æ¬ããã°ã¯ãè±èªçããã°ãhttps://www.proofpoint.com/us/corporate-blog/post/dont-let-cloud-threats-rain-your-paradeãã®ç¿»èš³ã§ãã
ãµã€ããŒç¯çœªè ãã¯ã©ãŠãã¢ã«ãŠã³ãã䟵害ããæé ã詳ãã解説ããå æ¥ã®ããã°èšäºããã¯ãMicrosoft Office 365ãšGoogle G Suiteãžã®æ»æã«é¢ããéèŠãªã€ã³ãµã€ããåŸãããŸãããããã®ãã«ãŒããã©ãŒã¹æ»æããã³ãã£ãã·ã³ã°ã«é¢é£ããæ»æã®çµæãã¯ã©ãŠããå©çšããŠããããã³ãäŒæ¥ã®40%ããèªãã®ç°å¢å ã«å°ãªããšãã²ãšã€ã®äžæ£ãªã¢ã«ãŠã³ããæã£ãŠããã®ã§ããè åšã¢ã¯ã¿ãŒã¯ãããã³ãå éšã«è¶³ããããåŸãåŸãçµç¹ã®ä»ã®ã¡ã³ããŒãããžãã¹ããŒãããŒãžã®ãã£ãã·ã³ã°æ»æãè¡ã£ãŠçµç¹å ã®ã©ãã©ã«ã ãŒãã¡ã³ãïŒæšªæ¹åãžã®ç§»åïŒãéå§ãããµã€ããŒè©æ¬ºãããŒã¿çªçã®å¯èœæ§ãæ¢ããŸãã
Office 365ããã³G Suiteã®ã¢ã«ãŠã³ãã¯ã貎éãªããŒã¿ãæ±ããéèŠãªããžãã¹ã³ãã¥ãã±ãŒã·ã§ã³ãè¡ããããéåžžã«çãããããã¿ãŒã²ããã§ããæ»æè ã¯ããŠãŒã¶ãŒã®é»åã¡ãŒã«ã¢ã«ãŠã³ããä»ã®ã¯ã©ãŠããµãŒãã¹ã¢ã«ãŠã³ãã«åãç¶ããããšãã«ããããã®ã¢ã«ãŠã³ãã®ãã¹ã¯ãŒãããªã»ããããããšãã§ããŸããããã2ã€ã®ã¯ã©ãŠããµãŒãã¹ãã¢ã«ãŠã³ã䟵害ããä¿è·ããããã«ã¯ãæ»æãåããå¯èœæ§ãæãé«ããŠãŒã¶ãŒãæ»æã«å¯ŸããŠè匱ãªãŠãŒã¶ãŒãããã³/ãŸãã¯æ©å¯ããŒã¿ãžã®ã¢ã¯ã»ã¹ç¹æš©ãäžãããããŠãŒã¶ãŒãå®ãã人äžå¿ãã®ã»ãã¥ãªãã£ã¢ãããŒããšãšãã«ãè åšé²åŸ¡ãèªèšŒããã³ããŒã¿ã»ãã¥ãªãã£ã®æ©èœãæ éã«ç©ã¿äžããå¿ èŠããããŸãã
Proofpointã¯ãçµç¹ãã¯ã©ãŠãäžã®è åšãæ€åºããŠèªåçã«å¯Ÿå¿ã§ãããããµããŒãããŸãããã®ãœãªã¥ãŒã·ã§ã³ã«ã€ããŠèª¬æããåã«ãã¯ã©ãŠãæ»æãã©ã®ããã«è¡ãããããèŠãŠã¿ãŸãããã
ã¯ã©ãŠãæ»æã®ããã»ã¹
Proofpointã¯ã¯ã©ãŠãã¢ã«ãŠã³ãã«å¯Ÿããæ»æãç ç©¶ãã4ã€ã®ã¹ããŒãžãç¹å®ããŸããã
ã¹ããŒãž1ïŒåµå¯
è åšã¢ã¯ã¿ãŒã¯ãæ»æã®æå¹æ§ãé«ããããã«ã¯ã©ãŠããµãŒãã¹ã®ã¯ã¬ãã³ã·ã£ã«ïŒèªèšŒæ å ±ïŒãæ¢ããŠããŸãã圌ãã¯ãæšçã«å¯Ÿãããã«ãŒããã©ãŒã¹æ»æã仿ããåã«ããã£ãã·ã³ã°ã¡ãŒã«ãéä¿¡ããããããŒãã¬ãŒãªã©ã®ãã«ãŠã§ã¢ã«ææããããããCollection #1ããªã©ã®ã¯ã¬ãã³ã·ã£ã«ãã³ãããæŒããããã¯ã¬ãã³ã·ã£ã«ãåéãããããŸãã
