æãããªåçŽãã«ãããããããThreat Intelligenceã䜿çšããäœæ¥ã®éå§ã¯ãã»ãšãã©ã®æéãèŠããæãèŠçãªããã»ã¹ã§ãã ããããäŸå€ã¯ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã§Application Controlãæå¹ã«ãªã£ãŠããæšæºOSã€ã¡ãŒãžã管çè æš©éã®ãªããŠãŒã¶ãŒãããã³ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæä»çã«ãã¯ã€ããªã¹ãã«ç»é²ãããŠããå Žåã®ã¿ã§ãã æ®å¿µãªãããç§ãã¡ã¯ä»äºã®å šæéã«ããã£ãŠãã®ãããªäŒç€Ÿã«ãŸã äŒã£ãŠããŸããã ãã®ç¹ã§ãè åšã€ã³ããªãžã§ã³ã¹ã®ãããã¯ã«èå³ããããã¹ãŠã®äºº-ç«ãžããããã
ã°ããŒãã«ã§è€éã§æãããæ»æã®å Žåãæåã®ç ç²è ã®ã©ã³ã¯ã«ããå Žåã¯åžžã«æ²ããã§ãã ãŠã€ã«ã¹å¯Ÿçã«ã¯ãŸã ã·ã°ããã£ãSZI-ãã©ãã¯ãªã¹ããMSSPãããã€ããŒãããã³SOC'ov-æ€åºã«åœ¹ç«ã€ã€ã³ãžã±ãŒã¿ãŒãšã«ãŒã«ããããŸããã ãã®å Žåã顧客ã¯å®éã«èªåã§æ»æã«å¯ŸåŠããããšãäœåãªããããŸãïŒãããããé«äŸ¡ãªã€ã³ã·ãã³ã調æ»ãµãŒãã¹ãè³Œå ¥ããããšãªãïŒã
äžè¬çã«ãè åšã€ã³ããªãžã§ã³ã¹ã«ãããã第2ã®è¢«å®³è ãã¯æ»æãæéããæºåãããããšãã§ããŸãã ãã¡ãããããã¯å¥ã®ãéã®åŒŸäžžãã§ã¯ãããŸãããTIã¯ãã¹ãŠã®æ»æããæãããã§ã¯ãããŸããã ããããé©åã«æ§æãããããã»ã¹ãšé©åã«éžæãããç¥èãœãŒã¹ã«ãããå€ãã®å Žåã«åœ¹ç«ã¡ãŸãã
è åšæ å ±æ§é
è åšã€ã³ããªãžã§ã³ã¹ãšã¯äœãããè¯ããææšã¯ã©ã®ããã«èŠããã¹ããããæªããææšã¯ã©ã®ããã«èŠãããã«ã€ããŠããã§ã«å€ãã®èšäºãæžãããŠããŸããã±ãŒã¹ã
ãã£ãŒãïŒãã£ãŒãã§ããããŸãïŒ
ãããããææçãšç¡æçã®äž¡æ¹ã§æãå©çšå¯èœãªãæãèšå€§ã§é »ç¹ã«ééããæ å ±ã§ãã ååãšããŠããããã¯æªæã®ããã¢ãã¬ã¹ãURLãé»åã¡ãŒã«ãªã©ãžã®ããŠã³ããŒãã絶ããæŽæ°ãããã³ããŒã§ãã
ããã§æãéèŠãªããšã¯ãSOCã®ãã¹ãŠã®æ¢åã®ãã©ãã¯ãªã¹ãããã©ãã°ã¢ãŠãããªãããšã§ãã ãã£ãŒãã®å質ãåæãããšãã¯ããã£ãŒãå ã®è åšã«é¢ããæ¡åŒµæ å ±ã®ååšã«æ³šæããããšããå§ãããŸãã 以äžã®äŸïŒ
