Canalysã«ãããšïŒãããŠåœŒå¥³ã¯æ å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®ãã·ã¢åžå Žãè©äŸ¡ãç¶ããŠããå¯äžã®äººç©ã§ãïŒãã·ã¹ã³ã¯åœå åžå Žã®ãªãŒããŒã§ããç¶ããŠããŸãã ãããã£ãŠãSIEM / SOCéçºè ãçŽé¢ããæåã®ã¿ã¹ã¯ã®1ã€ã¯ãåœç€Ÿã®ãœãªã¥ãŒã·ã§ã³ãšã®çµ±åã§ãããšæ³å®ããããšã¯éåžžã«åççã§ãã ãããããã®çµ±åã®åšèŸºã«ã¯ãæè¿åœå ã®SIEMã¡ãŒã«ãŒã®1ã€ãšè¡ã£ã察話ã§èª¬æã§ããå€ãã®ç¥è©±ãšèª€è§£ããããŸãã
ããªãã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ãšçµ±åããªãã®ã§ããïŒã
-ããã§ãããªãã¯ãã¹ãŠæææš©ãæã£ãŠããŸããïŒ
ãããããããã§ã¯ãããŸããïŒã
-ã¯ãïŒ ãããŠã圌ãã¯ããªããAPIãéããŠããããããã«ã¢ã¯ã»ã¹ããã«ã¯ãéãããããšèšã£ãã
-ããããããã¯ããã§ã¯ãããŸããïŒ
ãã®ãããæ¬æ¥ãã·ã¹ã³ãä¿æããŠããAPIãç°¡åã«èª¬æãããã®APIã䜿çšããŠãµã€ããŒã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã«æ¥ç¶ããããšã«ããŸããã ãããã¯ããã€ãã®ã¿ã€ãã«åããããšãã§ããŸãïŒ
- äŒæ¥ã®ä¿è·ããããããã¯ãŒã¯ã®ã·ã¹ã³ãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠåéãããã»ãã¥ãªãã£ã€ãã³ãããã°ãã³ã³ããã¹ãã«ã¢ã¯ã»ã¹ã§ããAPIã
- Ciscoã¯ã©ãŠãã»ãã¥ãªãã£ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããŠãçããããã¡ã€ã«ããã¡ã€ã³ãIPã¢ãã¬ã¹ãªã©ããã§ãã¯ã§ããAPI
- å€éšã·ã¹ãã ããã·ã¹ã³ãœãªã¥ãŒã·ã§ã³ã管çããããã®APIã
- å€éšãœãŒã¹ããã®è åšããŒã¿ã§ã·ã¹ã³ãœãªã¥ãŒã·ã§ã³ã匷åããAPIã
APIã®æåã®ã¿ã€ãã¯æ¬¡ã®ãšããã§ãã
- eStreamer API ã Firepoweræ©èœãè±å¯ãªã»ãã¥ãªãã£ãã©ãããã©ãŒã ããSIEMã«ã»ãã¥ãªãã£ã€ãã³ããéä¿¡ã§ããAPIã
- ãã¹ãå ¥åAPI ãããã¯ãŒã¯äžã®ããŒãã«é¢ããè匱æ§æ å ±ããã³ãã®ä»ã®æ å ±ãåéã§ããããã«ããAPIã Positive Technologiesã®åãMaxPatrolã䜿çšããŠãã¹ãã£ã³ãããããŒãäžã®è匱æ§ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãããã³ã¢ããªã±ãŒã·ã§ã³ã«é¢ããFirepoweræ å ±ãéä¿¡ããNGIPSäŸµå ¥æ€ç¥ãµãã·ã¹ãã ãŸãã¯Firepowerãã©ãããã©ãŒã äžã®AMPãã«ãŠã§ã¢å¯Ÿçã³ãŒãã«ãã£ãŠåéãããè åšã«é¢ããããŒã¿ãšçžé¢ããŸãã
- JDBCããŒã¿ããŒã¹ã¢ã¯ã»ã¹API ã ããŸããŸãªã¢ããªã±ãŒã·ã§ã³ããFirepowerããŒã¿ããŒã¹ãç §äŒã§ããAPIã
- pxGrid ããã¯ãCisco ISEãããã¯ãŒã¯ã¢ã¯ã»ã¹å¶åŸ¡ã·ã¹ãã ãšå€éšãœãªã¥ãŒã·ã§ã³ïŒSIEMãMDMãITUãNACãIRPãUEBAãCASBãIââAMïŒã®éã§ã»ãã¥ãªãã£ã³ã³ããã¹ãïŒèª°ãã©ããã©ã®ããã«ãã©ãã§ãã©ã®ã¢ã¯ã»ã¹ã§ïŒã亀æã§ãããã¬ãŒã ã¯ãŒã¯å šäœã§ãã VMãªã©ïŒã ãã®APIã䜿çšãããšããŠãŒã¶ãŒããã³ããã€ã¹ã®ã¢ã¯ã»ã¹ã€ãã³ãã«é¢ããæ å ±ããã·ã¹ã³ã®ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ïŒã¹ã€ãããã«ãŒã¿ãŒãã¢ã¯ã»ã¹ãã€ã³ããªã©ïŒããçŽæ¥åä¿¡ã§ããŸãã
