ãµã€ããŒæ»æã®ç¶ç¶çãªéçºã«ã¯ã絶ãéãªãæ€åºãšåäœçšãå¿ èŠã§ãããæçµçã«ã¯æ»æè ãšé²åŸ¡è ã®éã®ç¡éã®è»æ¡ç«¶äºã®èãã«ã€ãªãããŸãã åŸæ¥ã®ä¿è·ã·ã¹ãã ã¯ãç¹å®ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«åãããŠæçµæ±ºå®ããããšãªãããªã¹ã¯ã¬ãã«ãäŒæ¥ã®äž»èŠæ¥çžŸè©äŸ¡ææšïŒçµæžçãæ¿æ²»çãè©å€ïŒã«åœ±é¿ãåãŒããªã蚱容ã¬ãã«ã®ã»ãã¥ãªãã£ãæäŸã§ããªããªããŸããããäžè¬çã«ã¯ããã€ãã®ãªã¹ã¯ãã«ããŒããŸãã ãã§ã«å®è£ ãšæ§æã®ããã»ã¹ã§ãçŸä»£ã®ä¿è·ã·ã¹ãã ã¯è¿œãã€ããçŸä»£ã®èª²é¡ã«å¯Ÿå¿ããå¿ èŠããããŸãã
åºæ
æ å ±ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã®æ代ã®èª²é¡ã«å¯Ÿããçãã®1ã€ã¯ãThreat Huntingãã¯ãããžãŒãããããŸããã è åšãã³ãã£ã³ã°ïŒä»¥äžãTHãšåŒã¶ïŒãšããçšèªã¯æ°å¹Žåã«ç»å ŽããŸããã ãã¯ãããžãŒèªäœã¯éåžžã«èå³æ·±ããã®ã§ãããäžè¬ã«åãå ¥ããããŠããæšæºãã«ãŒã«ã¯ãŸã ãããŸããã æ å ±æºã®äžåäžæ§ãšããã®ãããã¯ã«é¢ããå°æ°ã®ãã·ã¢èªæ å ±æºãåé¡ãè€éã«ããŠããã ãã®ç¹ã§ãLANIT-Integrationã§ã¯ããã®æè¡ã®ã¬ãã¥ãŒãæžãããšã«ããŸããã
é¢é£æ§
THãã¯ãããžãŒã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ç£èŠããã»ã¹ã«äŸåããŠããŸãã å éšç£èŠã«ã¯ãã¢ã©ãŒããšãã³ãã£ã³ã°ã®2ã€ã®äž»ãªã·ããªãªããããŸã ã ïŒMSSPãµãŒãã¹ã®çš®é¡å¥ã®ïŒã¢ã©ãŒãã¯ã以åã«éçºãããã·ã°ããã£ãšæ»æã®å åãæ€çŽ¢ãããããã«åå¿ããåŸæ¥ã®æ¹æ³ã§ãã åŸæ¥ã®çœ²åã»ãã¥ãªãã£æ©èœã¯ããã®ã·ããªãªãæ£åžžã«å®äºããŸãã ãã³ãã£ã³ã°ïŒMDRã¿ã€ãã®ãµãŒãã¹ïŒã¯ãã眲åãšã«ãŒã«ã¯ã©ãããæ¥ãŸããïŒããšãã質åã«çããç£èŠæ¹æ³ã§ãã ããã¯ãæ»æã®é ãããŸãã¯æªç¥ã®ææšãšå åãåæããããšã«ãããçžé¢ã«ãŒã«ãäœæããããã»ã¹ã§ãã Threat Huntingãå±ããã®ã¯ããã®ã¿ã€ãã®ç£èŠã§ãã
äž¡æ¹ã®ã¿ã€ãã®ç£èŠãçµã¿åãããããšã«ãã£ãŠã®ã¿ãçæ³ã«è¿ãä¿è·ãåŸãããŸãããããçšåºŠã®æ®åãªã¹ã¯ãåžžã«æ®ããŸãã
2çš®é¡ã®ç£èŠã䜿çšããä¿è·
ãããŠãTHïŒããã³å šäœã®ç©ãïŒïŒããŸããŸãéèŠã«ãªãçç±ã¯æ¬¡ã®ãšããã§ãã
è åšãææžçããªã¹ã¯ã åºæ
ãã¹ãŠã®è åšã®95ïŒ ã¯ãã§ã«ååã«ç解ãããŠããŸãã ãããã«ã¯ãã¹ãã ãDDoSããŠã€ã«ã¹ãã«ãŒããããããã®ä»ã®ãã«ãŠã§ã¢ãªã©ã®çš®ãå«ãŸããŸãã åãå€å žçãªé²åŸ¡çã§ããããã®è åšãã身ãå®ãããšãã§ããŸãã