TORåºå£ããŒããªã¹ãïŒ
torstatus.blutmagie.de-ãã£ãŒããœãŒã¹èªäœã«ã¯TORããŒãã®ã¿ãå«ãŸããŸã+åºå£ããŒãããŒã+ã¹ããŒã¿ã¹æ å ±ïŒãªãã©ã€ã³/ãªã³ã©ã€ã³ïŒã®æ å ±ããããŸãã
panwdbl.appspot.com/lists/ettor.txt-ããã«ã¯ã¢ãã¬ã¹ã®ãªã¹ãã®ã¿ããããŸãïŒãã ããããã¯å ¬åŒã®ã¢ããããŒãã§ã¯ãããŸãããããã€ã³ãã§ã¯ãããŸããïŒã
åè ã®å Žåãããçãããæ£ç¢ºãªã«ãŒã«ãæ§æã§ããŸãã 2çªç®ã®å Žåãæãå¯èœæ§ãé«ãã®ã¯ãã«ãŒã«ã«ããå€ãã®èª€æ€ç¥ãçºçããããšã§ãã
IOCïŒäŸµå®³ã®å åïŒ
éåžžãç¹å®ã®è åšã®åæã«é¢ããæŠèŠã¬ããŒãã®äžå¯æ¬ ãªéšåã§ãã ãããŠãããã¯ãåææšãåå¥ã«ã§ã¯ãªãã察å¿ããã¬ããŒãã®ä»ã®ææšãšäžç·ã«æ€èšã§ããããšãæå³ããŸãã ããã«ãã€ã³ãžã±ãŒã¿ãŒã«å ããŠãç¹å®ã®ã¬ããŒããšåæããããããã³ã³ããã¹ããååŸã§ããŸãã
è匱æ§
ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã®æªçšã®å¯èœæ§ãèæ ®ããŠãè匱æ§ã®è©³çŽ°ãªèª¬æãšéèŠåºŠã«ããã©ã³ãã³ã°ã¯ãå®éã®ç掻ã§ãã®ãããªæªçšã®è©Šã¿ãèå¥ããããã«åŸã§äœ¿çšã§ããã€ãã³ããšã€ã³ãžã±ãŒã¿ã®ãã§ãŒã³ã«é¢ããæ å ±ãæäŸããŸãã
æ»æã¹ã¯ãªãã
ååãšããŠãæ»æã®ã·ããªãªã«ã¯ãã·ã¹ãã ãä¿é²ããããã®æ»æè ã®äžé£ã®ã¢ã¯ã·ã§ã³ã®äŸãå«ãŸããŠããŸãã TIã®ãã®ãããªç¥èã®äž»èŠãªå±€ã¯ãAPTæ»æã«é¢ãã顧客ããã³ãã³ããŒã®ã¬ããŒãã§é²è¡äžã®äŸµå ¥ãã¹ãã§ãã ãã®æ å ±ãåãåã£ãŠåæããããšã«ãããçŸåšã®æ€åºã·ããªãªãã¬ããŒãã«èšèŒãããŠããæ»æãã§ãŒãºãšæ¯èŒã§ããŸãã
ããšãã°ãæå·äœæè ã®æ°ã¯ããæè¿å¢å ããŠããŸãã åæã«ããããã®ã»ãšãã©ã¯åãå€ãæ¹æ³ã§é ä¿¡ãããŸã-æ·»ä»ãã¡ã€ã«ã«ãããããŒãã¡ã€ã«ãå«ãã¡ãŒãªã³ã°ãªã¹ããéããŠã ãŸããåãWordã䜿çšããŠãµãŒãããŒãã£ã®ã¹ã¯ãªãããå®è¡ãããã¹ãŠã®ãæ°ãããæ¹æ³ã«ãããããããOSã®åäœã¯ãã¹ãŠã®äººã§åãã§ãã
ãããã2ã€ã®çµè«ãå°ãåºãããšãã§ããŸãã
