ãµã€ããŒæ»æã®é«åºŠåã»å·§åŠåãåããŠãåŸæ¥ãªããã®äºå察çã«å ããäºåŸå¯Ÿçã®å¿ èŠæ§ãå«ã°ããŠããããšããããŠãã®äºåŸå¯Ÿçã广çã«å®è·µããããã«æ¬ ãããªãããŒã«ãšããŠãEDR(Endpoint Detection and Response)ããæ³šç®ãããŠããããã¯ãâEDRããŒã âã®æ§çžããåããŠããããšã«ã€ããŠè¿°ã¹ããããã§æ¬é£èŒç¬¬2åç®ãšãªãä»åã¯ãåã»ãã¥ãªãã£ãã³ããŒãããã£ãŠãªãªãŒã¹ããEDR補åããããéžã¶éã«å¿ èŠãšãªããæããã¹ããã€ã³ããã玹ä»ããã
ãŸãã¯ç®çã®æç¢ºåã
EDRãšããã®ã¯ã¢ã³ããŠã€ã«ã¹ããã¡ã€ã¢ãŠã©ãŒã«ã®ããã«ãå°å ¥ããã ãã§èªåçã«ãµã€ããŒæ»æãã察象ãå®ã£ãŠããããœãªã¥ãŒã·ã§ã³ãšã¯ç°ãªããæ å ±ã·ã¹ãã æ åœè ãã»ãã¥ãªãã£æ åœè ã調æ»ããŒã«ãšããŠèœåçã«äœ¿ãããªãããšãåæãšãªã£ãŠããããã®ããã瀟å ã§EDRãã©ã䜿ãããšããŠããã®ããæåã«ç®çãæç¢ºã«ããŠãããªããšãâPoC(å®èšŒè©Šéš)ããã£ãŠãããŸãâãšããçµæã«ãªããããªãã
ãã®ç®çã¯äŒæ¥ã«ãã£ãŠãŸã¡ãŸã¡ã ããããšãã°CSIRTãèšçœ®ããŠããäŒæ¥ã§ããã°ãèšçœ®ããŠããªãäŒæ¥ä»¥äžã«ã€ã³ã·ãã³ãã¬ã¹ãã³ã¹ãæ¯æŽããããŒã«ãšããŠEDRã®å®åãçºæ®ã§ããã ããããŸãããã©ã¬ã³ãžãã¯ãå éšç£æ»ãšãã£ãã³ã³ãã©ã€ã¢ã³ã¹ã®éµå®ãäžæ£é²æ¢ãšãã£ãçšéã«ãæå¹ã ããããã«ãããã©ã®EDR補åãå°å ¥ãããã®è°è«ä»¥åã«ããŸãã¯èªç€Ÿã®ã€ã³ã·ãã³ãã¬ã¹ãã³ã¹ã®äœå¶ãæé ãæŽã£ãŠããã®ãã確èªããããã«ãããã
ã©ãã ãæ€ç¥ã§ããã
ããã§ã¯ããããããããããæ¬é¡ãEDR補åãéžå®ããéã«å¿ ãæããŠããããæ¯èŒãã€ã³ãã«ã€ããŠè§£èª¬ããŠãããã
ããã€ã³ã1ãæ€ç¥å
EDRãå°å ¥ããäŒæ¥ãå®éã«éçšãè¡ããªãã§ãŸãçŽé¢ãã課é¡ãã誀æ€ç¥ãã ã
ãšã³ããã€ã³ãã«ããããæ¬åœã¯è åšã§ã¯ãªãæåããŸã§EDRãè åšãšã¿ãªããŠããŸããã¢ã©ãŒããé »çºããŠããŸããšãã£ãã±ãŒã¹ããã®æããäŸã§ããããããªããšæ åœè ã¯èª¿æ»ã«è¿œãããŠããŸããããã調æ»ããŠã¿ããšè åšã§ã¯ãªãã£ããšããã±ãŒã¹ã°ãããšãªããããæ¬ç©ã®è åšãæ€ç¥ããã¢ã©ãŒãã«å¯ŸããŠãããŸããããšè»œãããŠèŠéããŠããŸãäºæ ã«é¥ããããªããEDRãâãªãªã«ãå°å¹Žâãšãªã£ãŠããŸãã®ã¯ç¬ããªã話ã ããããããã±ãŒã¹ã¯å®éã«ã¿ãããŠããã
