã蟌ãããšãªãå®è¡ãããŸãã ãã®ããããã®ãããªæ»æã¯ãã¡ã€ã«ããªãŒãšåŒã°ããŠããŸãã
æåŸã«ãå€ãã®æ»æã§ã¯ãã³ãã³ãã©ã€ã³ã«ãã¯ããšPowerShellåŒæ°ã®çµã¿åããã䜿çšããŸãã ããšãã°ãåé¿çã䜿çšããŠãªã¢ãŒã管çãµãŒããŒã®PowerShellã¹ã¯ãªããã䜿çšããŠæ»æãé衚瀺ã«ããŠèµ·åãããã¯ãã䜿çšããŠWordææžãéãæ»æã確èªããŸããã
ãã¡ã€ã«ã¬ã¹æ»æãšéå®è¡å¯èœãã¡ã€ã«ã«åºã¥ãæ»æã¯æ°ãããã®ã§ã¯ãããŸããããããäžè¬çã«ãªãã€ã€ãããåŸæ¥ã®ãŠã€ã«ã¹å¯Ÿçãœãªã¥ãŒã·ã§ã³ã§ã¯æ€åºãããŸããã
Adaptive DefenseãšAdaptive Defense 360ââã«ã¯ãããã»ã¹ãç£èŠãããããã®é¢ä¿ãšæ£åœãªã¢ããªã±ãŒã·ã§ã³ã®æªæã®ããåäœãèå¥ãããœãªã¥ãŒã·ã§ã³ã®èœåãç£èŠããããšã«ããããã®ã¿ã€ãã®æ»æãå€å¥ããæè¡ãå«ãŸããŠããŸãã ãããã®ææ³ã¯ãæ°ããããŒãžã§ã³2.4ã§ããã«åŒ·åãããŠããŸãã ãã®ããŒãžã§ã³ããããã®ãããªæ»æã®æ€åºã¯ãä»ã®æ€åºãšåãæ¹æ³ã§å¶åŸ¡ã§ããŸãã ã³ã³ãããŒã«ããã«ã«è¡šç€ºããããã«ãŠã§ã¢æ€åºãšããŠã¬ããŒãã«è¡šç€ºãããŸãã ããã«ããã管çè ã¯ã©ã€ããµã€ã¯ã«ãç£èŠãããã®ã¿ã€ãã®æ»æãæ€åºããããã³ã«é»åã¡ãŒã«éç¥ãåä¿¡ã§ããŸãã
ãããã¯ãŒã¯æ»æã®æææºãšããŠäœ¿çšãããã³ã³ãã¥ãŒã¿ãŒïŒæææºïŒ
ãµã€ããŒç¯çœªè ãäŒæ¥ãããã¯ãŒã¯ã®åŒ±ç¹ãçªç Žãããšã³ãã¯ãŒã¡ã³ãææ³ããã€ãã¹ææ³ãã³ã³ãã¥ãŒã¿ãŒãšãµãŒããŒéã®æ°Žå¹³ããã¢ãŒã·ã§ã³ã䜿çšããŠç®æšãéæããããšã¯åšç¥ã®äºå®ã§ãã å€ãã®å Žåããããã¯ãŒã¯äžã®ç¹å®ã®ã³ã³ãã¥ãŒã¿ãŒã¯ããŸã³ããã«å€ããããããéããŠå€éšç®¡çãµãŒããŒãå¿ èŠãªã³ãã³ããéä¿¡ããŸãã ãã®ãããªããŸã³ããã³ã³ãã¥ãŒã¿ãŒã¯ãäŒæ¥ãããã¯ãŒã¯äžã®ä»ã®ã³ã³ãã¥ãŒã¿ãŒã«ãµã€ããŒæ»æãä»æããçºå°å°ãšããŠäœ¿çšã§ããŸãã
ãã®ãããªå Žåããã®ä»ã®å Žåãã©ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒãæææºã§ããããã§ããã ãæ©ãçºèŠããããšãéåžžã«éèŠã§ãã
ããŒãžã§ã³2.4以éããã«ãŠã§ã¢/ PUPãæ€åºãããããæªç¥ã®ãªããžã§ã¯ãããããã¯ããããã³ã«ãAdaptive Defenseã¯ææãåºãã£ããããã¯ãŒã¯ã³ã³ãã¥ãŒã¿ãŒããã®IPã¢ãã¬ã¹ãããã³æ¥ç¶ãŠãŒã¶ãŒã«é¢ããããŒã¿ã衚瀺ããŸãã ãããã®æ å ±ã¯ãã¹ãŠãè åšã®ã©ã€ããµã€ã¯ã«ããŒã¿ã®äžéšã§ãã
