æ å ±ã»ãã¥ãªãã£ããŒã«ã®é«ãå¹çã確ä¿ããããã«ãã³ã³ããŒãã³ãã®æ¥ç¶ãéèŠãªåœ¹å²ãæãããŸãã å€éšã®è åšã ãã§ãªããå éšã®è åšããããã¯ã§ããŸãã ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãèšèšããéãã¯ã©ã¹å ïŒãšã³ããã€ã³ãã»ãã¥ãªãã£ãŸãã¯NGFWïŒã§æ©èœããã ãã§ãªããçžäºã«é£æºããŠè åšãšæŠãèœåãæã€ããã«ããŠã€ã«ã¹å¯Ÿçã§ãããã¡ã€ã¢ãŠã©ãŒã«ã§ãããããããä¿è·æ段ãéèŠã§ãã
çè«ã®ããã
åœç¶ã®ããšãªãããçŸåšã®ãµã€ããŒç¯çœªè ã¯ããèµ·æ¥å®¶ã«ãªã£ãŠããŸãã 圌ãã¯ãã«ãŠã§ã¢ãæ¡æ£ããããã«å€ãã®ãããã¯ãŒã¯æè¡ã䜿çšããŠããŸã
ãã£ãã·ã³ã°ã¡ãŒã«ã¯ããã«ãŠã§ã¢ãæ¢ç¥ã®æ»æã䜿çšããŠãããã¯ãŒã¯ã®ããããå€ãè¶ ãããããŸãã¯ããŒããã€æ»æããšããã«ç¶ãç¹æš©ã®ææ ŒããŸãã¯ãããã¯ãŒã¯å šäœã®æšªæ¹åã®ç§»åãåŒãèµ·ãããŸãã ææããããã€ã¹ã1ã€ãããšããããšã¯ãæ»æè ã®mercå µç®çã§ãããã¯ãŒã¯ã䜿çšãããå¯èœæ§ãããããšãæå³ããŸãã
å Žåã«ãã£ãŠã¯ãæ å ±ã»ãã¥ãªãã£ã³ã³ããŒãã³ãã®çžäºäœçšã確ä¿ããå¿ èŠãããå Žåãã·ã¹ãã ã®çŸåšã®ç¶æ ã®æ å ±ã»ãã¥ãªãã£ç£æ»ãå®æœãããšãã«ãçžäºæ¥ç¶ãããåäžã®æž¬å®ã»ããã䜿çšããŠèª¬æã§ããŸããã ã»ãšãã©ã®å Žåãç¹å®ã®ã¿ã€ãã®è åšã«å¯Ÿæããããšã«çŠç¹ãåœãŠãå€ãã®æè¡çãœãªã¥ãŒã·ã§ã³ã¯ãä»ã®æè¡çãœãªã¥ãŒã·ã§ã³ãšã®çµ±åãæäŸããŸããã ããšãã°ããšã³ããã€ã³ãä¿è·è£œåã¯ã眲åããŒã¹ã®åäœåæã䜿çšããŠããã¡ã€ã«ãææããŠãããã©ãããå€æããŸãã æªæã®ãããã©ãã£ãã¯ãé»æ¢ããããã«ããã¡ã€ã¢ãŠã©ãŒã«ã¯Webãã£ã«ã¿ãªã³ã°ãIPSããµã³ãããã¯ã¹ãªã©ãå«ãä»ã®ãã¯ãããžãŒã䜿çšããŸãã ããã«ãããããããã»ãšãã©ã®çµç¹ã§ã¯ããããã®æ å ±ã»ãã¥ãªãã£ã³ã³ããŒãã³ãã¯çžäºã«æ¥ç¶ãããŠããããåç¬ã§åäœããŸãã
ããŒãããŒãæè¡ã®åå
