ç®æ¬¡
- ã©ãã©ã«ã ãŒãã¡ã³ãã®æžå¿µäºé
- ã©ãã©ã«ã ãŒãã¡ã³ãæ»æã®ä»çµã¿
- ã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³
- ã©ãã©ã«ã ãŒãã¡ã³ããå©çšãããµã€ããŒæ»æ
- ã©ãã©ã«ã ãŒãã¡ã³ãã®æ€ç¥æ¹æ³
- ã©ãã©ã«ã ãŒãã¡ã³ã察ç
- ã©ãã©ã«ã ãŒãã¡ã³ãã«å¯ŸããProofpointã®ãœãªã¥ãŒã·ã§ã³
ã©ãã©ã«ã ãŒãã¡ã³ããšã¯ããµã€ããŒç¯çœªè ãåæã®ã¢ã¯ã»ã¹ãåŸãåŸããããã¯ãŒã¯å ãé²ãããã«äœ¿çšããæé ãææ³ãæå³ããŠããŸããæ€åºãé¿ããªããæšªæ¹åïŒã©ãã©ã«ïŒã«ç§»åããããšã§ãæ»æè ã¯è¿œå ã®ã·ã¹ãã ãå¶åŸ¡ããç¹æš©ãæ¡å€§ãããçµç¹ã®ITã€ã³ãã©å ã§è²ŽéãªããŒã¿ãã¢ããªã±ãŒã·ã§ã³ãèŠã€ããããšãå¯èœãšãªããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ãã®äž»ãªç®çã¯ããã°ãã°ããŒã¿æŒæŽ©ã®ããã«ãçµç¹ã®ãã¯ã©ãŠã³ãžã¥ãšã«ãã«å°éããããšã§ããããã§èšããã¯ã©ãŠã³ãžã¥ãšã«ããšã¯ãç¥ç財ç£ã財åèšé²ãå人ããŒã¿ãªã©ã®æ©å¯æ å ±ãæãããããã¯ãã°ãã°æªæã®ããç®çã§ã®æåãããŒã¯ãŠã§ãã§ã®è²©å£²ãªã©ã«å©çšãããŸãããŸããæ»æè ã¯ã©ãã©ã«ã ãŒãã¡ã³ãã®æŠè¡ãç Žå£è¡çºïŒäŸ: ã©ã³ãµã ãŠã§ã¢ã®å±éïŒãã¹ãã€æŽ»åã«å©çšããããšããããŸãã
ãµã€ããŒã»ãã¥ãªãã£æè²ãšãã¬ãŒãã³ã°ãå§ããŸããã
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ãã®æžå¿µäºé
ã©ãã©ã«ã ãŒãã¡ã³ãã¯ãé²åŸ¡åŽã«ãšã£ãŠé倧ãªãµã€ããŒã»ãã¥ãªãã£ã®åé¡ã§ãããªããªãã©ãã©ã«ã ãŒãã¡ã³ãã¯æ»æè ã«ãæåã®ææãããã·ã³ãžã®äŸµå ¥ã ãã§ãªãã远å ã®ãªãœãŒã¹ãæ©å¯ããŒã¿ãžã®ã¢ã¯ã»ã¹ã䟵害ããææ®µãæäŸããããã§ãããã®çµæãã©ãã©ã«ã ãŒãã¡ã³ãã«ã¯å€ãã®æžå¿µäºé ããããŸãã
- äžå¯èŠæ§: ã©ãã©ã«ã ãŒãã¡ã³ãã䜿çšãããµã€ããŒç¯çœªè ã¯éåžžããããã¯ãŒã¯ãã©ãã£ãã¯ãã¿ãŒã³ã«çŽã蟌ã¿ãåŸæ¥ã®ã»ãã¥ãªãã£ããŒã«ã«ããæ€åºãåé¿ããããšããŸãã
- æç¶æ§: ã©ãã©ã«ã ãŒãã¡ã³ããå©çšããæ»æè ã¯ããããã¯ãŒã¯å ã§è€æ°ã®è¶³ããããäŸµå ¥ç¹ã確ç«ããããšãã§ããããã«ãããµã€ããŒã»ãã¥ãªãã£ããŒã ãå®å šã«æé€ããã®ãé£ãããªããŸããäžã€ã®äŸµå ¥ç¹ãèŠã€ããŠæé€ããŠããè åšã¢ã¯ã¿ãŒããããã¯ãŒã¯ããæé€ãããããã§ã¯ãããŸããã
- äŒæã®å®¹æã: å€ãã®çµç¹ãçžäºã«æ¥ç¶ããããŸãã¯ãã©ãããªãããã¯ãŒã¯ããã³çµ±åãããã¯ã©ãŠããµãŒãã¹ãæ¡çšããŠãããããè åšã¢ã¯ã¿ãŒãã©ãã©ã«ã ãŒãã¡ã³ããä»ããŠãããã®æ¥ç¶ãæªçšããããšããŸããŸã容æã«ãªã£ãŠããŸãã