ãããžã§ã¯ãã®å®è¡äžã äœæ¥ã®80ïŒ ãæéã®20ïŒ ãå ã ãæ®ãã®20ïŒ ãæéã®80ïŒ ãå ããŸãã åæ§ã«ãè åšå šäœã®äžã§ãæ°ããã¿ã€ãã®è åšã®5ïŒ ãäŒæ¥ã«ãšã£ãŠã®ãªã¹ã¯ã®70ïŒ ãå ããŸãã æ å ±ã»ãã¥ãªãã£ç®¡çããã»ã¹ãçµç¹ãããŠããäŒç€Ÿã§ã¯ããããåé¿ããïŒååãšããŠã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãæŸæ£ããïŒãåãå ¥ããïŒå¿ èŠãªã»ãã¥ãªãã£å¯Ÿçãå°å ¥ããïŒããŸãã¯ïŒããšãã°ãã€ã³ãã°ã¬ãŒã¿ãŒã®è©ã«ïŒç§»åããããšã«ãããæ¢ç¥ã®è åšã®ãªã¹ã¯ã®30ïŒ ãäœããã®æ¹æ³ã§ç®¡çã§ããŸããªã¹ã¯ã ãŒããã€èåŒ±æ§ ãAPTæ»æããã£ãã·ã³ã°ã ãµãã©ã€ãã§ãŒã³ãä»ããæ»æ ããµã€ããŒã¹ãã€ãŠã§ã¢ãããã³åœå æ¥åããããŸãä»ã®å€æ°ã®æ»æãã身ãå®ãããšã¯ããã§ã«ã¯ããã«å°é£ã§ãã ãããã®5ïŒ ã®è åšã®çµæã¯ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãã¬ã¹ãã¥ãŒããã¹ãã ããŠã€ã«ã¹ã®çµæãããã¯ããã«æ·±å»ã§ãïŒ buhtrapã°ã«ãŒãããã®éè¡ã®æ倱ã®å¹³åé¡ã¯1å4300äžä»¶ ïŒã
ã»ãŒå šå¡ãè åšã®5ïŒ ã«å¯ŸåŠããå¿ èŠããããŸãã æè¿ãPEARïŒPHPæ¡åŒµããã³ã¢ããªã±ãŒã·ã§ã³ãªããžããªïŒãªããžããªã®ã¢ããªã±ãŒã·ã§ã³ã䜿çšãã1ã€ã®ãªãŒãã³ãœãŒã¹ãœãªã¥ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããå¿ èŠããããŸããã Pearã€ã³ã¹ããŒã«ãä»ããŠãã®ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããããšããŠå€±æããŸããã ãµã€ããå©çšã§ããªãã£ãããïŒçŸåšã¹ã¿ãããããŸãïŒãGitHubããã€ã³ã¹ããŒã«ããå¿ èŠããããŸããã ãããŠã€ãæè¿ãPEARããµãã©ã€ãã§ãŒã³ãä»ããæ»æã®ç ç²è ã§ããããšãæããã«ãªããŸããã
çšã¬ããŒãããã°ã©ã MEDocã®æŽæ°ã¢ãžã¥ãŒã«ãä»ããŠãNePetyaã©ã³ãµã ãŠã§ã¢ã®æµè¡ã§ããCCleanerã䜿çšããŠæ»æãæãåºãããšãã§ããŸãã è åšã¯ããæŽç·ŽãããŠããŠãããããããã®5ïŒ ã®è åšã«ã©ã®ããã«èããŸããïŒããšããè«ççãªçåãçããŸãã
è åšãã³ãã£ã³ã°ã®å®çŸ©
ãã®ãããThreat Huntingã¯ãåŸæ¥ã®ä¿è·æ段ã§ã¯æ€åºã§ããªãé«åºŠãªè åšã®äºé²çãã€å埩çãªæ€çŽ¢ãšæ€åºã®ããã»ã¹ã§ãã é«åºŠãªè åšã«ã¯ãããšãã°ãAPTãªã©ã®æ»æã0æ¥éã®è匱æ§ãžã®æ»æãLiving off the Landãªã©ãå«ãŸããŸãã
THã¯ä»®èª¬æ€å®ããã»ã¹ã§ãããšèšãæããããšãã§ããŸãã ããã¯äž»ã«èªååèŠçŽ ã䜿çšããæåããã»ã¹ã§ãããã¢ããªã¹ãã¯ç¥èãšè³æ Œã«é Œã£ãŠãç¹å®ã®è åšã®ååšã«é¢ããæåã«å®çŸ©ããã仮説ã«å¯Ÿå¿ãã䟵害ã®å åãæ¢ããŠå€§éã®æ å ±ãéžå¥ããŸãã ãã®ç¹åŸŽã¯ãããŸããŸãªæ å ±æºã§ãã
