ãã«ãŒããã€ã³ããéžãã äŒæ¥ã®å€ãã¯ããã«ãŒããã€ã³ããé·ãéæçšããã ããŠããŸããå€ãã®äŒæ¥ã¯ããã«ãŒããã€ã³ãã®ã¡ãŒã«ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®äœ¿çšããå§ãŸãããã®ä»ã®ãµã€ããŒã»ãã¥ãªã㣠ããŒã«ã«ãã«ãŒããã€ã³ã補åãçµã¿åãããŠããŸãããããŠæçµçã«ã¯ãã¢ã€ãã³ãã£ãã£è åšãæ å ±ä¿è·ãªã©ããã®ä»ã®æ»æå¯Ÿè±¡é åã«å¯ŸããŠããã«ãŒããã€ã³ãã®è£œåãå°å ¥ããŠããŸãã
ããããçµå¶é£ãäžããæ±ºå®ã«ãããAbnormal Securityã®æ¡çšãäœåãªãããããã©ãããŸããïŒããFortune 500éèãµãŒãã¹äŒç€Ÿã«ãããŠå®éã«èµ·ãã£ãããšãæ¬ããã°ã§ã玹ä»ããŸãããã®äŒç€Ÿã¯å®éã«ProofpointãšAbnormal Securityã®äž¡æ¹ã䜿ã£ãçµéšããã䞡瀟ã®éãã«ã€ããŠèªã£ãŠãããŸããããã®å 容ãã玹ä»ããŸãã
å€å±€çãªé²åŸ¡ã¢ãããŒã
Microsoft 365 E5ãå©çšããŠãããã®äŒç€Ÿã¯ãå€å±€çãªé²åŸ¡ã»ãã¥ãªãã£ã¢ãããŒããå°å ¥ããŸããããã€ãã£ãã®ã»ãã¥ãªãã£æ©èœãMicrosoft Defenderã¡ãŒã«ã»ãã¥ãªãã£æ©èœã§ã¯ããã£ãã·ã³ã°ããã«ãŠã§ã¢ãã©ã³ãµã ãŠã§ã¢ãæ€ç¥ãããããã¯ããã®ã«ååã§ã¯ãªãã£ãããã§ãããŸããCrowdStrikeã䜿çšããProofpoint Threat Protectionã§ãããã®ããŒã«ãè£å®ããŠããŸããããã«ãŒããã€ã³ãã«ããã以äžãå«ãå·§åŠãªã¡ãŒã«è åšãæ€ç¥ãããããã¯ããããšãã§ããŸããã
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æ»æ
- ããžãã¹ã¡ãŒã«è©æ¬ºïŒBECïŒ
- é«åºŠãªèªèšŒæ å ±ãã£ãã·ã³ã°
ãã®äŒç€Ÿã¯ãMicrosoftãProofpointãCrowdStrikeãçµã¿åãããããšã«ããããã¯ãã«ãªã¡ãŒã«ã»ãã¥ãªãã£ãæã«å ¥ããŸããã äžçäžã®ãªãã£ã¹å šäœã§ã¡ãŒã«è åšãæ€ç¥ãããããã¯ãã修埩ãèªååã§ããŠããã®ã§ãã ãŸããã¡ãŒã«é ä¿¡ãããŒå šäœïŒé ä¿¡åãé ä¿¡åŸãã¯ãªãã¯æïŒã«ãããŠç¶ç¶çãã€åŒ·åãªæ€ç¥ã¢ãã«ãåããŠããŸãã å®éã«ãFortune 100äŒæ¥ã®87%ããã«ãŒããã€ã³ããå©çšããåŸæ¥å¡ãšäŒæ¥ãä¿è·ããŠããŸãã