- æå®³ã®çµæ: ã©ãã©ã«ã ãŒãã¡ã³ãã®æåã¯ãäž»èŠãªITã·ã¹ãã ãããŒã¿ã®æ©å¯æ§ãæŽåæ§ãå¯çšæ§ãç Žå£ããå¯èœæ§ããããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ããžã®å¯Ÿæçã¯ããµã€ããŒæ»æè ã®åããçè§£ããããšãšãé£ç¶çãªã¢ãã¿ãªã³ã°ãé«åºŠãªè åšæ€åºèœåãªã©ã®å ç¢ãªãµã€ããŒã»ãã¥ãªãã£å¯Ÿçã®å®æœãå¿ èŠã«ãªããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ãæ»æã®ä»çµã¿
ã©ãã©ã«ã ãŒãã¡ã³ãæ»æã¯ãåæã®äžæ£ã¢ã¯ã»ã¹ãåŸãåŸããµã€ããŒç¯çœªè ãæç¶æ§ãç¶æããçµç¹ã®ãããã¯ãŒã¯å ãæšªæçã«ç§»åããããã®å€æ®µéã®ããã»ã¹ã§æ§æãããŠããŸããã©ãã©ã«ã ãŒãã¡ã³ãã®äžè¬çãªã¹ããããçè§£ããããšã¯ãçµç¹ããµã€ããŒã»ãã¥ãªãã£å°éå®¶ããããã®è åšããã广çã«é²ããæ€åºããã®ã«åœ¹ç«ã¡ãŸãã
åæã®äŸµå®³
ã©ãã©ã«ã ãŒãã¡ã³ãæ»æã®æåã®æ®µéã¯åæã®äŸµå®³ã§ãããµã€ããŒç¯çœªè ã¯ããã£ãã·ã³ã°ã¡ãŒã«ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãã€ãã·ã£ã«ã¢ã¯ã»ã¹ãããŒã«ãŒïŒIABïŒããŸãã¯ãœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãå©çšããŠãåŸæ¥å¡ã®ããã€ã¹ãã¢ã«ãŠã³ããæ»æããäžæ£ãªã¢ã¯ã»ã¹ãåŸãããšããããŸãããããã¯ãŒã¯å ã«äŸµå ¥ããããæ»æè ã¯ããã€ã®æšéЬãªã©ã®ãã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ããããåµå¯ããããªãæ»æãç®çãšããä»ã®ããŒã«ã䜿çšãããããŠè¶³å Žãç¯ããŸãã
åµå¯
åµå¯ã®æ®µéã§ã¯ãæ»æè ã¯ç®æšç°å¢ã«é¢ããæ å ±ãåéããŸããããã«ã¯ã察象ã«é¢ããå ¬å ±ã®æ å ±ã®åéããããã¯ãŒã¯ã®ã¹ãã£ã³ã«ãããããã³ã°ããªãŒãã³ããŒãã®æ€çŽ¢ãããã³ãããäžã§å®è¡ãããŠããè匱ãªããã€ã¹ããµãŒãã¹ã®èå¥ãå«ãŸããŸãããã®æ å ±ã¯ãç¯çœªè ãæ¬¡ã®ã¹ããããèšç»ããåæã«ã»ãã¥ãªãã£ã·ã¹ãã ã«æ€åºãããã®ãåé¿ããã®ã«åœ¹ç«ã¡ãŸãã
ã¯ã¬ãã³ã·ã£ã«ããŒãã¹ãã£ã³ã°
ãããã¯ãŒã¯ã€ã³ãã©å ã§ã®ã©ãã©ã«ã ãŒãã¡ã³ãã容æã«ããããã«ãè åšã¢ã¯ã¿ãŒã¯é©åãªæš©éãæã€æå¹ãªãŠãŒã¶ãŒèªèšŒæ å ±ïŒãŠãŒã¶ãŒå/ãã¹ã¯ãŒãïŒãå¿ èŠã§ãããããã¯ãåæã®äŸµå®³ãã§ãŒãºã§ããŒãã¬ãŒãã€ã³ã¹ããŒã«ãããããã«ãŒããã©ãŒã¹ãèŸæžæ»æãã¯ã¬ãã³ã·ã£ã«ã¹ã¿ããã£ã³ã°ãªã©ã®ããŸããŸãªææ®µã䜿çšããŠãçµç¹ã®ãã¹ã¯ãŒãããªã·ãŒã®åŒ±ããæªçšããŠååŸãããŸãã
