ãã§ãã¯ãã€ã³ãSandBlastãšãŒãžã§ã³ã管çãã©ãããã©ãŒã ãœãªã¥ãŒã·ã§ã³ã·ãªãŒãºã®èšäº5ãžããããã以åã®èšäºã¯ãé©åãªãªã³ã¯ïŒ1çªç®ã2çªç®ã3çªç®ã4çªç®ïŒãã¯ãªãã¯ããŠèŠã€ããããšãã§ããŸãã仿¥ã¯ã管çãã©ãããã©ãŒã ã®ç£èŠæ©èœãã€ãŸãããã°ãã€ã³ã¿ã©ã¯ãã£ãããã·ã¥ããŒãïŒè¡šç€ºïŒãããã³ã¬ããŒãã®æäœã«ã€ããŠèª¬æããŸãããŸããè åšãã³ãã£ã³ã°ã®ãããã¯ã«è§ŠããŠããŠãŒã¶ãŒã®ãã·ã³äžã®çŸåšã®è åšãšç°åžžãªã€ãã³ããç¹å®ããŸãã
ãã°
ã»ãã¥ãªãã£ã€ãã³ããç£èŠããããã®äž»ãªæ å ±æºã¯ãåã€ã³ã·ãã³ãã®è©³çްæ å ±ã衚瀺ãããã°ã»ã¯ã·ã§ã³ã§ãããŸãã䟿å©ãªãã£ã«ã¿ã䜿çšããŠæ€çŽ¢æ¡ä»¶ãçµã蟌ãããšãã§ããŸããããšãã°ã察象ã®ãã°ã®ãã©ã¡ãŒã¿ïŒãã¬ãŒããã¢ã¯ã·ã§ã³ãé倧床ãªã©ïŒãå³ã¯ãªãã¯ãããšããã®ãã©ã¡ãŒã¿ã¯ãã£ã«ã¿ïŒããã©ã¡ãŒã¿ããŸãã¯ãã£ã«ã¿ã¢ãŠãïŒããã©ã¡ãŒã¿ããšããŠãã£ã«ã¿ãªã³ã°ã§ããŸãããŸãã[ãœãŒã¹]ãã©ã¡ãŒã¿ãŒã«ã¯ã[IPããŒã«]ãªãã·ã§ã³ãéžæã§ããŸãããã®ãªãã·ã§ã³ã§ã¯ãç¹å®ã®IPã¢ãã¬ã¹/ååã«pingãå®è¡ããããnslookupãå®è¡ããŠãœãŒã¹IPã¢ãã¬ã¹ãååã§ååŸã§ããŸãã
[ãã°]ã»ã¯ã·ã§ã³ã«ã¯ãã€ãã³ãããã£ã«ã¿ãªã³ã°ããããã®[çµ±èš]ãµãã»ã¯ã·ã§ã³ãããããã¹ãŠã®ãã©ã¡ãŒã¿ãŒã®çµ±èšã衚瀺ãããŸãããã°ã®æ°ãšåãã©ã¡ãŒã¿ãŒã®ããŒã»ã³ããŒãžãå«ãã¿ã€ã ãã£ãŒãã§ãããã®ãµãã»ã¯ã·ã§ã³ãããæ€çŽ¢è¡ãåç §ãããããã£ã«ã¿ãªã³ã°åŒãèšè¿°ãããããããšãªãããã°ãç°¡åã«ãã£ã«ã¿ãªã³ã°ã§ããŸããç®çã®ãã©ã¡ãŒã¿ãéžæããã ãã§ããã°ã®æ°ãããªã¹ããããã«è¡šç€ºãããŸãã
åãã°ã®è©³çްæ å ±ã¯ã[ãã°]ã»ã¯ã·ã§ã³ã®å³åŽã®ãã€ã³ã«è¡šç€ºãããŸãããããã«ã¯ãªãã¯ããŠã³ã³ãã³ããåæããŠãã°ãéãæ¹ã䟿å©ã§ãã以äžã¯ãææããã.docxããã¡ã€ã«ã§è åšãšãã¥ã¬ãŒã·ã§ã³ãã¬ãŒãã®é²æ¢ã¢ã¯ã·ã§ã³ãããªã¬ãŒããããã®è©³çްæ å ±ã衚瀺ãããã°ã®äŸã§ãïŒç»åã¯ã¯ãªãã¯å¯èœã§ãïŒããã°ã«ã¯ãã»ãã¥ãªãã£ã€ãã³ãã®è©³çްã衚瀺ããããã€ãã®ãµãã»ã¯ã·ã§ã³ããããŸããããªã¬ãŒãããããªã·ãŒãšä¿è·ããã©ã¬ã³ãžãã¯ã®è©³çްãã¯ã©ã€ã¢ã³ããšãã©ãã£ãã¯ã®æ å ±ã§ããç¹ã«æ³šç®ãã¹ãã¯ããã°ããå ¥æã§ããã¬ããŒãïŒè åšãšãã¥ã¬ãŒã·ã§ã³ã¬ããŒããšãã©ã¬ã³ãžãã¯ã¬ããŒãïŒã§ãããããã®ã¬ããŒãã¯ãSandBlastAgentã¯ã©ã€ã¢ã³ãããéãããšãã§ããŸãã
