ãµã€ããŒã»ãã¥ãªãã£ãšãµã€ããŒãªã¹ã¯ã®éã
ããµã€ããŒã»ãã¥ãªãã£å¯Ÿãµã€ããŒãªã¹ã¯ããã®éããšã¯ïŒãµã€ããŒã»ãã¥ãªãã£ãšãµã€ããŒãªã¹ã¯ã¯ããæ··åããã¡ã§ããéãªãéšåã¯ããªãå€ãã®ã§ãã埮åŠã«ç°ãªããŸãããã®éããç¥ã£ãŠããããšã¯éèŠã§ãã
ã»ãã¥ãªãã£ã«ã€ããŠèããæããããã¯ãŒã¯ãããŒã¿ããšã³ããã€ã³ããžã®ããŸããŸãªè åšããŸããã®é²åŸ¡çãé ã«æµ®ããã§ããã§ããããããããã ãããšèšã£ãŠâãµã€ããŒãªã¹ã¯"ãšåããšããããã§ã¯ãããŸããã
ãé¢é£èšäºã
âªèªåè»ã¡ãŒã«ãŒãããã«ãã®ã¬ã®è»èŒã€ãŒãµããããå¿
èŠãšããçç±â«
âªããŒãµã€ããããªæ³¢è¶
åºåž¯åæ§èœãã¹ãåãã·ã°ãã«ã»ã¢ãã©ã€ã¶ãçºè¡šâ«
ãã£ãšã·ã³ãã«ã«èª¬æããŸãããããµã€ããŒãªã¹ã¯ç®¡çãšã¯ãµã€ããŒã€ãã³ããåå ã§çµæžçæå€±ãèµ·ãããªã¹ã¯ãæå°éã«ããäžæ¹ã§ããããã¯ãŒã¯ã»ãã¥ãªãã£ã¯æªæã®ãããµã€ããŒã€ãã³ããé²ãããšãç®çãšããŠããŸãã
äŸãã°ãèªå® ãçé£ã«ãã£ãå Žåã100%æå®³è£åããŠãããä¿éºã«å ¥ã£ãŠãããšããŸãããããã®å Žåãçé£ã«ããçµæžçæå€±ã®ãªã¹ã¯ãç¡äºåé¿ããããšãã§ããŸããããã«å¯ŸããŠããŒã ã»ãã¥ãªãã£ã¯ãå€åºãããã³æžç· ããé²ç¯ã¢ã©ãŒã ã確èªããªããã°ãããªããšããããšã§ãã
ã»ãã¥ãªãã£ãåäžããã°ãµã€ããŒãªã¹ã¯ãæããããšã¯ã§ããã®ã
ãªã¹ã¯ç®¡çã«ã¯ãéãããããŸããäžã®äžã«ç¡åã®ç©ã¯ãããŸãããäŒç€Ÿããµã€ããŒè åšããå®ãã®ãäŸå€ã§ã¯ãããŸãããã ãããšèšã£ãŠã»ãã¥ãªãã£ãšãµã€ããŒãªã¹ã¯ã®éè€ãæå¹æŽ»çšã§ããªãããšããããã§ã¯ãããŸãããèŠã¯ãåªç§ãªãããã¯ãŒã¯ã»ãã¥ãªãã£ããããããµã€ããŒãªã¹ã¯ç®¡çãåäžãããšããããšã§ãã
ã§ã¯ãã©ãããã°ããã®ã§ããããä»ããã§ãã3ã€ã®æ¹æ³ããããŸãã
1.SIEMã¢ã©ãŒããæžãã
äŒæ¥ã®ã»ãã¥ãªãã£ããŒã ã¯éåžžSIEM(Security Information and Event Management)ã¢ã©ãŒããæ¯æ¥100äžå以äžåãåã£ãŠããŸããããŒã ãåççã«åªå é äœãä»ãã調æ»ããã«ã¯æ°ãå€ãããããšã¯äžç®çç¶ã§ãããã®ããå€ãã®SIEMã¢ã©ãŒããèŠéããããŠãããçµæçã«æ»æè ã«ä»ãå ¥ãéãäžããããšã«ãªããŸãã
ãã ãã¢ã©ãŒãã®å€ãã¯å®çšçã§ã¯ãããŸãããåã«èªåã¹ãã£ã³ã調æ»ã§æ€ç¥ããããã®æ¬¡ã®IPã«ããããããæåã®ãã±ããã§æ¥ç¶ããããã¯ã§ããã°ããã以äžãšãã¹ãè¡åã¯ãããŸãããã§ã¯ããããããªãã¢ã©ãŒããåŠçããã¹ããªã®ã§ããããïŒ
è åšã€ã³ããªãžã§ã³ã¹ã²ãŒããŠã§ã€ãå°å ¥ããããšã§ãæªæã®ãããã©ãã£ãã¯ãæå€§80%ãããã¯ãããŸãã¯ãããã¯ãŒã¯ãžã®äŸµå ¥ãé²ããŸãã
ãã®çµæãSIEMã¢ã©ãŒããæžå°ããã ãã§ãªããæ¬¡äžä»£ãã¡ã€ã¢ãŠã©ãŒã«(NGFW)ã®è² è·ãäœæžããŠãããŸããNGFWã¯ã倧éã«ãã©ãã£ãã¯ããããã¯ã§ããããèšèšãããããã§ã¯ãªããããåŠçæ©èœããã±ããã®è©³çŽ°ãªæ€èšŒãè åšã®æ€åºãªã©ãããéèŠãªã¿ã¹ã¯ã«æ®ããŠããããšãã§ããŸãã
