BGPã®è匱æ§ãä»ãããã©ãã£ãã¯ã®ãã©ãã
æè¿ãBGPã€ã³ã¿ãŒãããã«ãŒãã£ã³ã°ãããã³ã«ã®è匱æ§ãããé »ç¹ã«ãªããŸããã ãã©ãã£ãã¯ã®ååãšãªãã€ã¬ã¯ãã«ããããã©ãã£ãã¯ãåæããã³æäœã§ãããããæå·é貚ã®çé£ãæ©å¯æ§ã®äŸµå®³ãèŠå¯ãå¶åŸ¡ããã³ã³ãã¥ãŒã¿ãŒã®å¶åŸ¡ã®å埩ã«ã€ãªãããŸãã 2018幎ã®ç§ã«ããªã³ã©ã€ã³åºåã«ããè©æ¬ºã®ããã«ãµã€ããŒç¯çœªè ã«ãã£ãŠäœ¿çšãããæ°ããã¹ããŒã ãæ€åºãããŸããã 3veãšåŒã°ããæ»æè ã®æäœã¯ã150äžãè¶ ããIPã¢ãã¬ã¹ã®ãã©ãã£ãã¯ãååããåºåäŒç€Ÿã«ãå®éã®ãŠãŒã¶ãŒãå®éã«äœååãã®ã€ã³ã¿ãŒããããããŒã€ã³ãã¬ãã·ã§ã³ãèŠãããšãä¿¡ããããŸããã ã¯ããããã¯è±åœã®æ žå µåšæ©é¢ããã®ãã©ãã£ãã¯ã®çé£ã§ã¯ãããŸããã ãããŠãã¯ããããã¯MyEtherWalletã®Webãµã€ããè£ ãç®çã§1300ã®Amazonã¢ãã¬ã¹ã®ãã©ãã£ãã¯ãååãããã®ã§ã¯ãªãããã®åŸã®æå·é貚ã§ã®15äžãã«ã®çé£ã§ãã ããã¯ãMasterCardãVisaïŒããã³SymantecãVerisignïŒãå«ã20ãè¶ ããéèæ©é¢ããã®ãã©ãã£ãã¯ã®ååã§ã¯ãããŸããã ãã©ã°ã€ã³ãšç¹æ®ãªãœãããŠã§ã¢ã䜿çšããŠãã¹ãŠåé€ããããšããè¿·æãªåºåã ããããåºåäŒç€Ÿã®å Žåããã®æ»æã«ã¯2900äžãã«ã®è²»çšããããããæ·±byã«æã蟌ãŸããããã€ãŸãè匱æ§ãšäžæ£ãªBGPèšå®ã䜿çšããè©æ¬ºåž«ã«æ¯æãããŸããã
ã·ã¹ã³ãåçãããã® ïŒBGPãä»ããã©ã³ãã ãŸãã¯æªæã®ããè åšã®å®è£ ãç¡å¹ã«ãããããäœã販売ããŸãã:-)ããã¥ã¢ã«ïŒ ãããšãã ïŒã«ç²Ÿéããããã«å¿ããŠãããã¯ãŒã¯æ©åšãèšå®ããããšããå§ãããŸãã ããã«ãé©åãªBGPç£èŠãµãŒãã¹ã䜿çšããŠãããã¯ãŒã¯ã®ã«ãŒãã£ã³ã°æ å ±ãç£èŠããããšããå§ãããŸãã
ãããã¯ãŒã¯ããã€ã¹ã®ãããã³ã°
2018幎11ææ«ã«ã45,000å°ã®äŸµå®³ãããã«ãŒã¿ãŒãèŠã€ãããŸããã æ°é±éåã«ãBroadcomãAsusãTP-LinkãZyxelãD-LinkãNetgearãUS Roboticsãªã©ã®100,000å°ã®äŸµå®³ããããããã¯ãŒã¯ããã€ã¹ã®ãããããããçºèŠãããŸããã 5æã Cisco Talosã¯54ãåœã§50äžå°ã®äŸµå®³ããããããã¯ãŒã¯ããã€ã¹ãçºèŠããŸããã 圱é¿ãåãããã³ããŒã«ã¯ãASUSãD-LinkãHuaweiãUbiquitiãUPVELãZTEãLinksysãMikroTikãNetgearãTP-Linkãªã©ããããŸãã ãããã¯ãŒã¯æ©åšã®ãããã³ã°ã¯ãæ»æè ãæå·åãããŠããªã圢åŒã§éä¿¡ãããå¯èœæ§ã®ãã倧éã®æ å ±ã«ã¢ã¯ã»ã¹ã§ãããããå€ç«ããã±ãŒã¹ããäž»æµã«ãªããŸãã
ã·ã¹ã³ãäœãçããŸããïŒã·ã¹ã³ã®æ©åšã«ã€ããŠè©±ããŠããå Žåã Cisco IOS ã IOS XR ã IOS XEãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«åºã¥ããŠã«ãŒã¿ãä¿è·ããããã®å€ãã®æšå¥šäºé ãéçºããŸããã ããã«ãç§ãã¡ã¯ã«ãŒã¿ãŒã®æ»æã«æåã«ééããïŒäººæ°ãããããïŒã®ã§ãã»ãã¥ã¢ããŒãã»ãã¥ã¢ããŒãã¡ã«ããºã ãã¡ã¢ãªä¿è·ãããŒããŠã§ã¢ã³ã³ããŒãã³ãã®æ©åšãžã®ãªãããŸãã«å¯Ÿããä¿è·ãªã©ãå°å ¥ãå§ããŸããã
ä»ã®ã¡ãŒã«ãŒããããããæŽæ°ããã³ä¿è·ããæ¹æ³ã«ã€ããŠé©åãªæ瀺ãæã£ãŠããå¿ èŠããããŸãã ããã«ããããã¯ãŒã¯æ©åšããã®ãã¬ã¡ããªãåæããããšããå§ãããŸããããã«ããããããã¯ãŒã¯ãã©ãã£ãã¯ã®ç°åžžãç¹å®ãã2019幎ã«åŒãç¶ãæ»æè ã®é¢å¿ãåŒããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã¬ãã«ã§äŸµå®³ãæ€åºã§ããŸãã