ãã®äŒç€Ÿã®çµå¶é£ã¯å€å±€çãªé²åŸ¡ã¢ãããŒããä¿¡ããŠããããã远å ã®é²åŸ¡ã¬ã€ã€ãŒãšããŠAbnormal Securityã远å ããããšã決ããŸããã Abnormalã¯ã䜿ãããããç¹åŸŽãšããããAPIããŒã¹ã®é ä¿¡åŸä¿®åŸ©å°çšããŒã«ã§ãã æ¯ãèãAIãæèŒãããèšå®ããã°åŸã®äœæ¥ã¯äžèŠãã®ããŒã«ãšããŠè²©å£²ãããŠãããã¡ãŒã«è åšãè¿ éã«æ€ç¥ãã修埩ããªãããéçšå¹çãåäžãããããšè¬³ã£ãŠããŸãã
ãã®ããããã®äŒç€Ÿã¯ã䜿çšäžã®Microsoft 365 APIã«Abnormalãçµ±åããAbnormalã¯Microsoftããã®ã¡ãŒã«ãåä¿¡ã§ããããã«ããŸãããAbnormalã®ããŒã«ã«é ä¿¡åŸã®ã¡ãŒã«åæãæ ããããããProofpoint Threat Response Auto-Pullã§ã®èªå修埩ãç¡å¹ã«ããŸããã
ãAbnormalã¯èšå®ããã°åŸã®äœæ¥ã¯äžèŠããšèããããŠããŸããããçŸå®ã¯çšé ããã®ã§ãããã
â Fortune 500éèãµãŒãã¹äŒç€Ÿã®ããŒã¿ã»ãã¥ãªãã£æ åœITãã£ã¬ã¯ã¿ãŒ
çŽæ¥æ¯èŒïŒProofpoint vs. Abnormal
Abnormalã®äœ¿çšãéå§ãããšããµã€ããŒã»ãã¥ãªãã£ããŒã ã¯ããã®ãœãªã¥ãŒã·ã§ã³ã§ã§ããããšãæ¢ããäŒç€Ÿã®æ°ããå€å±€çãªé²åŸ¡ã¢ãããŒãã®é²åç¶æ³ãè©äŸ¡ããŸããã æèŠã¯ä»¥äžã®ãšããã§ãã
é ä¿¡åã®æå¹æ§ïŒãã«ãŒããã€ã³ããæå©
Proofpointãšã¯ç°ãªããAbnormalã¯é ä¿¡åã®æ€ç¥ãŸãã¯åææ©èœãæäŸããŠããããé ä¿¡åã®æå¹æ§ã¯0%ã§ãã Abnormalãšæ¯èŒããŠããã«ãŒããã€ã³ãã®é ä¿¡åæ€ç¥ã¯ãæ¢ç¥ã®è åšãæ°ããè åšããŠãŒã¶ãŒã®åä¿¡ãã¬ã€ã«å±ãåã«é»æ¢ããŸãã ããã«ããããŠãŒã¶ãŒã¯è åšãšæ¥è§Šããããšãªããã»ãã¥ãªãã£ããŒã ãžã®è² æ ã軜æžããããšãã§ããŸãã
Proofpointã¯ããã«ãã¬ã€ã€ãŒã®æ€ç¥ã¹ã¿ãã¯ã䜿çšããããŸããŸãªè åšãæ£ç¢ºã«ç¹å®ãããšãããŸãã Proofpointã®åºç¯ãªæ€ç¥æè¡ã»ããã«ãããé©åãªæè¡ãé©åãªè åšã«é©çšããããšãã§ããŸããããã«ã¯QRã³ãŒãè©æ¬ºãURLããŒã¹ã®è åšãBECæ»æãå«ãŸããŸãã
Proofpointã¯ãæ¢åã®æ·»ä»ãã¡ã€ã«ã®é²åŸ¡ãšãURLãå«ãã¡ãã»ãŒãžã«å¯Ÿããæ°ããé ä¿¡åããŒã«ããšãµã³ãããã¯ã¹ãçµã¿åãããããšã«ããããŠãŒã¶ãŒã®åä¿¡ãã¬ã€ã«å±ãæªæã®ããURLãå±éºãªãã€ããŒãã®æ°ãæããŠããŸãã ããã«ã¯ã¡ãŒã«ã«å«ãŸããã³ãŒããæªæã®ããæ·»ä»ãã¡ã€ã«ãªã©ããããŸãããŸããã»ãã³ãã£ãã¯è§£æã䜿çšããæ°ããé ä¿¡åå€§èŠæš¡èšèªã¢ãã«ïŒLLMïŒæ€ç¥ãšã³ãžã³ã«ãããçµç¹ã¯BECãªã©ã®è åšãããä¿è·ãããŸãã ãã®ãšã³ãžã³ã¯ãã¡ãŒã«ã¡ãã»ãŒãžã®èšèªã®æå³ãšã³ã³ããã¹ããå€å®ããããšãã§ããŸãã