è åšãšãã¥ã¬ãŒã·ã§ã³ã¬ããŒã
ãã§ãã¯ãã€ã³ãã¯ã©ãŠãã§ã®ãšãã¥ã¬ãŒã·ã§ã³åŸã«è åšãšãã¥ã¬ãŒã·ã§ã³ãã¬ãŒãã䜿çšãããšããšãã¥ã¬ãŒã·ã§ã³ã®çµæã«é¢ãã詳现ã¬ããŒããžã®ãªã³ã¯-è åšãšãã¥ã¬ãŒã·ã§ã³ã¬ããŒãã察å¿ãããã°ã«è¡šç€ºãããŸãããã®ãããªã¬ããŒãã®å 容ã¯ãCheck Point SandBlastNetworkãã©ã¬ã³ãžãã¯ã䜿çšãããã«ãŠã§ã¢åæã«é¢ããèšäºã§è©³ãã説æãããŠããŸãããã®ã¬ããŒãã¯ã€ã³ã¿ã©ã¯ãã£ãã§ãããåã»ã¯ã·ã§ã³ã®è©³çްãã確èªãã§ããããšã«æ³šæããŠãã ãããä»®æ³ãã·ã³ã§ã®ãšãã¥ã¬ãŒã·ã§ã³ããã»ã¹ã®èšé²ã衚瀺ããããå ã®æªæã®ãããã¡ã€ã«ãããŠã³ããŒããããããã®ããã·ã¥ãååŸãããããŠããã§ãã¯ãã€ã³ãã€ã³ã·ãã³ã察å¿ããŒã ã«é£çµ¡ããããšãã§ããŸãã
ãã©ã¬ã³ãžãã¯ã¬ããŒã
ã»ãšãã©ãã¹ãŠã®ã»ãã¥ãªãã£ã€ãã³ãã«ã€ããŠããã©ã¬ã³ãžãã¯ã¬ããŒããçæãããŸãããã®ã¬ããŒãã«ã¯ãæªæã®ãããã¡ã€ã«ã®ç¹æ§ãã¢ã¯ã·ã§ã³ãã·ã¹ãã ãžã®ãšã³ããªãã€ã³ããéèŠãªäŒæ¥è³ç£ãžã®åœ±é¿ãªã©ã®è©³çްæ å ±ãå«ãŸããŠããŸããã¬ããŒãã®æ§é ã«ã€ããŠã¯ãCheck Point SandBlastAgentãã©ã¬ã³ãžãã¯ã䜿çšãããã«ãŠã§ã¢åæã«é¢ããèšäºã§è©³ãã説æããŸããããã®ãããªã¬ããŒãã¯ãã»ãã¥ãªãã£ã€ãã³ãã調æ»ããéã®éèŠãªæ å ±æºã§ãããå¿ èŠã«å¿ããŠãã¬ããŒãã®å 容ããã§ãã¯ãã€ã³ãã€ã³ã·ãã³ã察å¿ããŒã ã«ããã«éä¿¡ã§ããŸãã
SmartView
Check Point SmartViewã¯ãåçããã·ã¥ããŒãïŒViewïŒãšã¬ããŒããPDF圢åŒã§äœæããã³è¡šç€ºããããã®äŸ¿å©ãªããŒã«ã§ãã管çè ã®ãŠãŒã¶ãŒãã°ãšç£æ»ã€ãã³ããSmartViewãã衚瀺ã§ããŸããæ¬¡ã®å³ã¯ãSandBlastAgentãæäœããããã®æã䟿å©ãªã¬ããŒããšããã·ã¥ããŒãã瀺ããŠããŸãã SmartViewã®ã¬ããŒãã¯ãç¹å®ã®æéã®ã€ãã³ãã«é¢ããçµ±èšæ å ±ãå«ãããã¥ã¡ã³ãã§ãã SmartViewãéããŠãããã·ã³ãžã®PDF圢åŒã®ã¬ããŒãã®ã¢ããããŒããããã³ç®¡çè ã®é»åã¡ãŒã«ãžã®PDF / Excelãžã®å®æçãªã¢ããããŒãããµããŒãããŸããããã«ãã¬ããŒããã³ãã¬ãŒãã®ã€ã³ããŒã/ãšã¯ã¹ããŒããç¬èªã®ã¬ããŒãã®äœæãããã³ã¬ããŒãã§ãŠãŒã¶ãŒåãé衚瀺ã«ããæ©èœããµããŒããããŠããŸããæ¬¡ã®å³ã¯ãåã蟌ãŸããè åšé²æ¢ã¬ããŒãã®äŸã瀺ããŠããŸãã
SmartViewã®ããã·ã¥ããŒãïŒãã¥ãŒïŒã䜿çšãããšã管çè ã¯å¯Ÿå¿ããã€ãã³ãã®ãã°ã«ã¢ã¯ã»ã¹ã§ããŸããã°ã©ãã®åãæªæã®ãããã¡ã€ã«ã®ååãªã©ãç®çã®ãªããžã§ã¯ããããã«ã¯ãªãã¯ããã ãã§ããã¬ããŒããšåæ§ã«ãç¬èªã®ããã·ã¥ããŒããäœæããŠãŠãŒã¶ãŒããŒã¿ãé衚瀺ã«ããããšãã§ããŸããããã·ã¥ããŒãã®å Žåããã³ãã¬ãŒãã®ã€ã³ããŒã/ãšã¯ã¹ããŒãããµããŒããããŠããã管çè ã®é»åã¡ãŒã«ãžã®PDF / Excelãžã®å®æçãªã¢ããããŒããšãã»ãã¥ãªãã£ã€ãã³ãããªã¢ã«ã¿ã€ã ã§ç£èŠããããã®èªåããŒã¿æŽæ°ãå¯èœã§ãã
远å ã®ç£èŠã»ã¯ã·ã§ã³
管çãã©ãããã©ãŒã ã®ç£èŠããŒã«ã®èª¬æã¯ããæŠèŠãããã³ã³ãã¥ãŒã¿ãŒç®¡çããããšã³ããã€ã³ãèšå®ããããã³ãããã·ã¥æäœãã»ã¯ã·ã§ã³ã«èšåããªããšäžå®å šã§ãããããã®ã»ã¯ã·ã§ã³ã«ã€ããŠã¯ã2çªç®ã®èšäºã§è©³ãã説æããŸããããã ããç£èŠã¿ã¹ã¯ã解決ããããã®å¯èœæ§ãæ€èšããããšã¯æçšã§ããæŠèŠããå§ããŸããããããã¯ãéçšã®æŠèŠãšã»ãã¥ãªãã£ã®æŠèŠã®2ã€ã®ãµãã»ã¯ã·ã§ã³ã§æ§æãããŠããŸãããããã¯ãä¿è·ããããŠãŒã¶ãŒãã·ã³ã®ç¶æ ãšã»ãã¥ãªãã£ã€ãã³ãã«é¢ããæ å ±ãå«ãããã·ã¥ããŒãã§ããä»ã®ããã·ã¥ããŒããšã®å¯Ÿè©±ãšåæ§ã«ã[æäœã®æŠèŠ]ããã³[ã»ãã¥ãªãã£ã®æŠèŠ]ãµãã»ã¯ã·ã§ã³ã§ã¯ãç®çã®ãã©ã¡ãŒã¿ãŒãããã«ã¯ãªãã¯ãããšãéžæãããã£ã«ã¿ãŒïŒããšãã°ã[ãã¹ã¯ããã]ãŸãã¯[èµ·ååã®ã¹ããŒã¿ã¹ïŒæå¹]ïŒã䜿çšããŠ[ã³ã³ãã¥ãŒã¿ãŒã®ç®¡ç]ã»ã¯ã·ã§ã³ã«ç§»åããããã»ã¯ã·ã§ã³ã«ç§»åãããã§ããŸããç¹å®ã®ã€ãã³ãã®ãã°ã [ã»ãã¥ãªãã£ã®æŠèŠ]ãµãã»ã¯ã·ã§ã³ã¯ããµã€ããŒæ»æãã¥ãŒ-ãšã³ããã€ã³ãããã·ã¥ããŒãã§ãããèªåããŒã¿æŽæ°ãã«ã¹ã¿ãã€ãºããã³èšå®ã§ããŸãã