ãµãã©ã€ãã§ãŒã³æ»æ
ãããã¯ãŒã¯æ©åšãžã®æ»æã¯ãäžçäžã®ã客æ§ã®äžéšãçŽé¢ããŠãããšããå€ã話ãæãåºãããŸããïŒå°æ°ããããŸããã§ããïŒã ç§ãã¡ã®æ©åšã®ãµãŒãã¹å¥çŽãªãã§ã圌ãã¯ãã§ã«ã€ã³ã¿ãŒããããµã€ãããå»æ¢ãããã«ãŒã¿ãŒã®æ°ãããã¡ãŒã ãŠã§ã¢ãããŠã³ããŒãããããã¯ããã€ã¹ææãæ å ±ååã«ã€ãªããããããã¯ãŒã¯æ©åšã®èªè¡æŠç¥ãä¿®æ£ãã Trustworthy Systemsã€ãã·ã¢ãããç«ã¡äžããããä¿ãããŸãããããã€ã¹ã®ã¢ãŒããã¯ãã£ãå€§å¹ ã«åèšèšãã ä¿¡é Œã§ããããŒãã¡ã«ããºã ãã¡ã¢ãªå ã®æªæã®ããã³ãŒãã®å®è¡ã«å¯Ÿããä¿è·ãé»åã³ã³ããŒãã³ãã®ãªãããŸãã«å¯Ÿããä¿è·ãåãããã¬ãŒã ã¯ãŒã¯ã§ ãªã©
2018幎ã«ãç±³åœåœåå®å šä¿éçã¯ãæªç¥ã®ããã«ãŒãåç±³ã®å€ãã®ãšãã«ã®ãŒäŒæ¥ãæ»æãããããããŠã©ãŒã¿ãŒããŒã«æ»æãéããŠæ»æããæ¹æ³ã«ã€ããŠã®è©±ãå ±æããŸããã æ»æã®æ¬è³ªã¯ãæ»æè ãæ»æã®æåã®ã¹ããããéå§ããã®ã¯ã被害è ã®äŒç€Ÿããããã³ã°ããããšã§ã¯ãªãã被害è ã䜿çšãããœãããŠã§ã¢ãŸãã¯ããŒããŠã§ã¢ã®ã¡ãŒã«ãŒã®ãµã€ãã䟵害ããããšã§ãã é ããæ©ããïŒçŸåšã®ãœãããŠã§ã¢ã®å質ã§ãé ããæ©ããïŒãäŒç€Ÿã¯ãœãããŠã§ã¢ãšãã¡ãŒã ãŠã§ã¢ã®æŽæ°ã®ããã«ã¡ãŒã«ãŒã®Webãµã€ãã«ã¢ã¯ã»ã¹ããä¿¡é Œã§ãããªãœãŒã¹ããææãããœãããŠã§ã¢ãããŠã³ããŒãããå®å šã«å®å šã«ä¿¡é ŒããŸãã ãã®ãããæ»æè ã¯çµç¹å ã«å ¥ã蟌ã¿ãããªããžããããæ¡å€§ãå§ããŸãã ãã®æ»æã«ããã1ã€ã§ã¯ãªãå€ãã®äŒæ¥ã«äžåºŠã«ææãã氎飲ã¿å Žã®ããã«ïŒãããã£ãŠãæ°ŽããŸãïŒã補é å ã®Webãµã€ãã«ã¢ã¯ã»ã¹ããŠæŽæ°ãè¡ãããšãã§ããŸãã
2018幎8ææ«ãããªãã£ãã·ã¥ãšã¢ãŠã§ã€ãºã®èªç©ºäŒç€Ÿã¯ããã±ããã泚æããéã«ãŠã§ããµã€ãã«å ¥åããããã€ã¡ã³ãã«ãŒãããŒã¿ã®æŒæŽ©ã«ãã£ãŠæ°åäžã®é¡§å®¢ã圱é¿ãåãããšããäºå®ã«çŽé¢ããŸããã 調æ»äžã«ãããã«ãŒã°ã«ãŒãã®Magecartããããã³ã°ããããšãå€æããŸããããããããªãã£ãã·ã¥ãšã¢ãŠã§ã€ãºã®ãµã€ãã§ã¯ãªããææããJavaScriptã®ããŠã³ããŒãå ã§ããè«è² æ¥è ã®ãµã€ããæ å ±æŒãããåŒãèµ·ãããŸããã Magecartã¯ãTicketmasterã®çºåžãµã€ãã«å¯Ÿããæ»æã®å Žåãããã³ä»ã®å€ãã®eã³ããŒã¹ãªãœãŒã¹ã«å¯Ÿããåæ§ã®æŠè¡ã«åŸããŸããã æåŸã«ãããããŒãžã§ã³ã«ãããšãããªãã£ãã·ã¥ãšã¢ãŠã§ã€ãºã®ã¡ã€ã³ãµã€ãã§ã¯ãªããã€ã³ã¿ãŒããããããã€ããŒã®CDNã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãããç¹å®ã®å Žæããèªç©ºäŒç€Ÿã®Webãµã€ããžã®ã¢ã¯ã»ã¹ãé«éåããããã«èšèšãããã¯ããŒã³ã®1ã€ãç ŽæããŠããããšã«æ³šæãã䟡å€ããããŸãã ãã®å Žåããããã³ã°ãããã®ã¯äŒç€Ÿèªäœã§ã¯ãªããã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžéšãæäŸããã®ã¯ååŒçžæã®1ã€ã§ããã
