äžæ°å³ã«èŠããŸããããã®ã¢ãŒããã¯ãã£ãæ¬çªç°å¢ã§æ©èœããå ŽåããããŸããè€éãã¯ã»ãã¥ãªãã£ã殺ããäžè¬çã«ãã¹ãŠã殺ããŸããå®éããã®ãããªå ŽåïŒææã³ã¹ãã®åæžã«ã€ããŠè©±ããŠããïŒã«ã¯ãã·ã¹ãã ã®ã¯ã©ã¹å šäœãã€ãŸãäžå€®ãã°ç®¡çïŒCLMïŒããããŸãã圌ããéå°è©äŸ¡ãããŠãããšèããŠããã®ã¬ãŒãããŒã«ã€ããŠæžããŠããŸããæšå¥šäºé ã¯æ¬¡ã®ãšããã§ãã
- äºç®ãšäººå¡ã®å¶çŽãã»ãã¥ãªãã£ç£èŠèŠä»¶ãããã³ç¹å®ã®ãŠãŒã¹ã±ãŒã¹èŠä»¶ãããå Žåã¯ãCLMæ©èœãšããŒã«ã䜿çšããŸãã
- SIEMãœãªã¥ãŒã·ã§ã³ãé«ããããè€éãªå Žåã¯ãCLMãå®è£ ããŠãã°ã®åéãšåæãæ¡åŒµããŸãã
- å¹ççãªã¹ãã¬ãŒãžãé«éæ€çŽ¢ãæè»ãªèŠèŠåãåããCLMããŒã«ã«æè³ããŠãã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®èª¿æ»/åæãšè åšæ€çŽ¢ã®ãµããŒããæ¹åããŸãã
- CLMãœãªã¥ãŒã·ã§ã³ãå®è£ ããåã«ã該åœããèŠçŽ ãšèæ ®äºé ãèæ ®ãããŠããããšã確èªããŠãã ããã
ãã®èšäºã§ã¯ãã©ã€ã»ã³ã¹ã¢ãããŒãã®éãã«ã€ããŠèª¬æããCLMãæ±ãããã®ã¯ã©ã¹ã®ç¹å®ã®ã·ã¹ãã ã§ããQuestInTrustã«ã€ããŠèª¬æããŸããã«ããã®äžã®è©³çްã
ãã®èšäºã®åé ã§ãSplunkã©ã€ã»ã³ã¹ãžã®æ°ããã¢ãããŒãã«ã€ããŠè©±ããŸãããã©ã€ã»ã³ã¹ã®çš®é¡ã¯ãè»ã®ã¬ã³ã¿ã«æéãšæ¯èŒã§ããŸãã CPUã¢ãã«ãç¡å¶éã®èµ°è¡è·é¢ãšã¬ãœãªã³ãåããçæå¹çã®è¯ãè»ã§ãããšããŸããããè·é¢å¶éãªãã§ã©ãã«ã§ãè¡ãããšãã§ããŸãããããŸãéãè¡ãããšãã§ããªãããã1æ¥ã«äœãããé転ã§ããŸããããŒã¿ããŒã¹ã®ã©ã€ã»ã³ã¹ã¯ããã€ã¬ãŒãžããšã®æ¯æãã¢ãã«ãåããã¹ããŒãã«ãŒã«äŒŒãŠããŸããããªãã¯æåã«é·è·é¢ãç©ã¿éããããšãã§ããŸãããããªãã¯äžæ¥ã®èµ°è¡è·é¢å¶éãè¶ ããããã«ãã£ãšãéãæããªããã°ãªããŸããã
è² è·ããŒã¹ã®ã©ã€ã»ã³ã¹ã䜿çšããã¡ãªãããåŸãã«ã¯ãGBã®ããŒã¿ãããŠã³ããŒãããããã®CPUã³ã¢ã®æ¯çãå¯èœãªéãå°ããããå¿ èŠããããŸããå®éã«ã¯ãããã¯æ¬¡ã®ãããªæå³ã§ãã
- .
- .
- ( CPU ).