[ã³ã³ãã¥ãŒã¿ãŒã®ç®¡ç]ã»ã¯ã·ã§ã³ããããŠãŒã¶ãŒãã·ã³äžã®ãšãŒãžã§ã³ãã®ã¹ããŒã¿ã¹ããã«ãŠã§ã¢å¯ŸçããŒã¿ããŒã¹ã®æŽæ°ã®ã¹ããŒã¿ã¹ããã£ã¹ã¯ã®æå·åæé ãªã©ãç£èŠã§ããŸãããã¹ãŠã®ããŒã¿ãèªåçã«æŽæ°ããããã£ã«ã¿ãŒããšã«é©æ ŒãªãŠãŒã¶ãŒãã·ã³ã®å²åã衚瀺ãããŸãã CSV圢åŒã§ã®ã³ã³ãã¥ãŒã¿ãŒããŒã¿ã®ãšã¯ã¹ããŒãããµããŒããããŠããŸãã ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ã»ãã¥ãªãã£ãç£èŠããéèŠãªåŽé¢ã¯ãéèŠãªã€ãã³ãïŒã¢ã©ãŒãïŒã«é¢ããéç¥ãèšå®ããäŒç€Ÿã®ãã°ãµãŒããŒã«ä¿åããããã«ãã°ããšã¯ã¹ããŒãïŒã€ãã³ãã®ãšã¯ã¹ããŒãïŒããããšã§ããäž¡æ¹ã®èšå®ã¯ã[ãšã³ããã€ã³ãèšå®]ã»ã¯ã·ã§ã³ãšã¢ã©ãŒãã«å¯ŸããŠè¡ãããŸã
ã¡ãŒã«ãµãŒããŒã«æ¥ç¶ããŠãã€ãã³ãã«é¢ããéç¥ã管çè ã«éä¿¡ããã€ãã³ãåºæºã«äžèŽããããã€ã¹ã®å²å/æ°ã«å¿ããŠéç¥ãããªã¬ãŒ/ç¡å¹åããããã®ãããå€ãæ§æããããšãã§ããŸããã€ãã³ãã®ãšã¯ã¹ããŒãã䜿çšãããšã管çãã©ãããã©ãŒã ããäŒç€Ÿã®ãã°ãµãŒããŒãžã®ãã°ã®è»¢éãæ§æããŠããã«åŠçããããšãã§ããŸãããµããŒããããŠãã圢åŒã¯ãSYSLOGãCEFãLEEFãSPLUNKãTCP / UDPãããã³ã«ãTLS / SSLæå·åããã³syslogã¯ã©ã€ã¢ã³ãèªèšŒã䜿çšããsyslogãšãŒãžã§ã³ããå®è¡ãããŠããSIEMã·ã¹ãã ã§ãã
ãšãŒãžã§ã³ãã®ã€ãã³ãã詳现ã«åæããå ŽåããŸãã¯ãã¯ãã«ã«ãµããŒãã«é£çµ¡ããå Žåã¯ã[ããã·ã¥æäœ]ã»ã¯ã·ã§ã³ã®åŒ·å¶æäœã䜿çšããŠSandBlastãšãŒãžã§ã³ãã¯ã©ã€ã¢ã³ããããã°ããã°ããåéã§ããŸããçæããããã°ä»ãã¢ãŒã«ã€ãã®ãã§ãã¯ãã€ã³ããµãŒããŒãŸãã¯äŒæ¥ãµãŒããŒãžã®è»¢éãæ§æã§ããŸãããã°ä»ãã¢ãŒã«ã€ãã¯ããŠãŒã¶ãŒã®ãã·ã³ã®CïŒ\ Users \ username \ CPInfoãã£ã¬ã¯ããªã«ãä¿åãããŸããæå®ãããæéã«ãã°ãåéããããã»ã¹ã®éå§ãšããŠãŒã¶ãŒã«ããæäœãå»¶æããæ©èœããµããŒãããŸãã
è åšãã³ãã£ã³ã°