- ã¹ãã 察çã«æ³šæããŠãã ããã ç§ãã¡ã®å®è·µã瀺ãããã«ãéåžžã«å€ãã®é¡§å®¢ã¯ãéä¿¡è ã¢ãã¬ã¹ãã¹ããŒãã£ã³ã°ããããã®æãç°¡åãªãã§ãã¯ãããããŸããã
- æ°ããã»ãã¥ãªãã£ã®è åšãšãå€éšãµãŒãã¹ãšäŒç€Ÿèªäœã®å éšãªãœãŒã¹ïŒã€ã³ã¿ãŒããããã¡ãŒã«ãAWPãªã©ïŒãå®å šã«äœ¿çšããããã®ã«ãŒã«ã«ã€ããŠãåŸæ¥å¡ã®æèãå®æçã«é«ããå¿ èŠããããŸãã
ãŠãŒã¶ãŒ
ã»ãã¥ãªãã£æèã¯é©ãã¹ããã®ã§ãã ãã£ãã·ã³ã°ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°-é©åãªã¢ãããŒããæã€äººã ãããµã³ãããã¯ã¹ã§ã¯ææã§ããªãæ°ã®ãµã³ãã«ãæäŸããŸãã
ããã«ãIoC /ã€ã³ãžã±ãŒã¿ã«ã€ããŠèšãã°ãã€ã³ãžã±ãŒã¿èªäœã«å ããŠããããã©ã®ãããªãã«ãŠã§ã¢/è åšãæããŠãããã«ã€ããŠå°ãªããšãæå°éã®æ å ±ããæã£ãŠããªãããšãæå³ããŸãã
ãã®ãããååãšããŠãã€ã³ãžã±ãŒã¿ãŒã¯ããã€ãã®ã°ã«ãŒãã«åããããšãã§ããŸãã
- ãããã¯ãŒã¯ã€ã³ãžã±ãŒã¿ãŒïŒipãfqdnãurlãemailãportãªã©ïŒã
- ãã¹ãã€ã³ãžã±ãŒã¿ãŒïŒãã¡ã€ã«/ããã»ã¹/ãµãŒãã¹ã®ååãMD5åèšãå®è¡å¯èœã³ãã³ãã®èª¬æãã¬ãžã¹ããªããŒå€ããŠãŒã¶ãŒ/ã°ã«ãŒãåãªã©ïŒã
- ãã®ä»ã®ïŒæ å ±ïŒã€ã³ãžã±ãŒã¿ã ããšãã°ããXããYã®æéã«DDoSæ»æãèšç»ãããŠããããšãéç¥ãããã·ãªãŒãºãããçŽçšç³åæžããšããèšèãå«ãæªæã®ããã¡ãŒã«åœ¢åŒã®ã¡ãã»ãŒãžãããã¯ãªã©ã®ã·ãªãŒãºããã®éç¥ããããŸãã
åã°ã«ãŒãã§ã¯ãã€ã³ãžã±ãŒã¿ã¯ãååãšããŠãæ€åºããããšãã«çµæã®ä¿¡é Œæ§ã®çšåºŠãç°ãªããŸãã ãŸããåãè åšã«å¯ŸããŠããå€ãã®ææšãæã£ãŠããã»ã©ã誀æ€ç¥ãé€å€ããå¯èœæ§ãé«ããªããŸãã
Threat Intelligenceã®äž»ãªåé¡
ããããThreat Intelligenceãµãã¹ã¯ãªãã·ã§ã³ããã®æ å ±ãä¿¡é Œããããšã¯å¯èœã§ããïŒ çµå±ã®ãšãããããã¯éåžžãæ¬åœã«è³æ Œã®ããå°é家ã«ãã£ãŠäœæãããéåžžã«å ·äœçãªãã«ãŠã§ã¢ãµã³ãã«ã®åæã§ãã äŸã«æ»ããŸãã
- å®å šãªè åšæ å ±ã®æ¬ åŠã