ã¹ããŒãž2ïŒäŸµå ¥
Proofpointã®ç ç©¶ã«ãããšãè åšã¢ã¯ã¿ãŒã¯æ€åºãéããã»ãã¥ãªãã£å¯Ÿçãåé¿ããããã®ææ³ãé²åããç¶ããŠããŸãããã£ãã·ã³ã°æ»æã¯ãç¹å®ã®å°åããå€ãžã®ã¢ã¯ã»ã¹ãå¶éããããã®æ¡ä»¶ä»ãã¢ã¯ã»ã¹å¯Ÿçãåé¿ããããã«VPNãªã©ã®å¿ååãµãŒãã¹ãå©çšããããšããããŸãããŸãæè¿ã§ã¯ãHR@company[.]comãhelp@company[.]comãªã©ã®ãµãŒãã¹çšã®å ±æã¢ã«ãŠã³ããæšçãšããIMAPããŒã¹ã®ãã¹ã¯ãŒãã¹ãã¬ãŒæ»æã芳枬ããŸãããäžè¬ã«ãããã®ã¢ã«ãŠã³ãã¯ãå€èŠçŽ èªèšŒïŒMFAïŒããµããŒãããŠããªãã¬ã¬ã·ãŒãªã¡ãŒã«èªèšŒãããã³ã«ã䜿ã£ãã¢ã¯ã»ã¹ãèš±å¯ããŸããããšãã°ãProofpointã¯äŸµå®³ãããŠæ»æã®äžéšãšããŠäœ¿çšãããŠããäŒè°å®€ã®é»åã¡ãŒã«ã¢ã«ãŠã³ããèŠã€ããŸãããå€ãã®ã±ãŒã¹ã§ãæ»æè ã¯ã¯ã¬ãã³ã·ã£ã«ã®çé£ããã«ãŒããã©ãŒã¹æ»æã®æåããæ°æ¥ã®ãã¡ã«ãã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ããŠæ»æãæ¡å€§ãå§ããŸãã
ã¹ããŒãž3ïŒæ¡æ£ããŠæœäŒ
䟵害ãããã¢ã«ãŠã³ããã²ãšã€ã§ãããã°ãæ»æãæ¥éã«æ¡å€§ããããšãã§ããŸããäŸµå ¥å ã®ã¢ã«ãŠã³ãã«ãã°ã€ã³ãããšãæ»æè ã¯æ å ±ãåéãå§ããŸãã圌ãã¯ã¡ãŒã«ãèªã¿ããŠãŒã¶ãŒã®ã«ã¬ã³ããŒããã§ãã¯ããé£çµ¡å ãããŠã³ããŒããããããŠããžãã¹ããã»ã¹ã«ã€ããŠåŠã³ãŸããããã«ãããçµç¹å å€ã®ä»ã®ãŠãŒã¶ãŒãã¿ãŒã²ããã«ããããšãã§ããŸããæåã«äŸµå®³ããã¢ã«ãŠã³ããééãããŒã¿ãçãããã®é©åãªæš©éãæã£ãŠããªãå Žåãè åšã¢ã¯ã¿ãŒã¯ãã£ãã·ã³ã°ã¡ãŒã«ã瀟å å€ã®ãŠãŒã¶ãŒã«éä¿¡ããããOneDriveãªã©ã®ã¯ã©ãŠãã¢ããªäžã§ãã«ãŠã§ã¢ãå ±æãããããŠææãæ¡å€§ãããŸãã
ããã«ãæ»æè ã¯ãã©ã«ãã®å ±ææš©éã倿ŽãããããŠãŒã¶ãŒã®ãã¹ã¯ãŒãã倿Žãããå Žåã§ãããŒã¿ã«ã¢ã¯ã»ã¹ãç¶ããããšãã§ããããã«OAuthã¢ããªãã€ã³ã¹ããŒã«ãããããŸãããŸããé»åã¡ãŒã«ã®è»¢éã«ãŒã«ãäœæãã管çè ã¢ã«ãŠã³ããäœæããäºèŠçŽ èªèšŒãç¡å¹ã«ãããªã©ããŠäŸµå ¥å ã®ã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹ãç¶æããŸãã
ã¹ããŒãž4ïŒæŒãã