Threat Huntingã¯äœããã®ãœãããŠã§ã¢ãŸãã¯ããŒããŠã§ã¢è£œåã§ã¯ãªãããšã«æ³šæããŠãã ããã ãããã¯ããœãªã¥ãŒã·ã§ã³ã§èŠãããã¢ã©ãŒãã§ã¯ãããŸããã ããã¯ãIOCïŒåŠ¥åèå¥åïŒãèŠã€ããããã®ããã»ã¹ã§ã¯ãããŸããã ãããŠãããã¯æ å ±ã»ãã¥ãªãã£ã¢ããªã¹ãã®åå ãªãã§è¡ãããååçãªæŽ»åã§ã¯ãããŸããã è åšãã³ãã£ã³ã°ã¯ãäœãããããã»ã¹ã§ãã
è åšæ¢çŽ¢ã³ã³ããŒãã³ã
Threat Huntingã®3ã€ã®äž»èŠã³ã³ããŒãã³ãïŒããŒã¿ããã¯ãããžãŒã人ã
ããŒã¿ïŒäœïŒïŒ ãããã°ããŒã¿ãå«ãã ããããçš®é¡ã®ãã©ãã£ãã¯ãããŒã以åã«å®æœãããAPTã«é¢ããæ å ±ãåæããŠãŒã¶ãŒã¢ã¯ãã£ããã£ããŒã¿ããããã¯ãŒã¯ããŒã¿ãåŸæ¥å¡ããã®æ å ±ãããŒã¯ãããäžã®æ å ±ãªã©ã
ãã¯ãããžãŒïŒæ¹æ³ïŒïŒãã®ããŒã¿ãåŠçããããã®ãã¹ãŠã®å¯èœãªæ¹æ³ã¯ãæ©æ¢°åŠç¿ãå«ããã®ããŒã¿ã®åŠçã§ãã
人ã ïŒèª°ïŒïŒã¯ ãããŸããŸãªæ»æã®åæã«è±å¯ãªçµéšããããçŽæãéçºããæ»æãæ€åºããèœåãæã£ãŠãã人ã§ãã éåžžããããã¯æ å ±ã»ãã¥ãªãã£ã¢ããªã¹ãã§ããã仮説ãçæãããããã®èšŒæ ãèŠã€ããèœåãå¿ èŠã§ãã ãããã¯ããã»ã¹ã®äž»èŠãªãªã³ã¯ã§ãã
ã¢ãã«PARIS
Adam Bateman 㯠ãçæ³çãªTHããã»ã¹ã®PARISã¢ãã«ã«ã€ããŠèª¬æããŠããŸãã ãã©ã³ã¹ã®æåãªã©ã³ãããŒã¯ãæ瀺ããŠãããã®ãããªååã ãã®ã¢ãã«ã¯ãäžäžã®2ã€ã®æ¹åã§èããããšãã§ããŸãã
è åšãæ¢ããŠã¢ãã«ãäžã«ç§»åããéçšã§ãæªæã®ãã掻åã®å€ãã®èšŒæ ã«å¯ŸåŠããŸãã ãã¹ãŠã®èšŒæ ã«ã¯ä¿¡é Œæ§ã®å°ºåºŠããããŸããããã¯ããã®èšŒæ ã®éã¿ãåæ ããç¹æ§ã§ãã æªæã®ãã掻åã®çŽæ¥çãªèšŒæ ã§ãããéãããããããã«ãã£ãŠããã«ãã©ãããã®é ç¹ã«å°éããæ¢ç¥ã®ææã®å®éã®éç¥ãäœæã§ããŸãã ãããŠãéæ¥çãªèšŒæ ãããããã®åèšã¯ãã©ãããã®é ç¹ã«ç§ãã¡ãå°ãããšãã§ããŸãã ãã€ãã®ããã«ãçŽæ¥çãªèšŒæ ãããã¯ããã«å€ãã®éæ¥çãªèšŒæ ããããŸããã€ãŸããããããåé¡ããŠåæããå¿ èŠããããè¿œå ã®èª¿æ»ãå®æœããå¿ èŠãããããããèªååããããšããå§ãããŸãã
ã¢ãã«PARISã åºæ
ã¢ãã«ã®äžéšïŒ1ãš2ïŒã¯èªååæè¡ãšå€æ§ãªåæã«åºã¥ããŠãããäžéšïŒ3ãš4ïŒã¯ããã»ã¹ãå¶åŸ¡ããç¹å®ã®è³æ Œãæã€äººã ã«åºã¥ããŠããŸãã ã¢ãã«ãäžããäžã«ç§»åãããšãéã®äžéšã«åŸæ¥ã®ä¿è·ããŒã«ïŒãŠã€ã«ã¹å¯ŸçãEDRããã¡ã€ã¢ãŠã©ãŒã«ã眲åïŒããã®éç¥ããããé«åºŠãªä¿¡é Œæ§ãšä¿¡é Œæ§ããããŸãã以äžã¯ã€ã³ãžã±ãŒã¿ãŒïŒIOCãURLãMD5ãªã©ïŒã§ããèªä¿¡ããªããããã«èª¿æ»ããå¿ èŠããããŸãã ãããŠãæãäœããŠæãåãã¬ãã«ïŒ4ïŒã¯ã仮説ã®çæãäŒçµ±çãªæ²»çæ³ã®ä»äºã®æ°ããã·ããªãªã®äœæã§ãã ãã®ã¬ãã«ã¯ã瀺ããã仮説ã®ãœãŒã¹ã«éå®ãããŸããã ã¬ãã«ãäœãã»ã©ãã¢ããªã¹ãã®è³æ Œã«é¢ããèŠä»¶ãå€ããªããŸãã
