äžå°äŒæ¥ã«ãè¿«ããµã€ããŒæ»æïŒèª²é¡ã¯äººå¡ã®ç¢ºä¿ãšã»ãã¥ãªãã£å¯Ÿçã®å¹çåã ãâŠâŠ
æšçåæ»æãã©ã³ãµã ãŠã§ã¢ãã¯ãããšãããäŒæ¥ãåãå·»ããµã€ããŒã»ãã¥ãªãã£äžã®è åšã¯ãŸããŸãå¢å€§ãã€ã€ãããç¹ã«2017幎ã«å ¥ã£ãŠèªå·±å¢æ®åãæã€ã¯ãŒã åã©ã³ãµã ãŠã§ã¢ã®è åšãå«ã°ããŠãããäŒæ¥ã®ã»ãã¥ãªãã£ã»ã¬ãã«ã®ç¶æã®ããã«ã¯ããäžæ©èžã¿èŸŒãã 察çãåŒ·ãæ±ããããããã«ãªã£ãŠããã
ãã®äžæ¹ã§ããµã€ããŒæ»æããäŒæ¥ã®å€§åãªè³ç£ã§ãããæ å ±ããå®ã圹å²ãæ ãæ å ±ã»ãã¥ãªãã£å°éã¹ã¿ããã¯ã©ã®æ¥çš®ã«ãããŠãå§åçã«äžè¶³ããŠããã®ãçŸå®ã ããšãããäžå ã»äžå°äŒæ¥ãšãªãã°ãããå°æ°ã®æ å ±ã·ã¹ãã æ åœè ãã»ãã¥ãªãã£å¯Ÿç以å€ã«ãèšå€§ãªæ¥åãæ±ããªãããããããŠå¯Ÿå¿ããŠããã±ãŒã¹ãå€ãããã®ãããªãªãœãŒã¹äžè¶³ããããªãã»ãã¥ãªãã£ã»ã¬ãã«ã®äœäžã«ã€ãªãããããªãç¶æ³ã«ããã
å®éã2015幎ã«çºçããæ¥æ¬å¹Žéæ©æ§ã®æ å ±æŒããäºæ¡ã«ä»£è¡šãããå ¬çæ©é¢ãå€§äŒæ¥ãžã®ãµã€ããŒæ»æã®å¯Ÿè±¡ã¯ãçŸåšã§ã¯ããã¬ãŒãã®èãäžå ã»äžå°äŒæ¥ãžãšç§»ãã€ã€ãããå ±éã«ããã°ãçŸåšãäžçäžã§ææãæ¡å€§äžã®WannaCryã©ã³ãµã ãŠã§ã¢ã«ææããäŒæ¥ãå€ãããã ãããŸãäŒæ¥ã®èŠæš¡ãæ¥çš®ã«ããããããå€§äŒæ¥ã¬ãã«ïŒãšã³ã¿ãŒãã©ã€ãºã°ã¬ãŒãïŒã®ã»ãã¥ãªãã£å¯Ÿçãå¿ é ãšãªã£ãŠããã®ã§ããã
ãšã¯ããäžå ã»äžå°äŒæ¥ã«ãšã£ãŠå€§ããªå£ãšãªãã®ããå ã«æãã人çãªãœãŒã¹äžè¶³ã§ãããã»ãã¥ãªãã£å¯Ÿçã®ããã®ååãªæéãšããŠããŠããªããããå€§äŒæ¥ã¬ãã«ãšåæ§ã®ã»ãã¥ãªãã£å¯Ÿçã©ããããã¯ã©ã€ã¢ã³ãPCäžã®ã¢ã³ããŠã€ã«ã¹ãœããããã¡ã€ã¢ãŠã©ãŒã«ã ãã§æžãŸããŠããŸã£ãŠããäŒæ¥ãæå€ãšå€ãååšãããæ°ãããŠã£ã«ã¹ã1ç§éã«5åãçãŸããŠãããšããããŠãããªãã察å¿ãŸã§ã«æéãèŠããã¢ã³ããŠã€ã«ã¹ãœããã§ã¯æªç¥ã®ãã«ãŠã§ã¢ãé²ãããšãã§ããããã®ãŸãŸã§ã¯ãã€ãµã€ããŒæ»æã®è¢«å®³ã«ãã£ãŠãããããã¯ãªãã ãããç¹ã«æ ç¹ãè€æ°ååšããå Žåãæ å ±ã·ã¹ãã æ åœè ã®ç®ã®å±ãã«ããæ¬ç€Ÿä»¥å€ã®æ ç¹ã®ã»ãã¥ãªãã£ã»ã¬ãã«ã¯ããã«äœäžããŠããŸãããšã«ãªãã