æ»æãé©åã«æ€åºã§ãããæšªç§»åããŠæ¡æ£ããŠããŸã£ãå Žåãã¢ã«ãŠã³ãã®äŸµå®³ã«ããäžæ£ãªééãè¡ããããã財åèšé²ãç¥ç財ç£ãªã©ã®è²ŽéãªããŒã¿ãæµåºãããããå¯èœæ§ããããŸããProofpointã¯ãäžéè æ»æãããžãã¹ã¡ãŒã«è©æ¬ºïŒBECïŒããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãé»åã¡ãŒã«ã«ããããŒã¿ã®æµåºããã¡ã€ã«ã®ããŠã³ããŒãããŸãã¯OAuthã¢ããªã±ãŒã·ã§ã³ã®å ±æãšã€ã³ã¹ããŒã«ãªã©ã®æŽ»åã芳枬ããŠããŸãã
ããããã¹ããŒãžã§ã¯ã©ãŠãã¢ããªæ»æã«å¯Ÿæ
ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ãçã£ãæ»æã«å¯Ÿæããããã«ã¯ã人ãäžå¿ãšããã»ãã¥ãªãã£ã¢ãããŒããå¿ èŠã§ãã誰ããã©ã®ããã«æ»æãããŠãããã«ã€ããŠçè§£ããå¿ èŠããããŸãã
ãããã®ã¯ã©ãŠãæ»æã®åã¹ããŒãžã§ã人ã ãã©ã®ããã«ä¿è·ãã¹ãããèããŠã¿ãŸãããã
ã¹ããŒãž1ïŒãã«ããã£ãã«è åšã€ã³ããªãžã§ã³ã¹
æŒãããŸãã¯çé£ã«éã£ãã¯ã¬ãã³ã·ã£ã«ã¯ãã¯ã©ãŠããµãŒãã¹ã®ããã³ãçµç¹ãå±éºã«ãããèžã¿å°ãšãªãããã䟵害ãããã¢ã«ãŠã³ããæ£ç¢ºã«ç¹å®ããå¿ èŠããããŸãããã®ããã«ã¯ã次ã®ãããªã¯ãã¹ãã£ãã«ã®è åšã€ã³ããªãžã§ã³ã¹ãå¿ èŠã§ãïŒ
- ãã£ãã·ã³ã°ã«é¢é£ããã€ã³ã·ãã³ããç¹å®ããããã®ã¡ãŒã«è åšã€ã³ããªãžã§ã³ã¹ã
- ãã«ãŒããã©ãŒã¹æ»æã«å¯ŸããŠè匱ãªã¢ã«ãŠã³ããç¹å®ããããã®æŒããã¯ã¬ãã³ã·ã£ã«ã€ã³ããªãžã§ã³ã¹ã
- çããããæªæã®ããæŽ»åã«é¢äžããIPããã³ãã¡ã€ã³ãç¹å®ããããã®æ°èè åšã€ã³ããªãžã§ã³ã¹ã
ã¹ããŒãž2ïŒè åšã®æ€åºãšãªã¹ã¯ããŒã¹ã®MFA
è åšã¢ã¯ã¿ãŒã®ãã£ãŒã«ãã§æŠãããšã¯ãç°¡åã§ã¯ãããŸãããäœçŸäžäººãã®ãŠãŒã¶ãŒã®ãã°ã€ã³ã®äžãã圌ãã®é«åºŠãªæ»æãæ£ç¢ºã«æ€åºããããã«ã¯ãé«åºŠãªæ©æ¢°åŠç¿ãªã©ã«åºã¥ãæ©èœãå¿ èŠã§ãïŒ
- ãŠãŒã¶ãŒãšãšã³ãã£ãã£ã®è¡ååæïŒUEBAïŒUser and Entity Behavior AnalyticsïŒã¯ãããã€ã¹ããã±ãŒã·ã§ã³ãISPãªã©ã®ãŠãŒã¶ãŒã®ã¯ã©ãŠãã¢ã¯ã»ã¹ãã¿ãŒã³ã調æ»ããç°åžžãªè¡åãæ€åºããŸãã
- æ»æè ã®åºç¯å²ãªè¡åèå¥ã¯ããã«ãŒããã©ãŒã¹æ»æã§èŠããããããªãè€æ°ã®ã¯ã©ãŠããµãŒãã¹ããã³ãã«ããã£ãŠè€æ°ã®ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ããIPãæ€åºããŸãã