ãã«ãŒããã€ã³ãã¯ãAIãMLã«ãããŠ20幎以äžã®çµéšãèªããŸãã ãã«ãŒããã€ã³ãã®ã¢ãã«ã¯ãè±å¯ãªããŒã¿ã»ããã§ãã¬ãŒãã³ã°ãããŠãããããåªããæ£ç¢ºæ§ãšå¹çæ§ãæäŸããŸãã äžç51äžä»¥äžã®çµç¹ã«ããæ¯å¹Ž3å ä»¶ã®ã¡ãã»ãŒãžãè§£æãããŠããŸãã ãã«ãŒããã€ã³ãã§ã¯ãé©åãªããŒã¿ã§AIã¢ãã«ãMLã¢ãã«ãç¶ç¶çã«ãã¬ãŒãã³ã°ããŠããããã99.99%ã®æå¹æ§ãå®çŸããŠããŸãã
è åšã€ã³ããªãžã§ã³ã¹ã®å¯èŠæ§ïŒãã«ãŒããã€ã³ããæå©
ãã«ãŒããã€ã³ããšã¯éããAbnormalã¯ãè åšç¶æ³å šäœã«ããããæªç¥ã®è åšãæ°ããè åšã«å¯Ÿããè åšã€ã³ããªãžã§ã³ã¹ã®å¯èŠæ§ããã¬ã¡ããªãæäŸããŠããŸããã ãã®ãããAbnormalã§ã¯ãæ€ç¥ã«ãããŠå€§ããªç²ç¹ããããŸãã 察ããProofpointã¯ãè±å¯ãªè åšã€ã³ããªãžã§ã³ã¹ãæäŸãããããå€åãç¶ããè åšç¶æ³ã«å¯Ÿãå æãæã€ããšãã§ããŸãã æ©æèŠåã·ã¹ãã ãšããŠå©çšã§ããŸãã
ãã«ãŒããã€ã³ãã¯ãè åšã調æ»ããæ°ããååãç¹å®ããAPTïŒé«åºŠæšçåæ»æïŒæ»æè ãªã©ã®æ»æè ã¢ã¯ãã£ããã£ã远跡ãããå°éè åšãªãµãŒãã£ãŒããŒã ãæ§ããŠããŸãã ããã«ãããããããŒã¿ããã«ãŒããã€ã³ãå ã«ãšã©ããŠããã®ã§ã¯ãªãã çµå¶å¹¹éšãææ¡ãã¹ãã°ããŒãã«è åšããŒã¿ãæ¥çè åšããŒã¿ã®æŠèŠãããã¢ã¯ãã£ãã«æäŸããããã顧客ã¯çŸåšã®ã¡ãŒã«è åšç¶æ³ãåžžã«ææ¡ããããšãã§ããŸãã ãŸããäŒæ¥ãæšçã«ããŠããæ»æè ã«é¢ãã詳现ãªç¥èŠãæäŸããŸãã ãã®ãããªç¥èŠã«ã¯ãæ»æè ãæŠè¡ãææ³ãã©ãé²åãããŠããããšãã£ãæ å ±ãå«ãŸããŸãã
ãã«ãŒããã€ã³ãã®è åšã€ã³ããªãžã§ã³ã¹ã¯çè§£ãããããã®ã§ããããŸãã è åšãšããŠå€å®ãããçç±ã®èª¬æã ãã§ãªããã¿ã€ã ã©ã€ã³ãææãããŠãŒã¶ãŒã®ãªã¹ããæ¯ãèãAIã«ãã£ãŠç¢ºèªããããã®ä»ã®ãã€ã³ããæäŸããŸãã ãã®äŒç€Ÿã¯ããã«ãŒããã€ã³ãã®è±ãã§æ·±ãè åšã®å¯èŠæ§ã¯éåžžã«è²Žéã§ãããšè©äŸ¡ããŠããŸãã ãŸãããã«ãŒããã€ã³ããšæ¯èŒããŠãAbnormalã®ã€ã³ããªãžã§ã³ã¹ãšå¯èŠæ§ã¯éåžžã«éå®çã§ãããšããŠããŸãã
