Check Point SandBlast Agent ManagementPlatformã·ãªãŒãºã®4çªç®ã®èšäºãžããããã以åã®èšäºïŒ1çªç®ã2çªç®ã3çªç®ïŒã§ã¯ãWeb管çã³ã³ãœãŒã«ã®ã€ã³ã¿ãŒãã§ã€ã¹ãšæ©èœã«ã€ããŠè©³ãã説æããè åšé²æ¢ããªã·ãŒã確èªããŠãããŸããŸãªè åšã«å¯ŸããŠãã¹ãããŸããããã®èšäºã§ã¯ã2çªç®ã®ã»ãã¥ãªãã£ã³ã³ããŒãã³ãã§ããããŒã¿ä¿è·ããªã·ãŒã«ã€ããŠèª¬æããŸããããŒã¿ä¿è·ããªã·ãŒã¯ããŠãŒã¶ãŒã®ãã·ã³ã«ä¿åãããŠããããŒã¿ã®ä¿è·ãæ åœããŸãããŸãããã®èšäºã®ããããã€ã¡ã³ããã»ã¯ã·ã§ã³ãšãã°ããŒãã«ããªã·ãŒèšå®ãã»ã¯ã·ã§ã³ã«ã€ããŠã説æããŸãã
ããŒã¿ä¿è·ããªã·ãŒ
ããŒã¿ä¿è·ããªã·ãŒã§ã¯ãèš±å¯ããããŠãŒã¶ãŒã®ã¿ãããã«ãã£ã¹ã¯æå·åããã³ããŒãä¿è·æ©èœã䜿çšããŠæ¬çªãã·ã³ã«ä¿åãããŠããããŒã¿ã«ã¢ã¯ã»ã¹ã§ããŸããçŸåšããã£ã¹ã¯æå·åãæ§æããããã®æ¬¡ã®ãªãã·ã§ã³ããµããŒããããŠããŸããWindowsã®å Žå-ãã§ãã¯ãã€ã³ãæå·åãŸãã¯BitLockeræå·åãMacOSã®å Žå-ãã¡ã€ã«ããŒã«ããåãªãã·ã§ã³ã®æ©èœãšèšå®ã«ã€ããŠè©³ããèŠãŠãããŸãããã
ãã§ãã¯ãã€ã³ãæå·å
ãã§ãã¯ãã€ã³ãæå·åã¯ãããŒã¿ä¿è·ããªã·ãŒã®æšæºã®ãã£ã¹ã¯æå·åæ¹åŒã§ããããŠãŒã¶ãŒãã·ã³ã®ç¶æ ã«åœ±é¿ãäžããããšãªããããã¯ã°ã©ãŠã³ãã§ãã¹ãŠã®ã·ã¹ãã ãã¡ã€ã«ïŒäžæãã·ã¹ãã ããªã¢ãŒãïŒãæå·åããŸããæå·ååŸãæš©éã®ãªããŠãŒã¶ãŒã¯ãã©ã€ãã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã ãã§ãã¯ãã€ã³ãæå·åã®äž»ãªèšå®ã¯ãããªããŒããæå¹ã«ãããã§ããããã«ããããŠãŒã¶ãŒã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãããŒãããåã«èªèšŒã§ããŸãããã®ãªãã·ã§ã³ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¬ãã«ã§ã®èªèšŒãã€ãã¹ããŒã«ã®äœ¿çšã劚ããããã䜿çšããå§ãããŸããèµ·ååã®æéãã€ãã¹ãã©ã¡ãŒã¿ãèšå®ããããšãã§ããŸãã
- Allow OS login after temporary bypass â Pre-boot ;
- Allow pre-boot bypass (Wake On LAN â WOL) â pre-boot , Ethernet;
- Allow bypass script â Pre-boot Pre-boot;
- Allow LAN bypass â pre-boot .