ãã¹ã¯ãŒãã¹ãã¬ãŒæ»æ
ã¯ã¬ãã³ã·ã£ã«ããŒãã¹ãã£ã³ã°ã§ãã䜿çšãããææ³ã®äžã€ããããã¹ã¯ãŒãã¹ãã¬ãŒæ»æãã§ãããã®æŠè¡ã§ã¯ãæ»æè ã¯äžè¬çã«äœ¿çšããããã¹ã¯ãŒããå€ãã®ã¢ã«ãŠã³ãã«å¯ŸããŠåæã«è€æ°åã®ãã°ã€ã³è©Šè¡ã§äœ¿çšããã¢ã«ãŠã³ãã®ããã¯ã¢ãŠããçºçããã«æ©èœãããã®ãèŠã€ãããŸã§ç¶ããŸãã
è匱æ§ã®æªçš
æ»æè ã¯æå¹ãªèªèšŒæ å ±ãååŸãããããã°ãã°æ¢ç¥ã®ãœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®è匱æ§ãæªçšããŠæš©éãææ ŒãããŸããããã«ãããæ»æè ã¯ãããã¯ãŒã¯å ã®ä»ã®ããã€ã¹ã§æ©å¯ããŒã¿ã«ã¢ã¯ã»ã¹ããããã³ãã³ããå®è¡ãããããŠã广çã«åœ±é¿ã暪æçã«è€æ°ã®ã·ã¹ãã ã«åºããããšãã§ããŸãã
æç¶æ§ãšããŒã¿æŒæŽ©
ã©ãã©ã«ã ãŒãã¡ã³ãæ»æã®æçµæ®µéã¯ã䟵害ãããã·ã¹ãã ãã貎éãªããŒã¿ãæã¡åºããããå°æ¥ã®ã¢ã¯ã»ã¹ã®ããã®ããã¯ãã¢ãäœæããæç¶æ§ã確ç«ããããšãå«ã¿ãŸããè åšã¢ã¯ã¿ãŒã¯ããªã¢ãŒãã¢ã¯ã»ã¹çšã®ã©ã³ãµã ãŠã§ã¢ãRATïŒé éæäœãŠã€ã«ã¹ïŒã®ãããªè¿œå ã®æªæã®ãããœãããŠã§ã¢ãå°å ¥ããŠã浞éãããã·ã³ãé éã§å¶åŸ¡ããçµç¹ã®ITãããã¯ãŒã¯ã«æç¶çãªè¶³å Žãç¯ãããšããããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³
ã©ãã©ã«ã ãŒãã¡ã³ãæ»æã§ã¯ããµã€ããŒç¯çœªè ã¯ããŸããŸãªææ³ã䜿çšããŠãããã¯ãŒã¯ã暪åãã貎éãªããŒã¿ã«äžæ£ã¢ã¯ã»ã¹ã詊ã¿ãŸãããããã®ææ³ãçè§£ããããšã¯ãITã¹ã¿ããããµã€ããŒã»ãã¥ãªãã£ã®å°éå®¶ãçµç¹ã®æ©å¯æ å ±ãšã·ã¹ãã ãããè¯ãä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã以äžã¯äžè¬çãªã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³ã§ãã
- ãã¹ã»ã¶ã»ããã·ã¥ïŒPtHïŒ: ãã®ææ³ã§ã¯ãæ»æè ã¯æå·ããã·ã¥åããããŠãŒã¶ãŒèªèšŒæ å ±ã1ã€ã®ã·ã¹ãã ããçã¿ãããã䜿çšããŠåããããã¯ãŒã¯ãã¡ã€ã³å ã®ä»ã®ã·ã¹ãã ã«èªèšŒããŸããããã«ãããå®éã®å¹³æãã¹ã¯ãŒããå¿ èŠãšããã«ãã¹ã¯ãŒãããŒã¹ã®èªèšŒã¡ã«ããºã ã䜿çšã§ããŸãã
- ãªã¢ãŒãå®è¡: æ»æè ã¯å¯Ÿè±¡ã®ã·ã¹ãã ã§æªæã®ããã³ãŒããå®è¡ããããã«ããªã¢ãŒããµãŒãã¹ãã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãæªçšããŸãããªã¢ãŒãå®è¡ãå®è¡ããããã®äžè¬çãªããŒã«ã®äŸã«ã¯ãPowerShellãPsExecãããã³Windows Management InstrumentationïŒWMIïŒããããŸãã
