VPOéçºç£æ¥
ããããåã ã®æè¡çã¬ã³ã¬ããé²è·å£ãæ§ç¯ãå§ããåã«ãçŸä»£ã®ãã«ãŠã§ã¢ãã©ã®ãããªãã®ãæãåºããŠã¿ãŸãããã ããã¯éåžžã«éèŠã§ããã¡ãŒã«ãŒãæªç¥ã®ãŠã€ã«ã¹ã100ïŒ æ€åºãããšããããŒã±ãã£ã³ã°ã¹ããŒãã¡ã³ããäœæããããšãèš±å¯ããå¿ èŠã¯ãããŸããããçŸä»£ã®ãã«ãŠã§ã¢ãã§ããããšãšããã§ãªããã®ãèªèããããã«å¿ããŠããã«å¯ŸåŠããæ¹æ³ãç解ããããã§ãã
ã¯ããåžå Žã§æšæºçã§åºã䜿çšãããŠãããŠã€ã«ã¹å¯Ÿçãœããã«ãã£ãŠååã«æ€åºãããå€ããŠã€ã«ã¹ããããŸãã ããããæªãããã°ã©ã ã®ç·æ°ã®çŽ80ïŒ ããããŸãã å€ãã®å ŽåãäŒæ¥ã®YouTubeãã£ã³ãã«ã®ããŸããŸãªãããªã§èŠãããšãã§ããŸãããŸããããã·ã¥ã¯ããŸããŸãªãã¬ãŒã³ããŒã·ã§ã³ãè³æã«ããç»å ŽããŸãã 次ã«ãVirusTotalã«ãã®ãããªããã·ã¥ãå ¥åããããšã§ã補åããã®ãããªæ¹æ³ã§ãã®ææããã£ããããããšã確èªã§ããŸãã ãããšã䟡å€ããªãïŒ
ãããŠãæªæã®ããã³ãŒãã®äœæè ã§ããäœæè ã®èŠ³ç¹ããèŠãŠã¿ãŸãããã 圌ããŸãã¯çŸä»£ã®ãã¹ãŠã®ãéå°æãã®èåŸã«ããè³æ Œã®ããããã°ã©ããŒããã³ã¢ãŒããã¯ãã®ã°ã«ãŒãå šäœããåæããŒã¿ãšããŠæ¬¡ã®åçãæã£ãŠããŸãã
- 圌ãã¯ãã«ãŠã§ã¢ãæ å ±ä¿è·ã®ããŸããŸãªæ段ã§æ€çŽ¢ãããããšãç¥ã£ãŠããŸã
- ãµã³ãããã¯ã¹ã䜿çšããŠæªç¥ã®æªæã®ããã³ãŒããåæã§ããããšãç¥ã£ãŠããŸã
- 被害è ã®äŒæ¥ã®99ïŒ ãåºç¯å²ã«è³Œå ¥ããä¿è·ãœãããŠã§ã¢ã䜿çšããŠããããšãç¥ã£ãŠããŸãã
ã»ãã¥ãªãã£ã¬ãŒããç¥ã£ãŠããããã3ã€ã®æçœãªãã€ã³ããããäœããã®çç±ã§ãæªã®åŽã«ç«ã¡ãåŸæ¥ã®ä¿è·ã·ã¹ãã ããã¹ãŠåé¿ããããšãããããã«ãŒã®ããã«ãèããªãããã«ãã©ã®ãããªçµè«ãå°ãåºãããšãã§ããŸããïŒ ç§ã¯ããã«æ¬¡ã®çµè«ãå°ããŸãã
- æªæã®ããã³ãŒãã¯äžæã§ããå¿ èŠããããç¹°ãè¿ããªãã§ãã ãã
- æªæã®ããã³ãŒãã¯è€æ°ã®é åžãã¯ãã«ã䜿çšããå¿ èŠããããŸã
- æªæã®ããã³ãŒãã¯ã¢ãžã¥ãŒã«åããå¿ èŠããããŸã
- æªæã®ããã³ãŒãã¯ããã®æ€åºãšåæã®æ¹æ³ããã€ãã¹ããå¿ èŠããããŸãã