ãããã®äŸã¯ãæå·é貚çªçã®å Žåã®BGPãä»ãããã©ãã£ãã¯ã€ã³ã¿ãŒã»ããã®äžèšã®ã±ãŒã¹ãšåæ§ã«ãäŒç€Ÿã®ããã«ãŒã«ãšã£ãŠé¢å¿ã®ãããªãœãŒã¹ã ãã§ãªãããããæäŸããã€ã³ãã©ã¹ãã©ã¯ãã£ãæ»æãããå¯èœæ§ãããããšã瀺ããŠããŸãã ç§ãã¡ã®æèŠã§ã¯ããã®ãããªæ»æã¯ããé »ç¹ã«ãªãã ãã§ããããµã€ããŒã»ãã¥ãªãã£ã®å°é家ã®æ³šæã®ç¯å²ãæ¡å€§ããèªåèªèº«ã ãã§ãªãããŒãããŒãè«è² æ¥è ãè«è² æ¥è ã®ã»ãã¥ãªãã£ãç£èŠããããã®ã»ãã¥ãªãã£æŠç¥ãéçºããå¿ èŠæ§ã®åé¡ãæèµ·ããŸãã
ã·ã¹ã³ã®åç ïŒããã«ã¯æ®éçãªã¬ã·ãã¯ãããŸããããã¹ãŠã¯ãããã«ãŒãã¯ã©ããã³ã°ããè«è² æ¥è ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã©ã®ããã«ã©ã®ããã«äŸåãããã«ãã£ãŠå€§ããç°ãªããŸãã BGPãžã®æ»æã«ã€ããŠè©±ããŠããå Žåã¯ãBGPã«ãŒããç£èŠããå¿ èŠããããŸãã 䟵害ããã補é å ã®Webãµã€ãã®ææããã¹ã¯ãªãããä»ããæ»æã«ã€ããŠè©±ããŠããå Žåã Cisco Umbrellaã䜿çšããDNSç£èŠã圹ç«ã¡ãŸããã¹ããŒãã£ã³ã°ããããœãããŠã§ã¢ã®ããŠã³ããŒãã«ã€ããŠè©±ããŠããå Žåã Cisco Stealthwatchã䜿çšãããã¬ã¡ããªãŒã®ç°åžžã®åæã圹ç«ã¡ãŸãã æãéèŠãªããšã¯ã2019幎ã«ãã®è åšãé¢é£ããè åšã®ãªã¹ãã«å«ããããšã§ãã
ä»åŸã®TLS 1.3
誰ããTLSãããã³ã«ã«ã€ããŠèããããšããããŸããããã®å身ã¯SSLãããã³ã«ã§ããã æè¿ã§ã¯ã2018幎8æã«RFC 8446å§åãå ¬éãããæ°ããããŒãžã§ã³1.3ãç¹å®ãããŸããã æ°ããããŒãžã§ã³ã®å©ç¹ã«ã¯ãé«éæ§ãšæå·åŒ·åºŠãå«ãŸããŸãã åæã«ã以åã®ããŒãžã§ã³ã®è匱æ§ãæé€ãããæ°ãã䟿å©ãªæ©èœãè¿œå ãããŸããã çŸåšãTLS 1.3ã¯å€ãã®äžè¬çãªãã©ãŠã¶ãšæå·ã©ã€ãã©ãªïŒChromeãFirefoxãOpenSSLãªã©ïŒããµããŒãããŠããŸãã ãã¹ãŠãããŸãããããã§ãããæ²ããããªã TLS 1.3ã®æ¡çšã®é ãã¯ããšãããããã®ããŒãžã§ã³ã®ãããã³ã«ã§ã¯ãå€ãã®äŒæ¥ã®ãµã€ããŒã»ãã¥ãªãã£ãµãŒãã¹ã«å¿ èŠãªäžéããã€ã¹ïŒNGFWãIDSããããã·ãªã©ïŒã䜿çšãããã©ãã£ãã¯ã®æ€æ»ãèš±å¯ãããŠããªãããã§ãã TLS 1.3ãè°è«ããŠããå€ãã®äŒæ¥ã¯ããã匱ãéµäº€æãããã³ã«ãå«ããããšãææ¡ããŸããããã€ã³ã¿ãŒãããäžã®æ©å¯æ§ã確ä¿ããéä¿¡ã®èªç±ã«ãããæ¿åºã®å¹²æžããä¿è·ããããã«ããããã®ææ¡ã¯ãã¹ãŠæåŠãããŸããã TLS 1.3ãç©æ¥µçã«äœ¿çšãããšããããæ€æ»ã§ããªããªãããšãéåžžã«æ·±å»ã«ãªããæåã®åé¡ã¯2019幎ããå§ãŸãå¯èœæ§ããããŸãã
ã·ã¹ã³ã®åç ïŒæ°ããããŒãžã§ã³ã®TLSãå°å ¥ããéã«ïŒç¹ã«ãœãªã¥ãŒã·ã§ã³ã§å®è£ ããŠããããïŒé²è¡ã劚ããããè»èŒªã«æ£ãå ¥ãããããäºå®ã¯ãããŸããããã€ã³ãã©ã¹ãã©ã¯ãã£ã§åãæ¿ããå¿ èŠããããã©ãããæ€èšããããšããå§ãããŸãTLS 1.2ããããã³ã°ãããŠãããããŸã çŠæ¢ãããŠããªãå Žå ããããé ããæ©ãããã®ãããªç§»è¡ãè¡ããããããæ å ±ã»ãã¥ãªãã£ã®å°é家ã¯ãç£èŠã§ããªããã©ãã£ãã¯ãç£èŠããæ¹æ³ã«ã€ããŠã®çåã«çŽé¢ããŸãã çãã¯ãåœç€ŸãéçºããEncrypted Traffic Analyticsã«äŒŒããã¯ãããžãŒãããããŸãããããã«ãããæå·åããããã©ãã£ãã¯ã®å 容ãæå·åããã³åŸ©å·åããã«ïŒãã ããã³ã³ãã³ãèªäœã«ã¢ã¯ã»ã¹ããããšãªãïŒç解ã§ããŸãã
ãã©ãã£ãã¯æå·å
