第6åã§ç޹ä»ãããããªå®éã®æ»æãçºçããŠããå Žåã«ãAzure Security Centerãå©çšããŠã©ã®ãããªå¯Ÿå¿ãã§ããã®ããæ€åº&åæ(Detection & Analytics)ã®æ©èœãäžå¿ã«ã玹ä»ããŸãã
Azure Security Centerã®æ€åºæ©èœ
Azure Security Centerã§ã¯ãAzureãªãœãŒã¹ã«ãããã»ãã¥ãªã㣠ã¢ã©ãŒããéç©ãã€ã€ãäžçäžã®è åšæ å ±ãéçŽããããŒã¿ããŒã¹ã«ç §ããåãããŠåæããå®éã«çºçããŠããè åšãæ€åºããŠè¡šç€ºããŸããã¯ã©ã€ã¢ã³ã端æ«äžã®äžå¯©ãªã¢ããªã±ãŒã·ã§ã³ããããããæ»æãã¿ãŒã³ã«åèŽããæåã ã£ãå Žåã¯ã¢ã©ãŒãã衚瀺ãããŸãã
ãã®æ©èœã¯AzureãOffice 365ãšãã£ãã¯ã©ãŠããµãŒãã¹ã¯ãã¡ãããoutlook.comãBingæ€çŽ¢ãšã³ãžã³ããåéããããŒã¿ãç¯çœªå¯Ÿçéšéãªã©ãã®ä»ããŸããŸãªçš®é¡ã®ããŒã¿ãéçŽããŠããŸãããŸããã»ãã¥ãªãã£ããŒãããŒããªãµãŒãã£ãŒãšãããŒããã·ãããéãããäºãã«è åšæ å ±ã®äº€æãå¹ åºãè åšãéããŠããŸããããããŠéããããããŒã¿ãšåãè åšãAzure ç°å¢ã§çºçããŠããªãããšããããšãåç §ã»æ¯èŒããŠåæããŠããã®ã§ãã
ãŸãããã©ãã¯ãªã¹ããšã®æ¯èŒä»¥å€ã«ãèšå€§ãªè åšããŒã¿ãæ©æ¢°åŠç¿ã«ãããŠè©äŸ¡ããä»çµã¿ãæã£ãŠãããããæäœæ¥ãæ»æã®é²åãäºæž¬ããææ³ã ãã§ã¯ç¹å®ã§ããªãè åšãæ€åºã§ããŸãã
è¡ååæ
è€éãªæ©æ¢°åŠç¿ã¢ã«ãŽãªãºã ã«ãã£ãŠããŠãŒã¶ãŒãã·ã¹ãã ãæ®æ®µåäœããŠããç¶æ³ãèžãŸããäžã§ç°åžžè¡åãæ€ç¥ããŸãããŠãŒã¶ãŒãã·ã¹ãã ã®åäœã«ã¯çžé¢é¢ä¿ããããããããéžè±ããæ»æã®å åãèŠã€ãåºãããšãã§ããã®ã§ããäŸãã°ããã«ãŠã§ã¢ã«å¯ŸããŠæ£èŠã®ã·ã¹ãã ãã¡ã€ã«ãšåãååãä»ããŠæ¬æ¥ãšã¯ç°ãªãå Žæã«é 眮ããããã¡ã¢ãªã«æœããã«ãŠã§ã¢ã®ã³ãŒãã®çè·¡ããªã¢ãŒã ã³ãã³ãå®è¡ãPowerShell ã¹ã¯ãªããã®å®è¡ãéä¿¡æ¹åã®éä¿¡ãªã©ãããšã«ãæ¢ç¥ã®æ»æãšäžèŽããŠããç°åžžè¡åãæ€åºããã®ã§ãã
ç°åžžæ€åº
ãŠãŒã¶ãŒãã·ã¹ãã ãæ®æ®µåäœããŠããçµ±èšããåºæºå€ãå®ããéžè±ããåäœãããå Žåã«èŠåããŸãããã¡ãã®äŸã§ã¯ããé垞皌åçãäœãä»®æ³ãã·ã³ã®ãªãœãŒã¹äœ¿çšçãæ¥éš°ããŠããããéåžžã¯ã¹ã¯ãªãããå®è¡ããªãä»®æ³ãã·ã³ããå€ãã®ã¹ã¯ãªãããå®è¡ããŠããããšãã£ãã±ãŒã¹ãæããããŸãã
ããããè åšæ å ±ãæ€ç¥ããããã«ã¯ãåžžæ¥é ãããã¥ãŒãã³ã°ãè¡ãããšãå¿ èŠã§ãããããŸã§ã§ããªãã£ããããªè åšã®æ€åºãæ¯æ¥ã®ããã«æ¹åãããŠæ€åºã®ç²ŸåºŠãåäžããŠããŸãããããããå³å¿æ§ãã¯ã©ãŠããµãŒãã¹ã®ã¡ãªãããšèšããã§ãããã
ãµã€ããŒãã«ãã§ãŒã³