ã¢ããªã¹ããäºåã«å®çŸ©ããã仮説ã®æéã»ããããã§ãã¯ããã ãã§ãªããæ°ãã仮説ãšãããããã¹ãããããã®ãªãã·ã§ã³ãåžžã«çæããããšãéåžžã«éèŠã§ãã
THæç床ã¢ãã«ã䜿çš
çæ³çãªäžçã§ã¯ãTHã¯ç¶ç¶çãªããã»ã¹ã§ãã ããããçæ³çãªäžçã¯ãªãããã䜿çšãã人ãããã»ã¹ãããã³ãã¯ãããžãŒã®ã³ã³ããã¹ãã§æç床ã¢ãã«ãšææ³ãåæããŸãã çæ³çãªçé¢THã®ã¢ãã«ãèããŸãã ãã®ãã¯ãããžãŒã®äœ¿çšã«ã¯5ã€ã®ã¬ãã«ããããŸãã ã¢ããªã¹ãã®åäžããŒã ã®é²åã®äŸã§ããããèæ ®ããŠãã ããã
æç床ã¬ãã« | 人 | ããã»ã¹ | ãã¯ãããžãŒ |
ã¬ãã«0 | SOCã¢ããªã¹ã | 幎äžç¡äŒ | åŸæ¥ã®æ¥œåšïŒ |
ãã©ãã£ã·ã§ãã« | ã¢ã©ãŒãã»ãã | ããã·ãã¢ãã¿ãªã³ã° | IDSãAVããµã³ãããã¯ã¹ã |
THãªã | ã¢ã©ãŒããæäœãã | 眲ååæããŒã«ãè åšã€ã³ããªãžã§ã³ã¹ããŒã¿ã | |
ã¬ãã«1 | SOCã¢ããªã¹ã | ã¯ã³ã¿ã€ã TH | EDR |
å®éšç | æ³å»åŠã®åºç€ç¥è | IOCæ€çŽ¢ | ãããã¯ãŒã¯ããã€ã¹ããã®ããŒã¿ã®éšåçãªã«ãã¬ããž |
THã®å®éš | ãããã¯ãŒã¯ãšã¢ããªã±ãŒã·ã§ã³ã«é¢ããååãªç¥è | éšåé©çš | |
ã¬ãã«2 | äžæçãªè·æ¥ | ã¹ããªã³ã | EDR |
å®æç | æ³å»åŠã®å¹³åçãªç¥è | æãããã®é± | å®å šãªã¢ããªã±ãŒã·ã§ã³ |
äžæçãªTH | ãããã¯ãŒã¯ãšã¢ããªã±ãŒã·ã§ã³ã®åªããç¥è | ã¬ã®ã¥ã©ãŒth | EDRããŒã¿äœ¿çšã®å®å šèªåå |
é«åºŠãªEDRæ©èœã®éšåçãªäœ¿çš | |||
ã¬ãã«3 | å°çšã®THããŒã | 幎äžç¡äŒ | 仮説THããã¹ãããéšåçãªèœå |
ç©æ¥µç | ãã©ã¬ã³ãžãã¯ãšãã«ãŠã§ã¢ã«é¢ããåªããç¥è | ããã¢ã¯ãã£ãTH | é«åºŠãªEDRæ©èœã®å®å šãªäœ¿çš |
ç¹å¥ãªã±ãŒã¹TH | æ»æè ã®åªããç¥è | ç¹å¥ãªã±ãŒã¹TH | ãããã¯ãŒã¯ããã€ã¹ããã®ããŒã¿ã®å®å šãªã«ãã¬ããž |
ã«ã¹ã¿ã æ§æ | |||
ã¬ãã«4 | å°çšã®THããŒã | 幎äžç¡äŒ | TH仮説ããã¹ãããå®å šãªèœå |
äžæµ | ãã©ã¬ã³ãžãã¯ãšãã«ãŠã§ã¢ã«é¢ããåªããç¥è | ããã¢ã¯ãã£ãTH | ã¬ãã«3ãããã³ïŒ |
THã䜿çšãã | æ»æè ã®åªããç¥è | TH仮説ã®ãã¹ããèªååãæ€èšŒ | ããŒã¿ãœãŒã¹ã®ç·å¯ãªçµ±åã |
ç 究èœå | ã«ã¹ã¿ã éçºããã³ã«ã¹ã¿ã APIã®äœ¿çšã |
ã¬ãã«0ïŒåŸæ¥ãTHã䜿çšããªãã åŸæ¥ã®ã¢ããªã¹ãã¯ãIDSãAVããµã³ãããã¯ã¹ã眲ååæããŒã«ãªã©ã®æšæºããŒã«ãšãã¯ãããžãŒã䜿çšããŠãããã·ãã¢ãã¿ãªã³ã°ã¢ãŒãã§ã¢ã©ãŒãã®æšæºã»ãããåŠçããŸãã