ãã®ããããã«ãŠã§ã¢äœææ¥çãçºå±ããäºç®ãååã«ããããœãããŠã§ã¢éçºã®ãã¹ããã©ã¯ãã£ã¹ãã³ããŒããŠããŸãïŒããããŠã€ã«ã¹éçºè ã«ãã¢ãžã£ã€ã«ããããŸãïŒã ããããæãéèŠãªããšãšããŠããã«ãŠã§ã¢éçºè ã¯ãäœæç©ã®ææçãšæ€åºçãäœãããããšã«é«ãé¢å¿ãæã£ãŠããŸãã ããã¯ã2016幎åé ã®éåžžã«å€ã1ã€ã®äŸã§ããã¢ã³ããŠã€ã«ã¹ã¯ãæãåçŽãªæªæã®ããããã°ã©ã ã§ãããæ€åºã§ããªãããšã瀺ããŠããŸãã
ãã«ãŠã§ã¢ããä¿è·ããããã®å žåçãªã¢ãããŒãã¯ãæãªããã®æ¹æ³ã§ãŠã€ã«ã¹ãšåŒã°ããããšãå€ããåé¡ã®è»œèããæããããããããŠã€ã«ã¹å¯Ÿçãšãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¢ã䜿çšããããšã§ãã ãã ããäžã§èŠãããã«ãææ°ã®æªæã®ããã³ãŒãã¯ã¯ããã«è€éã§ãã ããã€ãã®ææçµè·¯ããããŸã-é»åã¡ãŒã«ãWebãWi-Fiããã©ãã·ã¥ãã©ã€ãããœãããŠã§ã¢ã¢ããããŒããè«è² æ¥è ã®ã©ãããããã管ççšã®å人ã®ã¢ãã€ã«ããã€ã¹ãªã©ãããã«ãäœæããããã«ãŠã§ã¢ã¯ãæ¢ç¥ã®å€ãè匱æ§ãšæªç¥ã®ç©Žã®äž¡æ¹ã䜿çšã§ããŸãïŒ0 -æ¥ïŒã åæã«ã誰ãããã§ã«äœ¿çšããŠãããŠã€ã«ã¹ã®æçã¯ãæªæã®ããã³ãŒãã®åºç€ãšããŠäœ¿çšããããšãããŒãããäœæããã³ãŒãïŒããŸããŸãªã¬ãã«ã§ä¿è·ããŒã«ããã€ãã¹ããããã®ããŸããŸãªæè¡ã®äœ¿çšãå«ãïŒãšããŠäœ¿çšããããšãã§ããŸãã
ITUã®æªãã¢ã³ããŠã€ã«ã¹ãšã¯äœã§ããïŒ
2ã€ãŸãã¯3ã€ã®ç°ãªããŠã€ã«ã¹å¯Ÿçã䜿çšããããšããããŸãïŒããšãã°ããã·ã¢éè¡ã®èŠå¶ææžã§æšå¥šãŸãã¯èŠæ±ãããŠããããïŒããããã¯ããŸã圹ã«ç«ã¡ãŸããã ç°ãªããŠã€ã«ã¹å¯Ÿçãšã³ãžã³ã䜿çšããŠããå ŽåïŒãŸãã¯ããã§ãªãå ŽåããããŸã:-)ã§ããäœå¹Žãåã«å€±æããæ¹æ³ã«åºã¥ããŠããŸã-æ»æã·ã°ããã£ãšã®æ¯èŒãã€ãŸãæ¢ç¥ã®ãã®ã®æ€åºã ä»æ¥ã®å€ãã®æ å ±ã»ãã¥ãªãã£ãã¬ãŒã€ãŒã®çµ±èšã«ãããšããããŸã§ç¥ãããŠããªãã£ããã«ãŠã§ã¢ã¯ãã»ãšãã©ã®ã客æ§ã«ãšã£ãŠå§åçã«ãŠããŒã¯ã§ãã ããã¯ãã»ãšãã©ã®ãŠã€ã«ã¹å¯Ÿç補åãã衚瀺ãããªããã®ãç¥ããªããã®ã«å¯ŸåŠã§ããªãããšãæå³ããŸãã
