è åš
ACSãšããçšèªã¯ãã³ã³ãã¥ãŒã¿ãŒæè¡ãå¶åŸ¡ã·ã¹ãã ã«å°å ¥ããããšããã«ç»å ŽããŸãããæåã®æãåçŽãªACSã¯ãæ å ±åéãšæææ±ºå®ã®2ã€ã®ã¬ãã«ã®ã¿ã§æ§æãããŠããŸãããæ å ±ã¯å¶åŸ¡ãªããžã§ã¯ããããªãã¬ãŒã¿ãŒã«éããããªãã¬ãŒã¿ãŒã¯ã³ã³ãã¥ãŒã¿ãŒãšããŒã¿ã亀æããŠãªããžã§ã¯ããå¶åŸ¡ããŸãããããã§ã¯ãèšç®èœåã人éã®ç®¡çãšæææ±ºå®ã®è£å©ãšããŠæ©èœããŸããã
æåã®ã³ã³ãã¥ãŒã¿ãŒã®æä»£ãããèªååãããããã»ã¹å¶åŸ¡ã·ã¹ãã ã¯å€§ããªé£èºãéããŸããããããã圌ãã®ç¹åŸŽã¯ã人ãåŸãèªååãããæ©æ¢°ããã»ã¹ã§ãã
ãããã®ã·ã¹ãã ã¯ãç£æ¥ããã»ã¹ã§ã®ã¿äœ¿çšããããšãç®çãšããŠããŸããéèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã«é¢äžããŠããããã»ã¹å¶åŸ¡ã·ã¹ãã ã¯ãéå®³èæ§ããããä¿¡é Œæ§ã®é«ãã³ã³ãã¥ãŒãã£ã³ã°ãã¯ãããžãŒã«åºã¥ããŠæ§ç¯ãããŠããŸããããã¯ãç£æ¥æœèšã§ã®é·æã®24æé皌åã®ããã«ç¹å¥ã«èšèšãããç£æ¥ã°ã¬ãŒãã®æè¡ã§ããã·ã¹ãã ã®æ éãŸãã¯æ éã®çµæã¯ãæ©åšã人éã®çåœããã³å¥åº·ã«å¯Ÿããæ·±å»ãªè åšã§ãã
ããã»ã¹ã®ç¶ç¶æ§ã«å¯Ÿãããã®ãããªè²¬ä»»ã«ãããããããããã»ã¹å¶åŸ¡ã·ã¹ãã ã®å®å šã¬ãã«ãæ¹åããå¿ èŠæ§ã¯æè¿è°è«ãããã°ããã§ãã 2010幎代åã°é ã«å®æçã«è¡ããããŠã€ã«ã¹æ»æã¯ããã®ãããã¯ã«å€§ããªé¢å¿ãéããŸãããããšãã°ãéå»10幎éã«çºçããæ»æã®äžéšïŒ
- 2012 Flame, , . . .
- 2014 , , .
- 2017 , , Triton, Trisis/HatMan.
Triton . , , . - 2018 . . Windows XP. HMI SCADA-, .
- 2018 . , . , .
- 2018 , «» , . , , .
, 13- , , «» - , , , ( ).