ããã§æãåé¡ãšãªãã®ã¯ãæ£èŠåãããããŒã¿ã§ãã SIEMãçµç¹å ã®ãã¹ãŠã®ãã°ã®ã¢ã°ãªã²ãŒã¿ãŒã«ãããå Žåã¯ãèšå€§ãªéã®è§£æãšåŸåŠçã®äœæ¥ãå¿ èŠã«ãªããŸããè² è·ããé¢ããªãã¢ãŒããã¯ãã£ã«ã€ããŠãèããå¿ èŠãããããšãå¿ããªãã§ãã ããã远å ã®ãµãŒããŒãå¿ èŠã«ãªãããã远å ã®ããã»ããµãŒãå¿ èŠã«ãªããŸãã
ããªã¥ãŒã ã©ã€ã»ã³ã¹ã¯ãSIEMãžã§ãŒã«éä¿¡ãããããŒã¿ã®éã«åºã¥ããŠããŸãã远å ã®ããŒã¿ãœãŒã¹ã¯ã«ãŒãã«ïŒãŸãã¯ä»ã®é貚ïŒã«ãã£ãŠçœ°ãããããããå®éã«ã¯åéããããªããã®ã«ã€ããŠèããããšãã§ããŸãããã®ã©ã€ã»ã³ã¹ã¢ãã«ãã ãŸãããã«ãSIEMã·ã¹ãã ã«æ¿å ¥ãããåã«ããŒã¿ãåãããšãã§ããŸããæ³šå ¥åã®ãã®ãããªæ£èŠåã®äžäŸã¯ãElasticStackããã³ãã®ä»ã®åçšSIEMã§ãã
ãã®çµæãã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã©ã€ã»ã³ã¹ã¯ãæå°éã®ååŠçã§ç¹å®ã®ããŒã¿ã®ã¿ãåéããå¿ èŠãããå Žåã«å¹æçã§ãããããªã¥ãŒã ããšã®ã©ã€ã»ã³ã¹ã§ã¯ãã¹ãŠãåéããããšã¯ã§ããŸãããäžéãœãªã¥ãŒã·ã§ã³ãæ€çŽ¢ãããšã次ã®åºæºãæ±ããããŸãã
- ããŒã¿ã®éçŽãšæ£èŠåã®ç°¡çŽ åã
- ãã€ãºãšæãéèŠåºŠã®äœãããŒã¿ããã£ã«ã¿ãªã³ã°ããŸãã
- åææ©èœãæäŸããŸãã
- ãã£ã«ã¿ãªã³ã°ããã³æ£èŠåãããããŒã¿ãSIEMã«éä¿¡ãã
ãã®çµæãã¿ãŒã²ããSIEMã·ã¹ãã ã¯ãåŠçã«è¿œå ã®CPUãã¯ãŒãè²»ããå¿ èŠããªããäœãèµ·ãã£ãŠããã®ããå¯èŠåããããšãªããæãéèŠãªã€ãã³ãã®ã¿ãèå¥ããããšã§å©çãåŸãããšãã§ããŸãã
çæ³çã«ã¯ããã®ãããªããã«ãŠã§ã¢ãœãªã¥ãŒã·ã§ã³ã¯ãæœåšçã«æå®³ãªã¢ã¯ã·ã§ã³ã®åœ±é¿ã軜æžããã€ãã³ãã®ãããŒå šäœãSIEMãžã®äŸ¿å©ã§ã·ã³ãã«ãªããŒã¿ã¹ã©ã€ã¹ã«éçŽããããã«äœ¿çšã§ãããªã¢ã«ã¿ã€ã ã®æ€åºããã³å¿çæ©èœãæäŸããå¿ èŠããããŸããããã§ãããSIEMã䜿çšããŠã远å ã®éèšãçžé¢ãããã³éç¥ããã»ã¹ãäœæã§ããŸãã
ãã®éåžžã«ç¥ç§çãªäžéãœãªã¥ãŒã·ã§ã³ã¯ãèšäºã®åé ã§è¿°ã¹ãCLMã«ãããŸãããããã¯GartnerããããèŠãæ¹æ³ã§ãïŒ
ããã§ãInTrustãGartnerã®æšå¥šäºé ã«ã©ã®ããã«æºæ ããŠããããçè§£ããããšãã§ããŸãã
- , .