äžèšã®èµ·ååã®äžæãã€ãã¹ãªãã·ã§ã³ã¯ãæãããªçç±ïŒã¡ã³ããã³ã¹ããã©ãã«ã·ã¥ãŒãã£ã³ã°ãªã©ïŒããªãããæšå¥šãããŸãããæåã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯ãäžæãã€ãã¹ã«ãŒã«ãæå®ããã«èµ·ååãæå¹ã«ããããšã§ãããã¬ããŒãããã€ãã¹ããå¿ èŠãããå Žåã¯ãä¿è·ã¬ãã«ãé·æéäœäžãããªãããã«ãäžæçãªãã€ãã¹ãã©ã¡ãŒã¿ã«å¿ èŠãªæå°æéæ ãèšå®ããããšããå§ãããŸãã ãŸãããã§ãã¯ãã€ã³ãæå·åã䜿çšãããšãããŒã¿ä¿è·ããªã·ãŒã®è©³çްèšå®ãæ§æã§ããŸããããšãã°ãæå·åèšå®ãããæè»ã«æ§æããããèµ·ååæ©èœãWindowsèªèšŒã®ããŸããŸãªåŽé¢ãæ§æãããã§ããŸãã
BitLockeræå·å
BitLockerã¯Windowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®äžéšã§ãããããŒããã©ã€ããšãªã ãŒããã«ã¡ãã£ã¢ãæå·åã§ããŸãããã§ãã¯ãã€ã³ãBitLockerManagementã¯ãSandBlast Agentã¯ã©ã€ã¢ã³ãã§èªåçã«èµ·åããBitLocker管çAPIã䜿çšããWindowsãµãŒãã¹ã³ã³ããŒãã³ãã§ãã ããŒã¿ä¿è·ããªã·ãŒã§ãã©ã€ãã®æå·åæ¹æ³ãšããŠBitLockeræå·åãéžæãããšã次ã®ãªãã·ã§ã³ãæ§æã§ããŸãã
- åææå·å-åææå·åèšå®ãæ¢åã®ãŠãŒã¶ãŒããŒã¿ïŒãã¡ã€ã«ãããã¥ã¡ã³ããªã©ïŒã䜿çšãããã·ã³ã«æšå¥šããããã©ã€ãå šäœãæå·åïŒãã©ã€ãå šäœãæå·åïŒããããæ°ãããã®ã«æšå¥šãããããŒã¿ã®ã¿ãæå·åïŒäœ¿çšæžã¿ãã£ã¹ã¯é åã®ã¿ãæå·åïŒããããšãã§ããŸãã Windowsã€ã³ã¹ããŒã«;
- æå·åãããã©ã€ã-æå·åãããã©ã€ã/ããŒãã£ã·ã§ã³ãéžæãããã¹ãŠã®ãã©ã€ãïŒãã¹ãŠã®ãã©ã€ãïŒãŸãã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãåããããŒãã£ã·ã§ã³ã®ã¿ïŒOSãã©ã€ãã®ã¿ïŒãæå·åã§ããŸãã
- æå·åã¢ã«ãŽãªãºã -æå·åã¢ã«ãŽãªãºã ã®éžæãæšå¥šããããªãã·ã§ã³ã¯Windowsã®ããã©ã«ãã§ããXTS-AES-128ãŸãã¯XTS-AES-256ãæå®ããããšãã§ããŸãã
ãã¡ã€ã«ããŒã«ã
File Vaultã¯ãAppleã®æšæºæå·åããŒã«ã§ãããèš±å¯ããããŠãŒã¶ãŒã®ã¿ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒããŒã¿ã«ã¢ã¯ã»ã¹ã§ããããã«ããŸããFile Vaultãã€ã³ã¹ããŒã«ãããŠããå ŽåããŠãŒã¶ãŒã¯ãã¹ã¯ãŒããå ¥åããŠã·ã¹ââãã ãèµ·åããæå·åããããã¡ã€ã«ã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸããFile Vaultã䜿çšããããšã¯ãMacOSãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãŠãŒã¶ãŒã®ããŒã¿ä¿è·ããªã·ãŒã«ä¿åãããŠããããŒã¿ã確å®ã«ä¿è·ããå¯äžã®æ¹æ³ã§ãã