ã¬ãã«1ïŒ THã䜿çšããå®éšçã ãã©ã¬ã³ãžãã¯ã®åºæ¬ç¥èãšãããã¯ãŒã¯ããã³ã¢ããªã±ãŒã·ã§ã³ã®ååãªç¥èãæã€åãã¢ããªã¹ãã¯ã䟵害ã®å åãæ€çŽ¢ããããšã«ããã1åéãã®è åšãã³ãã£ã³ã°ãå®è£ ã§ããŸãã ãããã¯ãŒã¯ããã€ã¹ããã®ããŒã¿ãéšåçã«ã«ããŒããEDRãããŒã«ã«è¿œå ãããŸãã ããŒã«ã¯éšåçã«é©çšãããŸãã
ã¬ãã«2ïŒæç¶çãäžæçãªTHã ãã©ã¬ã³ãžãã¯ããããã¯ãŒã¯ãããã³ã¢ããªã±ãŒã·ã§ã³éšåã®ç¥èããã§ã«æŽ»çšããŠããã¢ããªã¹ãã¯ãããšãã°æã«1é±éãå®æçã«è åšãã³ãã£ã³ã°ã«åŸäºãã矩åãè² ã£ãŠããŸãã ããŒã«ã«ã¯ããããã¯ãŒã¯ããã€ã¹ããã®ããŒã¿ã®å®å šãªèª¿æ»ãEDRããã®ããŒã¿åæã®èªååãããã³é«åºŠãªEDRæ©èœã®éšåçãªäœ¿çšãè¿œå ãããŠããŸãã
ã¬ãã«3ïŒ THã®äºé²çã§é »ç¹ãªã±ãŒã¹ã ç§ãã¡ã®ã¢ããªã¹ãã¯å°ä»»ã®ããŒã ã«ç·šæããããã©ã¬ã³ãžãã¯ãšãã«ãŠã§ã¢ã®åªããç¥èãšãæ»æåŽã®æ¹æ³ãšæŠè¡ã®ç¥èãæã¡å§ããŸããã ãã®ããã»ã¹ã¯æ¢ã«24æé幎äžç¡äŒã§é²è¡äžã§ãã ããŒã ã¯ãTH仮説ãéšåçã«ãã¹ããããããã¯ãŒã¯ããã€ã¹ããã®ããŒã¿ãå®å šã«ã«ããŒããé«åºŠãªEDRæ©èœãæ倧éã«æŽ»çšã§ããŸãã ãŸããã¢ããªã¹ãã¯ããŒãºã«åãããŠããŒã«ãæ§æã§ããŸãã
ã¬ãã«4ïŒ THã䜿çšãããã€ãšã³ãã åãããŒã ã¯ã調æ»ããèœåã仮説THããã¹ãããããã»ã¹ãçæããã³èªååããèœåãç²åŸããŸããã çŸåšãããŒã¿ãœãŒã¹ã®ç·å¯ãªçµ±åãããŒãºã«åããããœãããŠã§ã¢éçºãAPIã®éæšæºçãªäœ¿çšãããŒã«ã«è¿œå ãããŠããŸãã
è åšç©ãã®ãã¯ããã¯
åºæ¬çãªè åšæ¢çŽ¢ãã¯ããã¯
䜿çšããããã¯ãããžãŒã®æç床ã®é ã§ã®TH ãã¯ããã¯ã«ã¯ãåºæ¬æ€çŽ¢ãçµ±èšåæãèŠèŠåãã¯ããã¯ãåçŽãªéçŽãæ©æ¢°åŠç¿ãããã³ãã€ãžã¢ã³ææ³ãå«ãŸããŸãã
æãåçŽãªæ¹æ³ã¯åºæ¬çãªæ€çŽ¢ã§ãç¹å®ã®ã¯ãšãªã䜿çšããŠèª¿æ»ç¯å²ãçµã蟌ãããã«äœ¿çšãããŸãã çµ±èšåæã¯ãããšãã°ãçµ±èšã¢ãã«ã®åœ¢åŒã§å žåçãªãŠãŒã¶ãŒãŸãã¯ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ãæ§ç¯ããããã«äœ¿çšãããŸãã èŠèŠåæè¡ã䜿çšããŠãã°ã©ãããã£ãŒãã®åœ¢ã§ããŒã¿åæãèŠèŠåããç°¡çŽ åããŸããããã«ããããµã³ãã«ã®ãã¿ãŒã³ãç°¡åã«ãã£ããã§ããŸãã ããŒãã£ãŒã«ãã®åçŽãªéèšææ³ã䜿çšããŠãæ€çŽ¢ãšåæãæé©åããŸãã THããã»ã¹ã®çµç¹ã®æç床ãé«ãã»ã©ãæ©æ¢°åŠç¿ã¢ã«ãŽãªãºã ã®äœ¿çšã¯ããé¢é£æ§ããããŸãã ãŸããã¹ãã ã®ãã£ã«ã¿ãªã³ã°ãæªæã®ãããã©ãã£ãã¯ã®æ€åºãäžæ£è¡çºã®æ€åºãªã©ãåºã䜿çšãããŠããŸãã æ©æ¢°åŠç¿ã¢ã«ãŽãªãºã ã®ããé«åºŠãªã¿ã€ãã¯ãåé¡ããµã³ãã«ãµã€ãºã®çž®å°ãããã³äž»é¡ã¢ããªã³ã°ãå¯èœã«ãããã€ãºæ³ã§ãã
ãã€ã€ã¢ã³ãã¢ãã«ãšTHæŠç¥