ãµã€ããŒã»ãã¥ãªãã£ã確ä¿ããããã®æ°ããã¢ãããŒãã«ã¯ãåã¬ãã«ã§ã®ä¿è·ãå«ãŸããŸããåã¬ãã«ã§äœ¿çšããããœãªã¥ãŒã·ã§ã³ã¯çžäºæ¥ç¶ãããæ å ±ã亀æããæ©èœããããŸãã ããã«ãããSynchronized SecurityïŒSynSecïŒã·ã¹ãã ãäœæãããŸãã SynSecã¯ãåäžã·ã¹ãã ãšããŠã®æ å ±ã»ãã¥ãªãã£ããã»ã¹ã§ãã ãã®å Žåãåæ å ±ã»ãã¥ãªãã£ã³ã³ããŒãã³ãã¯ãªã¢ã«ã¿ã€ã ã§çžäºã«æ¥ç¶ãããŸãã ããšãã°ã Sophos Centralãœãªã¥ãŒã·ã§ã³ã¯ãã®ååã«åŸã£ãŠå®è£ ãããŸãã
ã»ãã¥ãªãã£ããŒãããŒããã¯ãããžãŒã¯ãã»ãã¥ãªãã£ã³ã³ããŒãã³ãéã®éä¿¡ãæäŸããã·ã¹ãã ãšãã®ç£èŠã®å ±åæ©èœãä¿èšŒããŸãã 以äžã®ã¯ã©ã¹ãSophos Centralã«çµ±åãããŠããŸãã
- ãšã³ããã€ã³ãä¿è· -å€å žçãªã·ã°ããã£ã¢ã³ããŠã€ã«ã¹ã
- ãµãŒããŒä¿è· -ãµãŒããŒå°çšã®ãŠã€ã«ã¹å¯Ÿçã
- Intercept-X-æ°äžä»£ã®ãŠã€ã«ã¹å¯ŸçïŒçœ²åãªãã人工ç¥èœæè¡ã䜿çšïŒ;
- Sophos XG Firewall-次äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ã
- ã¢ããªãã£ç®¡çïŒEMMïŒ -ã¢ãã€ã«ããã€ã¹ç®¡çããã³äŒæ¥ã®ã¡ãŒã«ãšãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ã
- ããŒã¿ä¿è·ïŒæå·åïŒ ;
- ã»ãã¥ã¢Wi-Fi-ã¯ã©ãŠããããããã³Sophos UTM / Sophos XGãä»ããŠããŒã«ã«ã«ç®¡çãããã¢ã¯ã»ã¹ãã€ã³ãã
- Webã»ãã¥ãªã㣠-Webãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããããã®å€å žçãªãœãªã¥ãŒã·ã§ã³ã
- é»åã¡ãŒã«ã»ãã¥ãªã㣠-ã¯ã©ãŠã/ããŒã«ã«ã¹ãã 察ç/ãŠã€ã«ã¹å¯Ÿçãœãªã¥ãŒã·ã§ã³ã
- ãã£ãã·ã³ã°ã®è åš -åŸæ¥å¡ã®èªèãé«ãããã¹ããã£ãã·ã³ã°ã¡ãŒã«ãå®æœããŸãã
- Cloud Optix-ã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç£æ»ã
Sophos Centralãããªãåºç¯å²ã®æ å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ããµããŒãããŠããããšã¯å®¹æã«ç解ã§ããŸãã Sophos Centralã®SynSecã³ã³ã»ããã¯ãæ€åºãåæãå¿çãšãã3ã€ã®éèŠãªååã«åºã¥ããŠããŸãã ãããã®è©³çŽ°ãªèª¬æã«ã€ããŠã¯ãããããã«ã€ããŠèª¬æããŸãããã
SynSecã®æŠå¿µ
æ€åº ïŒæªç¥ã®è åšã®èå¥ïŒ