ã€ã³ãã£ã±ãŒã¿ãŒã®ãã¡ãããªããmalvariã®ã³ã³ãããŒã«ã»ã³ã¿ãŒã®IPã¢ãã¬ã¹ã®ã¿ãæã£ãŠãããšæ³åããŠã¿ãŸãããã ãããã®ã¢ãã¬ã¹ã¯ã1ã€ã®ãã¡ã€ã³ããé¢ããŠããå ŽåããããŸãã ãããŠãSkype /ã©ããã®ãã¬ã³ããŸãã¯ãã®ä»ã®p2pã¢ããªã±ãŒã·ã§ã³ãèš±å¯ããŸããã ãã³ããŒã®1ã€ã®ææšããã¹ãããäŸïŒ
- ãµã€ããŒç¯çœªè ã«ããåæ³çãªãœãããŠã§ã¢ã®äœ¿çšã
Kaspersky Labã®ã¬ããŒãã®1ã€ã«ãããšãæ»æè ã¯ç¬èªã®ç®çã§ããªã¢ãŒãã¢ã¯ã»ã¹çšã®å¥ã®éåžžã«æ£åœãªããŒã«winexecã䜿çšããŠããŸãã ãããŠããã¹ãŠã¯åé¡ãããŸããããããšãã°ããã¹ãã®ã€ã³ãã³ããªã«ãŸã£ããåãããŒã«ã䜿çšããSZIããããšããŸãã ãŸããwinexesvcãµãŒãã¹ãã€ã³ã¹ããŒã«ãã察å¿ããããã»ã¹ãèµ·åããMD5ã®åèšãæ€åºããããã®ã€ã³ãžã±ãŒã¿ãŒã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£å šäœã§æ°çŸã®æ€åºãæäŸããŸãã
å®éãçµè«ã¯ç°¡åã§ãããã³ããŒãæäŸããæ å ±ã¯ãŸã äžè¬çãããŸãã ç¹å®ã®å顧客ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã³ã³ããã¹ããšæ©èœã«å¿ããŠãåä¿¡ããæ å ±ã®äžéšããã£ã«ã¿ãªã³ã°ããã¡ã«ããºã ãå¿ èŠã«ãªããŸãã
ãã®çµæãThreat Intelligenceã§äœæ¥ãéå§ããå Žåã¯ã次ã®ç¹ãèæ ®ããå¿ èŠããããŸãã
- çæ³çã«ã¯ãäœæ¥ã§1ã€ãŸãã¯å¥ã®IOC / TIããŒã¿ããŒã¹/ãããã€ããŒã®äœ¿çšã決å®ããåã«ãã€ã³ãã©ã¹ãã©ã¯ãã£ã§ããããè©Šéšããããšããå§ãããŸããã€ãŸãããã©ã€ããã§è©ŠããŠãã ããã ããšãã°ãæ°ãæéããããèµ·åããŠå¿çãåæãã確èªãããå¿çã®å²åãè©äŸ¡ããŸãã
- IOC / TIãããã€ããŒãéžæããããé¢é£æ§ã«ãã£ãŠã©ã³ã¯ä»ãããå¿ èŠããããŸãã ãã®å ŽåããœãŒã¹ãã€ã³ãžã±ãŒã¿ã®ã¿ã€ãã«ãã£ãŠããã¢ã©ãŒãã«å¯Ÿããåå¿ã¯ç°ãªããŸãã ä¿¡é Œã§ãããœãŒã¹/é¢é£æ§ã®é«ãææšã®å Žå-察å¿ããã»ã¹ãéå§ããŸãã æ®ãã«ã€ããŠã¯ããããå€ãè¶ ãããšçµ±èšãšã¢ã©ãŒããåéãããŸãã
