Splunk Service Japanã¯6æ4æ¥ãSOC(ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒ)ãçŽé¢ããŠãã課é¡ãæãäžããã°ããŒãã«èª¿æ»ã¬ããŒãã2025幎ã®ã»ãã¥ãªãã£ã®çŸç¶ããå ¬éãããåã¬ããŒãããã»ãã¥ãªãã£æ¥åãåæ»ããçµç¹ãè åšã«ãããããèŠå ãæããã«ãªã£ããšããã
調æ»çµæã§æµ®ã圫ããšãªã£ãSOCã®å®æ
調æ»ã¯ãOxford Economics瀟ã®ååãåŸãŠã2024幎10æïœå12æã«ã°ããŒãã«2058人ã®ã»ãã¥ãªãã£ãªãŒããŒ(ã»ãã¥ãªãã£æ åœãã£ã¬ã¯ã¿ãŒããµã€ããŒã»ãã¥ãªãã£æ åœãã€ã¹ãã¬ãžãã³ããã»ãã¥ãªãã£éçšæ åœãã£ã¬ã¯ã¿ãŒãã»ãã¥ãªãã£ã¢ããªã¹ããªã©)ã察象ã«å®æœã察象åœã¯ãªãŒã¹ãã©ãªã¢ããã©ã³ã¹ãã€ã³ããæ¥æ¬ããã¥ãŒãžãŒã©ã³ããã·ã³ã¬ããŒã«ãè±åœãç±³åœã®9ã«åœãæ¥çã¯ããžãã¹ãµãŒãã¹ã建èšã»ãšã³ãžãã¢ãªã³ã°ãæ¶è²»è²¡ãæè²ãéèãµãŒãã¹ãæ¿åºæ©é¢(é£éŠ/äžå€®ãå·ãå°æ¹)ããã«ã¹ã±ã¢ãã©ã€ããµã€ãšã³ã¹ã補é ããã¯ãããžãŒãã¡ãã£ã¢ãç³æ²¹ã»ã¬ã¹ããªããŒã«(å°å£²ã)ã»åžå£²ããéä¿¡ãé茞ã»èŒžéã»ç©æµãå ¬çã®16çš®é¡ã
åé ãSplunk Services Japan ã»ãã¥ãªãã£ã»ã¹ãã©ããžã¹ãã®ç¢åŽèª äºæ°ã¯ãæ¥ã èšå€§ã«çºçããã»ãã¥ãªãã£ã€ãã³ããSOCã®æ åœè ãã©ã®ããã«å¹ççã«ãã³ããªã³ã°ããŠããã®ãã¯ãéåžžã«éèŠãªèª²é¡ã«ãªã£ãŠãããäžæ¹ããã¥ãŒãã³ã°ããããŠã»ãã¥ãªãã£ã€ãã³ããåŠçããããšãã§ããªããããã¢ã©ãŒããçºå ±ãããªããšããèãæ¹ããããéçšã¯äžæããããå®éã«å€§ããªåé¡ããããšå¯Ÿçãé£ãããªã£ãŠããŸããããã仿¥ã«ãããSOCã®å®æ ããšææããã
åæ°ã«ãããšãäž»ãªèª¿æ»çµæãšããŠãSOCã®å¹çåã¯æãã©ããããªãããAIãSOCãæªæ¥ã«å°ãããæªæ¥ã®SOCãæšé²ããã¹ãã«ããè åšæ€ç¥ã®æä»£ããSOCã®çµ±åãšæ¥ç¶ãã®5ã€ãèŠããŠãããšããã
SOCã®å¹çåã«ã€ããŠãç¢åŽæ°ã¯CSIRT(Computer Security Incident Response)ãšé£æºããå¿ èŠæ§ã匷ã蚎ããŠãããããµã€ããŒã»ãã¥ãªãã£å šäœãšãªããšå®çŸ©ã¯åãããŠããŠãããã®å¢ç®ãææ§ãšã®ããšã ã
åæ°ã¯ãSOCã¯ãã©ãã§äœãçããŠããããªã©æ€ç¥ã«é¢ããããšãäž»ãªåœ¹å²ããã ãã»ã³ã·ã³ã°ã«ã¯ãšã³ããã€ã³ãããããã¯ãŒã¯ããµãŒããã¯ã©ãŠããªã©ã®é åã«å¯Ÿããã»ã³ã·ã³ã°ã®ä»çµã¿ããããŸãããããŒã«ãååã«çµ±åãããŠããªããã管çã«æéãšåŽåãããã£ãŠãããéåã鲿©ãé»å®³ããŠã¢ãããŒã·ã§ã³ãããã§ããŸã£ãŠããããšè©±ãã