å³ 14.æææºã瀺ãã©ã€ããµã€ã¯ã«ããŒã¿ã掻çšãã
ãã®ç¬éã«æ¥ç¶ãããŠãŒã¶ãŒ
ã³ã³ãã¥ãŒã¿ãŒã¹ããŒã¿ã¹ã¬ããŒã
å€ãã®å Žåãç¹ã«ãšã³ãããã€ã¹ã®ã»ãã¥ãªãã£ã管çããäŒç€Ÿã®ITéšéãŸãã¯ãµãŒãããŒãã£çµç¹ïŒã¢ãŠããœãŒã·ã³ã°ïŒã«ãã£ãŠç®¡çãããã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ãããã»ã¹ãããã³ããŒã«ãæã€äžèŠæš¡ããã³å€§èŠæš¡äŒæ¥ã§ã¯ãã¯ãŒã¯ã¹ããŒã·ã§ã³ããã³ãµãŒããŒã®ã¹ããŒã¿ã¹ã«é¢ããæ å ±ãå¿ èŠã§ãããããã®ããã»ã¹ãŸãã¯ããŒã«ã«çµ±åããŸãã ãã®äŸã¯ããŠãŒã¶ãŒèŠæ±ã管çããããã®äŒæ¥ã·ã¹ãã ã§ãïŒå éšãã¯ãã«ã«ãµããŒãïŒã
ãã®ãããæ°ããããŒãžã§ã³2.4ã«ã¯ãä¿è·ãããŠãããã¹ãŠã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒã®ã¹ããŒã¿ã¹ã«é¢ããæ å ±ãå«ãæ°ããã¬ããŒãã¿ã€ãïŒCSV圢åŒïŒãå«ãŸããŠããŸãã 管çè ã¯ããã®ã¬ããŒãããšã¯ã¹ããŒãããããèªåçã«éä¿¡ãããããã«ã¹ã±ãžã¥ãŒã«ãããã§ããŸãã
å³ 15.ã³ã³ãã¥ãŒã¿ãŒã®ã¹ããŒã¿ã¹ã«é¢ããã¬ããŒããããã«ããããŠãŒã¶ãŒã®é話管çã·ã¹ãã ãªã©ãçµç¹ã®ãªãã¬ãŒãã£ã³ã°ãœãããŠã§ã¢ã«ãã®ããŒã¿ãçµ±åã§ããŸãã
é«åºŠãªã¬ããŒãããŒã«ã®æ¹å
ãã®æ©èœã¯ã Advanced Reporting ToolïŒARTïŒã®ã©ã€ã»ã³ã¹ãæã£ãŠããã客æ§ã®ã¿ãå©çšã§ããŸãã
æ¢åã®ããŒãã«ã®æ°ããããŒã¿
- OPSããŒãã«ã«ããã©ã¡ãŒã¿ãŒãå«ããã¢ããªã±ãŒã·ã§ã³ã®èµ·åã«äœ¿çšãããã³ãã³ãã©ã€ã³åŒæ°ã衚瀺ãããããã«ãªããŸããã
- ã¢ã©ãŒãè¡šïŒ
-ãã®ããŒãã«ã«ã¯ãããšã¯ã¹ããã€ããã¿ã€ãã®ã€ãã³ããšãæåŸã«ã¢ã¯ã»ã¹ããURLïŒUrlListãã£ãŒã«ãã§ã*ãã§åºåãããæ倧10åã®URLïŒã衚瀺ãããŸãã
-ãã«ãŠã§ã¢ãæ€åºãããå Žåãæªæã®ãããã¡ã€ã«ããããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒããå¥ã®ã³ã³ãã¥ãŒã¿ãŒã«è»¢éããããšãã«çºçããå ŽåãããŒãã«ã«ã¯ãœãŒã¹ã³ã³ãã¥ãŒã¿ãŒãšããã«æ¥ç¶ãããŠãŒã¶ãŒã®IPã¢ãã¬ã¹ã衚瀺ãããŸãã