EDRã¯ãšã³ããã€ã³ãã®æåãç¶ç¶çã«ç£èŠããŠãããããäžå®ã®ã«ãŒã«ã«æ²¿ã£ãŠãäžå¯©ãªæå(ïŒè åšã®å¯èœæ§)ããæ€åºãããããããäžå¯©ãªæåãEDRãæ€åºã§ããªãã£ããããããã¯éåžžã®æåãå«ããŠäœã§ãããã§ãäžå¯©ãªæåãšå€æããŠã¢ã©ãŒããåºãç¶ãããããã®ã§ã¯ãããããã®åæã厩ããŠããŸããå®å šãªæåãè åšãšã¿ãªãã¿ã€ãã®èª€æ€ç¥ã«ã€ããŠã¯ã«ãŒã«èšå®ãšã®å Œãåããããã®ã§ããã®ç¹ã«ã€ããŠã¯åŸè¿°ããããšãšããã
-

éåžžã®æåãè åšãšèª€æ€ç¥ããããšãªããæ¬ç©ã®è åšã ããæ£ããæ€ç¥ããæ£ç¢ºæ§ãéèŠ
ãªã®ã§ãããã§ã¯ãŸãEDRãã¢ã³ããŠã€ã«ã¹ããã¡ã€ã¢ãŠã©ãŒã«ãšãã£ãæ¢åã®ã»ãã¥ãªãã£è£œåãšã¯ç°ãªããèŠéãããŠããŸã£ãè åšã«éããã«å¯ŸåŠããããã®ãã®ã§ããããšãããããã«è åšãšãªãããããããæåãæ€åºã§ããé«åºŠãªæ€åºãšã³ãžã³ãåããé«ãæ€ç¥åãæã€è£œåãéžã¶ãšããããšããã€ã³ããšããŠããããã
ãããŠãã§ããã°ãšã³ãžã³ã1ã€ã§ã¯ãªããè€æ°ã®ãã®ãçµã¿åãããŠããã»ãããããã ãå€è§çãªè§£æãè¡ããããæ€ç¥çãé«ãŸãã ãããããã«ãæšä»ã§ã¯AIãæ©æ¢°åŠç¿ãªã©ãçšããæ€åºãšã³ãžã³ãç»å ŽããŠããŠãããããããææ°ã®ãã¯ãããžãŒãšã®çµã¿åãããéèŠãªãã€ã³ããšãªãã ããã
ãŸããEDRã¯èªç€Ÿã«æœãè åšãå¯èŠåããŠå¯Ÿçãè¡ãããã®ãã®ã§ãããããåã«æ€ç¥ã§ãããšããã ãã§ã¯ååã§ã¯ãªãããªãè åšã§ãããšå€æããã®ãããã®å€æçç±ãŸã§ç€ºããããšãå¿ èŠãšãªã£ãŠããã
å®éã®éçšãæ³å®ããŠ
ããã€ã³ã2ãéçšæ§/ã«ã¹ã¿ãã€ãºæ§
åè¿°ã®ãšãããEDRã¯ãšã³ããã€ã³ãã®æåãç¶ç¶çã«ç£èŠããŠãããããäžå®ã®ã«ãŒã«ã«åããäžå¯©ãªæå(ïŒè åšã®å¯èœæ§)ããæ€åºãããã®ã ããæ€åºããæåãè åšãšå€å®ããåºæºã¯äŒæ¥ããšã«ããªãç°ãªã£ãŠãããä»®ã«ãã管çè æš©éã§å®è¡ãã¡ã€ã«ãéãããšããæåããã£ããšããŠãããã¯ãŠãŒã¶ãŒã®æå³ãããæ£åœãªæåããããããªããããããã¯ãã«ãŠã§ã¢ãªã©ãåŒãèµ·ããããäžæ£ãªæåããããããªãã
ãã®ããã«ããšã³ããã€ã³ãã«ãããŠç®¡çè æš©éã§å®è¡ãã¡ã€ã«ãéãããšããæåãæ€åºãããéãEDRã«ã¯ã©ã¡ãã«å€æããŠã»ããã®ããšããåºæºã¯ãäŒæ¥ããšã«ãŸã¡ãŸã¡ã§ããã¯ãã ãããã«ãå¶æ¥ãäŒç»ãªã©ã®éšéã§ã¯åºæºã®ããŒãã«ãæ¯èŒçäœããéã«ç·åã»äººäºãç ç©¶éçºãªã©ã®å€ãã®æ©å¯æ å ±ãæ±ãéšéã§ã¯ããŒãã«ãé«ãã«ãšãã£ãããã«ãåãäŒæ¥ã§ãã£ãŠãã«ãŒã«ãç°ãªã£ãŠããããšãå€ãã
ãã®ãããEDRã®å°å ¥åŸã«ã¯ãæ€ç¥ã«ãŒã«ãèªç€Ÿç°å¢ã«åãããŠæé©åããäœæ¥ãå¿ é ãšãªãããéçšéå§åŸããããç¶ç¶çã«ãã¥ãŒãã³ã°ããŠãããªããã°ãªããªãããã®ãã¥ãŒãã³ã°ãã«ã¹ã¿ãã€ãºã®ãããããEDR補åéžã³ã®ãã€ã³ããšãããã ããã
