ããŒãœãã«ã³ã³ãã¥ãŒã¿çšã®æ°ããã¯ã©ãŠãããŒã¹ã®ã»ãã¥ãªãã£ç®¡çã³ã³ãœãŒã«ã«é¢ããã·ãªãŒãºã®3çªç®ã®èšäºã§ããCheckPoint SandBlast Agent ManagementPlatformãžãããããæåã®èšäºã§ãInfinity Portalã«ç²Ÿéããã¯ã©ãŠãããŒã¹ã®ãšãŒãžã§ã³ã管çãµãŒãã¹ã§ããEndpoint ManagementServiceãäœæããããšãæãåºããŠãã ãããã§ã¯ç¬¬äºã®èšäºãç§ãã¡ã¯ãWeb管çã³ã³ãœãŒã«ã€ã³ã¿ãã§ãŒã¹ãæ€èšãããŠãŒã¶ãŒã®ãã·ã³äžã®æšæºããªã·ãŒã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããŸããã仿¥ã¯ãæšæºã®è åšé²æ¢ã»ãã¥ãªãã£ããªã·ãŒã®å 容ã確èªããäžè¬çãªæ»æã«å¯Ÿæãã广ããã¹ãããŸãã
è åšé²æ¢æšæºããªã·ãŒïŒèª¬æ
äžã®å³ã¯ãããã©ã«ãã§çµç¹å šäœïŒã€ã³ã¹ããŒã«ãããŠãããã¹ãŠã®ãšãŒãžã§ã³ãïŒã«é©çšãããä¿è·ã³ã³ããŒãã³ãã®3ã€ã®è«çã°ã«ãŒãïŒWebãšãã¡ã€ã«ã®ä¿è·ãåäœä¿è·ãåæãšä¿®åŸ©ïŒãå«ãæšæºã®è åšé²æ¢ããªã·ãŒã«ãŒã«ã瀺ããŠããŸããåã°ã«ãŒãã詳ããèŠãŠãããŸãããã
Webãšãã¡ã€ã«ã®ä¿è·
URLãã£ã«ã¿ãªã³ã°
URL Filtering -, 5 . 5 , , , Games Instant Messaging, Productivity Loss. URL, , Check Point. , URL, URL Categorization.
Prevent, Detect Off. Detect , URL Filtering . Prevent . Block List, , IP- .csv .
Prevent, Detect Off. Detect , URL Filtering . Prevent . Block List, , IP- .csv .
URLãã£ã«ã¿ãªã³ã°ã®æšæºããªã·ãŒã§ã¯ãã¢ã¯ã·ã§ã³Detectãèšå®ããã1ã€ã®ã«ããŽãªïŒã€ãã³ããæ€åºãããã»ãã¥ãªãã£ïŒãéžæãããŠããŸãããã®ã«ããŽãªã«ã¯ãããŸããŸãªå¿ååæ©èœãé倧/é«/äžãªã¹ã¯ã¬ãã«ã®ãµã€ãããã£ãã·ã³ã°ãµã€ããã¹ãã ãªã©ãå«ãŸããŸãããã ãã[ãŠãŒã¶ãŒãURLãã£ã«ã¿ãªã³ã°ã¢ã©ãŒããéããŠWebãµã€ãã«ã¢ã¯ã»ã¹ããããšãèš±å¯ãã]èšå®ã®ãããã§ããŠãŒã¶ãŒã¯åŒãç¶ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã
ããŠã³ããŒãïŒãŠã§ãïŒä¿è·
Emulation & Extraction Check Point « », , PDF. :
, Check Point â .
- Prevent â , ;
- Detect â , , ;
- Off â .
, Check Point â .
ããŠã³ããŒãä¿è·ã®ããã©ã«ãããªã·ãŒã¯ãæªæã®ããå¯èœæ§ã®ããã³ã³ãã³ããåé€ãããå ã®ããã¥ã¡ã³ãã®ã³ããŒãååŸããæ©èœãšããšãã¥ã¬ãŒã·ã§ã³ããã³ã¯ãªãŒã³ã¢ããããŒã«ã§ãµããŒããããŠããªããã¡ã€ã«ã®ããŠã³ããŒããèš±å¯ããæ©èœãåãã鲿¢ã¢ã¯ã·ã§ã³ã«èšå®ãããŠããŸãã
è³æ Œæ
å ±ã®ä¿è·
Credential Protection 2 : Zero Phishing Password Protection. Zero Phishing , Password Protection . Zero Phishing Prevent, Detect Off. Prevent , . Detect . Password Protection , , : Detect & Alert ( ), Detect Off.