- MDM API ãµãŒãããŒãã£ã®MDMãœãªã¥ãŒã·ã§ã³ïŒAirwatchãMaaS360ãMerakiãSAPãXenMobileãSymantecãMobileIronãGoodãIntuneãªã©ïŒãISEããã¢ãã€ã«ããã€ã¹ã®ã¹ããŒã¿ã¹ã«é¢ããæ å ±ãåä¿¡ã§ããããã«ããŸãã
- AnyConnectãããã¯ãŒã¯å¯èŠæ§ã¢ãžã¥ãŒã«ã³ã¬ã¯ã·ã§ã³ ã ãã®APIã䜿çšããŠãAnyConnectã»ãã¥ãªãã£ã¯ã©ã€ã¢ã³ãã¯ããããã¯ãŒã¯ãã©ãã£ãã¯åæããŒã«ïŒããšãã°ãCisco StealthwatchïŒãšã®çžé¢ã®ããã«IPFIXããŒã¿ãæäŸããŸãã
- AMP for Endpoints API ã Cisco AMP Advance Malware ProtectionããµãŒãããŒãã£ãœãªã¥ãŒã·ã§ã³ããŸãã¯ãã®ä»ã®ã·ã¹ã³ãœãªã¥ãŒã·ã§ã³ïŒCisco Cognitive Threat Analyticsãªã©ïŒã«ãã£ãŠæ€åºãããæªæã®ããã³ãŒãã«é¢é£ããã»ãã¥ãªãã£ã€ãã³ããéä¿¡ã§ããAPIã ãã®ãããªã€ãã³ãã«ã¯ãè匱ãªã³ã³ãã¥ãŒã¿ãŒãããã€ã¹ã®è»è·¡ïŒãããã¯ãŒã¯ã¢ã¯ãã£ããã£ïŒãå éšãŸãã¯å€éšããŒããšã®éä¿¡ãææãªã©ãå«ãŸããŸãã
- ESA REST API ã ã»ãã¥ãªãã£ã€ãã³ããšé»åã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ã®çµ±èšãåéã§ããŸãã
- Stealthwatch Data Exporter SDK ã Cisco Stealthwatchãããã¯ãŒã¯ãã©ãã£ãã¯ç£èŠã·ã¹ãã ãããããã¯ãŒã¯ãããŒã«é¢ããã€ãã³ããååŸããç¬èªã®ç®çã«äœ¿çšã§ããŸãã
AMP for Endpointsã®APIã®äœ¿çšäŸãèŠãŠã¿ãŸããããããã¯ãWindowsãLinuxãiOSãAndroidãMacOSãå®è¡ããŠããå人ããã³ã¢ãã€ã«ããã€ã¹ã«ã€ã³ã¹ããŒã«ããå¹ åºãè åšããä¿è·ãããœãªã¥ãŒã·ã§ã³ã§ãã æè¿çºçããã»ãã¥ãªãã£ã€ãã³ããååŸãããšããŸãã ãã®ããã«ããªã¯ãšã¹ããGET / v1 / eventsãã䜿çšãããŸããããã«ã¯ãç¹å®ã®ããŒããŸãã¯ããŒãã®ã°ã«ãŒãã察象ãã¡ã€ã«ã®ããã·ã¥ãã€ãã³ãã®ã¿ã€ããæéãªã©ãéžæã§ããå€ãã®è¿œå ãªãã·ã§ã³ããããŸãã ããšãã°ãç¹å®ã®ããŒãã§ã®ã€ãã³ãã«é¢å¿ãããå ŽåãAMP for Endpoints APIãä»ãããªã¯ãšã¹ãã¯æ¬¡ã®ããã«ãªããŸãã
GET /v1/events?connector_guid[]=af73d9d5-ddc5-4c93-9c6d-d5e6b5c5eb01&limit=1
çãã¯æ¬¡ã®ãšããã§ãã
{ "version": "v1.2.0", "metadata": { "links": { "self": "https://api.amp.cisco.com/v1/events?connector_guid[]=af73d9d5-ddc5-4c93-9c6d-d5e6b5c5eb01&limit=1", "next": "https://api.amp.cisco.com/v1/events?connector_guid%5B%5D=af73d9d5-ddc5-4c93-9c6d-d5e6b5c5eb01&limit=1&offset=1" }, "results": { "total": 41, "current_item_count": 1, "index": 0, "items_per_page": 1 } }, "data": [ { "id": 6455442249407791000, "timestamp": 1503024774, "timestamp_nanoseconds": 