- äžéè æ»æïŒMitMæ»æïŒ: ãµã€ããŒç¯çœªè ã¯ã察話ãããŒã®äžéã«èªåãé 眮ããããšã§ã2ã€ã®åœäºè éã®éä¿¡ãååããŸããMitMæ»æã䜿çšããããšã§ã圌ãã¯äž¡æ¹ã®åœäºè ãèªåã䟵害ãããããšãç¥ããã«äº€æãããããŒã¿ãååããŸãããã®ããŒã¿ã¯ãã³ã³ãã¥ãŒãã£ã³ã°ã»ãã·ã§ã³ãä¹ã£åãããä»ã®äžæµã®ç®çã«äœ¿çšã§ããŸãã
- ã©ãã©ã«ãã£ãã·ã³ã°: çµç¹å ã®ã¡ãŒã«ã¢ã«ãŠã³ãã䟵害ããåŸãæ»æè ã¯ãã®ã¢ã«ãŠã³ãããä»ã®åŸæ¥å¡ãããŒãããŒã«ãã£ãã·ã³ã°ã¡ãŒã«ãéä¿¡ããæ©å¯æ å ±ãèŠæ±ããããæªæã®ãããªã³ã¯ãã¯ãªãã¯ãããããããæ±ããŸãããã®ææ³ã¯ååéã®ä¿¡é Œãå©çšããã¡ãŒã«ãä¿¡é Œãããååããã®ãã®ã§ãããã®ããã«èŠããããæ»æã®æå確çãé«ããŸãã
- ç°å¢å¯çåæ»æïŒLiving Off The LandïŒ: æ»æè ã¯çµç¹ã®ç°å¢ã«ååšããçµã¿èŸŒã¿ã®ããŒã«ãã¹ã¯ãªãããããã³ã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠæ»æãå®è¡ããŸããæ£åœãªããŒã«ãæªæã®ããç®çã«äœ¿çšããããšã§ã圌ãã¯éåžžã®ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ã«çŽã蟌ã¿ãå€ãã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã«ããæ€åºãåé¿ã§ããŸãã
ãããã®ã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³ã¯ãæ»æè ãæ€åºãããã«ãããã¯ãŒã¯ã暪æããããã€ãã®äŸã«éããŸããããããã®è åšã«å¹æçã«å¯Ÿæããããã«ã¯ãçµç¹ã¯ãããã®æªæ¿èªã¢ã¯ã»ã¹ãæ€åºããã³é²æ¢ããããšã«çŠç¹ãåœãŠãå ç¢ãªãµã€ããŒã»ãã¥ãªãã£å¯Ÿçã宿œããå¿ èŠããããŸããããã«ã¯ãæœåšçãªè匱æ§ãç¹å®ããã©ãã©ã«ã ãŒãã¡ã³ããçºçããåã«é»æ¢ããããã®å éšã¹ãã£ã³ãå«ãŸããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ããå©çšãããµã€ããŒæ»æ
ã©ãã©ã«ã ãŒãã¡ã³ãã¯ãããŸããŸãªçš®é¡ã®æ»æã§ãµã€ããŒç¯çœªè ããã䜿çšããæŠè¡ã§ããç°ãªãæ»æã·ããªãªãçè§£ããããšã§ãITããŒã ããµã€ããŒã»ãã¥ãªãã£ã®å°éå®¶ã¯ãããã®è åšã«å¯Ÿããããè¯ãé²åŸ¡çãæºåã§ããŸãã以äžã¯ãã©ãã©ã«ã ãŒãã¡ã³ããå©çšããäžè¬çãªãµã€ããŒæ»æã®çš®é¡ã§ãã
- APTæ»æïŒAdvanced Persistent ThreatïŒïŒ APTã¯ãæŽç·Žãããæ»æè ããããã¯ãŒã¯ã«äžæ£ã¢ã¯ã»ã¹ãã鷿鿀åºãããªããŸãŸã§ããé·æãã€æšçåã®æ»æã§ãããããã®æ»æè ã¯éåžžãã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³ã䜿çšããŠãããã¯ãŒã¯ãç§»åããç¹æš©ããšã¹ã«ã¬ãŒããããæ©å¯ããŒã¿ãæã¡åºããŸãã詳现ã¯ãAPTæ»æïŒAdvanced Persistent ThreatïŒãšã¯ïŒæå£ãšå¯Ÿçããã芧ãã ããã