è³æ Œæ å ±ä¿è·ã®æšæºããªã·ãŒã¯ããŠãŒã¶ãŒãæªæã®ããå¯èœæ§ã®ãããµã€ãã«ã¢ã¯ã»ã¹ã§ããªãããã«ãããã£ãã·ã³ã°ãªãœãŒã¹ã®é²æ¢ãæäŸããŸããäŒæ¥ãã¹ã¯ãŒãã®äœ¿çšã«å¯Ÿããä¿è·ãå«ãŸããŠããŸããããã®æ©èœã¯æå®ããããã¡ã€ã³ããªããšæ©èœããŸããã
ãã¡ã€ã«ä¿è·
Files Protection , , : Anti-Malware Files Threat Emulation. Anti-Malware , . , , . Files Threat Emulation Check Point, Detect.
ãã¡ã€ã«ä¿è·ã®æšæºããªã·ãŒã«ã¯ããã¡ã€ã«è åšãšãã¥ã¬ãŒã·ã§ã³ã䜿çšãããã«ãŠã§ã¢å¯Ÿçä¿è·ãšãã«ãŠã§ã¢æ€åºãå«ãŸããŸãã宿çãªã¹ãã£ã³ãæ¯æå®è¡ããããŠãŒã¶ãŒã®ãã·ã³ã®çœ²åã¯4æéããšã«æŽæ°ãããŸããåæã«ããŠãŒã¶ãŒãã¹ã±ãžã¥ãŒã«ãããã¹ãã£ã³ããã£ã³ã»ã«ããæ©èœãæ§æãããŠããŸãããæåŸã«æåããã¹ãã£ã³ãã30æ¥ä»¥å ã§ãã
è¡åä¿è·
ã¢ã³ãããããããã€ãã¢ã¬ãŒãïŒã¢ã³ãã©ã³ãµã ãŠã§ã¢ãã¢ã³ããšã¯ã¹ããã€ã
Behavioral Protection : Anti-Bot, Behavioral Guard & Anti-Ransomware Anti-Exploit. Anti-Bot C&C Check Point ThreatCloud. Behavioral Guard & Anti-Ransomware (, , ) . , , . , , . Anti-Exploit . Behavioral Protection : Prevent, Detect Off.
Behavioral Protectionã®æšæºããªã·ãŒã§ã¯ãAnti-Botããã³Behavioral GuardïŒAnti-Ransomwareã³ã³ããŒãã³ãã®é²æ¢ãšãå ã®ãã£ã¬ã¯ããªå ã®æå·åããããã¡ã€ã«ã®å埩ãæäŸãããŸããAnti-Exploitã³ã³ããŒãã³ãã¯ç¡å¹ã«ãªã£ãŠããã䜿çšãããŠããŸããã
åæãšä¿®åŸ©
èªåæ»æåæïŒãã©ã¬ã³ãžãã¯ïŒã修埩ããã³å¯Ÿå¿
: Automated Attack Analysis (Forensics) Remediation & Response. Automated Attack Analysis (Forensics) â . Threat Hunting, . Remediation & Response : , .
æšæºã®AnalysisïŒRemediationããªã·ãŒã«ã¯ãå埩ã®ããã®èªåã¢ã¯ã·ã§ã³ïŒããã»ã¹ã®çµäºããã¡ã€ã«ã®åŸ©å ãªã©ïŒãå«ãä¿è·ãšããã¡ã€ã«ãæ€ç«ã«éä¿¡ãããªãã·ã§ã³ãå«ãŸãããŠãŒã¶ãŒã¯æ€ç«ãããã¡ã€ã«ãåé€ããããšããã§ããŸããã
è åšé²æ¢æšæºããªã·ãŒïŒãã¹ã
ãã§ãã¯ãã€ã³ãCheckMeãšã³ããã€ã³ã
æãäžè¬çãªã¿ã€ãã®æ»æã«å¯ŸããŠãŠãŒã¶ãŒãã·ã³ã®ã»ãã¥ãªãã£ããã§ãã¯ããæãéããŠç°¡åãªæ¹æ³ã¯ãCheck Point CheckMeãªãœãŒã¹ã䜿çšããŠãã¹ããå®è¡ããããšã§ãããã®ãªãœãŒã¹ã¯ãããŸããŸãªã«ããŽãªã®å€ãã®å žåçãªæ»æãå®è¡ãããã¹ãçµæã«é¢ããã¬ããŒããååŸã§ããŸãããã®å Žåããšã³ããã€ã³ããã¹ããªãã·ã§ã³ã䜿çšããŸããããã®ãªãã·ã§ã³ã§ã¯ãå®è¡å¯èœãã¡ã€ã«ãããŠã³ããŒããããŠã³ã³ãã¥ãŒã¿ãŒã«èµ·åãããæ€èšŒããã»ã¹ãéå§ãããŸãã