ãã®ãããªäžå ã»äžå°äŒæ¥ãæ±ããã»ãã¥ãªãã£å¯Ÿçã®èª²é¡è§£æ±ºã«å€§ããªå¹æãçºæ®ããã®ãããšã³ããã€ã³ãããããã¯ãŒã¯ãªã©ãå æ¬ããå€å±€é²åŸ¡ã宿œãããšãšãã«ãããæ°å°ãªã人å¡ã§éäžç®¡çã§ããäœå¶ã¥ããã§ããããã®ããã®ã¢ãããŒãããå€ãã®å°å ¥äºäŸãããå žåçãªäŒæ¥ãµã³ãã«ãšããŠç޹ä»ãããã
ãCASE 01ã倿 ç¹å±éã®äžå äŒæ¥ãæ±ããã»ãã¥ãªãã£äžã®æ©ã¿
æ±äº¬ã«æ¬ç€Ÿãèµ·ããåœå ã«æ¯ç€Ÿ4æ ç¹ãšèš5æ ç¹ãå±éããè£œé æ¥ã®A瀟ã¯ãåŸæ¥å¡700人匱ãæããæ¥çäžå ã®å°äœã確ç«ããŠãããæ å ±ã·ã¹ãã æ åœè ã¯æ¬ç€Ÿã«3人ã§ãæ¯ç€Ÿã®ã»ãã¥ãªãã£å¯Ÿçã ãã§ãªãIT管çå šè¬ãæ ããå šæ ç¹ã®å šã¯ã©ã¢ã³ãã«ã¢ã³ããŠã€ã«ã¹ãœãããšãã¡ã€ã¢ãŠã©ãŒã«ãå°å ¥ããŠãããã®ã®ãæ å ±ã·ã¹ãã æ åœè ã®èª°ããçŸç¶ã®ã»ãã¥ãªãã£å¯Ÿçã§ã¯ååã§ã¯ãªãããšãéã æ¿ç¥ããŠãããããããªããITäºç®ãå³ããåãè©°ããããæ°ããªã»ãã¥ãªãã£ã»ã³ã¹ãã¯äžå±€éšããã®æ¿èªãåŸã¥ããç¶æ³ã«ãã£ãã®ã§ããã
ãããããªããæ¥çå£äœããæšçåæ»æãšã©ã³ãµã ãŠã§ã¢ã®è åšã«ã€ããŠã®ééããã£ãããšã«ãããçµå¶è ã®æ 床ãäžå€ãææ°ãã€æªç¥ã®è åšã«å¯ŸããŠããèªç€Ÿã®ãããã¯ãŒã¯ïŒã·ã¹ãã ãå®ãããšãã§ããå€å±€é²åŸ¡ããäžå åãããã»ãã¥ãªãã£ããªã·ãŒã«åºã¥ããŠéçšããç°å¢æ§ç¯ãæåªå ãããããšãšãªã£ãã
ãªãŒã«ã€ã³ã¯ã³ã§èª²é¡ã解決ããã¢ãããŒããéžæ