é ä¿¡åŸä¿®åŸ©ïŒãã«ãŒããã€ã³ããæå©
Abnormalã¯ãæ€ç¥æ¹æ³ãšããŠã¯ç°åžžæ€ç¥ã®ã¿ã«é Œã£ãŠããŸãã ç°åžžæ€ç¥åäœã§ã¯ãéåžžã«ããã€ãºãå€ããã倧éã®èª€æ€ç¥ãçºçããŸãã æ£èŠã®ã¡ãã»ãŒãžã«ãäžå¯©ãããæªæããããªã©ã®ãã©ã°ãä»ããããŠã¯ãæ¥åãæ··ä¹±ããŸãã ããã ãã§ã¯ãããŸããã ã»ãã¥ãªãã£ããŒã ã®ä»äºãå¢ããŸããAbnormalã§ã¯ãã©ã°ã®ä»ããã¡ãã»ãŒãžãæåã§åªå é äœä»ããããããã調æ»ãšä¿®åŸ©ãè¡ãå¿ èŠãããããã§ãã
Abnormalã¯æéãããã£ãããšãã®äŒç€Ÿã¯è¿°ã¹ãŠããŸãã ã»ãã¥ãªãã£ããŒã ã¯ãçµ¶ããã¡ãŒã«ã確èªãã誀æ€ç¥ã¡ãŒã«ã¯ãŠãŒã¶ãŒã®åä¿¡ãã¬ã€ã«æ»ããäŸµå ¥ãèš±ããŠããŸã£ãæªæã®ããã¡ãŒã«ã¯åé€ããªããã°ãªããŸããã§ããã å®éã«ãã»ãã¥ãªãã£ããŒã ã¯ãã»ãŒ1å¹Žäžæ¯æ¥åã¢ã©ãŒãã調ã¹ãªããã°ãªããªãããããã«ã¿ã€ã ã®ãªãµãŒãã£ãŒãå²ãåœãŠãããããŸããã§ããã
ããã«æªãããšã«ãã»ãã¥ãªãã£ããŒã ã¯Abnormalã®ããã«å€ã®äœæ¥ã«é§ãåºãããŸããã çç±ã¯ããã§ãã ããã¡ãã»ãŒãžãæªæã®ãããã®ã§ãããšãã«ãŒããã€ã³ããå€å®ãããšãé ä¿¡åŸã¢ã©ãŒããAbnormalã«éããŸãã ãã®æç¹ã§ãã¡ãã»ãŒãžããŠãŒã¶ãŒã®åä¿¡ãã¬ã€ããåé€ãããã©ãããæ±ºããã®ã¯AbnormalãšãªããŸãã ã¡ãã»ãŒãžã«åé¡ããªããšAbnormalãå€å®ããã°ããã®ã¡ãŒã«ã¯åé€ãããããšãªãããŠãŒã¶ãŒã®åä¿¡ãã¬ã€ã«ãšã©ãŸããŸãã ã€ãŸãããã«ãŒããã€ã³ããæªæã®ãããã®ãšããŠãã©ã°ãä»ããåã¡ãã»ãŒãžãåé€ããã«ã¯ãããŒã ã¡ã³ããŒãã·ã¹ãã å ãæ¯å確èªããªããã°ãªããŸããã ïŒç¹ã«é±æ«ã®åå1æã«æåã§ã¡ãã»ãŒãžãåé€ãããšãªãã°ãã»ãã¥ãªãã£ããŒã ã®ææ ¢ã®éçã詊ãããã§ããããïŒ
äŒç€Ÿã¯ãã®åé¡ãAbnormalã®ããŒã ã«äŒãããã®ã®ã ãAbnormalã®ã¢ã«ãŽãªãºã ãæ··ä¹±ãããããããããããšããçç±ã§ã ãã«ãŒããã€ã³ãããã®ãæªæãã¢ã©ãŒãã«å¯ŸããäŸå€åŠçã¯èšå®ãããŸããã§ããã
éžæã¯æãã