Threat Huntingã¡ãœããã¯ãã·ã¹ãã å ã®æªæã®ããã¢ã¯ãã£ããã£ãç°åžžãªåäœãããã¢ã¯ãã£ãã«æ€çŽ¢ããŠãæœåšçãªã»ãã¥ãªãã£ã€ãã³ããããã«èª¿æ»ããããã«äœ¿çšãããŸãã管çãã©ãããã©ãŒã ã®è åšãã³ãã£ã³ã°ã»ã¯ã·ã§ã³ã§ã¯ããŠãŒã¶ãŒãã·ã³ã®ããŒã¿ã§æå®ããããã©ã¡ãŒã¿ãŒã䜿çšããŠã€ãã³ããæ€çŽ¢ã§ããŸãã Threat HuntingããŒã«ã«ã¯ãããã€ãã®äºåå®çŸ©ãããã¯ãšãªããããŸããããšãã°ãæªæã®ãããã¡ã€ã³ãŸãã¯ãã¡ã€ã«ãåé¡ãããããç¹å®ã®IPã¢ãã¬ã¹ãžã®ãŸããªåŒã³åºãã远跡ããããïŒäžè¬çãªçµ±èšãšæ¯èŒããŠïŒãèŠæ±æ§é ã¯ãã€ã³ãžã±ãŒã¿ãŒïŒãããã¯ãŒã¯ãããã³ã«ãããã»ã¹IDããã¡ã€ã«ã¿ã€ããªã©ïŒãæŒç®åïŒ "is"ã "is not"ã "includes"ã "one of"ãªã©ïŒãããã³èŠæ±æ¬æã®3ã€ã®ãã©ã¡ãŒã¿ãŒã§æ§æãããŸãã
..ããªã¯ãšã¹ãæ¬æã§ã¯éåžžã®åŒã䜿çšã§ããæ€çŽ¢æååã§ã¯è€æ°ã®ãã£ã«ã¿ãŒãåæã«äœ¿çšã§ããŸãã ãã£ã«ã¿ãéžæããŠãªã¯ãšã¹ãã®åŠçãå®äºãããšãé©åãªãã¹ãŠã®ã€ãã³ããžã®ã¢ã¯ã»ã¹ã衚瀺ãããã€ãã³ãã«é¢ãã詳现æ å ±ã衚瀺ãããããªã¯ãšã¹ããªããžã§ã¯ããæ€ç«ããããã€ãã³ãã®èª¬æãå«ã詳现ãªãã©ã¬ã³ãžãã¯ã¬ããŒããçæãããã§ããŸããçŸåšããã®ããŒã«ã¯ããŒã¿çã§ãããå°æ¥çã«ã¯ãMitre AttïŒckãããªãã¯ã¹ã®åœ¢åŒã§ã€ãã³ãã«é¢ããæ å ±ã远å ãããªã©ãäžé£ã®æ©èœãæ¡åŒµããäºå®ã§ãã
çµè«
èŠçŽãããšããã®èšäºã§ã¯ãSandBlast Agent Management Platformã§ã»ãã¥ãªãã£ã€ãã³ããç£èŠããå¯èœæ§ãæ€èšãããŠãŒã¶ãŒãã·ã³äžã®æªæã®ããã¢ã¯ã·ã§ã³ãç°åžžãããã¢ã¯ãã£ãã«æ€çŽ¢ããããã®æ°ããããŒã«ã§ããThreatHuntingã調æ»ããŸãããæ¬¡ã®èšäºã¯ãã®ãµã€ã¯ã«ã®æåŸã®èšäºã§ããããã®äžã§ã管çãã©ãããã©ãŒã ãœãªã¥ãŒã·ã§ã³ã«é¢ããæãäžè¬çãªè³ªåãèŠãŠããã®è£œåã®ãã¹ãæ©èœã«ã€ããŠèª¬æããŸãã
TSãœãªã¥ãŒã·ã§ã³ããã®ãã§ãã¯ãã€ã³ãã®ææã®è±å¯ãªéžæãSandBlast Agent Management Platformãããã¯ã«é¢ããæ¬¡ã®åºçç©ãèŠéããªãããã«ããœãŒã·ã£ã«ãããã¯ãŒã¯ïŒTelegramãFacebookãVKãTS Solution BlogãYandex.ZenïŒã«æ³šç®ããŠãã ãããïŒã