98000000, "date": "2017-08-18T02:52:54+00:00", "event_type": "Threat Detected", "event_type_id": 1090519054, "detection": "benign_qa_testware7", "detection_id": "6455442249407791109", "group_guids": [ "b077d6bc-bbdf-42f7-8838-a06053fbd98a" ], "computer": { "connector_guid": "af73d9d5-ddc5-4c93-9c6d-d5e6b5c5eb01", "hostname": "WIN-S1AC1PI6L5L", "external_ip": "10.200.65.31", "user": "johndoe@WIN-S1AC1PI6L5L", "active": true, "network_addresses": [ { "ip": "10.0.2.15", "mac": "08:00:27:85:28:61" } ], "links": { "computer": "https://api.amp.cisco.com/v1/computers/af73d9d5-ddc5-4c93-9c6d-d5e6b5c5eb01", "trajectory": "https://api.amp.cisco.com/v1/computers/af73d9d5-ddc5-4c93-9c6d-d5e6b5c5eb01/trajectory", "group": "https://api.amp.cisco.com/v1/groups/b077d6bc-bbdf-42f7-8838-a06053fbd98a" } }, "file": { "disposition": "Unknown", "file_name": ".zip", "file_path": "\\\\?\\C:\\Users\\johndoe\\Downloads\\.zip", "identity": { "sha256": "f8a6a244138cb1e2f044f63f3dc42beeb555da892bbd7a121274498cbdfc9ad5", "sha1": "20eeee16345e0c1283f7b500126350cb938b8570", "md5": "6853839cde69359049ae6f7bd3ae86d7" }, "archived_file": { "disposition": "Malicious", "identity": { "sha256": "46679a50632d05b99683a14b91a69ce908de1673fbb71e9cd325e5685fcd7e49" } }, "parent": { "process_id": 3416, "disposition": "Clean", "file_name": "explorer.exe", "identity": { "sha256": "80ef843fa78c33b511394a9c7535a9cbace1deb2270e86ee4ad2faffa5b1e7d2", "sha1": "ea97227d34b8526055a543ade7d18587a927f6a3", "md5": "15bc38a7492befe831966adb477cf76f" } } } } ] }
APIã®2çªç®ã®ã¿ã€ãã¯æ¬¡ã®ãšããã§ãã
- è åšã°ãªããAPI ã çããããã¡ã€ã«ãåæçšã«Threat Gridãµã³ãããã¯ã¹ã«éä¿¡ãããããã®ã¹ããŒã¿ã¹ïŒãã¯ãªãŒã³ããŸãã¯æªæã®ããïŒã«é¢ããå€å®ãåãåãããšãã§ããŸãã ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãçŸä»£ã®è åšãå¹æçã«èªèããªããªãç¶æ³ã§ã¯ããµã³ãããã¯ã¹ãšã®çµ±åïŒãããŠäžçã«ã¯ããã»ã©å€ããããŸããïŒãçŸä»£ã®ä¿è·ã·ã¹ãã ã®å¿ é èŠçŽ ã«ãªããŸãã ãšããã§ãåæã®ããã«åãåã£ããã¡ã€ã«ã«å¯Ÿããåçã®1ã€ã¯ãSnortã®èªåçæããã眲åãååŸããããšã§ãã ã»ãšãã©ãã¹ãŠã®åœå æ»ææ€åºã·ã¹ãã ãåºæ¬çã«Snortã«åºã¥ããŠããããããã®æ©èœã¯å€ãã®ã¢ããªã±ãŒã·ã§ã³ã«éåžžã«åœ¹ç«ã¡ãŸãã