2.é²åŸ¡ãè ãããã®ãæåç·ã§æããã
ã©ã³ãµã ãŠã§ã¢ã®ãããªããã«ãŠã§ã¢ããã®ã³ãã³ãã»ã¢ã³ãã»ã³ã³ãããŒã«(C&C)ã³ãã¯ã·ã§ã³ãèªåçã«ãããã¯ããããšããè åšã€ã³ããªãžã§ã³ã¹ã²ãŒããŠã§ã€ã®ãã1ã€ã®å©ç¹ã§ãã
ãããã®ããŒã«ã¯ã幎äžç¡äŒã§ãã«ãŠã§ã¢ãæ€èšŒãããã«ãŠã§ã¢ãããã¯ãŒã¯ãæãC&CãµãŒããæ¢ç¥ããäžçèŠæš¡ã®ãããŒããããããã¯ãŒã¯ãšãšãã«ãè åšã€ã³ããªãžã§ã³ã¹ããŒã ããµããŒãããŠããŸãã
ãã®ããããããã®ããŒã«ã¯ã¢ã¯ãã£ããã«ãŠã§ã¢ãããããã¯ãŒã¯ã«äŸµå ¥ããããããããPhone Homeãã³ãã¯ã·ã§ã³ããããã¯ããããšãå¯èœã«ãªããŸããããã«ããããã«ãŠã§ã¢ã«ãããã¡ãŒãžã»æ¡æ£ãé²ãã ãã§ãªããã©ã®ã·ã¹ãã ãææã修埩ãå¿ èŠãªã®ããç¹å®ã§ããŸãã
ã ãããšãã£ãŠãè åšã€ã³ããªãžã§ã³ã¹ã²ãŒããŠã§ã€ããšã³ããã€ã³ãã®ãµããŸãæ€ç¥ãæªæã®ããã¢ã¯ãã£ããã£ãçºèŠã§ããã»ãã¥ãªãã£è£œåã代æ¿ã§ããããã§ã¯ãããŸãããããããææããå Žåã«ãããã¯ãŒã¯ã«äžããã€ã³ãã¯ããæžããããšãã§ããã®ã§ãã
3.é²åŸ¡ãçµ¶ãéãªããã¹ã
ã»ãã¥ãªãã£ã¯æ±ºããŠéçã§ã¯ãããŸãããæ°ããªèšå®ãã¹ãè åšãè匱æ§ãæ¥ã åºãŠããŸãããã®ããããããã¯ãŒã¯ããšã³ããã€ã³ãã»ã»ãã¥ãªãã£ã»ããªã·ãŒãåžæããããã«åŒ·åãããŠããããšãéåžžã«éèŠã«ãªããŸãã
ææ°ã®ãVerizon ããŒã¿æŒæŽ©æ€èšŒã¬ããŒããã«ãããšãåçŽãªèšå®ãã¹ãåå ã§æè¡ã®ã£ããããã¯ããã«å€§ããæŒããã»äŸµå®³ãåŒãèµ·ããããšãããããŸããã
ããã¯ã©ãããæå³ã§ãããããåºæ¬çã«ãæ»æè ã®ç«å Žã«ãªã£ãŠèããå¿ èŠããããšããããšã§ããããã§ã䟵ç¥ã𿻿ã®ã·ãã¥ã¬ãŒã·ã§ã³(Breach and Attack Simulation:BAS)ããŒã«ã®åºçªã§ãã
ããããããŒã«ã§ãã»ãã¥ãªãã£ãŒã¹ã¿ãã¯(ãšã³ããã€ã³ããFirewallãWAFãDLPãªã©)ãžã®åºç¯å²ãªãšã¯ã¹ã€ããã€ããæ»æãå®å šã«ã·ãã¥ã¬ãŒã·ã§ã³ããè匱ãªèšå®ãã¹ãçªãæ¢ããè©³çŽ°ãªæé æžã§ã®ã£ããã修埩ããŸãã
ã€ãŸãããããã¯ãŒã¯ããšã³ããã€ã³ãããŒã«ãã»ãã¥ãªãã£æ©èœãæäŸããBASããŒã«ããããã¯ãŒã¯ããŒã«ã®èšå®ãåäœãæ€èšŒããããšã§ããµã€ããŒã»ãã¥ãªãã£ã»ã€ã³ã·ãã³ãã®ãªã¹ã¯ãäœæžããã®ã§ãã
çŸã®æ²»çãããã²ãšã€ãã®äºé²
æ»æè ãæ»æã仿ããåã«åããŠãã ããããããã¯ãŒã¯ã»ãã¥ãªãã£ã®åŒ·åãžæè³ããããšã§ãæ·±å»ãªæŒããã»äŸµå®³ã®å¯èœæ§ãæããããšãã§ããŸãã
ãã®ãããªæ»æã§è¢«ãæå®³(æ³çãã³ã³ãã©ã€ã¢ã³ã¹ã«ãã眰éã颚è©è¢«å®³ããããŠæäŸ¡ç·é¡ã®æå€±ãªã©)ãèããŠã¿ãŠãã ããããªã¹ã¯äœæžãžã®æè³ã«ã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£ã®åäžã«åããã®ã¯ãªãã§ãããã