AIã«é¢ããŠã¯ã調æ»çµæã§ã¯å¹çããããçšåºŠåäžããããŸãã¯ãå€§å¹ ã«åäžããããšåçããå²åã¯59%ãšãªã£ãäžæ¹ã§ããå®å šã«ä¿¡é ŒããŠããããšåçããå²åã¯ã¯11%ãšäžä¿¡æãæããªãããã ã
ç¢åŽæ°ã¯ãAIã¯å®å šãªäžèœè¬ã§ã¯ãªãããå¹çæ§ã®åäžãç®æãSOCã«ãããŠã¯ééããªããæ£ããæ¹åã«å°ããŠããããšã®èŠè§£ã瀺ããã
ãæ€ç¥ãšã³ãžãã¢ãªã³ã°ããšããèãæ¹
SOCãæšé²ããã¹ãã«ã§ã¯1äœããæ€ç¥ãšã³ãžãã¢ãªã³ã°(Detection Engineering)ããšãªãããDevSecOpsããã³ã³ãã©ã€ã¢ã³ã¹ç®¡çããšç¶ããç¹ã«ãæªæ¥å¿åã®SOCãæ§ç¯ããããã«æ€ç¥ãšã³ãžãã¢ãªã³ã°ã泚ç®ãããŠããã調æ»ã§ã¯74%ãæãéèŠãªã¹ãã«ãšããŠæããŠããã
æ€ç¥ãšã³ãžãã¢ãªã³ã°ãšã¯ãçµç¹ã§äœ¿çšããæ€åºã®å質ã»ç²ŸåºŠã®åºæºãèšå®ããé«åºŠãªè åšãæ£ç¢ºã«çºèŠã§ããããã«æ€åºãèšèšã»éçºã»èª¿æŽããªã¢ã«ã¿ãŒã ã®ããã©ãŒãã³ã¹ææšã«åºã¥ããŠã³ã³ãã³ããè¿ éã«ã¢ããããŒãããããã«æ€åºãã³ãŒããšããŠå°å ¥ããäœæ¥ãæ åœããã
è åšæ€ç¥ã®æä»£ã«ã€ããŠç¢åŽæ°ã¯ããŒã¿ãè€éåããŠããŠæ€åºã®æ°ããªãžã¬ã³ããçãŸããŠãããšããã
åæ°ã¯ãæ€åºã®å質ãäœããéãèšãã°èª€æ€ç¥çãé«ããªã£ãŠãããããŒã¿ã®å質ãäœäžããŠããããã¬ã¡ããªã§ã¯ãããŒã¿ã®äžéšãèŠçŽããŠSIEM(Security Information and Event Management)ã«éãããããããæ€çŽ¢ã«å¯Ÿè±¡ã«ããªããã°ãªããªãå å®¹ãæŒããŠããããç¹å®ã®ãã©ãŒããããããŒã¿ãšããŠåŽ©ããŠããŸã£ãŠããããåé¡ãæ€åºã§ããªãããšããããçµç¹ã«é©åããå 容ã«åãããªããã°æ€ç¥ããžãã¯ã¯æ»æåŽã§ç°¡åã«å€ããããšãã§ããããšè¿°ã¹ãŠããã
ãã®ãããªè åšæ€åºã®æ°ããªæä»£ã«åããææ°ã®ã¢ãããŒãããDetection as Codeã(DaCïŒã³ãŒãã«ããæ€åº)ãšãªãã
ç¢åŽæ°ã¯ãããã¯æ€ç¥ãšã³ãžãã¢ãªã³ã°ããã£ã¬ã¯ã·ã§ã³ããããã®ããžãã¯ãäžåºŠäœæãããçµããã§ã¯ãªããèšç»çã«å 容ã確èªãã€ã€éå»ã®ããŒãžã§ã³ãšæ¯èŒããªãããã©ãã§å€åããŠããã®ããšããããšãã³ãŒããšããŠçè§£ããŠé²ããŠãããã®ããšèª¬æããã
SOCã®çµ±åãšæ¥ç¶ã«é¢ããŠã¯ã»ãã¥ãªãã£ããŒã«ã忣ãã飿ºããŠããªãšåçããå²åã¯78%ãšãªã£ãŠããã
ãã®ãããããããçµ±åããããšã§ã€ã³ã·ãã³ã察å¿ã®è¿ éåãããŒã«ã®ä¿å®ã«ãããæéã®ççž®ãè åšã«ãã¬ããžã®æ¡å€§ãªã©ã®ã¡ãªããã享åã§ãããšããã