- OpenDNS Investigate API ã 調æ»äžã«OpenDNSã¯ã©ãŠããµãŒãã¹ã«ãªã¯ãšã¹ããéä¿¡ã§ããŸãã ãã¡ã€ã³ã®æ害æ§ãåæããŸãã
- OpenDNS Umbrella API ã OpenDNSããŒã¿ããŒã¹ã«ãªãç¹å®ã®ãã¡ã€ã³ããããã¯ããããšã«ãããã«ã¹ã¿ã ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒãå®è£ ã§ããŸãã
äŸãšããŠã2çªç®ã®ã¿ã€ãã®API㯠ã Threat Grid APIã®äœ¿çšæ¹æ³ã調ã¹ãŸãã 以åã«åæã®ããã«ã¢ããããŒããããã¡ã€ã«ã®ã¹ããŒã¿ã¹ã確èªãããšããŸãã ãã®ãããªã¯ãšãªã¯æ¬¡ã®ããã«ãªããŸãã
https://panacea.threatgrid.com/api/v2/search/submissions?q=23aea7cf60fca3c6527c2b5255c6036f2dc414f8368196e198df091cf03dd95f&api_key=llgtslnd5cvb14h4p8m6e6s27f&before=2017-02-28&limit=1
ãããŠçãã¯ïŒ
{ "api_version": 2, "id": 7589645, "data": { "index": 0, "total": 3, "took": 416, "timed_out": false, "items_per_page": 1, "current_item_count": 1, "items": [ { "item": { "properties": { "metadata": null }, "tags": [ "Kovter" ], "vm_runtime": 300, "md5": "f3247e81cc3474559d0e14e2f15837d0", "private": false, "organization_id": 1, "state": "succ", "login": "adminharry", "sha1": "bfafd7f2cd9adff7782f4854bc712bf134ad56f6", "sample": "9b7ad0711262b31219ea1d41119868d8", "filename": "23aea7cf60fca3c6527c2b5255c6036f2dc414f8368196e198df091cf03dd95f", "analysis": { "metadata": { "malware_desc": [ { "sha1": "bfafd7f2cd9adff7782f4854bc712bf134ad56f6", "magic": "PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows", "filename": "23aea7cf60fca3c6527c2b5255c6036f2dc414f8368196e198df091cf03dd95f.exe", "size": 369566, "sha256": "23aea7cf60fca3c6527c2b5255c6036f2dc414f8368196e198df091cf03dd95f", "type": "exe", "md5": "f3247e81cc3474559d0e14e2f15837d0" } ], "sandcastle_env": { "controlsubject": "winxp-x86-intel-2017.01.17", "vm": "winxp-x86", "vm_id": "9b7ad0711262b31219ea1d41119868d8", "sample_executed": 1487231873, "analysis_end": "2017-02-16T08:03:48Z", "analysis_start": "2017-02-16T07:57:01Z", "run_time": 300, "sandcastle": "3.4.36.10823.577ea7a-1", "current_os": "2600.xpsp.080413-2111" }, "general_details": { "report_created": "2017-02-16T08:03:57Z", "sandbox_version": "pilot-d", "sandbox_id": "car-work-074" } }, "behaviors": [ { "name": "excessive-suspicious-activity", "threat": 90 }, { "name": "pe-encrypted-section", "threat": 9 }, { "name": "process-check-virtualbox", "threat": 90 }, { "name": "memory-execute-readwrite", "threat": 25 }, { "name": "registry-autorun-key-bat-file", "threat": 95 }, { "name": "ie-proxy-disabled", "threat": 49 }, { "name": "malware-kovter-registry", "threat": 95 }, { "name": "registry-large-data-entry", "threat": 40 }, { "name": "service-dll-registration", "threat": 25 }, { "name": "files-created-batch", "threat": 25 }, { "name": "file-handler-registration", "threat": 85 }, { "name": "antivirus-service-flagged-artifact", "threat": 95 }, { "name": "registry-detection-productid", "threat": 42 }, { "name": "registry-script-detected", "threat": 25 }, { "name": "registry-ie-zone-settings-modified", "threat": 49 }, { "name": "modified-file-in-user-dir", "threat": 56 }, { "name": "registry-modified-rootcerts", "threat": 36 }, { "name": "registry-detection-bios", "threat": 42 }, { "name": "mshta-in-registry", "threat": 95 }, { "name": "registry-autorun-key-modified", "threat": 48 } ], "threat_score": 95 }, "status": "job_done", "submitted_at": "2017-02-16T07:57:00Z", "sha256": "23aea7cf60fca3c6527c2b5255c6036f2dc414f8368196e198df091cf03dd95f" }, "score": 0.7660416, "matches": null } ] } }
Threat Grid APIã¯ãããŸããŸãªçš®é¡ã®ãã¡ã€ã«åäœã«å¯ŸããŠ100ãã€ã³ãã¹ã±ãŒã«ã§è åšã¬ãã«å€ãè¿ãããšãããããŸãïŒThreat Gridã¯ãããŠã³ããŒããããã¡ã€ã«ã«å¿ããŠæ倧800ã®ç°ãªããã©ã¡ãŒã¿ãŒãè©äŸ¡ã§ããŸãïŒã æçµå€ïŒthreat_scoreïŒã¯95ã§ããããã¯ãåæããããã¡ã€ã«ãæªæã®ããããšãæå³ããŸãã
ãã¡ã€ã³ã®ã»ãã¥ãªãã£ãITUããåä¿¡ã§ããæ å ±ãã¡ãŒã«ã²ãŒããŠã§ã€ããããã·ãã€ã³ã¿ãŒãããã¢ã¯ã»ã¹å¶åŸ¡ãªã©ãè©äŸ¡ã§ããå¥ã®APIã®äœ¿çšäŸãæããããšãã§ããŸãã OpenDNS Investigate APIã䜿çšããŠãé¢å¿ã®ãããã¡ã€ã³ã確èªãããªã¯ãšã¹ããäœæã§ããŸãã
curl --include \ --header "Authorization: Bearer %YourToken%" \ https://investigate.api.opendns.com/security/name/{name}.json
ãããŠçãã§ã¯ãOpenDNSããã¡ã€ã³ãIPã¢ãã¬ã¹ãèªåŸã·ã¹ãã ãªã©ã®ã»ãã¥ãªãã£ãè©äŸ¡ããããŸããŸãªãã©ã¡ãŒã¿ãŒã®å€ãååŸããŸãã