- 以åã¯ã SOCKETSããŒãã«ã«ã¯ãããã¯ãŒã¯ãããã³ã«ïŒTCPãUDPãICMPïŒã®ã¿ã衚瀺ãããŠããŸããã æ°ããããŒãžã§ã³ã§ã¯ãRDPãã©ãã£ãã¯ã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ã®æ¥ç¶ã«é¢ããæ å ±ã衚瀺ãããŸãïŒãªã¢ãŒããã¹ã¯ãããïŒã ããã«ãããRDPæ»æãèå¥ã§ããŸãïŒãProtocolãããŒã«ã¯å€ãTCP-RDPãã衚瀺ãããŸãïŒã
ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®æ°ãããŠã£ãžã§ãã
æææºã§ããã³ã³ãã¥ãŒã¿ãŒã«é¢ããæ å ±ãå«ã2ã€ã®æ°ãããŠã£ãžã§ãããç»å Žããæªæã®ããããã°ã©ã ãä»ã®ã³ã³ãã¥ãŒã¿ãŒã«ã³ããŒãŸãã¯è»¢éããããšããŸããã
æåã®ãŠã£ãžã§ããã¯ãéžæããæéã«2ã€ã®ã³ã³ãã¥ãŒã¿ãŒéã§ç¢ºç«ãããé¢ä¿ã衚瀺ããããŒãã°ã©ãã§ãã ããã«ããããã«ãŠã§ã¢ãã©ã®ã³ã³ãã¥ãŒã¿ãŒããã©ã®ã³ã³ãã¥ãŒã¿ãŒã«è»¢éããããšããŠããããæç³»åã§ç¢ºèªã§ããŸãã
å³ 16.ãšã³ãããã€ã¹ã®ã¿ã€ãã³ã°å³ãåããARTã®æ°ãããŠã£ãžã§ããã
æææºããã³ææè
2çªç®ã®ãŠã£ãžã§ããã¯ã¢ãã£ããã£ã°ã©ãã§ãã ããã¯ãããã³ã³ãã¥ãŒã¿ãŒïŒæææºïŒããä»ã®ã³ã³ãã¥ãŒã¿ãŒã«ãã«ãŠã§ã¢ã転éããããšããåæ°ã瀺ããŠããŸãã
å³ 17.ãšã³ãããã€ã¹ããªã³ã¯ããARTã®æ°ãããŠã£ãžã§ããã
æææºããã³ææè
ã€ãã³ãã«é¢é£ä»ããããŠããçŸåšã®ããã·ã¥ã«ããŽãªã«é¢ããæ å ±
芪ããã»ã¹ãšåããã»ã¹ã®ããã·ã¥ã«é¢é£ä»ããããã«ããŽãªã瀺ããã¹ãŠã®ããŒãã«ã«ãã€ãã³ãçºçæã®ã«ããŽãªãšçŸåšã®ã«ããŽãªïŒæ倧ãªãã¬ãã·ã¥ã¬ãŒã4æéïŒã衚瀺ãããããã«ãªããŸããã
SIEMFeederãµãŒãã¹ã®æ¹å
ãã®æ©èœã¯ããµãŒãããŒãã£ã®SIEMã·ã¹ãã ãšãœãªã¥ãŒã·ã§ã³ãçµ±åããSIEMFeederã®ã©ã€ã»ã³ã¹ãæã£ãŠããAdaptive DefenseãŠãŒã¶ãŒã®ã¿ãå©çšã§ããŸãã
ãã®ä»ã®ã€ãã³ãæ å ±
- OPSã€ãã³ãã¯ããã©ã¡ãŒã¿ãå«ããã¢ããªã±ãŒã·ã§ã³ã®èµ·åã«äœ¿çšãããã³ãã³ãã©ã€ã³åŒæ°ã衚瀺ããããã«ãªããŸããã
- ã¢ã©ãŒãã€ãã³ãïŒ
-çŸåšãããšã¯ã¹ããã€ããã¿ã€ãã®ã€ãã³ããšæåŸã«ã¢ã¯ã»ã¹ããURLïŒUrlListãã£ãŒã«ãã§ã*ãã§åºåãããæ倧10åã®URLïŒã衚瀺ãããŸãã ããã¥ã¡ã³ãããçºçãããšã¯ã¹ããã€ãã®å ŽåãDoclistãã£ãŒã«ãã«å ¥åãããŸãã