- é»åã¡ãŒã«ã®è åšã€ã³ããªãžã§ã³ã¹ãšUEBAã®çµæãé¢é£ä»ããããšã§ããã£ãã·ã³ã°æ»æã®æåãšã¢ã«ãŠã³ã䟵害ãçµã³ã€ããŸãã
- çŽè¿ã«æŒããããã¯ã¬ãã³ã·ã£ã«ã®ãããªäººäžå¿ã®ãã©ã¡ãŒã¿ãŒãããªã¹ã¯ã¬ãã«ã®èšç®ã«äœ¿çšããŸãã
- IPã¬ãã¥ããŒã·ã§ã³ãã§ãã¯ã¯ããã°ã€ã³ãæªæã®ããIPããã®ãã®ãã©ããã倿ããŸãã
- æªæã®ãããã¡ã€ã«ã®ã¹ãã£ã³ãšãµã³ãããã¯ã¹ã«ãã£ãŠãã¯ã©ãŠãå ã§å ±æãããŠãããã«ãŠã§ã¢ãæ€åºããŸãã
- ã¯ã©ãŠãè åšã®ç ç©¶ããŒã ããçµ¶ããé²åããè åšã©ã³ãã¹ã±ãŒãã«ã€ããŠã®æå 端ã®å¯èŠæ§ãæäŸããŸãã
ãã¹ã¯ãŒããšã¯ã¹ããã€ããå¢ãç¶ããã¯ã©ãŠããµãŒãã¹ãæ¥å¢ããŠããç¶æ³ã§ã¯ãèªèšŒæ¹æ³ãé²åããªããã°ãªããŸãããã¬ã¬ã·ãŒãªèªèšŒãããã³ã«ããããã¯ãããå Žåã¯ãã¢ãã³èªèšŒãæå¹ã«ããå¿ èŠããããŸãïŒ
ãªã¹ã¯ããŒã¹ã®MFAã䜿çšãããšãçµç¹ã¯äžèšã®è åšæ€åºæ©èœãå©çšããŠããŠãŒã¶ãŒã¢ã¯ã»ã¹ãèš±å¯ãããã©ããããŸãã¯MFAãèŠæ±ãããã©ãããæ±ºå®ããããšãã§ããŸãããŠãŒã¶ãŒã®åœ¹å²ãæš©éãå ŽæãIPã¬ãã¥ããŒã·ã§ã³ãããã€ã¹ã®è¡çç¶æ ãã³ã³ãã©ã€ã¢ã³ã¹ãªã©ã®ããŸããŸãªæ å ±ãããã°ã€ã³è©Šè¡ã®ãªã¹ã¯ã倿ããããã«äœ¿çšãããŸãã
ã¹ããŒãž3ïŒè åšããã®ä¿è·ãšç¶ç¶çãªèªèšŒ
æ€åºãããè åšã®ã¬ãã«ãšçš®é¡ã«å¿ããŠãçµç¹ã¯ããŸããŸãªã¯ã©ãŠãã¢ã¯ã»ã¹ã»ãã¥ãªãã£å¯Ÿçãç©ã¿éããŠå€éå±€åããŸãïŒ
- ã¢ã«ãŠã³ãã䟵害ãããå¯èœæ§ãããå Žåã詳现ãªã¢ã¯ãã£ããã£ãã©ã¬ã³ãžãã¯ã«ãã調æ»ã§ã䟵害ã¢ã«ãŠã³ããæ¡å€§ãæ°žç¶åãããããšããè åšã¢ã¯ã¿ãŒã®æŽ»åãèŠã€ãåºããŸãã
- é«ãã¬ãã«ã®è åšãæ€åºãããMFAãéžæè¢ã§ã¯ãªãå ŽåïŒããšãã°ã¬ã¬ã·ãŒãªèªèšŒãããã³ã«ãŸãã¯å ±æã¢ã«ãŠã³ãããµããŒãããå¿ èŠãããå ŽåïŒããŠãŒã¶ãŒã¢ã«ãŠã³ããäžæåæ¢ãããªã©ã®èªå修埩ãè¯ãéžæè¢ãšãªããŸãã
- ã»ãã·ã§ã³äžã«å±éºãªè¡åããšã¹ã«ã¬ãŒãïŒããšãã°ã代çã¢ã«ãŠã³ãã®å€æŽããã©ã«ãã®åºç¯å²ãªå ±æãªã©ïŒããå Žåãã¢ã¯ã»ã¹æš©éã衚瀺ã®ã¿ã«å¶éããããç¶ç¶çèªèšŒã䜿ã£ãŠã¢ã¯ã»ã¹ãå¶éãããããŸããããšãã°ãé©åããŠããªãããã€ã¹ãžã®ãã¡ã€ã«ã®ããŠã³ããŒãã¯Webåé¢ããŒã«ã䜿çšããŠãããã¯ã§ããŸããããªã¹ã¯ããŒã¹ã®MFAã¯ã»ãã·ã§ã³ã®éäžã§ãé©çšã§ããŸãã