åäœäžã®ã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£ããã§ãã¯ããŠããéãSandBlast Agentã¯ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«å¯Ÿããæ»æãç¹å®ããŠåæ ããŸããããšãã°ãAnti-Botãã¬ãŒããææãå ±åããAnti-Malwareãã¬ãŒããæªæã®ãããã¡ã€ã«CP_AM.exeãæ€åºããŠåé€ããThreatEmulationãã¬ãŒããã€ã³ã¹ããŒã«ãããŸããã CP_ZD.exeãã¡ã€ã«ãæªæã®ãããã®ã§ããããšã CheckMe Endpointã䜿çšãããã¹ãã®çµæã«åºã¥ããŠã次ã®çµæãåŸãããŸãããæ»æã®6ã€ã®ã«ããŽãªã®ãã¡ãæšæºã®è åšé²æ¢ããªã·ãŒã¯1ã€ã®ã«ããŽãªïŒãã©ãŠã¶ã®æªçšïŒã§ã®ã¿å€±æããŸãããããã¯ãæšæºã®è åšé²æ¢ããªã·ãŒã«æªçšé²æ¢ãã¬ãŒããå«ãŸããŠããªãããã§ããSandBlast Agentãã€ã³ã¹ããŒã«ãããŠããªãå ŽåããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã¯Ransomwareã«ããŽãªã«ã€ããŠã®ã¿ã¹ãã£ã³ãããããšã«æ³šæããŠãã ããã
KnowBe4 RanSim
Anti- Ransomwareãã¬ãŒãããã¹ãããã«ã¯ãç¡æã®KnowBe4 RanSimãœãªã¥ãŒã·ã§ã³ã䜿çšã§ããŸãããã®ãœãªã¥ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒã®ãã·ã³ã§äžé£ã®ãã¹ããå®è¡ããŸãã18ã®ã©ã³ãµã ãŠã§ã¢ææã·ããªãªãš1ã€ã®ã¯ãªãããã€ããŒææã·ããªãªã§ãã鲿¢ã¢ã¯ã·ã§ã³ãåããæšæºããªã·ãŒïŒè åšãšãã¥ã¬ãŒã·ã§ã³ããã«ãŠã§ã¢å¯Ÿçãè¡åã¬ãŒãïŒã«å€ãã®ãã¬ãŒããååšãããšããã®ãã¹ããæ£ããå®è¡ã§ããªãããšã«æ³šæããŠãã ããããã ããã»ãã¥ãªãã£ã¬ãã«ãäžããŠãïŒãªãã¢ãŒãã§ã®è åšãšãã¥ã¬ãŒã·ã§ã³ïŒãAnti-Ransomwareãã¬ãŒããã¹ãã¯è¯å¥œãªçµæã瀺ããŸãã19åã®ãã¹ãã®ãã¡18åãæåããŸããïŒ1åã¯éå§ããŸããã§ããïŒã
æªæã®ãããã¡ã€ã«ãšããã¥ã¡ã³ã
ãŠãŒã¶ãŒã®ãã·ã³ã«ããŠã³ããŒããããäžè¬çãªåœ¢åŒã®æªæã®ãããã¡ã€ã«ã䜿çšããŠãæšæºã®è åšé²æ¢ããªã·ãŒã®ããŸããŸãªãã¬ãŒãã®åäœã確èªããããšã¯æçã§ãããã®ãã¹ãã«ã¯ãPDFãDOCãDOCXãEXEãXLSãXLSXãCABãRTF圢åŒã®66åã®ãã¡ã€ã«ãå«ãŸããŠããŸããããã¹ãçµæã¯ãSandBlast Agentã66ã®ãã¡64ã®æªæã®ãããã¡ã€ã«ããããã¯ã§ããããšã瀺ããŸãããææãããã¡ã€ã«ã¯ããŠã³ããŒãåŸã«åé€ãããããThreat Extractionã䜿çšããŠæªæã®ããã³ã³ãã³ããåé€ããããŠãŒã¶ãŒã«ãã£ãŠååŸãããŸããã
è åšé²æ¢ããªã·ãŒãæ¹åããããã®æšå¥šäºé