æè¿ãååããCisco Threat Gridãµã³ãããã¯ã¹ã§ç¢ºèªããããã«äŸé Œãããã¡ã€ã«ãéãããŠããŸããã 圌ã¯ãã®ãã¡ã€ã«ã«é¢ããŠç念ãæ±ããŠããã圌ã®ã¢ã³ããŠã€ã«ã¹ã¯ãã¡ã€ã«ã«äžåå¿çããŸããã§ããã åæã®éå§ããæ°ååŸãCisco Threat Gridã¯å€å®-ZBotããã€ã®æšéŠ¬ãçºè¡ããŸããã ããããããã¯ããªãããç¥ãããå€ããã«ãŠã§ã¢ã§ãã ãŠã€ã«ã¹å¯Ÿçãããããã£ããããªãã£ãã®ã¯ãªãã§ããïŒ ããŒã¯ãŒãã¯ãå€ããã§ãã ã¢ã³ããŠã€ã«ã¹ãã³ããŒã¯ãåããŒãœãã«ã³ã³ãã¥ãŒã¿ãŒã«ã泚ãããã眲åããŒã¿ããŒã¹ã®ãµã€ãºãå°ããããããã«ãå€ã眲åãç¡å¹ã«ããããšã«ããŸããã ãããŠãããã¯ç解ããããšãã§ããŸãã 眲åã®æ°ã¯çµ¶ããå¢å ããŠãããæ¢ã«æ°åããæ°åååäœã§æž¬å®ãããŠããŸãããã®ãããªæ å ±ããã¹ãŠä¿åããã®ã«ååãªããŒããã£ã¹ã¯ã¯ãããŸããã ç§ãã¡ã¯éžæãããªããã°ãªãããããã¯æ²æšãªçµæã«ã€ãªããå¯èœæ§ããããŸãã
ã¯ããWannaCryã®è©±ãèŠããŠããã§ããããå€ãã®ã¢ã³ããŠã€ã«ã¹ãã³ããŒãããæªç¥ã®ãŠã€ã«ã¹ã®100ïŒ æ€åºããã¹ãã§åå©ãèªã£ãŠãæµè¡ã®çºçåŸã®ç¿æ¥ïŒãã¹ãŠã®éææ¥ã®å€ã§ã¯ãªãïŒã«æšå¥šãéä¿¡ãå§ãããšããã®ææãå æããããã«äœãããå¿ èŠããããã èŠããŠãïŒ å¥åŠãªç¶æ³ãåŸãããŸãã WannaCryã䜿çšããè匱æ§ã«é¢ããæ å ±ã¯1ãæéç¥ãããŠããŸãããæªæã®ããã³ãŒãã§ã¯ãŸã 䜿çšãããŠããªãããããŠã€ã«ã¹å¯ŸçããŒã¿ããŒã¹ã«çœ²åã¯ãããŸããã ãããã£ãŠãæªæã®ããã³ãŒããšæŠãåŸæ¥ã®æ段ã®ã»ãšãã©ã¯äºåŸçã«åäœããæ¢ç¥ã®ãã®ãšæ ŒéããŠããŸãã 倧èŠæš¡ãªæµè¡ã«é¢ããŠã¯ããã®ã¢ãããŒãã¯æ©èœããŸããããã»ãšãã©ããŠããŒã¯ãªãã«ãŠã§ã¢ã®ç¶æ³ã§ã¯å€±æãå§ããŸããã
ããããŸããããITUã¯CïŒCãµãŒããŒãžã®æ¥ç¶ãåæããã®ã«åœ¹ç«ã¡ãŸãããïŒ çè«çã«ã¯ãã¯ãã å®éã«ã¯ã2ã€ã®å°é£ã«çŽé¢ããŸãã ãŸããã·ã¹ã³ã®çµ±èšã«ãããšãæªæã®ããããã°ã©ã ã®çŽ92ïŒ ãDNSãããã³ã«ã䜿çšããŠããŸããããã¯ãéåžžã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãã£ã«ã¿ãªã³ã°ã§ããªããã®ã§ãïŒããã§ã¯ã Cisco Firepower NGFWãªã©ã®DNSã€ã³ã¹ãã¯ã·ã§ã³ã䌎ãNGFWãå¿ èŠã§ãïŒã 次ã«ãCïŒCããŒããšã®çžäºäœçšããããã¯ããã«ã¯ããããã®ããŒãã®ã¢ãã¬ã¹ãç¥ãå¿ èŠããããŸãããããã®ããŒãã¯çµ¶ããå€åãããããITUãã«ãŒã«ãè¿ éã«æŽæ°ããå¿ èŠããããŸãããããã¯å®éã«ã¯è¡ãããŸããã