è€æ°ã®ãœãªã¥ãŒã·ã§ã³ãæ¯èŒæ€èšããçµæãA瀟ãå°å ¥ããã®ãããŠã©ããã¬ãŒãã»ãã¯ãããžãŒã»ãžã£ãã³ïŒä»¥äžããŠã©ããã¬ãŒãïŒãæäŸããUTMïŒçµ±å管çïŒïŒNGFWïŒæ¬¡äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ïŒã¢ãã©ã€ã¢ã³ã¹ãFireboxãã·ãªãŒãºãšããããšé£æºããŠçšŒåããWIPSïŒã¯ã€ã€ã¬ã¹äžæ£äŸµå ¥é²æ¢ã·ã¹ãã ïŒãåããã¯ã©ãŠã察å¿Wi-Fiã¢ã¯ã»ã¹ãã€ã³ããWatchGuard Access Pointããœãªã¥ãŒã·ã§ã³ã§ãã£ããéžå®çç±ã¯ããŸããŸã ããA瀟ãç¹ã«éèŠããã®ã以äžã®ç¹ã§ããã
ã»éçšç®¡çæ§ãé«ããå°ãªã人å¡ã§ã容æã«å€æ ç¹ã®ã»ãã¥ãªãã£ã管çã§ãã
ã»äžå çãªã»ãã¥ãªãã£ããªã·ãŒã«åºã¥ãããèªååãå«ããå¹ççãªéçšãå¯èœ
ã»å¶æ¥éšéããªãã£ã¹å€ã§æ¥åãè¡ããããªããªãã©ã€ã³ç°å¢ã§ãã©ã³ãµã ãŠã§ã¢å¯Ÿçãæå¹
ã»ç¡ç·LANã¢ã¯ã»ã¹ãã€ã³ããå«ããã»ãã¥ãªãã£ã®äžå 管çãå¯èœ
ã»ãã¹ãŠã®ã»ãã¥ãªãã£æ©èœãæå¹ã«ããç¶æ³ã§ããæ³å®ä»¥äžã«ã¹ã«ãŒããããžã®åœ±é¿ãçºçããªãããš
ã»æå·åéä¿¡ã«æœãã§ãããã«ãŠã§ã¢ãæ€ç¥ã§ãããŸãæå·åéä¿¡ã®æ€ç¥æ©èœãæå¹ã«ããŠãã¹ã«ãŒããããžã®åœ±é¿ãå°ãã
ã»æ°ããªæ»æææ³ã«å¯Ÿããæ©èœã®ã¢ããããŒããæ°èŠæ©èœã®æ¡åŒµãæè»ã«è¡ãããã©ãããã©ãŒã
ãFireboxãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãIPSïŒäžæ£äŸµå ¥æ€ç¥ã»é²åŸ¡ïŒãã²ãŒããŠã§ã€ã¢ã³ããŠã€ã«ã¹ãWebã³ã³ãã³ããã£ã«ã¿ãªã³ã°ãè¿·æã¡ãŒã«å¯Ÿçãã¢ããªã±ãŒã·ã§ã³ã³ã³ãããŒã«ãæšçåæ»æå¯Ÿçãæ å ±æŒãã察çãã©ã³ãµã ãŠã§ã¢å¯Ÿçãªã©ãå€åœ©ãªã»ãã¥ãªãã£æ©èœãæèŒãããçµ±ååã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ãšãªã£ãŠããããŠã©ããã¬ãŒã補åã¯ãUTMïŒNGFWãšããŠã®æ©èœã®ã»ãã«ããæšæºã§æäŸãããå¯èŠåããŒã«ããããã¯ãŒã¯äžã®ãšã³ããã€ã³ããèŠèŠåãã管çããŒã«ãªã©ãéçšç®¡çãæ¯æŽããããã®è±å¯ãªæ©èœãæäŸãããŠãããæ°ããªæ©èœããµãŒãã¹ã®è¿œå ã«é¢ããŠããæè»ã«å¯Ÿå¿å¯èœãªãã©ãããã©ãŒã ãæäŸããŠããã