File Vaultã®å ŽåããèªåãŠãŒã¶ãŒååŸãæå¹ã«ããããªãã·ã§ã³ã䜿çšã§ããŸããããã«ã¯ããã£ã¹ã¯æå·åããã»ã¹ãéå§ããåã«ãŠãŒã¶ãŒèªèšŒãå¿ èŠã§ãããã®æ©èœãæå¹ã«ãªã£ãŠããå ŽåãSandBlast AgentãããªããŒãæ©èœãé©çšããåã«èš±å¯ããå¿ èŠã®ãããŠãŒã¶ãŒæ°ãæå®ããããèš±å¯ããããã¹ãŠã®ãŠãŒã¶ãŒã«å¯ŸããŠããªããŒãæ©èœãèªåçã«å®è£ ããããŸã§ã®æ¥æ°ãæå®ãããã§ããŸãããã®æéäžãå°ãªããšã1人ã®ãŠãŒã¶ãŒãã·ã¹ãã ã§èš±å¯ãããŸãã
ããŒã¿åŸ©æ§
ã·ã¹ãã ã®èµ·åã«åé¡ãããå Žåã¯ãããŸããŸãªæ¹æ³ã§ããŒã¿ãå埩ã§ããŸãã管çè ã¯ã[ã³ã³ãã¥ãŒã¿ãŒã®ç®¡ç]â[ãã«ãã£ãã¯æå·åã¢ã¯ã·ã§ã³]ã»ã¯ã·ã§ã³ãããæå·åãããããŒã¿ã埩å ããããã»ã¹ãéå§ã§ããŸãããã§ãã¯ãã€ã³ãæå·åã䜿çšãããšã以åã«æå·åããããã©ã€ãã埩å·åããŠãä¿åãããŠãããã¹ãŠã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸãããã®æé ã®åŸãããŒã¿ä¿è·ããªã·ãŒãæ©èœãããã«ã¯ããã£ã¹ã¯æå·åããã»ã¹ãåéããå¿ èŠããããŸãã ããŒã¿ãªã«ããªçšã®ãã£ã¹ã¯ã®æå·åæ¹æ³ãšããŠBitLockerãéžæããå Žåãåé¡ã®ã³ã³ãã¥ãŒã¿ã®ãªã«ããªããŒIDãå ¥åããŠãªã«ããªããŒãçæããå¿ èŠããããŸãããªã«ããªããŒã¯ãæå·åããããã£ã¹ã¯ã«ã¢ã¯ã»ã¹ããããã«ãŠãŒã¶ãŒãå ¥åããå¿ èŠããããŸãã
File Vaultã䜿çšããŠä¿åãããæ å ±ãä¿è·ããMacOSãŠãŒã¶ãŒã®å Žåãå埩ããã»ã¹ã¯ã管çè ãåé¡ã®ãã·ã³ã®ã·ãªã¢ã«çªå·ã«åºã¥ããŠå埩ããŒãçæãããã®ããŒãå ¥åããŠãããã¹ã¯ãŒãããªã»ããããããšã§æ§æãããŸãã
å±éããªã·ãŒ
Web管çã³ã³ãœãŒã«ã€ã³ã¿ãŒãã§ã€ã¹ã確èªã ã2çªç®ã®èšäºã®ãªãªãŒã¹ä»¥éãCheck Pointã¯Deploymentã»ã¯ã·ã§ã³ã«ããã€ãã®å€æŽãå ããããšãã§ããŸãããããã«ã¯ããã§ã«ã€ã³ã¹ããŒã«ãããŠãããšãŒãžã§ã³ãã®æ§æïŒãã¬ãŒãã®æå¹å/ç¡å¹åïŒãæ§æãããŠããSoftwareDeploymentãµãã»ã¯ã·ã§ã³ãšãµãã»ã¯ã·ã§ã³ãå«ãŸããŠããŸããããã±ãŒãžã®ãšã¯ã¹ããŒãããã¬ãŒããäºåã«ã€ã³ã¹ããŒã«ãããããã±ãŒãžãäœæããŠãããšãã°Active Directoryã°ã«ãŒãããªã·ãŒã䜿çšããŠããŠãŒã¶ãŒã®ãã·ã³ã«ããã«ã€ã³ã¹ããŒã«ã§ããŸãããã¹ãŠã®SandBlastAgentãã¬ãŒããå«ããœãããŠã§ã¢å±éãµãã»ã¯ã·ã§ã³ãæ€èšããŠãã ããã