- ãªã¢ã«ã¿ã€ã ç£èŠã§ã€ã³ãžã±ãŒã¿ãèµ·åããåã«ãåä¿¡ããæ å ±ã確èªããããšããå§ãããŸãã ããã¯ãæ瀺çãªäžèœãé€å€ããããã®å±¥æŽããŒã¿ã®ã¯ã€ãã¯ãã§ãã¯ãããã³ã€ã³ãžã±ãŒã¿ãŒã®é¢é£æ§ã®ãã§ãã¯ã§ãã ããšãã°ããã¹ãã£ã³ã°ã«å±ããIPã¢ãã¬ã¹ã確èªããïŒã€ã³ãžã±ãŒã¿ãŒã«ç¹å®ã®URLãŸãã¯ãã¡ã€ã³ããªãå ŽåïŒããŸãã¯æšæºãŠãŒãã£ãªãã£ãã·ã¹ãã ãã¡ã€ã«ããŸãã¯ç®¡çããŒã«ã«å±ããMD5ããã·ã¥ã確èªããŸãã
- äŒæ¥ã®ã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ç¹å®ã®ææšã®èå¥ã«å¯Ÿå¿ããããã®ã·ããªãªãããã«æ±ºå®ããŠãããããã®å Žåã®è¡åæ¹æ³-åéããã³åæããä»ã®æ å ±ãå ¥æå ãªã©ãæ確ã«ç¥ãå¿ èŠããããŸãã ããã«ãããå¿çæéãå€§å¹ ã«ççž®ãããŸãã
Threat Intelligenceã®äœ¿çšãéå§ããæ¹æ³
ãã®ã³ã°ã®æ§æãšã€ãã³ããœãŒã¹ã®éžæ
䜿çšã§ããã€ã³ãžã±ãŒã¿ã®çš®é¡ãšããããã確èªããæ¹æ³ã決å®ããŠãã ããã ããšãã°ãMD5ã«é¢ããæ å ±ããããŸãã ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã©ã®SZI /ãã°ã«é¢é£æ å ±ãå«ããããšãã§ããŸããïŒ
ç§ãã¡ã®çµéšããïŒ
- ã«ã¹ãã«ã¹ããŒïŒããã³ã¢ã³ããŠã€ã«ã¹ïŒã¯ãåãã¹ãäžã®ãã¹ãŠã®å®è¡å¯èœãã¡ã€ã«ã«é¢ããæ å ±ãä¿åããŸãïŒãã ããæåã®èµ·åã«é¢ããæ å ±ã®ã¿ïŒã
- DLP /ã¢ã³ãã¹ãã ã¯ããã¹ãŠã®ã¡ãŒã«æ·»ä»ãã¡ã€ã«ã®MD5åèšãèšé²ããããã«æ§æã§ããŸãã
- Sysmonã¯ãå®è¡äžã®ãã¹ãŠã®ããã»ã¹ã®MD5åèšãèšé²ããŸãã
ãã®çµæãè¡šã衚瀺ãããã©ã®ãœãŒã¹ã®ã©ã®çš®é¡ã®ã€ã³ãžã±ãŒã¿ãŒãæ€åºããããã®èª¬æã衚瀺ãããŸãã ããšãã°ãããïŒ
ãããšã¯å¥ã«ãã€ãã³ãã®ãœãŒã¹ãéžæãããšããæ å ±ã®å®å šæ§ãæ£ããè©äŸ¡ããããšãéèŠã§ããããšã¯æ³šç®ã«å€ããŸãã ããšãã°ããããã·ãµãŒããŒã§SSL解æãæå¹ã«ãªã£ãŠããªãå ŽåãURLã«ããã€ã³ãžã±ãŒã¿ãŒã®åæã®å¯èœæ§ã¯éåžžã«å¶éãããããããããèæ ®ããå¿ èŠããããŸãã äŸïŒ
æªæã®ããã³ãŒãã¯ãé£èªåãããJavaScriptãã¡ã€ã«ã2015幎1æ1æ¥ã®é£éŠçšåå±ã®ææžäžèŠ§ã§ãã2015幎Docx_Iååæãã§ãã ãªã³ã¯hxxpsïŒ//yadi.sk/d/AXf0WGaqBpXhã«ããhead__CHECKED Dr.Web_ef73f6db_xls.jsã«ãã£ãŠçœ²åãããŠããŸãã