æ»æè ã¯ãçµç¹ãžã®æ»æã«ããŸããŸãªä»æããè¡ããŸããäžã€ã®ã¢ã©ãŒããäžãã£ããããšãã£ãŠããããã©ããã£ãæ»æãªã®ãããããå°èŠæš¡ãªãã®ãªã®ãã倧ããªæ»æã®äžéšãªã®ããšããå šäœåã¯ãªããªãèŠããŸãããå®éã«èµ·ããŠããã»ãã¥ãªãã£äŸµå®³ãæ£ç¢ºã«ææ¡ããããã«ã¯ãããã€ãã®ãã°ãéãåãããŠåæããå¿ èŠããããå°éçãªç¥èãšæéãå¿ èŠã§ãã
ç¹ã«çµç¹ãçã£ããµã€ããŒæ»æã§ã¯ãåµå¯ããæŠåšåãããªããªããšã¯ã¹ããã€ããææãC2éä¿¡ãç®çã®å®è¡ãšãã£ãããã«ãäžé£ã®æ»æã®ãæµãããååšããŸããç±³ããããŒãã»ããŒãã£ã³ãæå±ããããµã€ããŒãã«ãã§ãŒã³ããšåŒã°ãããã®äžé£ã®æ»æããã©ããã§åæã§ããããã«å€å±€é²åŸ¡ããããšããå®éã®æ»æã«æ²¿ã£ãããçŸå®çãªå¹çã®è¯ã察çãšãããŠããŸãã
Azure Security Centerã¯ããããããµã€ããŒãã« ãã§ãŒã³ã®ãã¿ãŒã³ã«äžèŽããã¢ã©ãŒãããã€ã³ã·ãã³ããšããŠéçŽã衚瀺ããæ©èœãæ°ããåãããçŸåšãã¬ãã¥ãŒãšããŠæäŸããŠããŸãã
ããã·ã¥ããŒãã«ãããã»ãã¥ãªãã£ã®èŠåãã§ã¯ãã»ãã¥ãªã㣠ã€ãã³ãã«ããããŠã€ã³ã·ãã³ãã衚瀺ãããŸããã€ã³ã·ãã³ããã¯ãªãã¯ãããšããäžé£ã®æ»æã®æµãããšçãããåã¢ã©ãŒãã衚瀺ãããŸãã
ãã®äŸã§ã¯ä»®æ³ãã·ã³ãVM1ãã«å¯Ÿãããªã¢ãŒããã¹ã¯ãããæ¥ç¶ãç·åœããã§è©Šè¡ããŠããæ§åãæ€åºãããŠããŸããæåã®æ¥ç¶ã¯ãããã¯ãããŠå€±æããŠããŸãããAzure Security Centerã§ã¯è¡ååæãè åšããã®æ©æ¢°åŠç¿ãéããŠãä»åã®æ¥ç¶è©Šè¡ããéåžžåäœãã§ã¯ãªããæ»æã®å段éããšå€æããŠããŸãã
ãã®åŸããªã¢ãŒããã¹ã¯ãããæ¥ç¶ãžã®è©Šè¡ã¯ãåãIPã¢ãã¬ã¹ããã®æ¥ç¶ãæåããŠãããšç¢ºèªã§ããŸããããã¯ãå®éã«é ãããããSVCHOSTããã»ã¹ããšããŠæ»æã³ãŒããå®è¡ããå€éšãžéä¿¡ããŠããæµãã§æ»æãè¡ãããŠããããšãåãããŸãã
ãã°
ã»ãã¥ãªãã£ã®ã¢ã©ãŒãã¯åéããã ãã§ãªããæ£ããåæããŠç·æ¥åºŠã倿ããå¿ èŠããããå ·äœçãªå¯Ÿçã®æ€èšã«ã¯å°éç¥èãå¿ èŠãšãªããŸãã
ç¹ã«ã»ãã¥ãªãã£é¢ã§ã¯ãæ¥çå šäœã§å°é人æã®äžè¶³ãåãæ²æ±°ãããŠããŸãããçµå¶å±€ã®èªèäžè¶³ãããã»ãã¥ãªãã£ã«å¯Ÿããè¿œå æè³ãããã«è¡ããªããšãã£ãç¶æ³ããããŸããç±³åœåœç«æšæºæè¡ç ç©¶æ(NIST)ã®ãComputer Security Incident Handling Guide (ã³ã³ãã¥ãŒã¿ãŒ ã»ãã¥ãªã㣠ã€ã³ã·ãã³ã察å¿ã¬ã€ã)ããªã©ã§æå±ãããŠãããããªã€ã³ã·ãã³ã察å¿ã®æ çµã¿ã¯ãAzure Security Centerã®æ€åºæ©èœã掻çšããããšã§å¯Ÿå¿å¯èœã«ãªããŸãã
ä»åã¯Azure Security Center管çããŒã¿ã«ã§ç¢ºèªããæ¹æ³ã玹ä»ããŸããããPower BIãMicrosoft Operations Management Suiteãä»ãã³ããŒã®SIEMãšãç°¡åã«é£æºã§ããŸãã®ã§ãããå¹çã®è¯ãã¢ã©ãŒããã»ãã¥ãªãã£ã€ã³ã·ãã³ããžã®å¯Ÿå¿ãæ€èšããŠã¿ãŠãã ããã