æšæºã®å±éããªã·ãŒã«ã¯ãè åšé²æ¢ãã¬ãŒãã®ã¿ãå«ãŸããŠããããšãæãåºããŠãã ãããåè¿°ã®ããŒã¿ä¿è·ããªã·ãŒãèæ ®ããŠãSandBlastAgentã䜿çšããŠã¯ã©ã€ã¢ã³ããã·ã³ã«ã€ã³ã¹ããŒã«ããã³æäœããããã«ãã®ã«ããŽãªãæå¹ã«ã§ããããã«ãªããŸããããªã¢ãŒãã¢ã¯ã»ã¹VPNæ©èœãæå¹ã«ããããšã¯çã«ããªã£ãŠããŸããããã«ããããŠãŒã¶ãŒã¯ãããšãã°ãçµç¹ã®äŒæ¥ãããã¯ãŒã¯ã«æ¥ç¶ã§ããŸãããŸããã¢ã¯ã»ã¹ãšã³ã³ãã©ã€ã¢ã³ã¹ã®ã«ããŽãªã«ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãšã¢ããªã±ãŒã·ã§ã³ã®å¶åŸ¡æ©èœãå«ãŸãããŠãŒã¶ãŒã®ãã·ã³ãã³ã³ãã©ã€ã¢ã³ã¹ããªã·ãŒã«æºæ ããŠãããã©ããã確èªã§ããŸãã
ããã±ãŒãžã®ãšã¯ã¹ããŒã
ã°ããŒãã«ããªã·ãŒèšå®
æãéèŠãªãã©ã¡ãŒã¿ã®1ã€ã¯ãã°ããŒãã«ããªã·ãŒèšå®ã§æ§æãããŸããããã¯ããŠãŒã¶ãŒã®ãã·ã³ããSandBlastAgentãåé€ããããã®ãã¹ã¯ãŒãã§ãããšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããåŸããŠãŒã¶ãŒã¯ãã¹ã¯ãŒãïŒããã©ã«ãã§ã¯ãã·ãŒã¯ã¬ãããïŒåŒçšç¬ŠãªãïŒïŒãå ¥åããã«ãšãŒãžã§ã³ããã¢ã³ã€ã³ã¹ããŒã«ããããšã¯ã§ããŸããããã ãããã®æšæºãã¹ã¯ãŒãã¯å ¬éãœãŒã¹ã§ç°¡åã«èŠã€ããããšãã§ããŸããSandBlastAgentãœãªã¥ãŒã·ã§ã³ãå®è£ ããå Žåã¯ãããã©ã«ãã®ãã¹ã¯ãŒãã倿ŽããŠãšãŒãžã§ã³ããåé€ããããšããå§ãããŸãã管çãã©ãããã©ãŒã ã§ã¯ãæšæºã®ãã¹ã¯ãŒãã§ã¯ããªã·ãŒã5åããèšå®ã§ããªãããããã¹ã¯ãŒãã倿ŽããŠåé€ããããšã¯é¿ããããŸããã
ããã«ãã°ããŒãã«ããªã·ãŒèšå®ã¯ãThreatCloudãµãŒãã¹ãåæããã³æ¹åããããã«ãã§ãã¯ãã€ã³ãã«éä¿¡ã§ããããŒã¿ãã©ã¡ãŒã¿ãæ§æããŸãã
ã°ããŒãã«ããªã·ãŒèšå®ããããã£ã¹ã¯æå·åããªã·ãŒã®ããã€ãã®ãã©ã¡ãŒã¿ãŒãã€ãŸããã¹ã¯ãŒãèŠä»¶ïŒè€éããäœ¿çšæéã以åã«æå¹ãªãã¹ã¯ãŒãã䜿çšããæ©èœãªã©ïŒãæ§æãããŸãããã®ã»ã¯ã·ã§ã³ã§ã¯ãPre-bootãŸãã¯OneCheckã®æšæºã®ç»åã®ä»£ããã«ãç¬èªã®ç»åãã¢ããããŒãã§ããŸãã
ã€ã³ã¹ããŒã«ããªã·ãŒ