Sergio KaltagironãAndrew Pendegastãããã³Christopher Betzã®ç 究 ã äŸµå ¥åæã®ãã€ã€ã¢ã³ãã¢ãã« ãã¯ãæªæã®ãã掻åã®äž»èŠãªäž»èŠã³ã³ããŒãã³ããšããããã®éã®åºæ¬çãªã€ãªããã瀺ããŸããã
æªæã®ãã掻åã®ãã€ã€ã¢ã³ãã¢ãã«
ãã®ã¢ãã«ã«åŸã£ãŠãé¢é£ããéèŠãªã³ã³ããŒãã³ãã«äŸåãã4ã€ã®è åšæ¢çŽ¢æŠç¥ããããŸãã
1.被害è äžå¿ã®æŠç¥ã 被害è ã«ã¯æµããããã¡ãŒã«ã§ãæ©äŒããæäŸãããšæ³å®ããŠããŸãã ã¡ãŒã«ã§æµã®ããŒã¿ãæ¢ããŠããŸãã ãªã³ã¯ãæ·»ä»ãã¡ã€ã«ãªã©ãæ€çŽ¢ããŸã ç¹å®ã®æéïŒæã2é±éïŒããã®ä»®èª¬ã®ç¢ºèªãæ¢ããŠããŸããèŠã€ãããªãå Žåã仮説ã¯åçãããŸããã§ããã
2.ã€ã³ãã©ã¹ãã©ã¯ãã£æåã®æŠç¥ã ãã®æŠç¥ã䜿çšããæ¹æ³ã¯ããã€ããããŸãã ã¢ã¯ã»ã¹ãšå¯èŠæ§ã«å¿ããŠãããã€ãã¯ä»ã®ãã®ããç°¡åã§ãã ããšãã°ãæªæã®ãããã¡ã€ã³ããã¹ãããŠããããšãããã£ãŠãããã¡ã€ã³ããŒã ãµãŒããŒãç£èŠããŸãã ãŸãã¯ãæ»æè ã䜿çšããæ¢ç¥ã®ãã¿ãŒã³ã®ãã¹ãŠã®æ°ãããã¡ã€ã³åç»é²ã远跡ããããã»ã¹ãå®æœããŠããŸãã
3.æ©äŒéèŠã®æŠç¥ã ã»ãšãã©ã®ãããã¯ãŒã¯æ¯æè ã䜿çšãã被害è æåã®æŠç¥ã«å ããŠãæ©äŒæåã®æŠç¥ããããŸãã 2çªç®ã«äººæ°ããããæ»æè ã®æ©èœãã€ãŸãããã«ãŠã§ã¢ããšãpsexecãpowershellãcertutilãªã©ã®æ£åœãªããŒã«ã䜿çšããæ»æè ã®èœåãæ€åºããããšã«çŠç¹ãåœãŠãŠããŸãã
4.å察è æåã®æŠç¥ã å察è æåã®ã¢ãããŒãã¯ãæµèªèº«ã«çŠç¹ãåãããŠããŸãã ããã«ã¯ãå ¬éãããŠãããœãŒã¹ïŒOSINTïŒããã®ãªãŒãã³æ å ±ã®äœ¿çšãæµã«é¢ããããŒã¿ã®åéã圌ã®ææ³ãšææ³ïŒTTPïŒãéå»ã®ã€ã³ã·ãã³ãã®åæãè åšæ å ±ããŒã¿ãªã©ãå«ãŸããŸãã
THã®æ å ±æºãšä»®èª¬
è åšãã³ãã£ã³ã°ã®æ å ±æº
å€ãã®æ å ±æºããããŸãã çæ³çãªã¢ããªã¹ãã¯ãåšå²ã®ãããããã®ããæ å ±ãæœåºã§ããã¯ãã§ãã ã»ãšãã©ãã¹ãŠã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžè¬çãªãœãŒã¹ã¯ãã»ãã¥ãªãã£æ©èœããã®ããŒã¿ã§ãïŒDLPãSIEMãIDS / IPSãWAF / FWãEDRã ãŸããæ å ±ã®å žåçãªææšã¯ãããããçš®é¡ã®äŸµå®³ã®ææšãè åšæ å ±ãµãŒãã¹ãCERTããã³OSINTããŒã¿ã«ãªããŸãã ããã«ãããŒã¯ãããããã®æ å ±ã䜿çšã§ããŸãïŒããšãã°ãçªç¶ãçµç¹ã®ãããã®ã¡ãŒã«ããã¯ã¹ããããã³ã°ããåœä»€ãããããŸãã¯ãããã¯ãŒã¯ãšã³ãžãã¢ã®å°äœã®åè£ã圌ã®æŽ»åã«çŸããïŒãHRããåãåã£ãæ å ±ïŒåã®ä»äºããã®åè£è ã«é¢ãããã£ãŒãããã¯ïŒãã»ãã¥ãªãã£ãµãŒãã¹ããã®æ å ±ïŒäŸïŒååŒçžæã®æ€èšŒçµæïŒã
ãã ãã䜿çšå¯èœãªãã¹ãŠã®ãœãŒã¹ã䜿çšããåã«ãå°ãªããšã1ã€ã®ä»®èª¬ãå¿ èŠã§ãã
åºæ