â , , â SCADA-, â , . , . â , - , , , . « » â , . . , , . , , .â
-JetInfosystemsã®æ å ±ã»ãã¥ãªãã£ã»ã³ã¿ãŒã®çæãšãšãã«ã®ãŒã®è€åæœèšã§äœæ¥ããéšéã®è²¬ä»»è ã§ããAlexeyKosikhin
ICSã«åºæã®ãµã€ããŒè åšã®äžã§ã3ã€ã®ã¯ã©ã¹ãåºå¥ã§ããŸãã
- 人çºçãªè åš;
- 人çºçè åš;
- äžæ£ã¢ã¯ã»ã¹ã®è åšã
æè¡ç㪠è åšã«ã¯ãAPCSã®ã³ã³ããŒãã³ããžã®ç©ççãªåœ±é¿ãå«ãŸããŸãã人çºç-人ã ã®æå³çããã³éæå³çãªã¢ã¯ã·ã§ã³ã¯ããªãŒãã¡ãŒã·ã§ã³ã»ã·ã¹ãã ããã¥ãŒãã³ãšã©ãŒãACSã®ã³ã³ããŒãã³ããšäœæ¥ã®çµç¹å ã®éã¡ã®ããã®ãµãŒãã¹ã«åŸäºããŸãããAPCSã®äžæ£ã¢ã¯ã»ã¹ã®è åšã¯ããã®ã³ã³ããŒãã³ããšäŒæ¥ã®ããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒãããã¯ãŒã¯ãšã®çžäºäœçšãååšããå Žåã«èæ ®ãããŸãããã®ãããªæ¥ç¶ã¯ãæè¡ç°å¢ã®ç¶æ ã«é¢ããæ å ±ã転éããæè¡ãªããžã§ã¯ããžã®åœ±é¿ãå¶åŸ¡ããããã«ååšããŸãã
ãããã®èŠçŽ ã®ç¹ã亀ãã¯ãã·ã¹ãã ã®å šäœçãªã»ãã¥ãªãã£ã«åœ±é¿ãäžããŸããããã«ã¯ãæå°éã®ã»ãã¥ãªãã£å¯Ÿçã®å€±æãã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒã®ã¡ã€ã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšããŠã®Windowsã®äœ¿çšãããã³åŸæ¥å¡ã®åŒ±ãèŠåŸãå«ãŸããŸãã
ä¿è·
APCSã®æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®å®è£ ã¯è€éãªäœæ¥ã§ãããã®è§£æ±ºçã¯ããã¹ãŠã®ã¬ãã«ã§ã®ã«ãŒã«ã®å®è£ ã«äŸåããŸãã
- 管çïŒæ å ±ã»ãã¥ãªãã£ã«é¢ããäœæ¥ããã°ã©ã ã®ç®¡çã«ãã圢æã
- æé ïŒãããã¯ãŒã¯ã«ãµãŒãã¹ãæäŸããæ åœè ã®ã«ãŒã«ãšèŠå¶ãå®çŸ©ããŸãã
- ãœãããŠã§ã¢ãšãââãŒããŠã§ã¢ïŒã¢ã¯ã»ã¹å¶åŸ¡ã
- å®å šæ§ã確ä¿ããã
- å®å šãªçžäºæ¥ç¶ã確ä¿ããã
- æãŠã€ã«ã¹ä¿è·;
- ã»ãã¥ãªãã£åæ;
- äŸµå ¥æ€åº;
- ç¶æ ã®ç¶ç¶çãªç£èŠãã€ã³ã·ãã³ãã®æ€åºã察å¿ã