- å éšã®ãã£ãã·ã³ã°ãã¹ãã ã¯äžè¬çãªææ³ã§ãããããé»åã¡ãŒã«ã¹ãã£ã³ããŒã«ããã³èªååŒãæ»ãããŒã«ã䜿çšããŠæªæã®ããé»åã¡ãŒã«ãæ€åºãããŠãŒã¶ãŒã®åä¿¡ãã¬ã€ããååããããšãã§ããŸãã
ã¹ããŒãž4ïŒããŒã¿ã»ãã¥ãªãã£
䟵害ãããã¢ã«ãŠã³ãã䜿ã£ãŠããŠãŒã¶ãŒããŒã¿ã ãã§ãªããMicrosoft SharePoint Onlineãªã©ã®ã³ã©ãã¬ãŒã·ã§ã³ããŒã«ã§åºãå ±æãããŠãããã®ä»ã®äŒæ¥ããŒã¿ãæµåºãããããå¯èœæ§ããããŸããããŒã¿ã®çé£ã鲿¢ããããã«ãçµç¹ã«ã¯ããŸããŸãªããŒã¿ã»ãã¥ãªãã£æ©èœãå¿ èŠã§ãïŒ
- ãã«ããã£ãã«ã®æ å ±æŒãã察çïŒDLPïŒæ©èœã¯ãçµç¹ããã©ã€ããªããŒã¿ã¹ãã¢ããã³ãªã³ãã¬ãã¹ãªããžããªãé»åã¡ãŒã«ãã¯ã©ãŠããªã©ã®ããŒã¿äº€æãã£ãã«ã暪æããŠéèŠãªããŒã¿ãæ£ç¢ºã«çºèŠããä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã
- ç°åžžãªãã¡ã€ã«æäœãšçããããã°ã€ã³ãšã®é¢é£ä»ããããã³ãã现ãããã¡ã€ã«ãã©ã¬ã³ãžãã¯ã«ãããæ å ±æŒãã/䟵害調æ»ã®ã¹ããŒããšæå¹æ§ãåäžããŸãã
- èªååããããã¡ã€ã«ãšãã©ã«ãã®ä¿®åŸ©æ©èœã¯ãåºç¯å²ãªå ±æãšããŒã¿çé£ã®å¯èœæ§ãæžãããŸãã
- é«ãªã¹ã¯ã®OAuthã¢ããªã®ã¢ã¯ã»ã¹èš±å¯ãåãæ¶ãæ©èœã«ãããè åšã¢ã¯ã¿ãŒãã¢ã«ãŠã³ããæ°žç¶åããŠé·æéã«ããã£ãŠããŒã¿æµåºãããããšãé²ããŸãã
è©³çŽ°ãªæ å ±
å€§èŠæš¡ãªã¯ã©ãŠãæ»æãæå¹ã§ãããšããäºå®ã¯ãã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã«ã€ããŠããã峿 Œãªã¢ãããŒããå¿ èŠã§ããããšã瀺ããŠããŸããOffice 365ããã³G Suiteãå©çšããŠããã客æ§ãã¹ãŠããå³åº§ã«ã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã®ãªã¹ã¯ãç£æ»ããããšããå§ãããŸãããã¡ããããç³ã蟌ã¿äžãããProofpointã§ã¯äžçåå°ã§ãProofpoint Cybersecurity SeriesïŒCASBã§ã¯ã©ãŠããä¿è·ããããéå¬ããŠãããŸãã®ã§ãè¿ãã®è¡ã§éå¬ãããå Žåã«ã¯ãæ¯éãåå äžããã
Proofpoint Cloud App Security BrokerïŒPCASBïŒãšInternal Mail DefenseïŒIMDïŒã¯ãã¯ã©ãŠãã¢ããªæ»æãæ©å¯ããŒã¿ã®çé£ãããã³ã¯ã©ãŠãå ã®ã³ã³ãã©ã€ã¢ã³ã¹ãªã¹ã¯ããçµç¹ãä¿è·ããŸãã PCASBã®è©³çްã¯ãã¡ããIMDã®è©³çްã¯ãã¡ãããã確èªãã ããã