Sophos Centralãå®è¡ãããœãã©ã¹è£œåã¯èªåçã«æ å ±ãå ±æãã以äžãå«ããªã¹ã¯ãšæªç¥ã®è åšãèå¥ããŸãã
- ãªã¹ã¯ã®é«ãã¢ããªã±ãŒã·ã§ã³ãšæªæã®ãããã©ãã£ãã¯ãèå¥ããæ©èœãåãããããã¯ãŒã¯ãã©ãã£ãã¯åæã
- ãããã¯ãŒã¯äžã§ã®ã¢ã¯ã·ã§ã³ã®çžé¢åæã«ããããªã¹ã¯ã®é«ãã°ã«ãŒããæã€ãŠãŒã¶ãŒã®æ€åºã
åæ ïŒå³æãã€çŽæçïŒ
ãªã¢ã«ã¿ã€ã ã®ã€ã³ã·ãã³ãåæã«ãããã·ã¹ãã ã®çŸåšã®ç¶æ³ãå³åº§ã«ææ¡ã§ããŸãã
- ãã¹ãŠã®ãã¡ã€ã«ãã¬ãžã¹ããªããŒãURLãªã©ãå«ããã€ã³ã·ãã³ãã«ã€ãªãã£ãã€ãã³ãã®å®å šãªãã§ãŒã³ã衚瀺ããŸãã
RESPONSE ïŒèªåã€ã³ã·ãã³ã察å¿ïŒ
ã»ãã¥ãªãã£ããªã·ãŒãèšå®ãããšãæ°ç§ã§ææãã€ã³ã·ãã³ãã«èªåçã«å¯Ÿå¿ã§ããŸãã ããã¯ä»¥äžã«ãã£ãŠæäŸãããŸãïŒ
- ææããããã€ã¹ãå³åº§ã«éé¢ãããªã¢ã«ã¿ã€ã ã§æ»æãåæ¢ããŸãïŒåããããã¯ãŒã¯/ãããŒããã£ã¹ããã¡ã€ã³å ã§ãïŒã
- ããªã·ãŒãæºãããªãããã€ã¹ã®äŒæ¥ãããã¯ãŒã¯ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶éããã
- çºä¿¡ã¹ãã ãæ€åºããããšããªã¢ãŒãã§ããã€ã¹ã®ã¹ãã£ã³ãéå§ããŸãã
Sophos Centralãæ©èœããåºæ¬çãªã»ãã¥ãªãã£ååãæ€èšŒããŸããã 次ã«ãSynSecãã¯ãããžãŒãå®éã«ã©ã®ããã«æ©èœãããã®èª¬æã«ç§»ããŸãããã
çè«ããå®è·µãž
ã¯ããã«ãSynSecãããŒãããŒããã¯ãããžãŒã䜿çšããŠããã€ã¹ã®çžäºäœçšã確ç«ããæ¹æ³ã説æããŸãããã æåã®ã¹ãããã¯ãSophos XGãSophos Centralã«ç»é²ããããšã§ãã ãã®æ®µéã§ã圌ã¯ãèªå·±èå¥ã®èšŒææžãHeartbeatãã¯ãããžãŒã䜿çšããŠãšã³ãããã€ã¹ãéä¿¡ããIPã¢ãã¬ã¹ãšããŒããããã³Sophos Centralã§ç®¡çãããŠãããšã³ãããã€ã¹IDã®ãªã¹ããšãã®ã¯ã©ã€ã¢ã³ã蚌ææžãåãåããŸãã
Sophos XGã®ç»é²ãè¡ãããçŽåŸã«ãSophos Centralã¯ããŒãããŒãéä¿¡ãéå§ããããã«ãšã³ãããã€ã¹ã«æ å ±ãéä¿¡ããŸãã
- Sophos XG蚌ææžã®çºè¡ã«äœ¿çšããã蚌ææ©é¢ã®ãªã¹ã
- Sophos XGã«ç»é²ãããŠããããã€ã¹IDã®ãªã¹ãã
- éä¿¡çšã®ããŒãããŒãIPã¢ãã¬ã¹ãšããŒãã