- ã©ã³ãµã ãŠã§ã¢æ»æïŒ ã©ã³ãµã ãŠã§ã¢ã¯ãææããã·ã¹ãã äžã®ãã¡ã€ã«ãæå·åãã被害è ã«å¯ŸããŠåŸ©å·éµã®æäŸãšåŒãæãã«æ¯æããèŠæ±ãããã«ãŠã§ã¢ã®äžçš®ã§ããæ»æè ã¯éåžžãã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³ã䜿çšããŠçµç¹ã®ãããã¯ãŒã¯å ã§ã©ã³ãµã ãŠã§ã¢ãæ¡æ£ããããã®åœ±é¿ãšæœåšçãªæ¯æé¡ãå¢å ãããŸãã
- ããŒã¿äŸµå®³ïŒ ããŒã¿äŸµå®³ã¯ãäžæ£ãªå人ãçµç¹ã®ã·ã¹ãã ãããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ããŠæ©å¯æ å ±ãçããšãã«çºçããŸããæ»æè ã¯éåžžãã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³ã掻çšããŠè²ŽéãªããŒã¿ãªããžããªãç¹å®ãããã®æ å ±ãæã¡åºããŸãã
- èªèšŒæ å ±ã®ç飿»æïŒ èªèšŒæ å ±ã®çé£ã¯ãæªæãæã£ãŠãŠãŒã¶ãŒãçµç¹ãããŠãŒã¶ãŒåããã¹ã¯ãŒããçãè¡çºã§ãããããã«ããäžæ£ã¢ã¯ã»ã¹ãè¡ã£ãããããããããŒã¯ãŠã§ãã§ä»ã®ãµã€ããŒç¯çœªè ã«å£²åŽãããããŸãããµã€ããŒç¯çœªè ã¯éåžžãã©ãã©ã«ã ãŒãã¡ã³ãã䜿çšããŠè€æ°ã®ã·ã¹ãã ããèªèšŒæ å ±ãåéãã察象ãããã¯ãŒã¯ã«å¯Ÿããç¹æš©ãšå¶åŸ¡ãæ¡å€§ãããŸãã
- å éšè åšïŒ å éšè åšã¯ãçµç¹ã®ã·ã¹ãã ãžã®åæ³çãªã¢ã¯ã»ã¹æš©ãæã€åŸæ¥å¡ãå¥çŽè ã«ãã£ãŠèµ·ããå ŽåããããŸããããããã®ã¢ã¯ã»ã¹ãæªçšããŠæªæããç®çã§äœ¿çšããŸãããããã®å人ã¯éåžžããã©ãã¯ãæ¶ãããããããã¯ãŒã¯å ã§ãããªãäžæ£ãªç¹æš©ãåŸãããã«ã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³ã䜿çšããããšããããŸãã
åæ»æã·ããªãªã§ã®ã©ãã©ã«ã ãŒãã¡ã³ãã®æ€åºãšç·©åã¯ãåºç¯ãªè¢«å®³ãé²ããæœåšçãªæå€±ãæå°éã«æããããã§éèŠã§ãã
ã©ãã©ã«ã ãŒãã¡ã³ãã®æ€ç¥æ¹æ³
ãµã€ããŒæ»æã«ãã被害ãæå°éã«æããããã«ã¯ãã©ãã©ã«ã ãŒãã¡ã³ããè¿ éã«æ€ç¥ããããšãéèŠã§ããååã«æ©ãæ€ç¥ã§ããªããšãæ»æè ã¯æ©å¯ããŒã¿ãéèŠãªã·ã¹ãã ã«ã¢ã¯ã»ã¹ããçµç¹ã«å€§ããªæå®³ãäžããå¯èœæ§ããããŸãã广çã«ã©ãã©ã«ã ãŒãã¡ã³ããèªèãã忢ãããããã®ç°ãªãæè¡ãã»ãã¥ãªãã£ã³ã³ãããŒã«ã«ã€ããŠææ¡ããããšãéèŠã§ãã
ãããã¯ãŒã¯ã®ã¢ãã¿ãªã³ã°