{ "dga_score": 38.301771886101335, "perplexity": 0.4540313302593146, "entropy": 2.5216406363433186, "securerank2": -1.3135141095601992, "pagerank": 0.0262532, "asn_score": -29.75810625887133, "prefix_score": -64.9070502788884, "rip_score": -75.64720536038982, "popularity": 25.335450495507196, "fastflux": false, "geodiversity": [ [ "UA", 0.24074075 ], [ "IN", 0.018518519 ] ], "geodiversity_normalized": [ [ "AP", 0.3761535390278368 ], [ "US", 0.0005015965168831449 ] ], "tld_geodiversity": [], "geoscore": 0, "ks_test": 0, "found": true }
APIã®3çªç®ã®ã¿ã€ãã¯æ¬¡ã®ãšããã§ãã
- 修埩API ã ãµãŒãããŒãã£ãœãªã¥ãŒã·ã§ã³ãCisco Firepowerå€æ©èœã»ãã¥ãªãã£ãã©ãããã©ãŒã ã管çã§ããããã«ããŸãã
- FirePOWER 9300ïŒSSPïŒREST API æ§æãµãŒãã¹ãã§ãŒã³ãæ§ç¯ã§ããŸãã
- Firepowerã®REST APIã®èªã¿åã/æžã蟌㿠ã Firepowerãåäœãããªããžã§ã¯ãã«å¯ŸããŠããŸããŸãªæäœãå®è¡ã§ããŸãã
- ASAã®ç®¡çAPI ã ãµãŒãããŒãã£ãœãªã¥ãŒã·ã§ã³ããã®Cisco ASAã®ç®¡çãISããªã·ãŒã®ç£æ»ãªã©ãæäŸããŸãã
- CloudLock Enterprise API ã Cisco CloudLockã¯ã©ãŠãã¢ã¯ã»ã¹å¶åŸ¡ãã©ãããã©ãŒã ã管çããCloudLockããåä¿¡ããæ å ±ã«åºã¥ããŠã¬ããŒããçæã§ããŸãã
- CloudLockéçºAPI ã ã¯ã©ãŠããã€ã¯ããµãŒãã¹ã管çã§ããŸãã
- pxGrid ã³ã³ããã¹ãæ å ±ãæäŸããã ãã§ãªãããããã¯ãŒã¯ã¢ã¯ã»ã¹ã®å¶åŸ¡ãã¹ã€ãããã«ãŒã¿ãŒãã¢ã¯ã»ã¹ãã€ã³ããªã©ã®ã¬ãã«ã§ã®Cisco ISEãä»ãããŠãŒã¶ãŒãšããã€ã¹ã®ãããã¯ãå¯èœã«ããAPIã
- AMP for Endpoints API ã AMP for Endpointsã§ãã©ãã¯ãªã¹ãã«ç»é²ãããã¢ããªã±ãŒã·ã§ã³ã管çããããã³ã³ãã¥ãŒã¿ãŒãããã°ã«ãŒãããå¥ã®ã°ã«ãŒãã«è»¢éãããã§ããŸãã
4çªç®ã®ã¿ã€ãã«ã¯ã
- è åšæ å ±ãã£ã¬ã¯ã¿ãŒ ã Cisco Firepowerã®è±å¯ãªæ©èœãåããã»ãã¥ãªãã£ãã©ãããã©ãŒã ããCisco Taloséšéããã ãã§ãªããSTIXããã³TAXIIãããã³ã«ãšæšæºããµããŒãããå€éšTIãã©ãããã©ãŒã ãããè åšã€ã³ããªãžã§ã³ã¹ïŒè åšã€ã³ããªãžã§ã³ã¹ïŒãåä¿¡ããã³çžé¢ã§ããããã«ãããœãªã¥ãŒã·ã§ã³ã
- AMPã¯ã©ãŠãããŒã¹ã®API ã æªæã®ããã³ãŒãã«é¢é£ããã»ãã¥ãªãã£ã€ãã³ããéä¿¡ã§ããã ãã§ãªããå€éšã®Threat IntelligenceãµãŒãã¹ã«ãã¢ã¯ã»ã¹ã§ããAPIã ããšãã°ãCisco AMP for Endpointã¯ãçããããã¡ã€ã«ãã¯ã©ãŠããŸãã¯Cisco AMP Threat Gridã®ããŒã«ã«ãµã³ãããã¯ã¹ã«éä¿¡ã§ããã ãã§ãªããããšãã°Virus Totalã«ãéä¿¡ã§ããŸãã
è«ççãªçåãçããŸãããããã®APIãžã®ã¢ã¯ã»ã¹æ¹æ³ãæããŠãã ããã ãã¹ãŠãéåžžã«ç°¡åã§ãã ã·ã¹ã³ã«ã¯ã2ã€ã®å€§ããªã»ã¯ã·ã§ã³ã§æ§æãããç¹å¥ãªCisco Security Technical Alliance ProgramããããŸãã