å³ 18. SIEMFeederã®ã¢ã©ãŒãã€ãã³ã圢åŒ
-ãã«ãŠã§ã¢ãæ€åºãããå Žåãæªæã®ãããã¡ã€ã«ããããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒããå¥ã®ã³ã³ãã¥ãŒã¿ãŒã«è»¢éããããšãã«çºçããå ŽåãããŒãã«ã«ã¯ãœãŒã¹ã³ã³ãã¥ãŒã¿ãŒãšããã«æ¥ç¶ãããŠãŒã¶ãŒã®IPã¢ãã¬ã¹ã衚瀺ãããŸãã
- 以åã¯ã SOCKETSã€ãã³ãã¯ãããã¯ãŒã¯ãããã³ã«ïŒTCPãUDPãICMPïŒã«ãã£ãŠã®ã¿è¡šç€ºãããŠããŸããã æ°ããããŒãžã§ã³ã§ã¯ãRDPãã©ãã£ãã¯ïŒãªã¢ãŒããã¹ã¯ãããïŒã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ã®æ¥ç¶ã«é¢ããæ å ±ã衚瀺ãããŸãã ããã«ãããRDPæ»æãèå¥ã§ããŸãïŒãProtocolãããŒã«ã¯å€ãTCP-RDPãã衚瀺ãããŸãïŒã
å³ 19. SIEMFeederã®ãœã±ããã€ãã³ã圢åŒ
ã¯ã©ã€ã¢ã³ãåŽã®ããŒã«ã«SIEMãœãªã¥ãŒã·ã§ã³ãšçµ±åããããã®æè»æ§ã®åäž
sFTPãŸãã¯FTPãä»ããŠã¯ãŒã¯ã¹ããŒã·ã§ã³ããã³ãµãŒããŒããã¢ã¯ãã£ããã£ãã°ãéä¿¡ããããšã«å ããŠãæ°ããããŒãžã§ã³2.4ã§ã¯Syslogãããã³ã«ãä»ããŠãã°ãéä¿¡ããããšãã§ããŸãã å¿ èŠã«å¿ããŠãéä¿¡ãããããŒã¿ã¯SSL / TLSæå·åã䜿çšããŠæå·åã§ããŸãã Syslogãããã³ã«ã䜿çšã§ããããã«ããã«ã¯ãç§ãã¡ã®åŽãããã°ãåä¿¡ããæºåãã§ããŠããSyslogãµãŒããŒããããã¯ãŒã¯ã«å®è£ ããå¿ èŠããããŸããããã¯ã»ãšãã©ã®å ŽåãSIEMãœãªã¥ãŒã·ã§ã³ã«æ¢ã«çµã¿èŸŒãŸããŠããŸãã
ãµãŒãã¹ãã©ã¡ãŒã¿ãèšå®ããã«ã¯ãäºåã®èšå®æ å ±ãšæéãå¿ èŠã§ããããšã«æ³šæããŠãã ããïŒäžŠåæ¥ç¶ã®æ°ãè©Šè¡ã®æ°ïŒããã©ã«ãã¯3ïŒãªã©ã
æåŸã«ããã®ããŒãžã§ã³ã§ã¯ãVPNãµãŒãã¹ãå®è£ ãããFTP / sFTPãä»ããŠãã°ãéä¿¡ããéã®ã»ãã¥ãªãã£ã¬ãã«ãåäžããŸãã
ããŒãžã§ã³2.4ã®ãã®ä»ã®æ¹å
ã»ãã¥ãªãã£ããŒãžã§ã³7.70ããã³ãšãŒãžã§ã³ãããŒãžã§ã³7.71ãåããããŒãžã§ã³2.4ã®Adaptive Defenseããã³Adaptive Defense 360ââãœãªã¥ãŒã·ã§ã³ã«ã¯ã以äžã®è¿œå ã®æ¹åãå«ãŸããŠããŸãã
1.äŸå€ç®¡çïŒ