ãããã¯ãŒã¯ã¬ãã«ã®ã¢ãã¿ãªã³ã°ã¯ããããã¯ãŒã¯ã€ã³ãã©å ã§ã®ç°åžžãªã¢ã¯ãã£ããã£ãæ€ç¥ããäžã§éèŠã§ãããããã¯ãŒã¯ãã©ãã£ãã¯ã®ãã¿ãŒã³ãç¶ç¶çã«åæããããã確ç«ãããåºæºãšæ¯èŒããããšã§ãã©ãã©ã«ã ãŒãã¡ã³ãã瀺åããç°åžžãæ©æã«ç¹å®ã§ããŸããIDSãSIEMãªã©ã®ããŒã«ã¯ããããã¯ãŒã¯ã®ã¢ãã¿ãªã³ã°ã«äžè¬çã«äœ¿çšãããäžå¯©ãªã¢ã¯ãã£ããã£ãæ€åºããŸãã
UEBAïŒUser and Entity Behavior AnalyticsïŒ
UEBAïŒãŠãŒã¶ãŒãšãšã³ãã£ãã£ã®è¡ååæïŒã¯ãçµç¹ã®ITç°å¢å šäœã§ãŠãŒã¶ãŒã®æŽ»åã远跡ããæªæã®ããæå³ã瀺ãå¯èœæ§ã®ããç°åžžãªè¡åãç¹å®ããææ³ã§ããUEBAããŒã«ã¯ãåãŠãŒã¶ãŒã¢ã«ãŠã³ãã«å¯Ÿããéåžžã®äœ¿çšãã¿ãŒã³ã確ç«ãããããã®ãã¿ãŒã³ããã®éžè±ãæœåšçãªè åšãšããŠæ€ç¥ããããã«æ©æ¢°åŠç¿ã¢ã«ãŽãªãºã ã䜿çšããŸãã
EDRïŒEndpoint Detection and ResponseïŒ
EDRïŒãšã³ããã€ã³ãæ€ç¥ããã³å¯Ÿå¿ïŒãœãªã¥ãŒã·ã§ã³ã¯ãçµç¹ã®ãããã¯ãŒã¯å šäœã§ã®ãšã³ããã€ã³ãã®æŽ»åã«å¯Ÿãããªã¢ã«ã¿ã€ã ã®å¯èŠæ§ãæäŸããŸãããããã®ããŒã«ã¯ã·ã¹ãã ããã»ã¹ããã¡ã€ã«ã®å€æŽãã¬ãžã¹ããªã®å€æŽãªã©ãç£èŠããã©ãã©ã«ã ãŒãã¡ã³ãã®è©Šã¿ã瀺åããå¯çãªã¢ã¯ã·ã§ã³ãç¹å®ããã»ãã¥ãªãã£ããŒã ã«å¯ŸããŠèœåçãªæ å ±ãæäŸããŸãã
广çãªã©ãã©ã«ã ãŒãã¡ã³ãæ€ç¥ã®ããã®ãã³ãïŒ
- ãããã¯ãŒã¯ã®ã¢ãã¿ãªã³ã°ããŠãŒã¶ãŒè¡ååæãã¢ã€ãã³ãã£ãã£è åšã®æ€åºãšå¯Ÿå¿ãç¹æš©ã¢ã¯ã»ã¹ã®ç®¡çãããã³ãšã³ããã€ã³ãã»ãã¥ãªãã£ã®æ€åºãçµã¿åããããè€æ°å±€ã®ã»ãã¥ãªãã£ã¢ãããŒããå®è£ ããŠãæœåšçãªè åšã«å¯Ÿããå¯èŠæ§ãæå€§åããŸãã
- 宿çãªã»ãã¥ãªãã£ã¢ã»ã¹ã¡ã³ããäŸµå ¥ãã¹ã/ã¬ããããŒã 掻åã宿œããã©ãã©ã«ã ãŒãã¡ã³ãã«æªçšãããå¯èœæ§ã®ããITã€ã³ãã©ã®è匱æ§ãç¹å®ããŸãã
ååãªã©ãã©ã«ã ãŒãã¡ã³ãã®æºåãšæ€ç¥ãäžè¶³ããŠãããšã壿» çãªããŒã¿æŒæŽ©ã財åäžã®æå€±ãè©å€ã®æå·ãããã³èŠå¶ã«å¯Ÿãã眰éãªã©ãæ·±å»ãªçµæã«ã€ãªããå¯èœæ§ããããŸããäžè¿°ã®ããŒã«ãšæŠç¥ã掻çšããããšã§ãçµç¹ã¯æªæã®ããæŽ»åãå šé¢çãªæ»æã«ãšã¹ã«ã¬ãŒãããåã«æ€åºããèœåãå€§å¹ ã«åäžãããããšãã§ããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ã察ç
ã©ãã©ã«ã ãŒãã¡ã³ãæ»æã广çã«é²ãããã«ãçµç¹ã¯ãããã¯ãŒã¯ãšãšã³ããã€ã³ãã®ã»ãã¥ãªãã£ã«çŠç¹ãåœãŠãå€å±€çãªã¢ãããŒããæ¡çšããå¿ èŠããããŸããããã«ã¯ããŸããŸãªã»ãã¥ãªãã£å¯Ÿçã®å®æœãçãããæŽ»åã®ã¢ãã¿ãªã³ã°ãåŸæ¥å¡ãžã®æœåšçãªè åšã«é¢ããæè²ãå«ãŸããŸãã以äžã¯ãã©ãã©ã«ã ãŒãã¡ã³ãã®ãªã¹ã¯ãæå°éã«æããããã®éèŠãªæé ã§ãã
- ãããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³: ãããã¯ãŒã¯ãå°ããªã»ã°ã¡ã³ãããŸãŒã³ã«åå²ããå¶éãããã¢ã¯ã»ã¹ã³ã³ãããŒã«ãå°å ¥ããŸããããã«ãããæ»æè ãç°å¢å ã§ã©ãã©ã«ã ãŒãã¡ã³ããè¡ãèœåãå¶éãããŸãã
- ã¢ã¯ã»ã¹å¶åŸ¡: POLPïŒæå°ç¹æš©ã®ååïŒã«åºã¥ãã峿 Œãªã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã確ç«ããŸãããŠãŒã¶ãŒã圌ãã®ä»äºã«å¿ èŠãªãªãœãŒã¹ã«ã®ã¿ã¢ã¯ã»ã¹ã§ããããã«ããŸããç¹ã«ç¹æš©ã¢ã«ãŠã³ãã匷åã«ç®¡çããããã«PAMïŒç¹æš©ã¢ã¯ã»ã¹ç®¡çïŒã䜿çšããŸãã
- ããã管ç: ãã¹ãŠã®ãœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ãšãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãææ°ã®ãããã§å®æçã«æŽæ°ããŠãæ»æè ãã©ãã©ã«ã ãŒãã¡ã³ãã®è©Šã¿äžã«æªçšããæ¢ç¥ã®è匱æ§ãéããŸãã
- å€èŠçŽ èªèšŒïŒMFAïŒ: ãªã¢ãŒãã¢ã¯ã»ã¹ãšç¹æš©ã¢ã«ãŠã³ãã«å¯ŸããŠMFAãèŠæ±ããçãŸããèªèšŒæ å ±ãç·åœããæ»æã«ããæªæ¿èªã®ãã°ã€ã³ãæžãããŸãã
- EDRïŒãšã³ããã€ã³ãæ€ç¥ããã³å¿çïŒ: EDRãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŠããšã³ããã€ã³ããåžžã«ç£èŠãã䟵害ã®å åãæ€åºãããªã¢ã«ã¿ã€ã ã§è åšã«å¯Ÿå¿ããŸãã
- UEBAïŒãŠãŒã¶ãŒãšãšã³ãã£ãã£ã®è¡ååæïŒ: ãŠãŒã¶ãŒã®è¡åãã¿ãŒã³ãåæããã©ãã©ã«ã ãŒãã¡ã³ãæ»æã®å åãšãªãç°åžžãèå¥ããUEBAããŒã«ã掻çšããŸããUEBAããŒã«ã¯ãããã¯ãŒã¯å ã®çãããæŽ»åãæ€åºããã®ã«åœ¹ç«ã¡ãŸãã
- ãµã€ããŒã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°: ã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ãéããŠãåŸæ¥å¡ã«ãã£ãã·ã³ã°ã¡ãŒã«ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®ææ³ãã©ãã©ã«ã ãŒãã¡ã³ããã£ã³ããŒã³ã§ãµã€ããŒç¯çœªè ã䜿çšããä»ã®äžè¬çãªæ»æææ³ã«é¢ãããªã¹ã¯ã«ã€ããŠæè²ããŸãã
ãããã®ç©æ¥µçãªå¯Ÿçã¯ãçµç¹ã®ãããã¯ãŒã¯ã«å¯Ÿããæåããã©ãã©ã«ã ãŒãã¡ã³ãæ»æã®å¯èœæ§ãèããæžå°ãããŸãã匷åãªã»ãã¥ãªãã£ããªã·ãŒãšå é²çãªã¢ãã¿ãªã³ã°æè¡ãåŸæ¥å¡æè²ã€ãã·ã¢ãããçµã¿åãããããšã§ãæé·ããè åšã«å¯Ÿããé²åŸ¡åãåäžããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ããé²ãããã®ç©æ¥µçãªææ®µãè¬ããããšãäŸãã°é©åãªãããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ã®å®æœããŠãŒã¶ãŒæš©éã®å¶éãªã©ãçµç¹ã¯æ»æã®æåãªã¹ã¯ãå€§å¹ ã«äœæžã§ããŸãããŸããProofpointã®å é²çãªã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã掻çšããããšã§ãITããŒã ã¯ã©ãã©ã«ã ãŒãã¡ã³ãã詊ã¿ãè åšã¢ã¯ã¿ãŒãããããã¯ãŒã¯ããã广çã«ä¿è·ã§ããŸãã
ã©ãã©ã«ã ãŒãã¡ã³ãã«å¯ŸããProofopointã®ãœãªã¥ãŒã·ã§ã³
ã©ãã©ã«ã ãŒãã¡ã³ãæ»æãžã®å¯ŸæçãšããŠãProofpointã¯ãããã®è åšãæ€åºãã鲿¢ãã察å¿ããããã®å æ¬çãªããŒã«ãšãœãªã¥ãŒã·ã§ã³ãæäŸããŠããŸããé«åºŠãªæè¡ãšãµã€ããŒã»ãã¥ãªãã£ã®å°éç¥èãæŽ»çšããããšã§ãProofpointã¯çµç¹ãäžæ£ãªã¢ã¯ã»ã¹ã詊ã¿ããµã€ããŒç¯çœªè ããæ©å¯æ å ±ãä¿è·ãããµããŒããããŠããŸãã
TAPïŒæšçåæ»æã®ä¿è·ïŒ
Proofpoint TAP(Targeted Attack Protection)ã¯ãæ»æã®ã©ã€ããµã€ã¯ã«ã®ããŸããŸãªæ®µéã§æªæã®ããæŽ»åãæ€åºãã驿°çãªãœãªã¥ãŒã·ã§ã³ã§ããTAPã¯ãæ©æ¢°åŠç¿ã¢ã«ãŽãªãºã ãšè åšã€ã³ããªãžã§ã³ã¹ã䜿çšããŠãèªèšŒæ å ±ã®çé£ããªã¢ãŒãã³ãŒãã®å®è¡ãªã©ãã©ãã©ã«ã ãŒãã¡ã³ãã®ææ³ã«é¢é£ããå¯çãªè¡åãã¿ãŒã³ãèå¥ããŸãã
ã¡ãŒã«ä¿è·
ã¡ãŒã«ã¯ããããã¯ãŒã¯ã®ã©ãã©ã«ã ãŒãã¡ã³ãã®æ©äŒãæ±ãããµã€ããŒç¯çœªè ã«ããæåã®æµžéã®ããã®æãäžè¬çãªææ®µã®äžã€ã§ãã Proofpointã®ã¡ãŒã«ä¿è·ãœãªã¥ãŒã·ã§ã³ã¯ããã£ãã·ã³ã°è©Šè¡ãã¡ãŒã«ã®æ·»ä»ãã¡ã€ã«ããªã³ã¯ãä»ãããã«ãŠã§ã¢ã®éä¿¡ãããã³çµç¹ã®ã€ã³ãã©ãžã®äŸµå ¥ææ³ã«å¯Ÿãã匷åãªä¿è·ãæäŸããŸãã
ã€ã³ã·ãã³ãã¬ã¹ãã³ã¹ãµãŒãã¹
ã©ãã©ã«ã ãŒãã¡ã³ãæ»æãçºçããå Žåãè¿ éãªå¯Ÿå¿ã被害ãæå°éã«æããè åšãå°ã蟌ããäžã§éèŠã§ãã Proofpointã®ã€ã³ã·ãã³ãã¬ã¹ãã³ã¹ãµãŒãã¹ã¯ãã©ãã©ã«ã ãŒãã¡ã³ãæè¡ãå©çšããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®èª¿æ»ãå°ã蟌ãã修埩ãå°éå®¶ã®æ¯æŽã§æäŸããŸãããããã®ãµãŒãã¹ã¯è åšã®èª¿æ»ãå°ãèŸŒãæŠç¥ãããã³ä¿®åŸ©æ¯æŽã«çŠç¹ãåœãŠãŠããŸãã
Proofpointã®å æ¬çãªããŒã«ãšãµãŒãã¹ã掻çšããããšã§ãã©ãã©ã«ã ãŒãã¡ã³ãæ»æã«å¯Ÿããçµç¹ã®æ€åºãäºé²ã广çãªå¯Ÿå¿èœåãå€§å¹ ã«åäžããŸãã Proofpointãã©ã®ããã«ããŠçµç¹ãã©ãã©ã«ã ãŒãã¡ã³ãæ»æããä¿è·ã§ããã詳ããç¥ãããå Žåã¯ãä»ããProofpointã«ãåãåãããã ããã