ãŸããã»ãã¥ãªãã£Webããã³é»åã¡ãŒã«ã²ãŒããŠã§ã€ãè¿œå ããå Žåã¯ã©ããªããŸããïŒ
ãã«ãŠã§ã¢ããã®äŒæ¥ã®ä¿è·ã匷åããã«ã¯ãäœãããå¿ èŠããããŸããïŒ ãŠãŒã¶ãŒã«ããããŒã«ã«ç®¡çè ã®æš©éã®äœ¿çšã«é¢ããããããããã¯ã¢ãããããã³å¶éã®å®æçãªã€ã³ã¹ããŒã«ã«å ããŠãèããããææçµè·¯ãæãåºããŠã¿ãŸãããã çµ±èšã«ãããšããã¹ãŠã®ææã®å€§éšåã¯ãWebãšé»åã¡ãŒã«ãšãã2ã€ã®äž»èŠãªãã£ãã«ãä»ããŠå®è¡ãããŸãã ããã¯ãæªæã®ããæ·»ä»ãã¡ã€ã«ã®ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããä¿è·ãœãªã¥ãŒã·ã§ã³ããããã®ãã£ãã«ãä¿è·ããå¿ èŠãããããšãæå³ããŸãã ã·ã¹ã³ã§ã¯ããããEã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ããã³Webã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ã§ãã
ããããçµç¹å ã«äŸµå ¥ããæªæã®ããã³ãŒãã®2ã€ã®äž»èŠãªãã£ãã«ãéè€ããŠããæ¢ç¥ã®ãŠã€ã«ã¹ã®ã¿ããã£ãããããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã®åé¡ã¯åãé€ãããŸããã ããžã¿ã«æçŽïŒçœ²åïŒã®æç¡ã«é¢ä¿ãªãããã¡ã€ã«ãåæã§ãããã¯ãããžãŒã¯ãããŸããïŒ ã¯ãããµã³ãããã¯ã¹ãšåŒã°ããã¬ãžã¹ããªãžã®ã¢ã¯ã»ã¹ããã¡ã€ã«ã®ã³ããŒãCïŒCãµãŒããŒãšã®å¯Ÿè©±ãèš±å¯ããããã©ãã£ãã¯ã®ã«ãã»ã«åãªã©ãäžæ£ãªã¢ã¯ã·ã§ã³ãå®è¡ããç®çã§ããã¡ã€ã«ã®éçããã³åçåæãå®è¡ã§ããŸãã åãCisco Threat Gridãµã³ãããã¯ã¹ã¯ã700ãè¶ ããããŸããŸãªãã©ã¡ãŒã¿ãŒãšãã¡ã€ã«ã®åäœèŠå ãåæããŠããã¡ã€ã«ã®æ害æ§ãå€æã§ããŸãã çµã¿èŸŒã¿ã®ãŠââã€ã«ã¹å¯Ÿçãšã³ãžã³ãåããããŒã«ãä¿è·ããã®ã¯ãµã³ãããã¯ã¹ã§ãããæªç¥ã®ãŠã€ã«ã¹ã¯æ€åºã§ããŸããã ãµã³ãããã¯ã¹ãšã®çµ±åã¯ããã®ãããªæ©äŒãæäŸããŸãã ã·ã¹ã³ã®ã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ã®å Žåããã¹ãŠã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯ãè åšã°ãªãããµã³ãããã¯ã¹ã«é¢é£ä»ããããŠããŸã-Ciscoé»åã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ãWebã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ãCisco Firepower NGFW / NGIPSãFirePOWERãµãŒãã¹ãåããCisco ASAããšã³ããã€ã³ãåãCisco AMPãCisco Umbrellaãªã©
ã¢ãã€ã«ãŠãŒã¶ãŒãä¿è·ããæ¹æ³
ãããã¯ãŒã¯å¢çãä¿è·ãããšä»®å®ããŸãããã¢ãã€ã«ãŠãŒã¶ãŒã¯ã©ãããŸããïŒ ãããã®åšèŸºã§ã¯ãITUãIPSãã³ã³ãã³ãã²ãŒããŠã§ã€ããµã³ãããã¯ã¹ããé²åŸ¡å£ãæ§ç¯ããããšã¯ã§ããŸããã MDMãœãªã¥ãŒã·ã§ã³ã¯ç®çãç°ãªããããæªæã®ããã³ãŒããžã®å¯ŸåŠã«ã¯ããŸã圹ç«ã¡ãŸããã ã¢ãã€ã«ãŠã€ã«ã¹å¯ŸçïŒ åœŒã¯ä»¥åã«èª¬æããã®ãšåãåé¡ãæ±ããŠããŸãã ãŸãããã¹ãŠã®ã¢ãã€ã«ãã©ãããã©ãŒã ã«ãã«ãŠã§ã¢å¯ŸçããŒã«ãæèŒãããŠããããã§ã¯ãããŸããïŒããšãã°ãiPhoneçšïŒã ã©ããã£ãŠæŠãã®ïŒ ç¹°ãè¿ããŸãããæ»æè ã®åŽã«ç«ã¡ãæ»æè ãã©ã®ããã«äœæç©ãäœæãããã確èªããå¿ èŠããããŸãã ååãšããŠããããã¯èªåŸçã«åäœããŸãããã管çãµãŒããŒãšã®éä¿¡ãæå³ããã¯ã©ã€ã¢ã³ããµãŒããŒã¢ãŒããã¯ãã£ã䜿çšããŸããããã«ã¯ãã»ãšãã©ã®å ŽåDNSãããã³ã«ã䜿çšãããŸãã æ€æ»ã§ããã°ãã¢ãã€ã«ãã©ãããã©ãŒã ã®æªæã®ããã³ãŒãã«é¢ããåé¡ã®ã»ãšãã©ã解決ã§ããŸãã ãã®å ŽåãGoogleãŸãã¯Yandexã®DNSãµãŒããŒã¢ãã¬ã¹ãç¹æ®ãªãµãŒãã¹ïŒ Cisco Umbrellaãªã© ïŒã®ã¢ãã¬ã¹ã«çœ®ãæããã ãã§ãDNSãµãŒãã¹ã«å ããŠãCïŒCãµãŒããŒãšã®çžäºäœçšãããå®å šã«ä¿è·ãããŸãã å®éãCisco Umbrellaã§ã¯ããã£ãã·ã³ã°ãªãœãŒã¹ããã«ãŠã§ã¢ã®æ¡æ£ã«äœ¿çšãããDGAãã¡ã€ã³ãã¯ããŒã³ãµã€ãã®è¿œè·¡ãã¹ã€ãããã¡ã€ã³ã®åŒ·å¶çµäºãªã©ãé®æããããšãã§ããŸãã
NTAãšEDRãèŠãŠã¿ãŸããã