æå·åãšèšãã°... ãµã€ããŒã»ãã¥ãªãã£ã«é¢ããå¹Žæ¬¡å ±åæž ïŒCisco Annual Cyberââsecurity Report 2018ïŒã§ãéå»1幎éã®ã°ããŒãã«Webãã©ãã£ãã¯ã®55ïŒ ãæå·åããã圢åŒã§éä¿¡ãããæšå¹Žãã12ïŒ å€ããæªæã®ããããã°ã©ã ã®æ°æå·åã®äœ¿çšã3åã«ãªããŸããã ã¬ãŒãããŒã¯ã圌ã®äºæž¬ã®1ã€ã§ãYellow Earth Pigã®å¹ŽïŒã¯ããããã¯2019幎ïŒã«ããã¹ãŠã®Webãã©ãã£ãã¯ã®80ïŒ ããã§ã«æå·åããããšäºæž¬ããŸããã ãããŠããã®ãããªç¶æ³ã§äœããã¹ããïŒ ç¹ã«ãäžèšã®TLS 1.3ã䜿çšããŠãã©ãã£ãã¯ãæå·åãããŠããå Žåã¯ã©ãã§ããïŒ
ã·ã¹ã³ã®åç ïŒèªç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãããŠãããã®åé¡ã«çŽé¢ããŠãããå€ãã®æšå¥šäºé ãäœæããçæ§ãšå ±æããæºåãæŽããŠããŸãã ãŸãããã³ãã«ãçµäºãã埩å·åããããã©ãã£ãã¯ãæ€æ»ã§ããïŒå°ãªããšãããŒãžã§ã³TLS 1.3ãŸã§ïŒäžéããã€ã¹ïŒ Cisco NGFWãCisco WSAãªã© ïŒãå²åŒã«ããªãã§ãã ããã ãããã¯ãŒã¯ã»ãã¥ãªãã£ããã€ã¹ã®ããã©ãŒãã³ã¹ããäœäžãããæããããå Žåãæå·åããããã©ãã£ãã¯ãçµäºããæ©èœããRadware Alteonãªã©ã®å€éšããã€ã¹ã«å²ãåœãŠãããšãã§ããŸãã æå·åããããã£ãã«ã解æã§ããªããŠãã絶æããªãã§ãã ããã æå·åããããã©ãã£ãã¯ã解èªããã«å éšã«ã浞éããããæ©æ¢°åŠç¿ãã¯ãããžãŒïŒããšãã°ã Cisco ETA ïŒã䜿çšããããã³ãã³ããµãŒããŒãã€ã³ã¿ãŒãããäžã®ãã®ä»ã®æªæã®ãããªãœãŒã¹ãšã®çžäºäœçšãæ€åºãããã§ããŸãã ã·ã¹ã³ã®ããŒããã©ãªãªã§ã¯ã Cisco Umbrellaããã®åé¡ã®è§£æ±ºã«åœ¹ç«ã¡ãŸãã æåŸã«ãæå·åããããã©ãã£ãã¯ã§ããã埩å·åãããŠããå Žæãããããšãå¿ããªãã§ãã ãã-ãããã¯ãšã³ãããã€ã¹-ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒã§ãé©åãªã»ãã¥ãªãã£æ©èœãã€ã³ã¹ããŒã«ïŒããã³å¿ èŠïŒããŸãã ãã ããåŸæ¥ã®ã¢ã³ããŠã€ã«ã¹ã¯ããã§ã¯æ©èœããŸããã80幎代åŸåã«éçºããããœãªã¥ãŒã·ã§ã³ãããææ°ã®ãã®ãå¿ èŠã§ãã ã·ã¹ã³ã§ã¯ããã®ãœãªã¥ãŒã·ã§ã³ã¯Cisco AMP for EndpointsãšåŒã°ããã©ãããããã§äœ¿çšããŠããŸãïŒãã¹ãŠã®ã»ãã¥ãªãã£éçºè ãèªæ ¢ã§ããããã§ã¯ãããŸããïŒãããã¡ãããä»ã®EDRïŒãšã³ããã€ã³ãæ€åºããã³å¿çïŒãœãªã¥ãŒã·ã§ã³ã䜿çšã§ããŸãã
ãã¡ã€ã«ã¬ã¹æ»æ
ãŠã€ã«ã¹å¯Ÿçæè¡ã¯80幎代åŸåã«ç»å Žãããã以éãã»ãšãã©ã®éšåã§å€§ããªå€åã¯ãããŸããã æªæã®ããããã°ã©ã ããããŸã;ãŠã€ã«ã¹ã¢ããªã¹ãã¯ããã調æ»ãã眲åãéçºãã補åãè£ åããŸãã 眲åããããŸã-ãã«ãŠã§ã¢ããã£ãããããŠããŸãã 眲åãªã-ãã£ãããããŸããã æ»æè ã®ã¿ã¹ã¯ã®1ã€ã¯ãã§ããã ãé·ãæ°ä»ãããªãããã«ããããšã§ããããã®ããã«ãèŠåå¡ãšç«ãšããŠã¹ãç©æ¥µçã«äœ¿çšãç¶ããŠããŸãã æªæã®ããç°åžžãªã¢ã¯ãã£ããã£ãæ€åºããèœåãé«ãããã®ãããã°ãã§ããã ãé·ãç®ã«èŠããªãå¯èœæ§ãé«ãããã®ããããŸãã æé·åŸåã®1ã€ã¯ãæ£åœãªã³ã³ãã¥ãŒã¿ãŒãŠãŒã¶ãŒãè£ ã£ãŠãOSããã³PowerShellã®çµã¿èŸŒã¿ã³ãã³ããç©æ¥µçã«æªçšãããã¡ã€ã«ã¬ã¹æ»æã®äœ¿çšã§ãã