ãã®æ å ±ã¯ã次ã®æ¹æ³ã§ã³ã³ãã¥ãŒã¿ãŒã«ä¿åãããŸããïŒ ProgramDataïŒ \ Sophos \ Hearbeat \ Config \ Heartbeat.xmlãå®æçã«æŽæ°ãããŸãã
ããŒãããŒããã¯ãããžãŒã¯ãããžãã¯IPã¢ãã¬ã¹52.5.76.173:8347ã«ãšã³ããã€ã³ãã¡ãã»ãŒãžãéä¿¡ããããšã§éä¿¡ããŸãã åæã«ããããã³ããŒãçºè¡šããããã«ããã±ããã¯15ç§ã®åšæã§éä¿¡ãããããšãæããã«ãªããŸããã Heartbeatã¡ãã»ãŒãžã¯XG Firewallã«ãã£ãŠçŽæ¥åŠçãããããšã«æ³šæããŠãã ãããXGFirewallã¯ãã±ãããååãããšã³ããã€ã³ãã®ã¹ããŒã¿ã¹ãç£èŠããŸãã ãã¹ãã§ãã±ããããã£ããã£ãããšããã©ãã£ãã¯ãããŒã¯å€éšIPã¢ãã¬ã¹ãšã®éä¿¡ã«äŒŒãŠããŸãããå®éã«ã¯ãšã³ããã€ã³ãã¯XGãã¡ã€ã¢ãŠã©ãŒã«ãšçŽæ¥éä¿¡ããŸãã
æªæã®ããã¢ããªã±ãŒã·ã§ã³ãäœããã®æ¹æ³ã§ã³ã³ãã¥ãŒã¿ãŒã«äŸµå ¥ããããã«ããŸãã Sophos Endpointã¯ãã®æ»æãæ€åºãããããã®ã·ã¹ãã ããã®ããŒãããŒãã®åä¿¡ãåæ¢ããŸãã ææããããã€ã¹ã¯ãã·ã¹ãã ææã«é¢ããæ å ±ãèªåçã«éä¿¡ããã¢ã¯ã·ã§ã³ã®èªåãã§ãŒã³ãåŒãèµ·ãããŸãã XG Firewallã¯å³åº§ã«ã³ã³ãã¥ãŒã¿ãŒãéé¢ããæ»æã®æ¡æ£ãšCïŒCãµãŒããŒãšã®çžäºäœçšãé²ããŸãã
Sophos Endpointã¯ãã«ãŠã§ã¢ãèªåçã«åé€ããŸãã åé€åŸããšã³ãããã€ã¹ã¯Sophos CentralãšåæãããXG Firewallã¯ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãå埩ããŸãã æ ¹æ¬åå åæïŒRCAãŸãã¯EDR-ãšã³ããã€ã³ãæ€åºããã³å¿çïŒã¯ãäœãèµ·ãã£ããã®è©³çŽ°ãªã¢ã€ãã¢ãæäŸããŸãã
ã¢ãã€ã«ããã€ã¹ãšã¿ãã¬ããã䜿çšããŠäŒæ¥ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ãããšä»®å®ãããšããã®å Žåã«SynSecãæäŸããããšã¯å¯èœã§ããïŒ
ãã®ã·ããªãªã§ã¯ãSophos Centralã¯Sophos MobileãšSophos Wirelessã®ãµããŒããæäŸããŸãã ãŠãŒã¶ãŒãSophos Mobileã§ä¿è·ãããã¢ãã€ã«ããã€ã¹ã®ã»ãã¥ãªãã£ããªã·ãŒã«éåããããšãããšããŸãã Sophos Mobileã¯ãã»ãã¥ãªãã£ããªã·ãŒéåãæ€åºããã·ã¹ãã