仮説ãæ€èšŒããã«ã¯ããŸã仮説ãæ瀺ããå¿ èŠããããŸãã ãããŠãå€ãã®å®æ§ç仮説ãæ瀺ããããã«ãäœç³»çãªã¢ãããŒããé©çšããå¿ èŠããããŸãã 仮説ãçæããããã»ã¹ã¯ã èšäºã§ãã詳现ã«èª¬æãããŠããŸã ;仮説ãç«ãŠãããã»ã¹ã®åºç€ãšããŠãã®ã¹ããŒã ãæ¡çšããããšã¯éåžžã«äŸ¿å©ã§ãã
仮説ã®äž»ãªæ å ±æºã¯ã ATTïŒCK ïŒæµã®æŠè¡ããã¯ããã¯ãããã³åžžèïŒ ãããªãã¯ã¹ã§ãã æ¬è³ªçã«ãããã¯ç¥èããŒã¹ã§ãããæ»æã®æçµæ®µéã§ã®æŽ»åãå®çŸããæ»æè ã®è¡åãè©äŸ¡ããããã®ã¢ãã«ã§ãããéåžžã¯ãã«ãã§ãŒã³ã®æŠå¿µã䜿çšããŠèšè¿°ãããŸãã ã€ãŸããäŸµå ¥è ãäŒæ¥ã®å éšãããã¯ãŒã¯ãŸãã¯ã¢ãã€ã«ããã€ã¹ã«äŸµå ¥ããåŸã®æ®µéã§ãã åœåãç¥èããŒã¹ã«ã¯æ»æã§äœ¿çšããã121ã®æŠè¡ãšãã¯ããã¯ã®èª¬æãå«ãŸããŠããŸãããããããã®æ¹æ³ã¯Wiki圢åŒã§è©³çŽ°ã«èª¬æãããŠããŸãã ããŸããŸãªè åšã€ã³ããªãžã§ã³ã¹åæã¯ã仮説ãçæããããã®åªãããœãŒã¹ã§ãã ç¹ã«æ³šç®ãã¹ãã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£åæãšäŸµå ¥ãã¹ãã®çµæã§ãããããã¯ãéã®ä»®èª¬ãç¹å®ã®æ¬ ç¹ãæã€ç¹å®ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«äŸåããŠãããããéã®ä»®èª¬ããåŸãããæã䟡å€ã®ããããŒã¿ã§ãã
仮説æ€å®ããã»ã¹
ã»ã«ã²ã€ã»ãœã«ãããã¯ãããã»ã¹ã®è©³çŽ°ãªèª¬æãå«ãè¯ãå³ãæäŸããŸãã;ããã¯ãåäžã®ã·ã¹ãã ã§TH仮説ããã¹ãããããã»ã¹ã瀺ããŠããŸãã äž»ãªæ®µéãç°¡åãªèª¬æã§ç€ºããŸãã
åºæ
ã¹ããŒãž1ïŒTIãã¡ãŒã
ãã®æ®µéã§ã¯ã ãªããžã§ã¯ããç¹æ§ã®ã©ãã«ãå²ãåœãŠãŠïŒè åšã«é¢ãããã¹ãŠã®ããŒã¿ãšäžç·ã«åæããããšã«ããïŒ ãªããžã§ã¯ããåºå¥ããå¿ èŠããããŸãã ããã¯ããã¡ã€ã«ãURLãMD5ãããã»ã¹ããŠãŒãã£ãªãã£ãã€ãã³ãã§ãã ããããThreat Intelligenceã·ã¹ãã ã«æž¡ãã«ã¯ãã¿ã°ãä»ããå¿ èŠããããŸãã ã€ãŸãããã®ãµã€ãã¯ãã®ãããªå¹Žã«CNCã§çºèŠããããã®MD5ã¯ãã«ãŠã§ã¢ã«é¢é£ä»ããããŠããŸããããã®MD5ã¯ããã«ããŒã«ãé åžããWebãµã€ãããããŠã³ããŒããããŸããã
ã¹ããŒãž2ïŒã±ãŒã¹
第2段éã§ã¯ããããã®ãªããžã§ã¯ãéã®çžäºäœçšã調ã¹ãããããã¹ãŠã®ãªããžã§ã¯ãéã®é¢ä¿ãç¹å®ããŸãã äœãæªãããšãããã©ãã«ä»ãã®ã·ã¹ãã ãååŸããŸãã
ã¹ããŒãž3ïŒã¢ããªã¹ã
3çªç®ã®æ®µéã§ãã±ãŒã¹ã¯åæã®è±å¯ãªçµéšãæã€çµéšè±å¯ãªã¢ããªã¹ãã«è»¢éããã圌ã¯è©æ±ºãäžããŸãã ãã®ã³ãŒããäœããã©ãã§ãã©ã®ããã«ããªãããªããã€ãåäœã§è§£æããŸãã ãã®æ¬äœã¯ãã«ãŠã§ã¢ã§ããããã®ã³ã³ãã¥ãŒã¿ãŒã¯ææããŠããŸããã ãªããžã§ã¯ãéã®æ¥ç¶ãé瀺ãããµã³ãããã¯ã¹ã®å®è¡çµæã確èªããŸãã