- .
- â , CLM, BI- .
- ( ).
Quest InTrustã¯ãæå€§40ïŒ1ã®ããŒã¿å§çž®ãšé«ãéè€æé€çãåããç¬èªã®ã¹ãã¬ãŒãžã·ã¹ãã ã䜿çšããŸããããã«ãããCLMããã³SIEMã·ã¹ãã ã®ã¹ãã¬ãŒãžãªãŒããŒããããåæžãããŸãã
googleã®ãããªæ€çŽ¢ãåããITã»ãã¥ãªãã£æ€çŽ¢ã³ã³ãœãŒã«
ITã»ãã¥ãªãã£æ€çŽ¢ïŒITSSïŒWebã€ã³ã¿ãŒãã§ã€ã¹ãåããå°çšã¢ãžã¥ãŒã«ã¯ãInTrustãªããžããªå ã®ã€ãã³ãããŒã¿ã«æ¥ç¶ã§ããè åšãæ€çŽ¢ããããã®ã·ã³ãã«ãªã€ã³ã¿ãŒãã§ã€ã¹ãæäŸããŸããã€ã³ã¿ãŒãã§ã€ã¹ã¯ãã€ãã³ããã°ããŒã¿ã«å¯ŸããŠGoogleã®ããã«æ©èœããããã«ç°¡çŽ åãããŠããŸãã ITSSã¯ãã¯ãšãªçµæã«ã¿ã€ã ã©ã€ã³ã䜿çšããã€ãã³ããã£ãŒã«ããçµã¿åãããŠã°ã«ãŒãåããããšãã§ããè åšãèŠã€ããã®ã«å¹æçã§ãã
InTrustã¯ãSIDããã¡ã€ã«åãããã³SIDã䜿çšããŠWindowsã€ãã³ãã匷åããŸããInTrustã¯ãŸããã€ãã³ããåçŽãªW6ã¹ããŒãïŒWhoãWhatãWhereãWhenãWhomãWhere From-whoãwhatãwhereãwhenãwhoãwhereïŒã«æ£èŠåããŠãããŸããŸãªãœãŒã¹ïŒãã€ãã£ãWindowsã€ãã³ããLinuxãã°ãŸãã¯syslogïŒããã®ããŒã¿ãäœæããŸããåäžã®åœ¢åŒãšåäžã®æ€çŽ¢ã³ã³ãœãŒã«ã§è¡šç€ºã§ããŸãã
InTrustã¯ãEDRã®ãããªã·ã¹ãã ãšããŠäœ¿çšã§ãããªã¢ã«ã¿ã€ã ã®ã¢ã©ãŒããæ€åºãããã³å¿çæ©èœããµããŒãããŠãçãããã¢ã¯ãã£ããã£ã«ãã£ãŠåŒãèµ·ããããæå·ãæå°éã«æããŸããçµã¿èŸŒã¿ã®ã»ãã¥ãªãã£ã«ãŒã«ã¯ã次ã®è åšãæ€åºããŸããããããã«éå®ãããŸããã
- ãã¹ã¯ãŒãã¹ãã¬ãŒã
- ã«ãŒããã¢ã¹ãã
- Mimikatzã®å®è¡ãªã©ãçãããPowerShellã¢ã¯ãã£ããã£ã
- LokerGogaã©ã³ãµã ãŠã§ã¢ãªã©ã®ããã»ã¹ã¯çãããã§ãã
- CA4FSãã°ã䜿çšããæå·åã
- ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§ç¹æš©ã¢ã«ãŠã³ãã䜿çšããŠãã°ã€ã³ããŸãã
- ãã¹ã¯ãŒãæšæž¬æ»æã
- ããŒã«ã«ãŠãŒã¶ãŒã°ã«ãŒãã®çããã䜿çšã
次ã«ãInTrustèªäœã®ã¹ã¯ãªãŒã³ã·ã§ãããããã€ã瀺ããŠããã®æ©èœã®å°è±¡ãã€ããããšãã§ããŸãã