è匱æ§å¶åŸ¡ã·ã¹ãã ã¯ãç£æ¥ãµã€ããŒè åšã«å¯Ÿæããããã®æã广çãªæ¹æ³ã®1ã€ã§ãããããã¯ãç£æ¥çšèªååã·ã¹ãã çšã«ç¹å¥ã«èšèšãããé«åºŠã«å°éåãããããã°ã©ã ã§ãããããã䜿çšãããšãããã€ã¹ã®å éšç°å¢ã®æŽåæ§ã倿ããã³ã³ãããŒã©ãŒã¢ããªã±ãŒã·ã§ã³ããã°ã©ã ã倿Žãããã¹ãŠã®è©Šã¿ããããã¯ãŒã¯ä¿è·ã®æ§æã®å€æŽãããã³éé»ç¶²å ã®å¶åŸ¡ããã€ã¹ãèšé²ã§ããŸãã
å€ãã®ãµã€ããŒã»ãã¥ãªãã£è£œåéçºè ã¯ããããããããã¯ãŒã¯å ã®å¯èŠæ§ãé«ããå¿ èŠæ§ãææããŠããŸã..ãçµéšã«ããã°ãããã¯æ¬åœã«éèŠã§ããæéå ã«æ°ä»ãããªããããã¯ãŒã¯ã®äŸµå®³ã¯ãéã¢ã¯ãã£ãåããããšã¯ã¹ããã€ãã§æ°ãæéæ©èœããå¯èœæ§ããããŸããå°çšã®ãµã€ããŒè åšæ€åºããã³é²æ¢ããŒã«ã¯ãè匱æ§ãæ€åºããã ãã§ãªãããŒããã€è åšãèå¥ããŸãã
å€ãã®æ å ±ã»ãã¥ãªãã£ãªã¹ã¯ã¯ãå€ãããŒããŠã§ã¢ãšãœãããŠã§ã¢ã«é¢é£ããŠããŸããããšãã°ãWindowsNTãŸãã¯Windows98ã§ã®ã¿æ©èœããSCADAã·ã¹ãã ããããŸãããããã®ãªã¹ã¯ã®äžéšã¯ãææ°ã®ä»®æ³åãã¯ãããžãŒã«ãã£ãŠè»œæžã§ããŸãããåžžã«å¯èœã§ãããšã¯éããŸãããããã«é¢é£ããå¥ã®ã¿ã€ãã®ä¿è·-çµ¶çž..ã SCADAããã³OPCïŒOLE for Process ControlïŒãµãŒããŒãPLCãããã³èªåå¶åŸ¡ã·ã¹ãã ã®ä»ã®ã³ã³ããŒãã³ãã¯ãã€ã³ã¿ãŒãããããåé¢ããå¿ èŠããããŸãã
ãããšã¯å¥ã«ãåœã®ã¿ãŒã²ããã®åæ£ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ããDDPïŒDistributed Deception PlatformïŒãäœæããããã®ãã©ãããã©ãŒã ã匷調ãã䟡å€ããããŸãããããã䜿çšãããšãå®éã®ããã€ã¹ãšã»ãšãã©åºå¥ãã€ããªãåœã®ãã³ã€ããã€ã¹ã®ãããã¯ãŒã¯ãå±éããŠãæ»æè ãåŒãä»ããããšãã§ããŸãã
ICSãµã€ããŒã»ãã¥ãªãã£ãã©ã®ããã«æ©èœãããã«ã€ããŠã®äžè¬çãªèãæ¹ãããã£ãã®ã§ããã®èšäºã®åŸåã«é²ã¿ãŸããæ¯èŒè¡šã«ç€ºãããŠããå®çšçãªã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®æŠèŠã説æããŸãã
ãã®èšäºã§ã¯ããŒããã€è åšæ€åºãçµ±åãç°åžžæ€åºãšãã©ãã£ãã¯åæãããã€ã¹ã€ã³ãã³ããªãè£œåæ©èœãªã©ã衚ããããã€ãã®éèŠãªãã€ã³ããéžæããŸããã
ãœãªã¥ãŒã·ã§ã³
ãã©ãŽã¹ç£æ¥ãµã€ããŒã»ãã¥ãªãã£ãã©ãããã©ãŒã
Dragosã¯2016幎ã«èšç«ãããç±³åœäŒæ¥ã§ãã圌女ã®ãè¥ãã幎霢ã«ããããããã圌女ã¯ãã§ã«ç£æ¥ã·ã¹ãã ã®ãµã€ããŒé²è¡ã®åéã§å€ãã®äžççãªè³ãåè³ããŠããŸãã