SSLã€ã³ã¹ãã¯ã·ã§ã³ãæå¹ã«ããªããšãyadi.skã®åãšã³ããªã«åå¿ããããŸãã
SSLã解æã§ããå Žåãéåžžã«ç¹å®ã®ãªã³ã¯ã«ã®ã¿å¿çã§ããŸããã€ãŸããçžé¢é¢ä¿ã§URLã䜿çšã§ããŸãã
å¿çèœå
æå§ãã«ãåã€ã³ãžã±ãŒã¿ãæ€åºããããšãã®ã¢ã¯ã·ã§ã³ã®å€§ãŸããªã·ãŒã±ã³ã¹ãçŽã«æžããŠã¿ãŠãã ããã ãµã³ãã«èšç»ã¯æ¬¡ã®ãšããã§ãã
ãããã¯ãŒã¯ã€ã³ãžã±ãŒã¿ãŒãæ©èœããŸããïŒããšãã°ãBadRabbitïŒ1dnscontrol.com/flash_install.phpïŒã 次ã«äœãããŸããïŒ
- ãã¹ããã©ã®ããã«æ±ºå®ããŸããïŒ
- ãã®æ¥ç¶ãéå§ããããã»ã¹ã確èªã§ããŸããïŒ
- ãã¹ãã€ã³ãžã±ãŒã¿ãŒããã§ãã¯ããŸããïŒæã£ãŠããŸããïŒïŒ
- ã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ãã¹ãŠã®ãã¹ãã«ã¢ã¯ã»ã¹ããŠãããªã¬ãŒããããã³ã«èªåãã§ãã¯ãå®è¡ã§ããŸããïŒ
- ã©ã®OSãã©ã®ãã¹ãäžã«ããããç解ããŠããŸããïŒãŸããã¬ããŒãã®ææšã¯ãã®ã·ã¹ãã ã«é©çšå¯èœã§ããïŒ
- ãŠãŒã¶ãŒã®ãã·ã³ããã€ã§ãéé¢ããæ©äŒã¯ãããŸããïŒ
- äžèšã®ãã¹ãŠã®ã¢ã¯ãã£ããã£ãèªååããããšã¯å¯èœã§ããïŒ
ã€ã³ãã©ã«ãã¬ããž
ååãšããŠãå€éšããŒã¿ã«ããã€ãã³ãã®åŒ·åãæ¬åœã«å¹æçã§ããã害ãããå€ãã®å©çãããããããã«ã¯ããããã¯ãŒã¯ã€ã³ãžã±ãŒã¿ãŒããã¹ãã€ã³ãžã±ãŒã¿ãŒã«é¢é£ä»ããåãè åšã€ã³ããªãžã§ã³ã¹ã¬ããŒãã®ç°ãªãã€ã³ãžã±ãŒã¿ãŒãçžäºã«é¢é£ä»ããããšãã§ããå¿ èŠããããŸãã ããšãã°ãæªæã®ãããã¡ã€ã³ïŒãŸãã¯URLïŒãžã®åŒã³åºããæ€åºããå Žåã察å¿ããè åšã«é¢é£ãããã¹ãã€ã³ãžã±ãŒã¿ãŒïŒãã¡ã€ã«ãã¬ãžã¹ããªãã©ã³ããMD5ããµãŒãã¹ïŒãã¯ãŒã¯ã¹ããŒã·ã§ã³/ãµãŒããŒã§ç¢ºèªããŸãã ããã¯ãæåã§ïŒãã¹ãã«æ¥ç¶ããŠïŒãŸãã¯èªåã§å®è¡ã§ããŸããã¹ã¯ãªãããŸãã¯ã»ãã¥ãªãã£ã¹ãã£ããŒã䜿çšããŸãã
ç¥èã®ããåãæ¹ãšåç²ã®æ¹æ³
ããã£ã ãœãŒã¹ãæ¥ç¶ãããããŒã¿ãåéãããŠããŸãã ãããããããã©ã®ããã«æ±ãã®ã§ããïŒ