ã®æ®ãã®éšåã«ã¢ã©ãŒããéä¿¡ããŠãã€ã³ã·ãã³ãã«å¯ŸããŠäºåã«æ§æãããå¿çãããªã¬ãŒããŸãã Sophos Mobileãããããã¯ãŒã¯æ¥ç¶ãçŠæ¢ãããããªã·ãŒã§èšå®ãããŠããå ŽåãSophos Wirelessã¯ãã®ããã€ã¹ã®ãããã¯ãŒã¯ã¢ã¯ã»ã¹ãå¶éããŸãã Sophos Wirelessã¿ãã®Sophos CentralããŒã«ããŒã«ã¯ãããã€ã¹ãææããŠãããšããéç¥ã衚瀺ãããŸãã ãŠãŒã¶ãŒããããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããšããŠããéãã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãå¶éãããŠããããšãç¥ãããã¹ãã©ãã·ã¥ç»é¢ãç»é¢ã«è¡šç€ºãããŸãã
ãšã³ããã€ã³ãã«ã¯ãããã€ãã®ããŒãããŒãã¹ããŒã¿ã¹ã¹ããŒã¿ã¹ããããŸãïŒèµ€ãé»ãç·ã
èµ€ã®ã¹ããŒã¿ã¹ã¯ã次ã®å Žåã«çºçããŸãã
- æ€åºãããã¢ã¯ãã£ããªãã«ãŠã§ã¢
- ãã«ãŠã§ã¢ãèµ·åããããšããŸããã
- æªæã®ãããããã¯ãŒã¯ãã©ãã£ãã¯ãæ€åºãããŸãã
- ãã«ãŠã§ã¢ã¯åé€ãããŠããŸããã
é»è²ã®ã¹ããŒã¿ã¹ã¯ãéã¢ã¯ãã£ããªãã«ãŠã§ã¢ããšã³ããã€ã³ãã§æ€åºãããããšããŸãã¯PUPïŒæœåšçã«äžèŠãªããã°ã©ã ïŒãæ€åºãããããšãæå³ããŸãã ç·è²ã®ã¹ããŒã¿ã¹ã¯ãäžèšã®åé¡ãæ€åºãããŠããªãããšã瀺ããŸãã
ä¿è·ãããããã€ã¹ãšSophos Centralã®çžäºäœçšã®å€å žçãªã·ããªãªã®ããã€ããæ€èšããåŸããœãªã¥ãŒã·ã§ã³ã®ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ãŒã¹ã«ã€ããŠèª¬æããåºæ¬èšå®ãšãµããŒããããæ©èœãæ€èšããŸãã
GUI
ã³ã³ãããŒã«ããã«ã«ææ°ã®éç¥ã衚瀺ãããŸãã ãŸãããã€ã¢ã°ã©ã ã®åœ¢åŒã§ãããŸããŸãªä¿è·ã³ã³ããŒãã³ãã®èŠçŽç¹æ§ã衚瀺ãããŸãã ãã®å ŽåãããŒãœãã«ã³ã³ãã¥ãŒã¿ãŒã®ä¿è·ã«é¢ããèŠçŽããŒã¿ã衚瀺ãããŸãã ãã®ããã«ã«ã¯ãäžé©åãªã³ã³ãã³ããå«ãå±éºãªãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹è©Šè¡ã«é¢ããæŠèŠæ å ±ãšãé»åã¡ãŒã«åæã®çµ±èšã衚瀺ãããŸãã