-

åäœãè¡ã£ãã®ãã·ã¹ãã éçºã«æºããéšéã®ç€Ÿå¡ãäžè¬ç€Ÿå¡ãã«ãã£ãŠããã®æåã®æ£åœæ§ã倿ã§ããã«ã¹ã¿ãã€ãºã®ããããããã€ã³ã
æ¢å補åãšã®å ±åãèãã
ããã€ã³ã3ãã¢ã³ããŠã€ã«ã¹ãã¢ã³ããã«ãŠã§ã¢è£œåãšã®çžæ§
æå€ãšèŠèœãšããã¡ã§å°å ¥åŸã«åé¡ãçããããã®ããã®ãã€ã³ãã ãããŸãã»ãšãã©ã®äŒæ¥ãã¢ã³ããŠã€ã«ã¹è£œåãå°å ¥ããŠããã¯ãã ãããããã補åãEDRãšåãããšã³ããã€ã³ããå®ãã»ãã¥ãªãã£è£œåã§ããããããã©ãã©ã®è£œåãå°å ¥ããŠããŸããšå€§å±çãªç®çã¯åãã§ããã®ã«ç®¡çã¯å¥ã âŠâŠããšããéå¹çãªéçšãæ±ããããããšãšãªãã
ãŸãäž¡è ã®ç«¶åã®åé¡ã«ãé æ ®ããå¿ èŠããããã¢ã³ããŠã€ã«ã¹ãEDRãå€ããã·ã¹ãã ã®ææ·±éšã®æ å ±ãŸã§ååŸã§ããã«ãŒãã«ã¢ãŒãã§çšŒåããããããšã³ããã€ã³ãäžã§å ±åããéã®åœ±é¿ããã£ããèŠæ¥µããã°ãªããªããå Žåã«ãã£ãŠã¯ã·ã¹ãã èªäœã匷å¶çã«ã·ã£ããããŠã³ããŠããŸããšãã£ããªã¹ã¯ãæ³å®ããããå©äŸ¿æ§ãšã»ãã¥ãªãã£ãšã¯ãã¬ãŒããªãã®é¢ä¿ãšããããããããã¢ã³ããŠã€ã«ã¹ãšEDRã®ç«¶åã®åœ±é¿ã§ãšã³ããã€ã³ãã®ããã©ãŒãã³ã¹ãäžãã£ãŠããŸã£ãã®ã§ã¯ããšã³ããŠãŒã¶ãŒã®ã¹ãã¬ã¹ãé«ãŸããã²ããŠã¯äŒæ¥å šäœã®çç£æ§äœäžããæããããªãã
ããããå ±åã«é¢ããåé¡ãé¿ããã«ã¯ãã¢ã³ããŠã€ã«ã¹è£œåãšåããã©ã³ãã®EDR補åãéžã¶ã®ãåŸçã ãç¹ã«ã¢ã³ããŠã€ã«ã¹ãšé£æºããŠåäœãããããªEDRã§ããã°ãåé¡ãé¿ããã°ããããããé«ãã»ãã¥ãªãã£ã®å®çŸã«ãå¯äžããããšã ããã
-

EDRãšã¢ã³ããŠã€ã«ã¹ãåããã©ã³ãã®è£œåã§éçšããããšã§ãå¹ççãã€ããé«ãã»ãã¥ãªãã£ãå®çŸ
ãã®ã»ãã«ããã³ã¹ãããã³ããŒã®å®çžŸããµããŒãäœå¶ãæãŠã¯ã¯ã©ãŠãããªã³ãã¬ãã¹ãããªã©ã補åãéžã¶ããã§æããŠãããããã€ã³ãã¯ãããã®ã®ãããã§ã¯æãéèŠãã€èŠèœãšããã¡ãªãã®ããããŠEDRã ããããã®ãã€ã³ãã«ãã©ãŒã«ã¹ãããŠããã ããã æ¬é£èŒã®æçµåãšãªã第3åã¯ãæ¬çš¿ã§åãäžããæããã¹ããã€ã³ããç¶²çŸ ãããçæ³çãªEDR補åããããESET Enterprise Inspectorãããã³ããŒæ åœè ã®å£°ãšãšãã«ç޹ä»ããã
ã»ãã¥ãªãã£æåç·
ãµã€ããŒæ»æã®ææ°ååãšã»ãã¥ãªãã£å¯Ÿçã«ã€ããŠãŸãšããã«ããŽãªã§ãã
[PR]æäŸïŒãã€ãã³ããŒã±ãã£ã³ã°ãžã£ãã³