ãã«ãã£ãŒã¯4æ2æ¥ã次äžä»£IPS補åã®ææ°ããŒãããããšæŠç¥çºè¡šãè¡ã£ããæšçåæ»æããããã«å®ããããã«ãã£ãŒã®äºæ¥æŠç¥ãšãšãã«ãèŠãŠããã
ãã«ãã£ãŒã®ã»ãã¥ãªãã£æŠç¥ã®åºç€
æåã«ç»å£ããã®ã¯ãããŒã±ãã£ã³ã°æ¬éšã·ãã¢ãããã¯ãããŒã±ãã£ã³ã°ã¹ãã·ã£ãªã¹ãã®äžæ ç©£æ°ã
ãã«ãã£ãŒã§ã¯ãå®éã®äŒæ¥ãªã©ã§å¹ççã«ã»ãã¥ãªãã£èª²é¡ãå æããããã®åºæ¬ãšããŠã3ã€ã®èŠçŽ ãçµ±åããå¿ èŠããããšããŠãã(äžå³)ã
äžææ°ã¯ãããããMcAfee Security ConnectedããšåŒã¶ãã€ã³ããªãžã§ã³ã¹ã§ã¯ãGlobal Threat Intelligence(GTI)ãäžæ žãšããããã«è åšã®æ å ±ãåéã倿ãããããã€ã³ããšããŠããã
補å飿ºã§ã¯ãGTIãçµç±ããç°ãªã補åéã§è åšæ å ±ãå ±æããããšãç®çãšãªãããŸãããšã³ããã€ã³ãã»ãã¥ãªãã£ãšãããã¯ãŒã¯ã»ãã¥ãªãã£ã§ã¯ãããããå®åç¯å²ãç°ãªããããã補åéã§å ±æããåæãå€æã®ææãšããã
æåŸã«ãéçšããã»ã¹ã§ã¯ãå šäœéçšç®¡çã®æé©åã§ãããçŸæç¹ã§ã¯ãePolicy Orchestratorãšãããšã³ããã€ã³ãã管çããã·ã¹ãã ãæäŸãããä»åŸã¯ããã³ããŒãªã©ã®æ ãè¶ ãéçšç®¡çãéçŽããSecurity Information and Event ManegementãæäŸäºå®ãšã®ããšã ã
IPSã«æ±ãããããã®
æšçåæ»æãé²ãããã«ãIPSã«æ±ãããã課é¡ã«ã€ããŠã¯å€§ãã3ã€ã®èª²é¡ãååšãããæšçåæ»æã§ãç°å€ã«æ°ã¥ãã®ãé ããããšãå°ãªããªãããã®åå ã¯ãæ®æ®µã®ç¶æ³ãç¥ããªãããšã§ãããããã§ã第äžã«æ±ããããã®ã¯ãã¢ããªã±ãŒã·ã§ã³å©çšç¶æ³ã®ææ¡ãšå¶åŸ¡ã§ããã
第äºãåºå£å¯Ÿçã§ãããäŸµå ¥ãããªãããã«ããããšãéèŠã§ããããããäŸµå ¥ãããŠããŸã£ãå ŽåããŸãå éšã®ãã«ãŠã§ã¢ãæ€ç¥ãã奪åãããæ å ±ãå€éšã«éä¿¡ãããªãããã«ããä»çµã¿ã§ããã
å®éã®æ»æã§ã¯ãäŒæ¥ã«ç¹åãããã«ãŠã§ã¢ãªã©ã䜿ããããåŸæ¥ã®æ¹æ³ã§ã¯æ€ç¥ãé£ãããªã£ãŠãããããã§ãæåŸã«æ±ããããã®ãæªç¥ã®ãã«ãŠã§ã¢æ€ç¥ã§ããã
ãã«ãŠã§ã¢æ€ç¥æè¡
次äžä»£IPSã®åã«ãMcAfee Labsæ±äº¬ã»äž»ä»»ç ç©¶å¡ã®æ¬å ä¿¡èŒæ°ã«ãããçŸåšã®ãã«ãŠã§ã¢ã®æ€ç¥æè¡ã«ã€ããŠç޹ä»ããã£ãã
äžè¬çã«ã¯ããã¡ã€ã«ã®å éšã³ãŒããè§£èªããããšãè¡ããããããããäžæ£ãªéšåãªã©ã¯ãé£èªåãããŠããããšãå€ããšã®ããšã ãæ¬¡ã«ãããããä»®æ³ç°å¢ã§å®è¡ãããããããæè¿ã®ãã«ãŠã§ã¢ã¯ãä»®æ³ç°å¢ã§ã¯å®è¡ã§ããªããæåãç°ãªããšãã£ããã®ãååšããåæãå°é£ã«ããŠãããå®ç°å¢ã§ããè匱æ§ã®æªçšã§ã¯ãOSãã¢ããªã®ããŒãžã§ã³ã§åäœãç°ãªã£ãããåããªãããšãå€ããšããã