1.URLãã£ã«ã¿ãªã³ã°
ã¯ã©ã€ã¢ã³ããã·ã³ã®ã»ãã¥ãªãã£ã¬ãã«ãäžããããã«æšæºããªã·ãŒã§æåã«ä¿®æ£ããå¿ èŠãããã®ã¯ãURLãã£ã«ã¿ãªã³ã°ãã¬ãŒããç§»åããŠé²æ¢ãããããã¯ããé©åãªã«ããŽãªãæå®ããããšã§ããç§ãã¡ã®å Žåãè·å Žã®ãŠãŒã¶ãŒãžã®ã¢ã¯ã»ã¹ãå¶éããããã«å¿ èŠãªãªãœãŒã¹ã®ã»ãšãã©ãå«ãŸããŠãããããäžè¬çãªäœ¿çšãé€ããã¹ãŠã®ã«ããŽãªãéžæãããŸããããŸãããã®ãããªãµã€ãã§ã¯ã[ãŠãŒã¶ãŒã«URLãã£ã«ã¿ãªã³ã°ã¢ã©ãŒãã®è§£é€ãšWebãµã€ããžã®ã¢ã¯ã»ã¹ãèš±å¯ãã]ãªãã·ã§ã³ããªãã«ããŠããŠãŒã¶ãŒãèŠåãŠã£ã³ããŠãã¹ãããããæ©èœãåé€ããããšãæãŸããŸãã
2.ããŠã³ããŒãä¿è·
泚æãã¹ã2çªç®ã®ãã©ã¡ãŒã¿ãŒã¯ããŠãŒã¶ãŒããã§ãã¯ãã€ã³ããšãã¥ã¬ãŒã·ã§ã³ã§ãµããŒããããŠããªããã¡ã€ã«ãããŠã³ããŒãããæ©èœã§ãããã®ã»ã¯ã·ã§ã³ã§ã¯ãæšæºã®è åšé²æ¢ããªã·ãŒã«å¯Ÿããã»ãã¥ãªãã£ã®åŒ·åã«ã€ããŠèª¬æããŠããããããµããŒããããŠããªããã¡ã€ã«ã®ããŠã³ããŒããçŠæ¢ããã®ãæåã®æ¹æ³ã§ãã
3.ãã¡ã€ã«ä¿è·
ãŸãããã¡ã€ã«ãä¿è·ããããã®èšå®ãç¹ã«å®æã¹ãã£ã³ã®ãã©ã¡ãŒã¿ãŒãšã匷å¶ã¹ãã£ã³ãå»¶æãããŠãŒã¶ãŒã®æ©èœã«ã泚æãæãå¿ èŠããããŸãããã®å ŽåããŠãŒã¶ãŒã®æéæ ãèæ ®ããå¿ èŠããããŸããã»ãã¥ãªãã£ãšããã©ãŒãã³ã¹ã®èгç¹ãããæ¯æ¥åŒ·å¶ã¹ãã£ã³ã®å®è¡ãæ§æããããšããå§ãããŸããæéã¯ã©ã³ãã ã«éžæããïŒ00:00ãã8:00ïŒããŠãŒã¶ãŒã¯ã¹ãã£ã³ãæå€§ã§å»¶æã§ããŸããäžé±éã
4.ã¢ã³ããšã¯ã¹ããã€ã
æšæºã®è åšé²æ¢ããªã·ãŒã®éå€§ãªæ¬ ç¹ã¯ãã¢ã³ããšã¯ã¹ããã€ããã¬ãŒããç¡å¹ã«ãªã£ãŠããããšã§ããã¯ãŒã¯ã¹ããŒã·ã§ã³ãæªç𿻿ããä¿è·ããããã«ã鲿¢ã¢ã¯ã·ã§ã³ã§ãã®ãã¬ãŒããæå¹ã«ããããšããå§ãããŸãããã®ä¿®æ£ã«ãããCheckMeã®åãã¹ãã¯ããŠãŒã¶ãŒã®äœæ¥ãã·ã³ã®è匱æ§ãæ€åºããã«æåããŸãã
çµè«
èŠçŽãããšããã®èšäºã§ã¯ãæšæºã®è åšé²æ¢ããªã·ãŒã®ã³ã³ããŒãã³ãã«ã€ããŠçè§£ããããŸããŸãªæ¹æ³ãšããŒã«ã䜿çšããŠãã®ããªã·ãŒããã¹ããããŠãŒã¶ãŒã®ãã·ã³ã®ã»ãã¥ãªãã£ã¬ãã«ãäžããããã«æšæºããªã·ãŒã®èšå®ãæ¹åããããã®æšå¥šäºé ã«ã€ããŠã説æããŸããããã®ã·ãªãŒãºã®æ¬¡ã®èšäºã§ã¯ãããŒã¿ä¿è·ããªã·ãŒã®èª¿æ»ã«é²ã¿ãã°ããŒãã«ããªã·ãŒèšå®ã«ã€ããŠèª¬æããŸãã
TSãœãªã¥ãŒã·ã§ã³ããã®ãã§ãã¯ãã€ã³ãã®ææã®å€§èŠæš¡ãªéžæãSandBlast Agent Management Platformã®æ¬¡ã®åºçç©ãèŠéããªãããã«ããœãŒã·ã£ã«ãããã¯ãŒã¯ïŒTelegramãFacebookãVKãTS Solution BlogãYandex.DenïŒã®æŽæ°ã«åŸã£ãŠãã ããã