圌ãã¯ãç£æ¥çšã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšã€ã³ã¿ãŒããããªãã·ã³ã°ã¹ãå°éãšããå°éå®¶ã®ããŒã ã§ãã圌ãã®äž»å補åã¯ãŸãã«ãã©ãããã©ãŒã ã§ãããDragosã¯ã€ã³ã·ãã³ã察å¿ãµãŒãã¹ããããã¯ãŒã¯ãžã®è åšåæããµã€ããŒã»ãã¥ãªãã£ãã¬ãŒãã³ã°ãæäŸããŠããŸãã
Dragos Industrial Cyberââsecurity Platformã¯ããããã¯ãŒã¯è³ç£ãèªåçã«æ€åºããŠèå¥ããç£æ¥çšãããã¯ãŒã¯ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã§ããããã°ã©ã ã¯è³ç£ãã¹ãã£ã³ãã誀ã£ãèšå®ãæ§ææ¹åã®æ©äŒãèŠã€ããŸãã
çãããã¢ã¯ãã£ããã£ãæ€åºãããå Žåããã©ãããã©ãŒã ã¯ãã€ã³ã·ãã³ãã調æ»ããŠå¯Ÿå¿ããããã®ã¹ããããã€ã¹ãããã®ã¬ã€ãã³ã¹ãšãã©ãã«ã·ã¥ãŒãã£ã³ã°ããŒã«ãæäŸããŸãã
æ©èœïŒ
ããã€ã¹ã€ã³ãã³ããªïŒã¯ã
ãŒããã€è åšæ€åºïŒããã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒã¯ã
çµ±åïŒSIEM
ãµããŒããããŠããã·ã¹ãã ïŒDCSãPLC
æ©èœïŒããŒã ãšãã¹ããŒãã«ããæ®µéçãªã»ãã¥ãªãã£ç®¡çã¬ã€ãããã¬ã€ããã¯ã§çºè¡ãããŸãã
CyberââX OT
CyberââX ãäœæããåã¯ã圌女ã®ããŒã ã¯éèŠãªç±³åœã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããåéã§åããŠããŸããã圌ãã®èªãã¯ããã³ã¿ãŽã³ã¬ãã«ã®ä¿è·ãšäžçã®åžå ŽãªãŒããŒãšã®ååã«å ããŠãæ©æ¢°åŠç¿ã®ç¹èš±ååŸæžã¿ã®æ¹æ³ã§ãã圌ãã®è£œåãç£æ¥ãããã¯ãŒã¯ã®ç°åžžãå³åº§ã«æããã«ããã®ã¯åœŒã®ãããã§ãã
Work CyberââX OTãã©ãããã©ãŒã ã¯ã5ã€ã®äž»èŠãªèŠçŽ ã«åºã¥ããŠããŸããç°åžžãªã¢ã¯ã·ã§ã³ãç¹å®ããããã®è³ç£ã®åäœåæããããã³ã«éåã®ç£èŠãæªæã®ãããšãŒãžã§ã³ãïŒé«åºŠãªè åšãå«ãïŒã®æ€åºãéçšäžã®åé¡ãèŠã€ããã ãéä¿¡ãããŠã¯ãªããªããã·ã³éã®æ¥ç¶ãèå¥ããŸãã
ãã®ãœãªã¥ãŒã·ã§ã³ã¯ããªãŒãã³APIã®ãããã§ãã»ãã¥ãªãã£ã¹ã¿ãã¯ã«å®å šã«çµ±åã§ããŸãããã®çµ±åã«ãããITç°å¢ãšç£æ¥ç°å¢ã®äž¡æ¹ã®ã»ãã¥ãªãã£åé¡ã解決ãããŸãã
æ©èœïŒ
ããã€ã¹ã€ã³ãã³ããªïŒã¯ã
ãŒããã€è åšæ€åºïŒã¯ã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒã¯ã