ã·ã¹ã³ã®åç ïŒç«¯æ«ããã€ã¹ã«ã€ããŠã®ã¿è©±ããŠããããããã¡ã€ã«ããªãŒæ»æã®ä¿è·ãšå¶åŸ¡ãç®çãšãã2ã€ã®ãœãªã¥ãŒã·ã§ã³ã Cisco AMP for EndpointsãšCisco AnyConnectããããŸãã æåã®ãœãªã¥ãŒã·ã§ã³ã¯EDRã¯ã©ã¹ã«å±ãããã®è匱æ§ã®åæãå«ããœãããŠã§ã¢ã®ã€ã³ãã³ããªãå®è¡ããã¡ã¢ãªå ã§èµ·åããããã®ãå«ããšã¯ã¹ããã€ãããããã¯ãã絶ããæŽæ°ããã䟵害ã€ã³ãžã±ãŒã¿ïŒIOCïŒãéããŠã¢ã¯ãã£ããã£ãåæããè åšã®èª¿æ»ãšæ€çŽ¢ïŒè åšãã³ãã£ã³ã°ïŒãå®è¡ã§ããŸãïŒ NVMïŒNetwork Visibility ModuleïŒãçµ±åãããCisco AnyConnectã䜿çšãããšããã¹ãäžã®ã¢ã¯ãã£ããã£ããŒã¿ãé©åããNetflow圢åŒã§åéãã Cisco Stealthwatchãããã¯ãŒã¯ã¬ã€ã€ãŒã§åä¿¡ããããŒã¿ãšçžé¢ãããããšãã§ããŸãã ããã«ãCisco Umbrellaã«ãã£ãŠè¿œå ã¬ãã«ã®ä¿è·ãæäŸããããã¡ã€ã«ãªãã®ãµãŒããŒãå«ããã«ãŠã§ã¢ã³ãã³ããµãŒããŒãšã®éä¿¡ãç£èŠããŸãã
çµ±åãèªååãããã³API
Cisco AnyConnectãšCisco Stealthwatchã®çµ±åã¯ã¡ãŒã«ãŒã®æ°ãŸããã§ã¯ãªããç·æ¥ã®ããŒãºã§ããããã¯ãå€åããè åšã®ç¶æ³ãšãWebããŒã¿ã«ã®è匱æ§ããã©ãã·ã¥ãã©ã€ãããŠã©ãŒã¿ãŒããŒã«æ»æãè匱æ§ãä»ããããŸããŸãªæ¹æ³ã§äŒæ¥ããã³éšéã®ãããã¯ãŒã¯ã«äŸµå ¥ãããã«ããã¯ãã«æ»æã®åºçŸã«ãã£ãŠæ±ºå®ãããŸããããŒãžã£ãŒãè«è² æ¥è ãªã©ã®ææããã©ãããããã«ãã£ãŠããããããwi-fi ææ°ã®è åšã«å¯ŸåŠã§ããã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯1ã€ã ãã§ã¯ãããŸããã æ¶è²»è ãååŸããæ å ±ã»ãã¥ãªãã£è£œåãçµ±åããã®ãåŸ ã€ã®ã¯é·ãããŠä¿¡é Œæ§ããããŸããã ããã»ã¹ãèªåã®æã«å§ããªããã°ãªããŸããã ã·ã¹ã³ã®çµ±èšã«ãããšãå€ãã®äŒæ¥ã¯ãçžäºäœçšã®æ¹æ³ãç¥ããªãããŸããŸãªã»ãã¥ãªãã£æ©èœãå€æ°äœ¿çšããŠããäžæ¹ã§ã誀ã£ãã»ãã¥ãªãã£ã®æèŠãçã¿åºããŠããŸãã ä»æ¥ããããã¯ãŒã¯å ã®æªæã®ããã¢ã¯ãã£ããã£ãæ€åºãããªãå¹³åæéã¯çŽ200æ¥ã§ãã ãããŠãã¹ãŠã¯ãä¿è·æ段ããã«ã«ã³å島ã®å·ã®ããã«æ©èœããŠããããã§ã-ãããããäºãã«ç¬ç«ããŠããŸãïŒã€ã³ã¿ãŒãããã®åœå®¶ã»ã°ã¡ã³ããäœæããããã®å矩èªãšããŠãã€ã³ã¿ãŒãããã®ãã«ã«ã³åããšããçšèªãç»å Žããã®ã¯å¶ç¶ã§ã¯ãããŸããïŒã ããããç¶æ³ã¯å€åããŸããããã¯ããŸããŸãè€éåããã³å éåããæ»æã«èããããã«çµ±åããã200ã®éçºäŒç€Ÿãçµéããåãã·ã¹ã³ãšãã®åãçµã¿pxGrid ãACIã Cisco Security Technology Allianceã®äŸã§ãã§ã«èŠãããŸãã
ã·ã¹ã³ãåçãããã® ïŒåœç€Ÿã®çãã¯ããã¹ãŠã®è£œåã«æµžéããŠããããåäžã®ã»ãã¥ãªãã£ã·ã¹ãã ã«çµ±åãããã®çžä¹å¹æããæãåºãããã®èªååãšAPIã§ããããã«ãããè åšæ€åºããã»ã¹ãæ°çŸæ¥ãã4æéåã«ãŸã§å éã§ããŸãã ããã¯ãè åšããŒã¿ã®äº€æã眲åçæã®èªååã䟵害ã€ã³ãžã±ãŒã¿ã®å€éšãœãŒã¹ããã®ã¢ã¯ã»ã¹ãã»ãã¥ãªãã£ããŒã«éã®ã³ãã³ã転éãªã©ã«ãã£ãŠå®çŸãããŸãã
ããªã±ãŒãã®äž¡åŽã§ã®äººå·¥ç¥èœã®äœ¿çšã®å¢å