- DevNet ããã¯2ã€ã®éšåãããªããã©ãããã©ãŒã ã§ãã ã SandNet ãïŒ DevNet Sandbox ïŒã¯ãé©åãªãœãªã¥ãŒã·ã§ã³ã®è¿
éãªéçºãšãã¹ãã®ããã«ãç©çããã³ä»®æ³ã®ãœãããŠã§ã¢ãšãââãŒããŠã§ã¢ãžã®ã¢ã¯ã»ã¹ãæäŸããŸãã DevNetãšã®é£æºã¯ç¡æã§ãã€ã³ã¿ãŒãããã«æ¥ç¶ãããŠããã©ã®ããã€ã¹ããã§ãæäŸãããŸãã DevNetã®2çªç®ã®ã³ã³ããŒãã³ãã¯DevNet Learning Labsã§ã ãããã¯ããã¬ãŒãã³ã°ã³ã³ãã³ããã·ã¹ã³ãœãªã¥ãŒã·ã§ã³ãšã®çµ±åã«é¢é£ãããµã³ãã«ã³ãŒããžã®ã¢ã¯ã»ã¹ãæäŸããŸãã ãã¬ãŒãã³ã°ã©ããç¡æã§ããã¹ãŠã®æ¥èšªè
ãå©çšã§ããŸãã äžèšã®APIã®ã»ãšãã©ã¯DevNetã§æäŸãããŠããŸãããã·ã¹ã³ã®Webãµã€ãã«ã¯åå¥ã®è©³çŽ°ãªã»ã¯ã·ã§ã³ããããã·ã¹ã³ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®ããã°ã©ãã³ã°æ©èœã«æ²¡é ããŠããŸãïŒãããã®äžéšã«ã¢ã¯ã»ã¹ããã«ã¯ã察å¿ãã補åãŸãã¯ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããå¿
èŠããããŸãïŒã
- ã·ã¹ã³ãœãªã¥ãŒã·ã§ã³ããŒãããŒããã°ã©ã ïŒSPPïŒ DevNetãçµ±åãœãªã¥ãŒã·ã§ã³ãéçºããã³ãã¹ãããã»ã«ããµãŒãã¹ãã©ãããã©ãŒã ã§ããå ŽåãSPPã¯æ¬¡ã®ã¹ãããã§ãããããã¯ã·ã¹ã³ãšã®ããæ£åŒãªé¢ä¿ãæå³ããŸãã ããã¯ãéçºãããçµ±åãœãªã¥ãŒã·ã§ã³ã®ç¬ç«ãããã¹ãã§ããããã¯ãããžãŒããŒãããŒã®ã¹ããŒã¿ã¹ãååŸããäžçäžã®äœçŸäžãã®äŒæ¥ãã¢ã¯ã»ã¹ã§ããã·ã¹ã³Webãµã€ãã®é©åãªãã£ã¬ã¯ããªã«ãã®ãœãªã¥ãŒã·ã§ã³ãå«ããŸãã
SIEMãšSOCãã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ãšçµ±åããã«ã¯ãDevNetã«ç»é²ããã ãã§ãã³ãŒãäŸãåãåã£ãåŸãAPIãä»ããŠé©åãªã³ã³ããŒãã³ããšããã°ã©ã åŒã³åºããè£ åããããšã§ãœãªã¥ãŒã·ã§ã³ãæ¹è¯ã§ããŸãã ååãšããŠãããã¯ãã§ã«ã·ã¹ã³ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšå¯Ÿè©±ããã®ã«ååã§ãã å®å šã«ç¡æã§ãïŒããã°ã©ããŒã®å ±é ¬ãé€ãïŒã åœéåžå Žãžã®åå ¥ãå¹ åºããŠãŒã¶ãŒãžã®è£œåã®ãã¢ã³ã¹ãã¬ãŒã·ã§ã³ããµã€ããŒã»ãã¥ãªãã£åžå Žã®äžççãªãŒããŒã§ããã·ã¹ã³ãšã®çµ±åã®çå£ãªæå³ã蚌æããããšãã¿ã¹ã¯ã®å Žåãç¹å®ã®æè³ãšSPPããã°ã©ã ãžã®åå ¥ãå¿ èŠã§ãã ãã®ãããªçµè·¯ã¯ãCheck PointãThreatQuotientãAnomaliãSymantecãªã©ã®äŒæ¥ã«ãã£ãŠæ¡çšãããŸããã
ãã®ãããªçããã¢ãŒã®åŸãå€éšã®ã»ãã¥ãªãã£è£œåããµãŒãã¹ãšã®çµ±åã«é¢ããŠãã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ãä»ã«é¡ãèŠãªãã»ã©ãªãŒãã³ã§ããããšã誰ããçãããšã¯ãªãã§ãããã å瀟ã¯æ°å¹Žåãããã®æ¹åã«é²ãã§ãããã·ã¹ã³ã®ãµã€ããŒã»ãã¥ãªãã£éšéãåŸã以åã«æå±ãããã¹ããŒã¬ã³ããªãŒãã³ã ã·ã³ãã« ãªãŒãã¡ãŒã·ã§ã³ãïŒãªãŒãã³æ§ãã·ã³ãã«ããªãŒãã¡ãŒã·ã§ã³ïŒã