æåã«ããªã¢ã«ã¿ã€ã ç£èŠã®æ°ããïŒãŸãã¯ããã§ãªãïŒè åšã«å¯Ÿãããã£ãŒããšäŸµå®³ã®ææšãè¿œå ããŸãã åæã«ã措氎ãç¡é¢ä¿ãªã€ã³ãžã±ãŒã¿ãŒãé€å€ããããã«ãäžèšã®ãããã®ã€ã³ãžã±ãŒã¿ãŒã®é¢é£æ§ãäºåã«ç¢ºèªããããšãå¿ããªãã§ãã ããã è¯ãæå³ã§ãããã¯ç¶ç¶çãªããã»ã¹ã§ãªããã°ãªããŸããã ãã®ãããªææšã®ãœãŒã¹ã¯ãå°éäŒæ¥ã®ææãµãã¹ã¯ãªãã·ã§ã³ãšãµãŒãã¹ã«å ããŠãããšãã°ãäž»èŠãªå°éã¡ãã£ã¢ã®åºçç©ãã»ãã¥ãªãã£æ©åšããã³ç 究ã°ã«ãŒãã®å€§æã¡ãŒã«ãŒã®ãã¥ãŒã¹ã¬ã¿ãŒãäŒæ¥ã®åŸæ¥å¡ã«éä¿¡ãããæªæã®ããã¡ãŒã«ã®åæãªã©ã§ãã èŠæãŠãŒã¶ãŒãã¹ãã 察ç/ã¡ãŒã«ãµã³ãããã¯ã¹ããISãµãŒãã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã
第äºã«ãéå»ïŒããšãã°ã1ãæéïŒã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ææã®äºå®ãç¹å®ããããã«ããããã®ææšã®é¡åæ€çŽ¢ãè¡ã£ãŠããŸãã æ€çŽ¢ã¯ãã€ãã³ããã°ïŒãããã¯ãŒã¯ã€ã³ãžã±ãŒã¿ãŒãã¡ãŒã«ãããã»ã¹ïŒãã»ãã¥ãªãã£ã¹ãã£ããŒãŸãã¯ã¹ã¯ãªããïŒãã¹ãã€ã³ãžã±ãŒã¿ãŒïŒãã¡ã€ã«ãã¬ãžã¹ããªãMD5ïŒã«ãã£ãŠå®è¡ã§ããŸãã ã¹ãã£ããŒã䜿çšãããšããã¹ãã«ååšããè匱æ§ã«é¢ããæ å ±ãããã«åéã§ããŸãã
第äžã«ãé©åãªä¿è·æ段ã®ITãŸãã¯æ å ±ã»ãã¥ãªãã£ç®¡çè ã®ãããã¯ã«å¯Ÿãã䟵害ã®ææšãéä¿¡ããŸãã
第4ã«ãã€ã³ãã©ã¹ãã©ã¯ãã£ã§ååŸããã€ã³ãžã±ãŒã¿ãŒã®æ€åºå¯èœæ§ããã¹ãããŸãã ãã«ãŠã§ã¢ãšæ»æã®ããŸããŸãªè§£æãè¡ãéèŠãªæ®µéã¯ãããã¹ãç°å¢ãã§ã³ã³ãã³ãã®åäœãšä¿è·ãæ€èšŒããããã«ããããã®æ»æã®å°ãªããšãäžéšãåçŸããããšã§ãã
è åšã€ã³ããªãžã§ã³ã¹ã¯ãééããªãSOCã®éèŠãªéšåã§ãã å€éšã®è åšã«ããè¿ éã«å¯Ÿå¿ã§ããŸãã ããããIOC / TIãããã€ããŒãæ éã«éžæããç¹å®ã®äŒæ¥å ã§ãã®æ å ±ã䜿çšããæ¹æ³ãæ確ã«ç解ããå¿ èŠããããŸããå©çšå¯èœãªäººçè³æºãšãã€ã³ãã©ã¹ãã©ã¯ãã£ã§ãããã®åãææšã®çºçŸã®äºå®ãèŠã€ããããã®æ¢åã®æè¡çæ段ãèæ ®ããŠãã ããã ããããªããšãããã»ã¹å šäœã1ã€ã®æªå€¢ã«å€ããããããããçµæãåŸãããªãã ãã§ãã