åæ°ã¯æªæ¥å¿åã®SOCãæ§ç¯ããã¹ããããšããŠãããŒã«ã»ãããæŽçããã¹ãã«ã»ãããã¢ããããŒãããããã§ãã¢ã©ãŒã察å¿ã®è² æ ã軜æžããŠãã¡ã€ã³ç¹ååã®çæAIã®å°å ¥ãã³ã©ãã¬ãŒã·ã§ã³åºç€ã®æ§ç¯ãDaCãããŒã å šäœã§åãå ¥ããæ®µéçãªã¢ãããŒããæšå¥šããŠããã
ã»ãã¥ãªãã£ã¬ãã«ã®åäžã«ã¯å£æ ¹ãè¶ ãã飿ºã»ååãéèŠ
ç¶ããŠãã¢ã¯ã»ã³ãã¥ã¢ ãã¯ãããžãŒã³ã³ãµã«ãã£ã³ã°æ¬éš ã»ãã¥ãªãã£ã°ã«ãŒã ã¢ãœã·ãšã€ãã»ãã£ã¬ã¯ã¿ãŒã®æ»å£åææ°ãåœå ã«ãããSOCã®çŸç¶ãšèª²é¡ã«ã€ããŠè§£èª¬ããããŸããåæ°ã¯åœå ã®ã»ãã¥ãªãã£ã¬ãã«ã®åäžã«åããŠãã³ããŒãå©çšè ãšãªã¹ã¯ã³ãã¥ãã±ãŒã·ã§ã³ãè¡ããªã©ã壿 ¹ãè¶ ãã飿ºã»ååãéèŠã ãšææããŠããã
-

ã¢ã¯ã»ã³ãã¥ã¢ ãã¯ãããžãŒã³ã³ãµã«ãã£ã³ã°æ¬éš ã»ãã¥ãªãã£ã°ã«ãŒã ã¢ãœã·ãšã€ãã»ãã£ã¬ã¯ã¿ãŒã®æ»å£åææ°
æ»å£æ°ã¯SOC=MSS(äŸµå ¥æ€ç¥ãµãŒãã¹)ãšããŠå®çŸ©ããMSSããèŠãCSIRTã®çŸç¶ãšèª²é¡ã以äžã®ããã«èª¬æããã
ãæ¥æ¬äŒæ¥ã®CSIRTããŒã ã®çŸç¶ã¯ãé©çšç¯å²ãæç¢ºã§ã¯ãªãäžããããã¿ã¹ã¯ãããªãã ãã§ãããå€éšãã³ããŒãšååçãªã³ãã¥ãã±ãŒã·ã§ã³ã®ããå Žåœããçãªå¯Ÿå¿ã§æŠç¥ãå®ãŸã£ãŠããªãããŸããå€éšã®ã»ãã¥ãªãã£ãã³ããŒãäŒæ¥ã®ã»ãã¥ãªãã£æŠç¥ã®äžè¶³ç¹ãç®æããŽãŒã«ãååã«çè§£ããŠããªãã(æ»å£æ°)
ããããçŸç¶ããµãŸããããã¹ãå§¿ãšããŠCSIRTããŒã ã¯ã»ãã¥ãªãã£æŠç¥ã®ãã¬ã€ã³ã§ãããå€éšãã³ããŒãåããŽãŒã«ã®ããšå¯Ÿçã«ã³ãã¥ãã±ãŒã·ã§ã³ãåãã€ã€ãã»ãã¥ãªãã£æŠç¥ã®å®è¡ã¯ãã³ããŒãå«ããã¯ã³ããŒã ã§åãå¿ èŠããããšããã
MSSã®æŽ»çšã«ãããæ¥æ¬ãšæµ·å€ã®çžéç¹ã«é¢ããŠãæäŸãããå 容ã¯å€§ããªéãã¯ãªããã®ã®ãæ¥æ¬ã§ã¯å æ¬çãªãµãŒãã¹ãšããŠæäŸããã±ãŒã¹ãå€ããšã®ããšããŸããæ¥æ¬äŒæ¥ã«ãããMSS掻çšã®åŸåã¯ãã³ããŒãšå¯Ÿçã«äŒè©±ããŠããããã¹ãã«ã»ããäžè¶³ã§ååçãã€ã»ãã¥ãªãã£æŠç¥ãååã«æŽ»çšã§ããŠããªãç¹ãæããŠããã
ããããããšãããæ¥æ¬äŒæ¥ã§ã¯èªç€Ÿã®ç€Ÿå¡ãã»ãã¥ãªãã£æŠç¥ã®ãã¬ã€ã³ãšããŠè²æãããšãšãã«ãå€éšãªãœãŒã¹ãå«ããã¯ã³ããŒã ã§å æ¬çäœå¶ãæ§ç¯ããããšãæãŸãããšããã
æåŸã«ãæ»å£æ°ã¯ãçµç¹å ã§èããŠããã»ãã¥ãªãã£ã®äºè±¡ã¯å€ããããŸããŸãªãã³ããŒãé¢ããããæšªé£æºãã§ããªãããšãå€ããã¯ã³ããŒã ã§ããã°æ å ±å ±æãã»ãã¥ãªãã£æŠç¥ã®å±éãå¯èœãªããé·æçã«èããŠã§ããããšãæå€§éã«å®è¡ããŠããããããã«ãããçµæçã«ã¯ã¹ãã«ã¬ãã«ã®åäžã«ã€ãªããããšè¿°ã¹ãŠããã