çµ±åïŒãã¡ã€ã¢ãŠã©ãŒã«ãCMDBãIDS / IPSãSIEMãSOC
ãµããŒããããŠããã·ã¹ãã ïŒDCSãPLCãRTU
æ©èœïŒèª€æ€ç¥ãæžããèªå·±åŠç¿åãã·ã³åæãŒãã«ããªã¬ãŒããŸãã
Cyberââbit SCADASchield
2015幎以æ¥ãCyberââbitã¯ãµã€ããŒã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãåžå Žã«æäŸããŠããŸãããå瀟ã¯ãæ å ±ã»ãã¥ãªãã£ããŒã ããšã³ããã€ã³ãä¿è·ãç£æ¥çšãããã¯ãŒã¯ä¿è·ãã»ãã¥ãªãã£ã·ã¹ãã ã®ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãšèªååã®ããã®æ»æã®ãšãã¥ã¬ãŒã·ã§ã³ãšãã¬ãŒãã³ã°ãå°éãšããŠããŸãã
SCADAShieldã¯ãåäŸã®ãªããããã¯ãŒã¯ã®å¯èŠæ§ãæ¢ç¥ããã³æªç¥ã®ç°åžžã®æ€åºãããã³éçšãã¯ãããžãŒã®ãšã©ãŒãæäŸããŸãããŸãã7å±€ã®ãã£ãŒããã±ããã€ã³ã¹ãã¯ã·ã§ã³ïŒDPIïŒã«ããããœãªã¥ãŒã·ã§ã³ã¯éçšäžã®éçãè¶ ããŠããŸãã
ãããã¯ãŒã¯å šäœã®èŠèŠåã¯ãªã¢ã«ã¿ã€ã ã§ãããIPããã€ã¹ãšéIPããã€ã¹ãå«ãŸããŸãã
æ©èœïŒ
ããã€ã¹ã€ã³ãã³ããªïŒããã
ãŒããã€è åšæ€åºïŒã¯ã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒãªã
çµ±åïŒ Cyberââbit EDRãSIEMã¯ã
ã·ã¹ãã ããµããŒãïŒ N /
æ©èœã®ïŒæ å ±ãããã®çæã¯ããããã¯ãŒã¯è³ç£ãã«ãŒã«ã®èªåçæã®éã«æµããŸãã
Clarotyãã©ãããã©ãŒã
Claroty㮠䜿åœã¯ãç£æ¥ãããã¯ãŒã¯ãä¿è·ããããšã§ããããã¯ãããŸããŸãªå°éåéã®å°éå®¶ã§æ§æãããããŒã ã§ããå ç±³è»ã®ãµã€ããŒã»ãã¥ãªãã£æç£ãå®å®æè¡è ãä¿éºã®å°éå®¶ãããŸãã
Clarotyãã©ãããã©ãŒã ã¯ãã»ãã¥ãªãã£ããŒã ã«ãç£æ¥çšå¶åŸ¡ãããã¯ãŒã¯ãšãªã¢ã«ã¿ã€ã ç£èŠã«å¯Ÿããåªããå¯èŠæ§ãæäŸããŸããç£èŠã¯ãé«åºŠãªè åšãèªèãããããã¯ãŒã¯ã®è匱æ§ãæéå ã«ç¹å®ããããšãã§ããŸãã
ãã®ãã©ãããã©ãŒã ã«ããããããã¯ãŒã¯ã®ã»ã°ã¡ã³ããŒã·ã§ã³ãå®å šãªãªã¢ãŒãã¢ã¯ã»ã¹ã®å¶åŸ¡ãšæäŸããã现ããã¢ã¯ã»ã¹ããªã·ãŒãããã³ã»ãã·ã§ã³ã®èšé²ãå¯èœã«ãªããŸãã
æ©èœïŒ
ããã€ã¹ã€ã³ãã³ããªïŒã¯ã
ãŒããã€è åšæ€åºïŒã¯ã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒããã
çµ±åïŒ SIEMãSOC
ãµããŒããããŠããã·ã¹ãã ïŒ HMIãPLC