Abnormalã1幎è¿ã䜿çšããŠã¿ããšããããã®äŒç€Ÿã¯å¢ãç¶ãã誀æ€ç¥ã«æ©ãŸãããAbnormalã®ãšã¯ã¹ããªãšã³ã¹ã«æºè¶³ã§ããŸããã§ããã ãããŠè åšã€ã³ããªãžã§ã³ã¹ã«å¯Ÿããååãªå¯èŠæ§ãåŸããããé ä¿¡åŸä¿®åŸ©ã广ã®äœããã®ã§ããã ãã®çµæããã®äŒç€Ÿã¯ãProofpoint Threat Response Auto-Pull (Proofpoint TRAP)ã®å¹Žæ¬¡æŽæ°ãååããã ã§ããã ãæ©ãAbnormalãç°å¢ããåé€ããŸããã
Abnormal Securityãšãã«ãŒããã€ã³ãã®æ¯èŒ
ãã®äŒç€Ÿã®ãšã¯ã¹ããªãšã³ã¹ãšçµè«ã¯çããããšã§ã¯ãããŸããã ãã«ãŒããã€ã³ãã®èª¿æ»ã«ãããšããã«ãŒããã€ã³ãã«ä¹ãæããäŒæ¥ã§ã¯ãæªæã®ããã¡ãã»ãŒãžã®æ€ç¥ãšé²æ¢ã«ãããŠ30%以äžã®æ¹åãèŠãããŠããŸãã
Abnormalã¯ãããã«ä»éãããªã¹ã¯ãèãããšãããã«éžæè¢ããå€ããŸãã Abnormalã«ã¯ãã¡ã³ããã³ã¹ããªãã¬ãŒã·ã§ã³ããµããŒããç·ææã³ã¹ãã®é¢ã§ãã®äŒç€Ÿã«ãšã£ãŠå€§ããªè² æ ãšãªããããªé ããã³ã¹ããè€éãããããŸããã ãããŠãAbnormalã䜿çšããã«ã¯Microsoftãå¿ èŠã§ãã ã€ãŸããäŒç€Ÿã®ã»ãã¥ãªãã£ã¯ãMicrosoftã®ã¡ãŒã«ã»ãã¥ãªãã£æ©èœã«äž»ã«äŸåããããšã«ãªããŸãã
ãã«ãŒããã€ã³ãã¯ã人ããäžå¿ãšããã»ãã¥ãªãã£ãæäŸ
ãµã€ããŒã»ãã¥ãªãã£ã®ããã«è¡ãéžæã¯ãåŸæ¥å¡ãšçµç¹ã«ãšã£ãŠéèŠã§ãã
ãã«ãŒããã€ã³ããšAbnormalãæ¯èŒããã°ããã«ãŒããã€ã³ããããããé¢ã§åªããŠããŸãã
仿¥ã®é«åºŠãªè åšããçµç¹ã®å®å šãç¶æããã«ã¯ããã€ãã£ãã®Microsoftã¡ãŒã«ã»ãã¥ãªãã£æ©èœãè£å®ãããå€å±€çãªé²åŸ¡æŠç¥ãæ¡çšããããšãéèŠã§ãã ã¡ãŒã«é ä¿¡ãããŒã«ãããŠïŒé ä¿¡åããé ä¿¡åŸãã¯ãªãã¯æã«ããããŸã§ïŒç¶ç¶çãªè åšæ€ç¥ãšåæã«ãã©ãŒã«ã¹ããããšã§ãææ°ã®ã¢ãããŒããã¡ãŒã«ã»ãã¥ãªãã£ã«æ¡çšããã°ãé ã ãŸã§ä¿è·ãå®çŸããããšãã§ããŸãã
ãã®ãã©ã°ã¡ã³ãåãããç¶æ³ã«ãããŠããã«ãŒããã€ã³ãã¯ãAI/MLãæŽ»çšããè åšå¯Ÿçãæ¯ãèãåæãèªå修埩ãçµ±åãããç·åçãªãœãªã¥ãŒã·ã§ã³ãæäŸããŸãã ãã«ãŒããã€ã³ãã®ã人ããäžå¿ãšããã»ãã¥ãªãã£ã¯ãããŸããŸãªå·§åŠãªã¡ãŒã«è åšã«å¯Ÿæããããã«äžå¯æ¬ ã§ãã
ã人ããäžå¿ãšããã»ãã¥ãªãã£ã«ã€ããŠããããŠåŸæ¥å¡ãçµç¹ã®ä¿è·ã«ãã«ãŒããã€ã³ããã©ãã圹ã«ç«ãŠããã«ã€ããŠã詳ããã¯ãã¡ãã®ããŒãžãã芧ãã ããã