ãã¹ãŠã®æ©èœãå å«ãããTotal Security Suiteãã©ã€ã»ã³ã¹ã¯ãšã³ããã€ã³ãã§ã©ã³ãµã ãŠã§ã¢å¯Ÿçãè¡ããã¹ãã»ã³ãµãŒãå«ããã¹ãŠã®ã»ãã¥ãªãã£æ©èœãå©çšå¯èœãšãªããæ°ããªæ©èœè¿œå ã®ããã®ããŒããŠã§ã¢ããªãã·ã§ã³ã©ã€ã»ã³ã¹ã®è³Œå ¥ã¯å¿ èŠãªããææ°ã®ã»ãã¥ãªãã£ã®è åšãšæŠãããã®ããã¹ãŠã®æ©èœããµãŒãã¹ãããã«å©çšå¯èœãšãªãç¹ãä»ç€Ÿè£œåã«ã¯ãªã倧ããªç¹åŸŽã ã
ã»ãã¥ãªãã£éçšç®¡çã®èªååãå®çŸ
A瀟ã§ã¯ãæ¬ç€Ÿã«ã¯ãFireboxãã®1Uã®ãããã¬ã³ãžã»ã¢ãã«ãèšçœ®ããåæ ç¹ã«ã¯ãFireboxãã®ããŒãã«ãããã»ã¢ãã«ãèšçœ®ãããããã®æ ç¹ã®éã¯ãFireboxããåããä¿¡é Œæ§ã®é«ãVPNæ©èœãå©çšããããšã§ãæ ç¹ééä¿¡ã«ãããã»ãã¥ãªãã£ã®ç¢ºä¿ãšåç·ã³ã¹ãåæžã®åæ¹ãå®çŸããã
å°ãªã人å¡ã§å€æ ç¹ã®ITã·ã¹ãã ã管çããA瀟ã«ãšã£ãŠãéçšç®¡çã®èªååãšéäžç®¡çã«å€§ãã圹ç«ã£ãã®ããã¯ã©ãŠãããŒã¹ã®ãµãŒãã¹ã§ãããThreat Detection and ResponseïŒTDRïŒïŒè åšæ€ç¥ïŒã¬ã¹ãã³ã¹ãã ãTDRã¯åæ ç¹ã«çœ®ããããFireboxããšãäŒæ¥å ã®ãã¹ãŠã®ãšã³ããã€ã³ãã«çµã¿èŸŒãŸããã»ã³ãµãŒãHost Sensorãã®åæ¹ããã»ãã¥ãªãã€ã€ãã³ãæ å ±ãåéããã¯ã©ãŠãäžã®è åšæ å ±å ±æåºç€ãThreatSyncãã§çžé¢åæãè¡ããã€ã³ã·ãã³ãã¬ã¹ãã³ã¹ã®èªååãå®çŸãããµãŒãã¹ã§ãããTDRã«ããã©ã³ãµã ãŠã§ã¢ããªã¢ã«ã¿ã€ã ã«æ€ç¥ããã©ã³ãµã ãŠã§ã¢ã«ããæå·åã宿œãããåã«ãå¿ èŠãªå¯Ÿçããšã³ããã€ã³ãã§å®è¡ããããšãå¯èœãšãªãããŸããæªæã®ããæ¯ãèããæ€ç¥ãããªã¹ã¯ãšéèŠåºŠã®é¢ããè åšæ å ±ã®ã¹ã³ã¢ãªã³ã°ãè¡ãããšãã§ããã