- ãããã¡ã€ã«ã¬ãã«ã®äŸå€ãæ¡åŒµä¿è·ã«åœ±é¿ããŸãã
- æ€åºéç¥ãšäŸå€éç¥ã®éã®ããé«ãã¬ãã«ã®äžè²«æ§ïŒãªããžã§ã¯ããæ¡åŒµä¿è·ããé€å€ãããŠããå Žåããœãªã¥ãŒã·ã§ã³ã¯ãäŸå€ãåé€ããããŸã§ãã®ãªããžã§ã¯ãã®ã¡ãŒã«éç¥ãéä¿¡ããŸããã
2.ããã¯ã¢ãŒããšäžçŽãŠãŒã¶ãŒïŒãŠãŒã¶ãŒããŸã ä¿¡é Œã§ãããšåé¡ãããŠããªãã¢ããªã±ãŒã·ã§ã³ãèµ·åããããšã決å®ããå Žåããœãªã¥ãŒã·ã§ã³ã¯ãä¿¡é Œã§ãããšåé¡ãããªãå Žåã§ããã¢ããªã±ãŒã·ã§ã³ãšå¿ èŠãªã©ã€ãã©ãªãèµ·åã§ããããã«ãªããŸããã ã€ãŸããŠãŒã¶ãŒã®äœæ¥ãäžæããªãããã«ããŠãŒã¶ãŒã®æ±ºå®ãåªå ãããŸãã
3.管çã³ã³ãœãŒã«ã«ãã¹ã衚瀺ãããŠããªããšãã«ãExchangeãµãŒããŒã§ã®ééäžã«ãªããžã§ã¯ããæ€åºããããšãã«çºçãããšã©ãŒãä¿®æ£ãããŸããã
4.ä¿®æ£ããããã°ïŒã¯ãŒã¯ã¹ããŒã·ã§ã³ãŸãã¯ãµãŒããŒã§ã¢ã³ããŠã€ã«ã¹ä¿è·ãç¡å¹ã«ãªã£ãŠããããé«åºŠãªä¿è·ãæå¹ã«ãªã£ãŠããå Žåãéç¥é åã«è¡šç€ºãããæ å ±ã«é«åºŠãªä¿è·ãæå¹ã«ãªã£ãããšã衚瀺ãããŸãã
5.æ¹åïŒã¯ãŒã¯ã¹ããŒã·ã§ã³ãŸãã¯ãµãŒããŒã®ãŠãŒã¶ãŒã«è¡šç€ºãããæ€åºéç¥ã¯æ°åã ã衚瀺ãããåŸãèªåçã«æ¶ããŸããããŠãŒã¶ãŒãããããã¹ãããããå ŽåãéèŠãªã»ãã¥ãªãã£æ å ±ãèŠéããŠããå¯èœæ§ããããŸãããã®ããŒãžã§ã³ããããããã®éç¥ã¯å®æçã«ãªãããŠãŒã¶ãŒãå¿çãããŸã§è¡šç€ºãããŸãã
ãã®ä»ã®æ¹åïŒ
- ããŒã«ã«ãšãŒãžã§ã³ãã«çµ±åããããªã¢ãŒãã³ã³ãããŒã«ã¢ãžã¥ãŒã«ãšãAdaptive Defense / Adaptive Defense 360ââä¿è·ãæå¹ã«ããæ©èœã
- Webã³ã³ãœãŒã«ã®ã¡ãã¥ãŒã«ã¯ãSIEMFeederãŠãŒã¶ãŒã¬ã€ããžã®ãªã³ã¯ãå«ãŸããŠããŸãã
å³ 20.SIEMFeeder
ããïŒ
- ãWindowsã¿ãŒããã«ãµãŒããŒã
âã ã
âãPanda Securityã ãã
ãµããŒããããæ°ããã·ã¹ãã
æ°ããããŒãžã§ã³2.4ã¯ã次ã®æ°ããã·ã¹ãã ããµããŒãããŠããŸãã
- Server Core 2008ïŒ32ãŸãã¯64ãããïŒã2008 R2ïŒ64ãããïŒã2012ããã³2012 R2ãGUIãªãããªããªã ãµãŒããŒã«ã¯GUIããããŸããã以äžããå§ãããŸãã
-ã»ãã¥ãªãã£ãããã¡ã€ã«ã§æ£ãããããã·èšå®ãæ§æããããšã確èªããŠãã ãããã€ã³ã·ãã³ããçºçãããšããµãŒããŒã¯ãããã·ããŒã¿ãå¿ èŠãšããããŒã«ã«ã¡ãã»ãŒãžã衚瀺ããŸããã