ãŸãäžè¬çãªæ€çŽ¢æ¹æ³ã¯ãã·ã°ããã£ã§ãããããã€ã®æšéЬãªã©ãæã€ãç¹å®ãã¿ãŒã³ã§æ€çŽ¢ããæ¹æ³ã§ãæ€åºç¯å²ã¯çãããããŠãããå°ãäžè¬åããè匱æ§ã®ç¹åŸŽãã¢ãããªãŒãé£èªåææ³ãªã©ãæ€çŽ¢ããæ¹æ³ããããããã¯ãã¥ãŒãªã¹ãã£ãã¯ã§äœ¿ãããŠãããããã«ãéã·ã°ããã£åã§ã¯ãéä¿¡ãã¬ãžã¹ããªã®å€æŽãªã©ãç¥ãã¹ãããã®æ¹æ³ã§ã¯ãåºç¯ãªæ€åºãå¯èœãšãªãã
æ€çŽ¢æ¹æ³ã®æ¯èŒã§ããããéã·ã°ããã£åã®å ŽåãåŠçã«æéãããããäžæ¹ãã·ã°ããã£åã§ã¯ãéåžžã«çæéã§å€æãã€ããã©ã¡ãããããšããã¬ãã«ã§ã¯ãªãããã®ç¶æ³ã«ãããŠç確ã«äœ¿ãåããŠããã¹ããšã®ããšã§ãããããã¯ãIPSãªã©ã§ãæ±ããããŠããã
次äžä»£ã®IPSã®ææ°æ å ±ãšè£œåå±é
次ãã§ç»å£ããã®ã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£ãããã¯ããããŒãžã¡ã³ãã»ã·ãã¢ãã£ã¬ã¯ã¿ãŒã®ãŽã£ãã€ã»ã¢ãã³ãæ°ã§ããã
ãŸããIPSã«æ±ããããèŠçŽ ã¯ã以äžã®3ã€ã§ããã
- å¯èŠåãšå¶åŸ¡(Awareness)
- ããããããæ€ç¥(Botnet detection)
- ãã«ãŠã§ã¢æ€ç¥(Malware detection)
ãŸããå¯èŠåãšå¶åŸ¡ã§ãããäžå³ã§ã¯ãæ»æã®ãã©ãã£ãã¯ãã©ããããã©ããžããããããããããã«é¢é£ããåœããããã
ããã«èšå®ç»é¢ã§ã¯ãFacebookã¯èš±å¯ããããFacebookã®ã²ãŒã ãŸã§ã¯èš±å¯ããªããšãã£ãæè»ãªèšå®ãã§ãããæ¬¡ã®å³ã¯ãããããããæ€ç¥äŸã§ããã
ãããŸã§ã®ããŒã¿ããŒã¹ãããã«McAfee Labsã®ãªãµãŒãããµããŸãæ€ç¥ãªã©ããéç©ãããããã«ãŠã§ã¢ã®æ€ç¥ã«ã¯è€æ°ã®ãšã³ãžã³ã䜿çšããŠãã(äžå³)ãã·ã°ããã£ãã¬ãã¥ããŒã·ã§ã³ã¯æ¢ç¥ã®è åšã®æ€åºã§ãããããã«æ°ãšã³ãžã³ã®ã¢ããã³ã¹ããã«ãŠã§ã¢ãšã³ãžã³ããã¡ã€ã«ã¢ããŒããªæ€ç¥ãªã©ã§ãæªç¥ã®è åšã«ã察å¿ã§ããããããŠãããäžè¿°ã®ããã«ãè€æ°ã®ææ³ãçµã¿åãããããšã§ãããŸããŸãªãã«ãŠã§ã¢ã®æ€ç¥ãè¡ãããšãå¯èœã ã
AV.TESTã®ãã¹ãã§ã¯ãè€åçãªãã«ãŠã§ã¢ã®96%ãæ€ç¥ãããããã«100%ã®æ€ç¥çãç®æãã¹ããValidEdgeãè²·åããŠããããã®æè¡ã¯ããããã¯ãŒã¯äžã§ãµã³ãããã¯ã¹ãå®è¡ãããã®ã§ãæªç¥ã®è åšãžã®å¯ŸçãšããŠããã«å¹æçãšãªãã
ãã®ãã¯ãããžãŒãæèŒãã補åã¯ã2013幎åŸå以éã«æå ¥ãããäºå®ã§ããããŸãã¯5æã«æ°è£œåNS-9100ãšNS-9200ãæå ¥ããäºå®ã§ããã
ç¹åŸŽã¯ã40GigEã€ã³ã¿ãã§ãŒã¹ãæèŒãã30%æ§èœäŸ¡æ Œæ¯ãåäžããããæšçåæ»æãé²ãã®ã¯é£ãããšããããããããå€å±€é²åŸ¡ãé©æé©æã«æé©ãªé²åŸ¡ãè¡ãããšã§ãå®å šæ§ãé«ããããšãã§ãããšããŠããã