TDRã¯ãè åšã®ã¹ã³ã¢ãªã³ã°ã«å¿ããŠãšã³ããã€ã³ãã§ã®å¯Ÿå¿ïŒã¬ã¹ãã³ã¹ïŒãèªåçã«è¡ãããããªã·ãŒãå®çŸ©ã§ãããããA瀟ã§ã¯æ å ±ã·ã¹ãã æ åœè ã®è² è·äœæžãå³ãã¹ãã平垞æã«ã¯ç®¡çè ã®ä»åšãªãã§ãã¯ãªãã£ã«ã«ãªãµã€ããŒæ»æã«åããäºãå¯èœãªèªåéçšãæ¡çšãããªã·ãŒã«ã¯èªåã¬ã¹ãã³ã¹ã®ãããå€ãèšå®ã§ããããšããããéåžžæããèŠææããç·æ¥æããšãç·æ¥åºŠã«å¿ããããªã·ãŒãèšå®ãããèªåã¬ã¹ãã³ã¹ã«ããã¢ã¯ã·ã§ã³ä»¥å€ã®å¯Ÿå¿ã§ãæšå¥šãããã¢ã¯ã·ã§ã³ãæç€ºãããã®ã§å®å¿æãé«ãã
å šç€Ÿã®ãããã¯ãŒã¯ã»ãã¥ãªãã£ãå¯èŠåããããã·ã¥ããŒãã§ç®¡ç
èªåã¬ã¹ãã³ã¹ã§ã®éçšãæ¡çšãããšããŠããæ¥ã ã®ãããã¯ãŒã¯ã®ç®¡çã»ç£èŠã¯å¿ èŠãšãªããããã§A瀟ã§ã¯ãè åšãå¯èŠåãããFireboxãã·ãªãŒãºã§æšæºæäŸã®ãWatchGuard DimensionïŒä»¥äžãDimensionïŒãã倧ãã«æŽ»çšããããšãšãããDimensionã¯ãããžã¥ã¢ã«åãããç£èŠæ©èœã«ããããããã¯ãŒã¯ã»ãã¥ãªãã£ã®è åšã課é¡ãå³åº§ã«æ€ç¥ããã¬ããŒããçæå¯èœããããšãã§ãããã¯ã©ãŠã察å¿ã®ãããã¯ãŒã¯ã»ãã¥ãªãã£å¯èŠåãœãªã¥ãŒã·ã§ã³ã ãèªç€Ÿã®ãããã¯ãŒã¯ã®ã»ãã¥ãªãã£ç¶æ³ãçŽæçãªUIã§ãªã¢ã«ã¿ã€ã ã«å¯èŠåããããããæè»ãªã»ãã¥ãªãã£ããªã·ãŒã®éçšãä¿ããã¯ã©ãŠã察å¿ã®ãã管çããæéãå ŽæãåããªãããšãããA瀟ã§ã¯æ¬ç€Ÿããã®å šæ ç¹ã®éäžç®¡çãå¯èœãšãªã£ãã
Aç€Ÿã®æ å ±ã·ã¹ãã æ åœè ã¯ãDimensionã®ããã·ã¥ããŒãããããããã¯ãŒã¯ãã¯ã©ã€ã¢ã³ãããšã®ç£èŠãè¡ã£ãŠãããéä¿¡éã®å€ãããã€ã¹ããã䜿ããããããã¯ãŒã¯ã¢ããªã±ãŒã·ã§ã³ãã¢ã¯ã»ã¹é »åºŠã®é«ãURLãªã©ã®ææ¡ãå¯èœãšãªã£ããããã€ã¹ããšã«ã¢ããªã±ãŒã·ã§ã³ã®å©çšãå¶åŸ¡ã§ããããããã«ãŠã§ã¢ææã®ãªã¹ã¯åæžãšãããã¯ãŒã¯åž¯åã®æé©åã®ããã«ãA瀟ã§ã¯éšçœ²ããšã«äœ¿çšã§ããã¢ããªã±ãŒã·ã§ã³ãå¶éããã»ããæŒäŒã¿ã«ã¯SNSãªã©ã®æ¥åå€ã¢ããªã±ãŒã·ã§ã³ã®å©çšãéæŸããéçšã«ããã
ãŸãã圹å¡ãããã»ãã¥ãªãã£ããããã¯ãŒã¯ã®å©çšç¶æ³ã«é¢ããå æ¬çãªæ å ±ææ¡ãæ±ããããŠããA瀟ã§ã¯ãããèŠèŠè¡šçŸãå€çšããããã·ã¥ããŒããã宿çã«PDFã¬ããŒããçæããŠå ±åããŠããã