人工ç¥èœã¯èªå€§åºåã§ãã ãã§ã«æšæºã«ãªã£ãŠããæ©æ¢°åŠç¿ãšã¯ç°ãªããæ å ±ã»ãã¥ãªãã£ã®äŸå€ã§ã¯ãããŸããã æ¥åžžæ¥åã®èªååãé ãããã»ã¹ã®å éããã§ã«äžè¶³ããŠããæè³æ Œè ã®äº€ä»£ã æ å ±ã»ãã¥ãªãã£ã§æ©æ¢°åŠç¿ã䜿çšããå©ç¹ã®ã»ãã®äžéšã次ã«ç€ºããŸãã çŸåšã§ã¯ãæªæã®ããã³ãŒããšæªæã®ãããã¡ã€ã³ãšã€ã³ã¿ãŒãããIPã¢ãã¬ã¹ããã£ãã·ã³ã°æ»æãšè匱æ§ãæ€åºããæèãé«ããã€ã³ãµã€ããŒãèå¥ããããã«äœ¿çšã§ããŸãã ãããã人工ç¥èœã¯åã®ããã ãã§ãªããæ害ã®ããã«ã䜿çšãããŸãã 圌ã¯ãæ©æ¢°åŠç¿ã䜿çšããŠè匱æ§ãæ€çŽ¢ãããã£ãã·ã³ã°æ»æãå®è£ ãããœãŒã·ã£ã«ãããã¯ãŒã¯ã§çäœèªèšŒãåé¿ããåœã®ãããã¡ã€ã«ãäœæãããã«ãŠã§ã¢ãäœæãããã¹ã¯ãŒããéžæããCAPTCHAã¡ã«ããºã ããã€ãã¹ããæ»æè ã«éžã°ããŸããã 2018幎ã«ã¯ãåœã®ãã¹ã¿ãŒãã£ã³ã¬ãŒããªã³ãã®äœæãé³å£°ã®åæããããªç»åã®é¡ã®å€æŽãåã®åããšããããªã¹ããªãŒã å ã®èª°ãã®ç»åã«éããããåæé³å£°ãšã®åæã«é¢ããéåžžã«èå³æ·±ããããžã§ã¯ããçºè¡šãããŸããã ç¯çœªè ã«ãããã«æ¡çšãããããšã¯ééããããŸããã2019幎ã«ã¯ãæ å ±ã»ãã¥ãªãã£ã®å°é家ã«AIã®æ害ãªäœ¿çšã«å¯Ÿæããäžã§å€ãã®æ°ãã質åãæããããããŸãã
ã·ã¹ã³ã®åç ïŒãµã€ããŒã»ãã¥ãªãã£è£œåã®æ°ããæ©æ¢°åŠç¿ã¡ã«ããºã ãéçºãã æ¢åã®æ©æ¢°åŠç¿ã¡ã«ããºã ãæ¹åãã åªåãç¶ããŸãã ãã§ã«ããã®ãããªã¢ãã«ã¯Cisco AMP for Endpoints ã Stealthwatch ã CloudLock ã Umbrella ã Cognitive Threat Analyticsã«çµã¿èŸŒãŸããŠããããã®ãªã¹ãã¯æ¡åŒµãããã ãã§ãã ãããŸã§ã®éãã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ã§äººå·¥ç¥èœã䜿çšããããã®å°çšãµã€ããã芧ãã ãã ã
å€èŠçŽ èªèšŒ
ããã€ã®èªèšŒèŠçŽ ãæå®ã§ããŸããïŒ äžãäºãäžïŒ ãããŠãããªããããã«ã€ããŠèãããïŒ ä»¥äžã¯ãããªããèå¥ããããšãã§ãããã®ã®çããªã¹ãã§ãã
- ç¥ã£ãŠããããšïŒã¯ããããã¯å€å žçãªãã¹ã¯ãŒãã§ãïŒ
- ããªããæã£ãŠãããã®ïŒã¯ããããã¯ããŒã¯ã³ã§ãïŒ
- ããªããæã£ãŠãããã®ïŒã¯ããããã¯çäœèªèšŒã§ãïŒ
- ããªããããããš
- 倱ã£ããã®
- å¿ãããã®
- èŠã€ãããã®
- ããªããšããªããèŠãå Žæ
- ããªããããå Žæ
- ããªããäœæãããã®
- ç Žå£ãããã®
- äœããç ç²ã«ãããã®
- çãã ãã®ã
å®éãéå»5幎éã§æã人æ°ããã£ãå€ããã¹ã¯ãŒãã¯123456ã§ããããéå»ã®ãã®ã«ãªãã€ã€ããã2èŠçŽ ããã³å€èŠçŽ èªèšŒã«çœ®ãæããããŠããŸããããã«ãããäŒæ¥ããã³å人ã®ããŸããŸãªãµãŒãã¹ããã³ããŒã¿ãžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã®ã»ãã¥ãªãã£ãå€§å¹ ã«åäžããŸããäŒæ¥ã®ããŒã¿ã»ã³ã¿ãŒå ããã³ã¯ã©ãŠãå ã«ä¿åãããŸãã ãããŠãFacebookãYandexãä»ããå€éšãµãŒãã¹ãžã®å ¥ãå£ã䜿çšããããšã«ãã§ã«æ £ããŠããããã2èŠçŽ èªèšŒã䜿çšããŠããå€èŠçŽ èªèšŒã䜿çšããããšã«æ £ããŸãã 2019幎ã«ã¯ãæèã®ã¿ãŒãã³ã°ãã€ã³ããçºçããå€ãã®ã»ãã¥ãªãã£ã¬ãŒããä¿¡é Œæ§ã®äœããã¹ã¯ãŒãã眮ãæããæ¹æ³ãèãããšæããŸãã ãããŠãã¯ããçäœèªèšŒã¯ãä»ã®å€èŠçŽ èªèšŒæ¹æ³ãšæ¯èŒããŠã³ã¹ããé«ãããã®ããã®è åšã¢ãã«ã®éçºããªãããããã®ãããªä»£æ¿ã«ãªãããã«ãããŸããã
ã·ã¹ã³ã¯äœãçããŸãã ïŒ2018幎ã«ãå€èŠçŽ èªèšŒåžå Žã®ãªãŒããŒã§ããDuoãè³Œå ¥ããŸãããããã¯ãã·ã¢åžå Žã§çºå£²ãããŸãã
ããŒã¿ã»ã³ã¿ãŒ