- Windows MultiPoint Server 2012
- Virus Barrier X9ã«åºã¥ããMacã®æ°ããä¿è·
ã³ãã³ãã©ã€ã³ããã©ã€ããµã€ã¯ã«æ å ±ãšããŒã¿ããšã¯ã¹ããŒãããïŒããŒãžã§ã³2.4.1ïŒ
ããŒãžã§ã³2.4.1ïŒ2017幎6æã«ãªãªãŒã¹äºå®ïŒã¯ã1ã€ä»¥äžã®æ€åºãŸãã¯ãããã¯ããããªããžã§ã¯ãã®ã©ã€ããµã€ã¯ã«ããŒã¿ãCSV圢åŒã«ãšã¯ã¹ããŒãããæ©èœãæäŸããŸãã次ã«ããã®ããŒã¿ãExcelãªã©ã®ä»ã®ã¢ããªã±ãŒã·ã§ã³ã«ç°¡åã«ã€ã³ããŒãã§ããããã管çè ã¯ããªããžã§ã¯ãã®æ倧ã¬ãã«ã®è©³çŽ°ãšçžé¢ã䜿çšããŠããããã¯ãŒã¯å šäœã®å°é家ã«ããåæãå®è¡ã§ããŸãã
ããšãã°ãéå»24æéã«çºçãããã¹ãŠã®æ€åºããšã¯ã¹ããŒãããŠãç¹å®ã®æªæã®ããæ»æã®åœ±é¿ãåããã³ã³ãã¥ãŒã¿ãŒã®æ°ã確èªã§ããŸãã
çµç¹ãžã®æ»æã®åœ±é¿ã®å¯èœæ§ã®çšåºŠãè©äŸ¡ããããã«ãæ»æäžã«ã¢ã¯ã»ã¹ããããã¡ã€ã«ã確èªããããšãã§ããŸãã
ããã«ãæéã®çµéãšãšãã«æ€åºãçžé¢ãããããšãã§ããããã«ãŒã䜿çšããæ»æè ããšã³ããªãã€ã³ãã®æ°Žå¹³çãªé²æ©ãç¹å®ããããšãã§ããŸãã
æåŸã«ãããŒãžã§ã³2.4.1ã®ç®¡çã³ã³ãœãŒã«ã«ã¯ãPowerShellã¹ã¯ãªããã®å±éæã«ããã«ãŒã䜿çšããã³ãã³ãã©ã€ã³ãªãã·ã§ã³ã«é¢ããæ å ±ã衚瀺ãããŸãã
ããŒãžã§ã³2.4ã«åãæ¿ããææãšæ¹æ³
æ°ããããŒãžã§ã³2.4ã¯2017幎5æ8æ¥ããå©çšå¯èœã«ãªããé¢é£ããæ å ±ãWeb管çã³ã³ãœãŒã«ã®éç¥é åã«å ¬éãããŸãã
ãããã£ãŠãAdaptive Defense 360ââã®ç¡æãã©ã€ã¢ã«ã©ã€ã»ã³ã¹ãç»é²ããããšãæåã«æ±ºå®ããå Žåãæ°ããããŒãžã§ã³2.4ãå©çšå¯èœã«ãªããŸãã
äŒæ¥ãããã¯ãŒã¯ã§Adaptive Defense 360ââãæ§æããæ¹æ³ã«ã€ããŠã¯ã以åã®èšäº
ãAdaptive Defenseåçšã©ã€ã»ã³ã¹ã®ãŠãŒã¶ãŒããåç §ããŠãã ããã
- ã³ã³ãœãŒã«ããŒãžã§ã³ãããŒãžã§ã³2.4ã«ã¢ããã°ã¬ãŒãããã«ã¯ã察å¿ããéç¥ã«ãããã¿ã³ãã¯ãªãã¯ããå¿ èŠããããŸãã
- ããŒãžã§ã³2.4ã®ãªãªãŒã¹åŸæ°é±é以å ã«ã管çã³ã³ãœãŒã«ã®ããŒãžã§ã³ãèªåçã«æŽæ°ãããããšã«æ³šæããŠãã ããã以äžã¯ãã³ã³ãœãŒã«ããŒãžã§ã³ã®èªåæŽæ°ã®ã«ã¬ã³ããŒã§ãã