ç¡ç·LANã¢ã¯ã»ã¹ãã€ã³ãã®ã»ãã¥ãªãã£åŒ·åãšã¯ã©ãŠã管çã«ããéçšè² è·ã®åæž
A瀟ã§ã¯ãä»åã®ãŠã©ããã¬ãŒã補åã®æŽ»çšãäžå¿ãšããå šç€Ÿçãªã»ãã¥ãªãã£ã¬ãã«åäžã«äŒŽããåæ ç¹å ±éããŠç¡ç·LANãå°å ¥ãããã«äŒŽããã¬ãã·ãã«ãªäœæ¥ç°å¢ãå®çŸããçç£æ§ã®åäžãç®æããŠããã
ç¡ç·LANã®ã¢ã¯ã»ã¹ãã€ã³ãã«ã¯ããŠã©ããã¬ãŒãã®ã¯ã©ãŠã管çåã¢ã¯ã»ã¹ãã€ã³ããWatchGuard Access Pointããæ¡çšããã®ãœãªã¥ãŒã·ã§ã³ã«ã¯ãWIPSïŒã¯ã€ã€ã¬ã¹äžæ£äŸµå ¥é²æ¢ã·ã¹ãã ïŒæ©èœãæšæºã§æèŒãããŠããããšãªã¢å ã®ã»ãã®ãã¹ãŠã®ã¢ã¯ã»ã¹ãã€ã³ããç¶ç¶çã«ã¹ãã£ã³ãããæ¿èªæžã¿ããå€éšããäžæ£ãã®ããããã«åé¡ããããšã§ãèš±å¯ãããŠããªãã¢ã¯ã»ã¹ãã€ã³ããžã®æ¥ç¶ã黿¢ãããããã«ãã®WIPSã¯èª€æ€ç¥çãã»ãŒãŒãã§ãæªæ¿èªããã€ã¹ãäžæ£ã¢ã¯ã»ã¹ãã€ã³ããããã³æªæããæ»æããç¡ç·LANç°å¢ã24æé365æ¥ä¿è·ããããšãå¯èœã ã
A瀟ã§ã¯ã»ãã¥ã¢ãªç¡ç·LANãå®çŸãããWatchGuard Access Pointãã®WIPSãæŽ»çšããããšã§ã瀟å ã®ããã€ã¹ããå€éšãäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã«ã¢ã¯ã»ã¹ãããªãç°å¢ãå®çŸãããã«å šæ ç¹ã®ãŠãŒã¶ãŒã®è©³çްãªå©çšç¶æ³ã®ææ¡ãšåæãã¯ã©ãŠãããŒã¹ã®ç®¡çããŒã«ãããã€ã§ãã©ãã§ãè¡ããããã«ããã
A瀟ã®ã¢ãããŒãã¯ãã¹ãŠã®äŒæ¥ã«æå¹ïŒ
ããããŠA瀟ã§ã¯ãå°ãªãã¹ã¿ããã«ãã倿 ç¹ã§ã®ã»ãã¥ãªãã£éçšãšããå°é£ãªèª²é¡ãå æãå€§äŒæ¥ã¬ãã«ã®ã»ãã¥ãªãã£ã人çè² è·ãã³ã¹ãã®äž¡é¢ããç¡çãªãå®çŸããã®ã§ãããåæ§ã®ã¢ãããŒãã¯ãããå°èŠæš¡ã§åäžæ ç¹ã®äŒæ¥ã§ãã£ãŠãæå¹ã ããã²A瀟ã®äºäŸãåèã«ãèªç€Ÿã®ã»ãã¥ãªãã£ã»ã¬ãã«ãæé©ãªã³ã¹ãã§ãšã³ã¿ãŒãã©ã€ãºã°ã¬ãŒãã«é«ããŠã¯ãããã ãããïŒ
[PR]æäŸïŒ