WannaCryã®è©±ã«æ»ããŸãããã éææ¥ã®å€æ¹ã倧äŒæ¥ã®CEOãèªå® ã®ã³ã³ãã¥ãŒã¿ãŒã§WannaCryãæŸããŸããã ããããããšãªããåææ¥ã®æã圌ã¯ææããã©ããããããè·å Žã«æã¡èŸŒã¿ããããäŒæ¥ãããã¯ãŒã¯ã«æ¥ç¶ããåæã«ITå°é家ã«ãæ°åãæ¶ãå»ã£ããã 圌ããä»äºãããŠããéãWannaCryã¯ãå¢çä¿è·ãããªãåªããŠããã«ãããããããå éšãããã¯ãŒã¯å šäœã«åºããå§ããŸããã ããããæªç¥ã®ãŠã€ã«ã¹ãWi-Fiã®ãããã³ã°ãè«è² æ¥è ã®ã©ããããããªã©ãæèŒãããã©ãã·ã¥ãã©ã€ãã¯ãŸã ååšããŸãã ãã®ç¶æ³ã§äœããã¹ããïŒ å¯äžã®çãã¯ãNTAããã³EDRãã¯ãããžãŒã䜿çšããŠå éšã€ã³ãã©ã¹ãã©ã¯ãã£ãç£èŠããããšã§ãã ãããã¯ããããã¯ãŒã¯ãã©ãã£ãã¯åæãšãšã³ããã€ã³ãã®æ€åºãšå¿çãšãã2ã€ã®ã¯ã©ã¹ã®ã»ãã¥ãªãã£æ©èœãæå³ããç¥èªã§ãã
ãããã¯ãŒã¯ãã©ãã£ãã¯ã®åæïŒããšãã°ã Cisco Stealthwatchã䜿çšïŒã«ããã端æ«ããã€ã¹ã«ä¿è·ããŒã«ããªããŠããå€ããªã£ãã¢ã³ããŠã€ã«ã¹ããã£ãŠããæªæã®ããã³ãŒãã®å åãèå¥ããããšãã§ããŸãã ããã«ã ETAãã¯ãããžãŒã«ãããæå·åããããã©ãã£ãã¯ã§ãæªæã®ããã¢ã¯ãã£ããã£ã®å åãæ€åºããããšãå¯èœã§ãã 次ã«ããã¹ãŠã®100ïŒ è åšãé²æ¢ãããšããååã«åºã¥ããŠæ§ç¯ãããŠããªãEDRã¯ã©ã¹ã®ãœãªã¥ãŒã·ã§ã³ïŒããšãã°ã Cisco AMP for Endpoint ïŒãšãŠã€ã«ã¹å¯Ÿçã亀æããŸãããã®äºå®ãæ€åºããããã«åå¿ããŸãã
å¢çäžã®ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãå éšãããã¯ãŒã¯ã«ç¬èªã®é¡äŒŒç¹ããããŸã-ããã¯ã äœããã®æ¹æ³ã§å éšãããã¯ãŒã¯ã«äŸµå ¥ããå Žåã«ãå éšãããã¯ãŒã¯ã®ã»ã°ã¡ã³ããŒã·ã§ã³ãšæªæã®ããã³ãŒãã®æ¡æ£ã®ããŒã«ãªãŒãŒã·ã§ã³ãæäŸãããããã¯ãŒã¯ã¢ã¯ã»ã¹å¶åŸ¡ã·ã¹ãã ïŒããšãã°ã Cisco ISE ïŒã§ãã çæ³çã«ã¯ãæªæã®ããã³ãŒããæ¡æ£ãããæåã®è©Šã¿ãæ€åºãããããã¯ãŒã¯ãã©ãã£ãã¯åæãœãªã¥ãŒã·ã§ã³ã¯ãã¹ã€ããããŒããç¡å¹ã«ããããã«ãŒã¿ãŒã®ACLãå€æŽããŠæ€ç«ãµããããã«å ¥ãããšã«ããããããã¯ãŒã¯ã¢ã¯ã»ã¹å¶åŸ¡ã·ã¹ãã ã«ã³ãã³ããéä¿¡ããææããã³ã³ãã¥ãŒã¿ãŒããããã¯ã§ããŸãã