-æ倧101ã©ã€ã»ã³ã¹ã®
ã¯ã©ã€ã¢ã³ãïŒ05/17 /2017-101ã501ã©ã€ã»ã³ã¹ã®ã¯ã©ã€ã¢ã³ãïŒ05
/29/2017-501ã©ã€ã»ã³ã¹ãè¶ ããã¯ã©ã€ã¢ã³ãïŒ06/12/2017
- ã³ã³ãœãŒã«ããŒãžã§ã³ãããŒãžã§ã³2.4ã«ã¢ããã°ã¬ãŒããããšããšãŒãžã§ã³ãã¯èªåçã«ããŒãžã§ã³7.71ã«ã¢ããã°ã¬ãŒããããŸã
- ä¿è·ã¯ããšã³ãããã€ã¹ã«é©çšãããã»ãã¥ãªãã£ããªã·ãŒã§æ§æãããŠããå Žåã«ã®ã¿ãèªåçã«ããŒãžã§ã³7.70ã«æŽæ°ãããŸããã»ãã¥ãªãã£ããªã·ãŒã®æ§æã確èªããŠãã ããã
ãã€ãã©ã®ããã«ããªããããŒãžã§ã³2.4.1ã«ã¢ããã°ã¬ãŒãããããšãã§ããŸã
æ°ããŒãžã§ã³2.4.1ã¯ãWebããŒã¹ã®ã³ã³ãœãŒã«ç®¡çéç¥é åã«ããã2017幎6æã«å©çšã§ããããã«ãªããé¢é£ããæ å ±ãå ¬éãããŸãã
ããŒãžã§ã³2.4ãšã¯ç°ãªããæ°ããããŒãžã§ã³2.4.1ã«ã¯ç®¡çã³ã³ãœãŒã«èªäœã®æŽæ°ã®ã¿ãå«ãŸããŸãã
ãããã«
ã ãé©å¿é²è¡ã
ããããã ãããããããã/ã ..
æ°ããããŒãžã§ã³2.4ã¯ãæªç¥ã®è åšã«å¯Ÿããä¿è·ã匷åããé«åºŠãªãµã€ããŒãã«ãã§ãŒã³ã¢ãžã¥ãŒã«ãèæ ®ããŠãæ»æã®éåžžã«åæã®æ®µéïŒæäœïŒææïŒã¹ããŒãžïŒã§æ¢ç¥ããã³æªç¥ã®ãšã¯ã¹ããã€ãã«å¯Ÿããããå¹æçãªä¿è·ã¬ãã«ããŠãŒã¶ãŒã«æäŸããŸãã
è¿ãå°æ¥ãAdaptive Defenseã¯ãŠãŒã¶ãŒã«æ°ããæ¹åãæäŸã§ããããã«ãªããŸãïŒ
-ä¿è·ãããã³ã³ãã¥ãŒã¿ãŒçšã®çµ±åãªã¢ãŒãã³ã³ãããŒã«ã·ã¹ãã
-æ°ããWebããŒã¹ã®ç®¡çã³ã³ãœãŒã«ïŒããæè»ã§äœ¿ãããããæ°çŸããã³æ°åã®ããã€ã¹ããªã¢ã«ã¿ã€ã ã§ç®¡çããããã®ããããããå¹æçãª
-ãã®ä»ã®æ¹åããŒã¿æŒæŽ©ãé²ãããã
ãã ããããã«ã€ããŠã¯æ¬¡ã®èšäºã§èª¬æããŸãã
Adaptive Defense 360ââãã¢ã³ã³ãœãŒã«
管çã³ã³ãœãŒã«ã«æ £ããã«ã¯ãéåžžã®ãã©ãŠã¶ïŒChromeãŸãã¯Firefoxãæšå¥šïŒãšå°ãã®ç©ºãæéãããã°ååã§ãã
ã³ã³ãœãŒã«ïŒdemologin.pandasecurity.com
ãã°ã€ã³ïŒDRUSSIAN_FEDERATION_C14@panda.com
ãã¹ã¯ãŒãïŒDRUSSIANïŒ123
ãã©ã€ã¢ã«ã©ã€ã»ã³ã¹Adaptive Defense 360 1ãæéãç¡æã®ãã«æ©èœã©ã€ã»ã³ã¹ã«ç»é²
ã§ããŸãã