誰ããåŸã ã«å¢çç·ãæŸæ£ããé²ãæ®ããŠåŸã ã«BYODãå°å ¥ããŠããŸãã ãããã¯ãŒã¯ããããã³ã°ãããŠãããã©ããã¯èª°ãæ°ã«ããŸããïŒãŸãããŸãã¯ã»ãšãã©èª°ãïŒã ããããããŒã¿ãæŒãããå Žåãæ±ããšæ··ããåããèŠå¶åœå±ãããªãã®ãšããã«æ¥ãŠãã¡ãã£ã¢ã§ããªããæŽãæµãã顧客ãåŸæ¥å¡ã®äžè©±ãããããšãã§ããªããšéé£ããŸãã å人ããŒã¿ãèå¥ããŒã¿ã®æŒæŽ©ã«èŠããã§ãã人ãã©ããããããã®ãçåã«æã£ãããšã¯ãããŸãããïŒ ç§ã¯çããªã¹ããäœæããããšãèš±å¯ããŸããããã€ã³ã¿ãŒãããã«ã©ãã ãã®ããŒã¿ãæŒããŠããã®ããèŠããš
- Exactis-340
- Facebook-50
- ãšã¯ã€ãã¡ãã¯ã¹-145
- ã¹ã¿ãŒãŠãã-500
- ã€ããŒ-3000
- ã¢ã³ããŒã¢ãŒããŒ-150
- Adult FriendFinder-412
- MySpace-164
- ã€ãŒãã€-145
- ã¿ãŒã²ãã-110
- ããŒãã©ã³ããã€ã¡ã³ãã·ã¹ãã -130
- LinkedIn-117
- ã©ã³ãã©ãŒ-98
- TJX-94
- AOL-92
- ã¯ãªã©-100
- VK-100
- ãã£ãŒãã«ãŒãåæ-198
- JPã¢ãŒã¬ã³ãã§ã€ã¹-78
- Mail.ru-25
- åœæ-80
- Dailymotion-85
- ãŠãŒããŒ-57
- Tumblr-65
- Dropbox-68
- ããŒã ãã-56
- ã¢ãã-38
- ãœããŒPSN-77
- RSAã»ãã¥ãªãã£-40ã
æšæž¬ããã®ã¯æãã®ã§ãããã€ã³ã¿ãŒãããå šäœã®åå以äžãããŒã¿ãææŸããŠãããšæããŸãïŒã¡ãªã¿ã«ãç§ã¯ããŸãã«ãå€ãã®ããŒã¿ããããŸããïŒã æŒæŽ©ã1,000äžä»¶ãè¶ ããã€ã³ã·ãã³ãã®æ°ã¯ãåäœãŸãã¯æ°åååäœã§æž¬å®ãããªããªã£ãŠããããšã«æ³šæããŠãã ããã ãããŠç¶æ³ã¯æªåããŸãã ã»ãã¥ãªãã£ãå¢çã§ã¯ãªãããŒã¿äžå¿ã«ãªã£ãããšãå¿ããŠãå¢çã®ä¿è·ã«åºå·ããŠããŸãã ãããŠãããã¯ããŒã¿ã®ã€ã³ã·ãã³ãã«é¢ããã ãã§ãªããããŒã¿ä¿è·ã«é¢é£ããèŠå¶äžã®è² æ ã®å¢å€§ã«é¢ãããã®ã§ããããŸãã GDPRã倧èŠæš¡ãªãŠãŒã¶ãŒããŒã¿ïŒããã¯æ°ããæ³æ¡ã®ãããã¯ã§ãïŒãé£éŠæ³-152ã®æ¹æ£ãªã©ãæ¥å¹Žãã·ã¢ã®äž¡æãåºããŠåŸ ã£ãŠããŸãã
ã·ã¹ã³ã®åç ïŒæ³çèŠä»¶ãžã®æºæ ãå®çŸããããã®ãããžã§ã¯ãã販売ããŠããŸããïŒãã ãã欧å·ã§ã¯GDPRã«é¢ããå€ãã®ãããžã§ã¯ãããããŸãïŒã ãŸããããŒã¿åé¡ããŒã«ãŸãã¯æŒåºå¶åŸ¡ïŒDLPïŒããŒã«ããããŸããã ãããã Cisco SAFEãããžã§ã¯ãã§èç©ããäŒæ¥ã®ãµã€ããŒã»ãã¥ãªãã£ã·ã¹ãã ã®æ§ç¯ã«ã¯è±å¯ãªçµéšããããŸããããã¯ãäŒæ¥ãŸãã¯éšéã®ãããã¯ãŒã¯ã®ããŸããŸãªã»ã¯ã·ã§ã³ãä¿è·ããããã®å®çšçãªæšå¥šäºé ã§ãã å¢çã ãã§ãªããããŒã¿ã»ã³ã¿ãŒãã¯ã©ãŠããWi-FiããŠããã¡ã€ãã³ãã¥ãã±ãŒã·ã§ã³ãç£æ¥çšãããã¯ãŒã¯ãªã©ãéèŠã§ãã ãã¹ãŠã®ã³ã³ããŒãã³ãã®ä¿è·ã®ã¿ãããŒã¿ãæŒæŽ©ããä¿è·ããåæã«æ³åŸã®èŠä»¶ãæºãããŸãã
5Gãããã¯ââãŒã¯ãæ»æã®æ©é asãšããŠäœ¿çšãã
ç±³åœã§ã¯ãããã€ãã®éœåžã第5äžä»£ïŒ5GïŒãããã¯ãŒã¯ã§é åãå®è³ªçã«ã«ããŒããŠããããšãçºè¡šããŸãããããã«ãããæ倧10 Gb / sã®é床ã§ã€ã³ã¿ãŒããããæäœã§ããŸãã ããã«ãããçŸåšã»ãšãã©ã®æ¥ç¶ãèç©ããŠããã«ãŒã¿ãŒã®ãäžéãããªããªããŸãã 5Gãããã¯ââãŒã¯ã§ã¯ãç¶æ³ãå€åããå¯èœæ§ããããããã«ããæ»æã®é åãå€§å¹ ã«å¢å ããã€ã³ã¿ãŒãããã«å¯Ÿããæ»æãããåºç¯ã«ãªããŸãã å®éãã€ã³ã¿ãŒãããã®ã¢ããæ»æã®èžã¿å°ãšããŠäœ¿çšããããšã§ïŒãã©ã€ã®5Gã®çãŸãå€ããã¯ããããã ãšæããŸãïŒãDDoSæ»æã®åšåãå€§å¹ ã«é«ããããšãã§ããŸãã ãã㊠ãããããã·ã¢ã§ã¯ã5Gã®å°å ¥ã¯2021幎æ«ãŸã§å»¶æãããŸããã ããã§ã¯ãé»åã®è±ã®å¹Žã®åŸåã¯äœã§ããïŒ ã¯ããããã§ããªãã¯æ£ããã§ãã ãã·ã¢ã®å Žåãæ°äžä»£ã®ãããã¯ãŒã¯ãä¿è·ããããã®ç§ãã¡ã®æšå¥šäºé ãšè§£æ±ºçã¯ãŸã é¢ä¿ãããŸããã ããããå°ãªããšãããã®æ©äŒãèŠããŠãã䟡å€ã¯ãããŸãã