æœåšçãªè匱æ§ãæ€çŽ¢ããããã®äºåå®çŸ©ããããã£ã«ã¿ãŒ
çããŒã¿ãåéããããã®äžé£ã®ãã£ã«ã¿ãŒã®äŸ
éåžžã®åŒã䜿çšããŠã€ãã³ããžã®åå¿ãäœæããäŸ
PowerShellèåŒ±æ§æ€çŽ¢ã«ãŒã«ã®äŸ
è匱æ§ã®èª¬æãå«ãçµã¿èŸŒã¿ã®ãã¬ããžããŒã¹
InTrustã¯ãåè¿°ã®ããã«ãç¬ç«ãããœãªã¥ãŒã·ã§ã³ãšããŠãSIEMã·ã¹ãã ã®äžéšãšããŠã䜿çšã§ãã匷åãªããŒã«ã§ããããããããã®ãœãªã¥ãŒã·ã§ã³ã®äž»ãªå©ç¹ã¯ãã€ã³ã¹ããŒã«åŸããã«äœ¿çšãéå§ã§ããããšã§ãã InTrustã«ã¯ãè åšãšãããã«å¯Ÿããåå¿ãæ€åºããããã®ã«ãŒã«ã®å€§èŠæš¡ãªã©ã€ãã©ãªããããŸãïŒããšãã°ããŠãŒã¶ãŒã®ãããã¯ïŒã
ãã®èšäºã§ã¯ãããã¯ã¹åãããçµ±åã«ã€ããŠã¯èª¬æããŸããã§ããããã ããã€ã³ã¹ããŒã«çŽåŸã«ãSplunkãIBM QRadarãMicrofocus Arcsightã«ããŸãã¯Webhookãä»ããŠä»ã®ã·ã¹ãã ã«ã€ãã³ããéä¿¡ããããã«æ§æã§ããŸãã以äžã¯ãInTrustããã®ã€ãã³ãã䜿çšããKibanaã€ã³ã¿ãŒãã§ã€ã¹ã®äŸã§ãã Elastic Stackã«ã¯ãã§ã«çµ±åãããŠãããç¡æããŒãžã§ã³ã®Elasticã䜿çšããŠããå Žåã¯ãè åšãæ€åºããããã¢ã¯ãã£ããªã¢ã©ãŒããå®è¡ããéç¥ãéä¿¡ããããã®ããŒã«ãšããŠInTrustã䜿çšã§ããŸãã
ããŸãããã°ãèšäºã¯ãã®è£œåã®æå°éã®ç޹ä»ãäžããŸããããã¹ããŸãã¯ãã€ããããããžã§ã¯ãã宿œããããã«ãInTrustãæäŸããæºåãæŽããŸãããã¢ããªã±ãŒã·ã§ã³ã¯ãåœç€Ÿã®Webãµã€ãã®ãã£ãŒãããã¯ãã©ãŒã ã«æ®ãããšãã§ããŸãã
æ å ±ã»ãã¥ãªãã£ã«é¢ããä»ã®èšäºãèªãã§ãã ããã
ã©ã³ãµã ãŠã§ã¢æ»æãç¹å®ãããã¡ã€ã³ã³ã³ãããŒã©ãŒã«ã¢ã¯ã»ã¹ããŠããããã®æ»æã«æµæããããšãã
Windowsã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ãã°ããååŸããã®ã«åœ¹ç«ã€ãã®ïŒäººæ°ã®èšäºïŒ
ãã©ã€ã€ãŒãããŒãã䜿çšããã«ãŠãŒã¶ãŒã®ã©ã€ããµã€ã¯ã«ã远跡ãã
誰ããããè¡ããŸãããïŒæ å ±ã»ãã¥ãªãã£ç£æ»ãèªååããŸãFacebookã®ããŒãžã
賌èªããçãã¡ã¢ãšè峿·±ããªã³ã¯ãå ¬éããŸãã