Sophos Centralã¯ãé倧床ã«å¿ããã¢ã©ãŒãã®è¡šç€ºããµããŒãããŠããããããŠãŒã¶ãŒã¯éèŠãªã»ãã¥ãªãã£ã¢ã©ãŒããã¹ãããã§ããŸããã Sophos Centralã¯ãä¿è·ã·ã¹ãã ã®ã¹ããŒã¿ã¹ã«é¢ããç°¡æœãªæŠèŠæ å ±ã«å ããŠãã€ãã³ããã°ãSIEMã·ã¹ãã ãšã®çµ±åããµããŒãããŠããŸãã å€ãã®äŒæ¥ã®Sophos Centralã¯ãå éšSOCãšã顧客ãžã®ãµãŒãã¹æäŸïŒMSSPïŒã®äž¡æ¹ã®ãã©ãããã©ãŒã ã§ãã
éèŠãªæ©èœã®1ã€ã¯ããšã³ããã€ã³ãã¯ã©ã€ã¢ã³ãã®æŽæ°ãã£ãã·ã¥ã®ãµããŒãã§ãã ããã«ãããå€éšãã©ãã£ãã¯ã®åž¯åå¹ ãç¯çŽãããŸãããã®å ŽåãæŽæ°ã¯ãšã³ããã€ã³ãã¯ã©ã€ã¢ã³ãã®1ã€ã«1åããŠã³ããŒãããããã®åŸãä»ã®ãšã³ãããã€ã¹ãããããæŽæ°ãããŠã³ããŒãããããã§ãã 説æããæ©èœã«å ããŠãéžæãããšã³ããã€ã³ãã¯ãã»ãã¥ãªãã£ããªã·ãŒã¡ãã»ãŒãžãšæ å ±ã¬ããŒãããœãã©ã¹ã¯ã©ãŠãã«äžç¶ã§ããŸãã ãã®æ©èœã¯ãã€ã³ã¿ãŒãããã«çŽæ¥ã¢ã¯ã»ã¹ã§ããªããä¿è·ãå¿ èŠãªãšã³ãããã€ã¹ãããå Žåã«åœ¹ç«ã¡ãŸãã Sophos Centralã«ã¯ãã³ã³ãã¥ãŒã¿ãŒä¿è·èšå®ã®å€æŽãŸãã¯ãšã³ããã€ã³ããšãŒãžã§ã³ãã®åé€ãçŠæ¢ãããªãã·ã§ã³ïŒæ¹ããé²æ¢ïŒããããŸãã
ãšã³ããã€ã³ãä¿è·ã®ã³ã³ããŒãã³ãã®1ã€ã¯ã次äžä»£ã®ãŠã€ã«ã¹å¯ŸçïŒNGAVïŒã§ããIntercept Xã§ãã ãã£ãŒããã·ã³ã©ãŒãã³ã°ãã¯ãããžãŒã䜿çšããŠããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã¯ãã·ã°ããã£ã䜿çšããã«ã以åã¯æªç¥ã§ãã£ãè åšãæ€åºã§ããŸãã æ€åºç²ŸåºŠã¯ã·ã°ããã£ã®åçç©ã«å¹æµããŸãããããããšã¯ç°ãªããããã¢ã¯ãã£ããªä¿è·ãæäŸãããŒããã€æ»æãé²ããŸãã Intercept Xã¯ãä»ã®ãã³ããŒã®ã·ã°ããã£ã¢ã³ããŠã€ã«ã¹ãšäžŠè¡ããŠåäœã§ããŸãã
ãã®èšäºã§ã¯ãSophos Centralã«å®è£ ãããŠããSynSecã®æŠå¿µãšããã®ãœãªã¥ãŒã·ã§ã³ã®æ©èœã®äžéšã«ã€ããŠç°¡åã«èª¬æããŸããã 以äžã®èšäºã§ãSophos Centralã«çµ±åãããåä¿è·ã³ã³ããŒãã³ãã®æ©èœã«ã€ããŠèª¬æããŸãã ãœãªã¥ãŒã·ã§ã³ã®ãã¢çã¯ãã¡ãããå ¥æã§ããŸã ã
ãœãªã¥ãŒã·ã§ã³ã«èå³ãããå Žåã¯ããœãã©ã¹ã®è²©å£²ä»£çåºã§ããFactor Groupã«ãåãåãããã ããã sophos@fgts.ruã«èªç±åœ¢åŒã§æžã蟌ãã ãã§ååã§ã ã