ããŒã¿ä¿è·ããªã·ãŒã®æ©èœãçè§£ãã[å±é]ã»ã¯ã·ã§ã³ã§å¯Ÿå¿ããèšå®ãæ§æããåŸããã§ãã¯ãã€ã³ãæå·åãšæ®ãã®SandBlastãšãŒãžã§ã³ããã¬ãŒãã䜿çšãããã£ã¹ã¯æå·åãå«ãæ°ããããªã·ãŒã®ã€ã³ã¹ããŒã«ãéå§ã§ããŸãã管çãã©ãããã©ãŒã ã«ããªã·ãŒãã€ã³ã¹ããŒã«ããåŸãã¯ã©ã€ã¢ã³ãã¯ãããªã·ãŒã®æ°ããããŒãžã§ã³ãä»ããã€ã³ã¹ããŒã«ããããã€ã³ã¹ããŒã«ãå¥ã®æéïŒæå€§2æ¥ïŒã«ç§»åããããã«ãšããã¡ãã»ãŒãžãåãåããŸãã æ°ããããªã·ãŒãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããåŸãSandBlast Agentã¯ããã«ãã£ã¹ã¯æå·åä¿è·ãæå¹ã«ããããã«ã³ã³ãã¥ãŒã¿ãŒãåèµ·åããããã«ãŠãŒã¶ãŒã«ä¿ããŸãã
åèµ·ååŸããŠãŒã¶ãŒã¯[ãã§ãã¯ãã€ã³ããšã³ããã€ã³ãã»ãã¥ãªãã£èªèšŒ]ãŠã£ã³ããŠã«è³æ Œæ å ±ãå ¥åããå¿ èŠããããŸãããã®ãŠã£ã³ããŠã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãèµ·åããïŒèµ·ååïŒåã«æ¯å衚瀺ãããŸããã·ã³ã°ã«ãµã€ã³ãªã³ïŒSSOïŒãªãã·ã§ã³ãéžæããŠãWindowsèªèšŒã«è³æ Œæ å ±ãèªåçã«äœ¿çšããããšãã§ããŸãã èªèšŒãæåãããšããŠãŒã¶ãŒã¯èªåã®ã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ããããã«ãªãããã£ã¹ã¯æå·åããã»ã¹ãããã¯ã°ã©ãŠã³ãã§éå§ãããŸãããã®æäœã¯ãïŒãã£ã¹ã¯å®¹éã«ãã£ãŠã¯ïŒæéããããå ŽåããããŸããããã·ã³ã®ããã©ãŒãã³ã¹ã«ã¯ãŸã£ãã圱é¿ããŸãããæå·åããã»ã¹ãå®äºãããšããã¹ãŠã®ãã¬ãŒãã皌åãããã©ã€ããæå·åããããŠãŒã¶ãŒã®ãã·ã³ãä¿è·ãããŠããããšã確èªã§ããŸãã
çµè«
èŠçŽãããšããã®èšäºã§ã¯ãããŒã¿ä¿è·ããªã·ãŒã®ãã£ã¹ã¯æå·åã䜿çšããŠãŠãŒã¶ãŒã®ãã·ã³ã«ä¿åãããæ å ±ãä¿è·ããSandBlast Agentã®æ©èœã調ã¹ãå±éã»ã¯ã·ã§ã³ãéããŠããªã·ãŒãšãšãŒãžã§ã³ããé åžããããã®èšå®ã調æ»ãããã£ã¹ã¯æå·åã«ãŒã«ãšè¿œå ã®ãã¬ãŒãã䜿çšããŠãŠãŒã¶ãŒã®ãã·ã³ã«æ°ããããªã·ãŒãã€ã³ã¹ããŒã«ããŸããã ..ãã·ãªãŒãºã®æ¬¡ã®èšäºã§ã¯ã管çãã©ãããã©ãŒã ãšSandBlastAgentã¯ã©ã€ã¢ã³ãã®ãã®ã³ã°ããã³ã¬ããŒãæ©èœã«ã€ããŠè©³ããèŠãŠãããŸãã
TSãœãªã¥ãŒã·ã§ã³ããã®ãã§ãã¯ãã€ã³ãã®ææã®å€§èŠæš¡ãªéžæã SandBlast Agent Management Platformã®æ¬¡ã®åºçç©ãèŠéããªãããã«ããœãŒã·ã£ã«ãããã¯ãŒã¯ïŒTelegramãFacebookãVKãTSãœãªã¥ãŒã·ã§ã³ããã°ãYandex.ZenïŒã