ãµã€ããŒ
ããªãã¯ãã§ã«2019幎ã«ç§ãã¡ãåŸ ã£ãŠãããã®ã«ã€ããŠã®ç§ã®äœåãèªãã®ã«ããããããŠããã®ã§ãç· ãããããŸãã ãããŠãç§ã¯æåŸã®èŠ³æž¬ã§çµãããããšæããŸããããã¯ãã§ã«ãã¬ã³ãã«ãªãã€ã€ãããæ¥å¹Žã ã匷ãŸããŸãã ç¹å®ã®ãµã€ããŒã»ãã¥ãªãã£ããã»ã¹ã®åŒ±ç¹ããã§ãã¯ããããããæé€ããèšç»ãç«ãŠãããšãã§ãããµã€ããŒã³ãŒã¹ã«ã€ããŠè©±ããŠããã ç¹å®ã®è£œåã§ã®äœæ¥ã§éåžžã«å ·äœçãªã¹ãã«ãéçºã§ããããã«ããç¥èãšãã¬ãŒãã³ã°ãæäŸããèªå®ã³ãŒã¹ãšã¯ç°ãªãããµã€ããŒæŒç¿ã§ã¯ãå®éã«èµ·ããå¯èœæ§ã®ããããŸããŸãªç¶æ³ãã·ãã¥ã¬ãŒãã§ããŸãïŒè åšã®çè·¡ãäºä»¶ã«é¢ããæ å ±ã®æŒæŽ©ãæ€çŽ¢ã¡ãã£ã¢ãæªæã®ããã³ãŒããå«ããã©ãã·ã¥ãã©ã€ããªã©ïŒãããã³ããããåæ¢ããæ¹æ³ãèŠã€ããŸãã éåžžããã®ãããªãµã€ããŒæ瀺ã®ãã¬ãŒã ã¯ãŒã¯å ã§ããã¹ãŠã®åŒ±ç¹ã¯ãçŽã«èšèŒãããŠããããã»ã¹ãšãå®éã®ç掻ã«ã¯å¿ ãããé©çšã§ããªãç¹å®ã®è£œåãæäœããç¿åŸããã¹ãã«ã®äž¡æ¹ã§çºèŠãããŸãã
2018幎ã«ã¯ãäŒæ¥ãå·ãå·éã¬ãã«ã®äž¡æ¹ã§ãµã€ããŒæ³šæãéåžžã«äººæ°ã«ãªããŸããã æ°å件ã®ãã®ãããªãµã€ããŒæ³šæã«ããŸããŸåå ããããšããããŸãããããã¯äŒæ¥ã®æ å ±ã»ãã¥ãªãã£ãµãŒãã¹ã®ãã¬ã³ãã«ãªãã€ã€ãããããŸããŸãªäºä»¶ãç·æ¥äºæ ã«èããã¹ãã·ã£ãªã¹ãã®ã¹ãã«ããã¹ãããŠããŸãã
ã·ã¹ã³ã¯äœãçããŸãã ïŒãã·ã¢ã®ãã®åŸåã¯ãç§ãã¡ã®å©ããªãã«ãã®ããã«ãªãã€ã€ãããŸãã æ°å¹Žåãã¢ã¹ã¯ã¯ã·ã¹ã³ã³ãã¯ãã§2æ¥éç¡æã®ã»ãã·ã§ã³ãæ°åéå¬ããæåã®Cisco Cyberââ Rangeãµã€ããŒæ³šæãéå§ããŸããã ãã®åŸããµã€ããŒã¬ã³ãžã®æåãç¹°ãè¿ãã4æã«ã¢ã¹ã¯ã¯ã®Cisco Connectã®äžç°ãšããŠããããã®ãµã€ããŒæ³šæãå床å®æœããããšèããŠããŸã ã 確ãã«ãCisco Connectã§ã¯ã4æéã®éäžçãªå®åäœæ¥ã«ççž®ããã軜éããŒãžã§ã³ãå®è¡ããŠããŸãã çŸå®ã«ã¯ã3æ¥éãŸãã¯5æ¥éã®ãµã€ããŒãªãŒããŒãæäŸããŸãããã®ãªãŒããŒã§ã¯ãå®éã®ç掻ããåã£ãæ°çŸã®å®æçã«æŽæ°ãããããŸããŸãªæ»æã·ããªãªã«å¯ŸåŠããã¹ãã«ãéçºããŸãã ãµã€ããŒã¬ã³ãžã«å ããŠãç§ãã¡ã¯ãªãã£ã¹ã§Cisco Threat Hunting Workshopã®1æ¥ã®ãµã€ããŒãªãŒããŒãç©æ¥µçã«éå§ããŸãããåå è ã¯ããŸããŸãªè åšã®çè·¡ãèŠã€ããããšããŸãïŒæ¬¡ã®ãµã€ããŒãªãŒããŒã®æ¥ä»ã¯ã·ã¹ã³ã®ãããŒãžã£ãŒã§ç¢ºèªã§ããŸãïŒã ããã«ã Cisco dCloudã€ã³ã¿ã©ã¯ãã£ããã¢ãµãŒãã¹ã§ã¯ãããŒãããŒã顧客ãå©çšã§ããä»ã®ãªã³ã©ã€ã³ãµã€ããŒæ³šæãå€æ°ãããŸãã
以äžã¯ãç§ãã¡ã話ããããã¬ã³ãã®ãªã¹ãã§ãããç§ãã¡ã®æèŠã§ã¯ã2019幎ã«ç§ãã¡ãåŸ ã£ãŠããŸãïŒ æããŸããŠããã§ãšãããããŸãïŒ