ã¢ããªã¹ãã®ä»äºã®çµæã¯äŒããããŸãã ããžã¿ã«ãã©ã¬ã³ãžãã¯ã¯ç»åââãæ€æ»ãããã«ãŠã§ã¢åæã¯èŠã€ãã£ããããã£ããæ€æ»ããŸããã€ã³ã·ãã³ãã¬ã¹ãã³ã¹ããŒã ã¯ãµã€ãã«ã¢ã¯ã»ã¹ããŠãæ¢ã«ãããã®ã調ã¹ãããšãã§ããŸãã äœæ¥ã®çµæã¯ã確èªããã仮説ãç¹å®ãããæ»æãããã³ããã«å¯ŸåŠããæ¹æ³ã«ãªããŸãã
åºæ
ãŸãšã
Threat Huntingã¯ãã«ã¹ã¿ãã€ãºãããæ°ããéæšæºã®è åšã«å¹æçã«æµæããããšãã§ããããªãè¥ããã¯ãããžãŒã§ããããããè åšã®å¢å ãšäŒæ¥ã€ã³ãã©ã¹ãã©ã¯ãã£ã®è€éããèãããšã倧ããªå¯èœæ§ããããŸãã ããŒã¿ãããŒã«ãåæãšãã3ã€ã®ã³ã³ããŒãã³ããå¿ èŠã§ãã Threat Huntingã®å©ç¹ã¯ãè åšãç©æ¥µçã«å®è£ ããããšã«éå®ãããŸããã æ€çŽ¢ããã»ã¹ã§ã¯ãã»ãã¥ãªãã£ã¢ããªã¹ãã®ç®ãéããŠã€ã³ãã©ã¹ãã©ã¯ãã£ãšãã®åŒ±ç¹ã«çªå ¥ãããããã®å Žæãããã«åŒ·åã§ããããšãå¿ããªãã§ãã ããã
ç§ãã¡ã®æèŠã§ã¯ãçµç¹ã§THããã»ã¹ãéå§ããããã«å®è¡ããå¿ èŠãããæåã®ã¹ãããã
- ãšã³ããã€ã³ãã®ä¿è·ãšãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã«æ³šæããŠãã ããã ãããã¯ãŒã¯å ã®ãã¹ãŠã®ããã»ã¹ã®å¯èŠæ§ïŒNetFlowïŒãšå¶åŸ¡ïŒãã¡ã€ã¢ãŠã©ãŒã«ãIDSãIPSãDLPïŒã«æ³šæããŠãã ããã ãšããžã«ãŒã¿ãŒããæåŸã®ãã¹ããŸã§ã®ãããã¯ãŒã¯ãææ¡ããŸãã
- MITER ATTïŒCKãã芧ãã ãã ã
- å°ãªããšãäž»èŠãªå€éšãªãœãŒã¹ã®å®æçãªãã³ãã¹ããå®æœãããã®çµæãåæããæ»æã®äž»ãªç®çãç¹å®ããè匱æ§ãéããŸãã
- ãªãŒãã³ãœãŒã¹ã®è åšã€ã³ããªãžã§ã³ã¹ã·ã¹ãã ïŒMISPãYetiãªã©ïŒãå®è£ ããããã䜿çšããŠãã°ãåæããŸãã
- ã€ã³ã·ãã³ã察å¿ãã©ãããã©ãŒã ïŒIRPïŒã®å®è£ ïŒR-Vision IRPãThe Hiveãäžå¯©ãªãã¡ã€ã«ãåæããããã®ãµã³ãããã¯ã¹ïŒFortiSandboxãCuckooïŒã
- å®æçãªããã»ã¹ãèªååããŸãã ãã°åæãã€ã³ã·ãã³ã管çãã¹ã¿ããã®èªèã¯ãèªååã®å€§ããªåéã§ãã
- ã€ã³ã·ãã³ãã§ååããããã«ããšã³ãžãã¢ãéçºè ãæè¡ãµããŒããšå¹æçã«å¯Ÿè©±ããæ¹æ³ãåŠã³ãŸãã
- ããã»ã¹å šäœãéèŠãªãã€ã³ããéæãããçµæãææžåããåŸã§ãããã«æ»ã£ããããã®ããŒã¿ãååãšå ±æãããããŸãã
- 瀟äŒçãªåŽé¢ãå¿ããªãã§ãã ãããåŸæ¥å¡ãããªããéã£ãŠãã人ãçµç¹ã®æ å ±ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŠãã人ã«äœãèµ·ãã£ãŠããããèªèããŠãã ããã
- æ°ããè åšãšä¿è·æ¹æ³ã®åéã®ååãåžžã«ææ¡ããæè¡ãªãã©ã·ãŒã®ã¬ãã«ïŒITãµãŒãã¹ãšãµãã·ã¹ãã ã®äœæ¥ãå«ãïŒãé«ããäŒè°ã«åºåžããååãšã³ãã¥ãã±ãŒã·ã§ã³ãåããŸãã
ã³ã¡ã³ãã§THããã»ã¹ã®æ§æãè°è«ããæºåãã§ããŸããã
ãŸãã¯ãä»äºã«æ¥ãŠãã ããïŒ