ãã¡ãããäžèšã®ãã¹ãŠã®æè¡ã¯åå¥ã«ãŸãã¯ãªãã©ã€ã³ã§æ©èœããã®ã§ã¯ãªããã¢ã©ãŒã ãã»ãã¥ãªãã£ããªã·ãŒãã³ãã³ããããã³äŸµå®³ã®ææšã亀æããŠäºãã«å¯æ¥ã«é£æºããå¿ èŠããããŸãã ãšããã§ãã€ã³ãžã±ãŒã¿ãŒïŒIoCïŒã«ã€ããŠã ãŸããå€éšãœãŒã¹ããå®æçã«ååŸããå¿ èŠãããïŒ Cisco Talosã¯ãã®ãããªãœãŒã¹ã®åœ¹å²ã§ãïŒã絶ããå€åããè åšã«é¢ããç¥èããã¹ãŠã®ä¿è·ããŒã«ïŒå¢çãã¯ã©ãŠããå人ããŸãã¯å éšïŒãåããŠããå¿ èŠããããŸãã
éãããœãããŠã§ã¢ç°å¢ã«æ»ããå€çããéé¢ãã
äžèšã®æŠç¥ã¯ãæªæã®ããã³ãŒãã®98ïŒ ã«å¯Ÿããä¿è·ã«æé©ã§ãã 倧åãªçŸã«è¿ã¥ãããšã§ããã®äŸ¡å€ãé«ããããšãã§ããŸããïŒ å®éã«ã¯å¯èœã§ããããã®å Žåããããã¯ãŒã¯ã®éçšç¹æ§ãå€§å¹ ã«äœäžããããŠãŒã¶ãŒã®äœ¿ãããããäœäžãããå¿ èŠãããããšãç解ããå¿ èŠããããŸãã ããã¯ããã©ãã¯ãªã¹ããã©ãã€ã ãæåŠãããæ¢ç¥ã®ãã®ã®ã¿ãèš±å¯ãããããšããã«ãŒã«ãžã®ç§»è¡ã«ãã£ãŠå®çŸãããŸãã èš±å¯ãããã¢ããªã±ãŒã·ã§ã³ãIPã¢ãã¬ã¹ããŠãŒã¶ãŒãªã© ç§ãã¡ãç解ããŠããããã«ããã®ã¢ãããŒãã«ã¯å®ç掻ã«ãããŠå€§ããªå¶éããããŸãããæªæã®ããã³ãŒãã®åäœãèããå¶éããå¯èœæ§ããããŸãã åé¢æè¡ãä»®æ³åããªã¢ãŒããã©ãŠã¶ãŒãTPMãOSæŽåæ§å¶åŸ¡ããªã¢ãŒãæ€èšŒãé»åã¡ãŒã«çœ²åã«ãããè¿œå ã®ä¿è·ã¬ãã«ãå®çŸãããŸãã
ãŸãšããšããŠ
æªæã®ããã³ãŒãããä¿è·ããããã®ããã€ãã®æŠç¥ã説æããŸãã-æå°ããæ倧ãŸã§ã ããã¯ãå éšãããã¯ãŒã¯ãšã¢ãã€ã«ãŠãŒã¶ãŒã®ææãå®å šã«é²ãããšãã§ãããšããããšã§ããïŒ ããã 100ïŒ ã®ä¿è·ãä¿èšŒã§ãã人ã¯ããŸããã ãããããã®ã¡ã¢ã®ã¿ã¹ã¯ã¯ç°ãªã£ãŠããŸãã-ãŠã€ã«ã¹å¯Ÿçã ãã§ææ°ã®ãã«ãŠã§ã¢ããä¿åã§ãããšãã芳ç¹ã¯ãŸã é·ãéãè æãããŠãããçµ±åã¢ãããŒãã®ã¿ãåé¡ã解決ã§ãããŠãŒã¹ã±ãŒã¹ãã䜿çšããå¿ èŠãããããšã瀺ãããç§ãã¡ããã§ã«æžããããš ã
è¿œå æ å ±ïŒ
Ciscoãããã¯ãŒã¯äžã®Cisco Stealthwatchã¢ããªã±ãŒã·ã§ã³ã®èª¬æ
æå·åããããã©ãã£ãã¯ã®æªæã®ããã³ãŒããæ€åºããæè¡ã®èª¬æ
ãããã¯ãŒã¯äžã®ã¯ãªãããã€ããŒãæ€åºããã¢ãããŒãã®èª¬æ
ãŠãŒã¹ã±ãŒã¹ã«åºã¥ããã»ãã¥ãªãã£ã·ã¹ãã ã®æ§ç¯
æå·åããã°ã©ã ãšæŠãããã®æŠç¥ã®èª¬æ
WannaCryãšæŠãããã®æŠç¥ã®èª¬æ
Ciscoãããã¯ãŒã¯ã§ã®Cisco ISE ã®äœ¿çšã®èª¬æ