æ©èœïŒãªã¢ãŒãã¢ã¯ã»ã¹å¶åŸ¡ãã»ãã¥ãªãã£ã€ã³ã·ãã³ããžã®è¿ éãã€æ£ç¢ºãªå¯Ÿå¿
Veracity Cerebellum
Veracityã® ç®æšã¯ãç£æ¥çšãããã¯ãŒã¯ã®å埩åãšå®å šæ§ãé«ããããšã§ããå瀟ã¯ãæé©ãªãããã¯ãŒã¯æ§æã管çãããã³ç£èŠã®ããã®ããŒã«ã«ã®éäžåãœãªã¥ãŒã·ã§ã³ãæäŸããŠããŸãã
äž»å補åã§ããVeracityCerebellumã¯ã人éã®å°è³ã«äŒŒããŠèšèšãããŠããŸããå°è³ã®æ©èœã¯ãèé«ãè³ãæèŠç³»ããä¿¡å·ãåä¿¡ããããŒã¿ã«åºã¥ããŠäœã®åãã調ç¯ããããšã§ããä¿¡ææ§å°è³ãã©ãããã©ãŒã ã¯ãç£æ¥çšãããã¯ãŒã¯ã«é¡äŒŒããæ©èœãå®è¡ããŸããæèŠå ¥åã«åå¿ãã補é ããã»ã¹ã®äºåã«èšèšãããå¿çã管çããŸããæ©èœïŒããã€ã¹ã€ã³ãã³ããªïŒã¯ããŒããã€è åšæ€åºïŒ
ããã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒã¯ã
çµ±åïŒ OT
ãµããŒããããŠããã·ã¹ãã ïŒ N / A
æ©èœïŒãã³ãã¬ãŒããŸãã¯ãŒãããã®ã»ãã¥ãªãã£ã¢ãã«ã®äœæãé«åºŠãªãããã¯ãŒã¯ããã€ã¹ç®¡çïŒæ€ç«ãå«ãïŒããããã¯ãŒã¯ã®ã»ã°ã¡ã³ããŒã·ã§ã³ãããã³ã»ãŒããŸãŒã³ã®å²ãåœãŠ
ãŠã©ãŒã¿ãŒãã©ãŒã«åæ¹åã»ãã¥ãªãã£ã²ãŒããŠã§ã€
Waterfall Security Solutionsã¯ã2007幎以æ¥éèŠãªç£æ¥ãããã¯ãŒã¯ãä¿è·ããŠããŸãããåæ¹åã»ãã¥ãªãã£ã²ãŒããŠã§ã€ã¯ãITãããã¯ãŒã¯ãšOTãããã¯ãŒã¯éã®å®å šãªçµ±åãšéä¿¡ã®ããã®ç¬èªã®ãœãªã¥ãŒã·ã§ã³ã§ãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãã¯ã©ãŠãããŒã¹ã®ãªã¢ãŒãç£èŠãšèšºæãå¯èœã«ããäžæ£ã¢ã¯ã»ã¹ããä¿è·ããŸããåæã«ããã¡ã€ã¢ãŠã©ãŒã«ãä»ããŠæ¥ç¶ãããšãã«ååšããè匱æ§ããããŸãããå
æ¹åã»ãã¥ãªãã£ã²ãŒããŠã§ã€ã¯ãããŒããŠã§ã¢ããŒã¹ã®ãããã¯ãŒã¯å¢çä¿è·ãæäŸããŸãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãããŒããŠã§ã¢ã³ã³ããŒãã³ãïŒTXã¢ãžã¥ãŒã«-å ãã¡ã€ããŒéä¿¡æ©ãRXã¢ãžã¥ãŒã«-å åä¿¡æ©ïŒãšãœãããŠã§ã¢ã³ã³ããŒãã³ãïŒç£æ¥çšã¢ããªã±ãŒã·ã§ã³ãœãããŠã§ã¢ã³ãã¯ã¿ïŒã§æ§æãããŠããŸãã
ãã®æ§æã«ãããOTãããã¯ãŒã¯ããå€éšãããã¯ãŒã¯ãžã®äžæ¹åã®ãµãŒããŒæ å ±ã®éä¿¡ãšè€è£œãå¯èœã«ãªãããŠã€ã«ã¹ãDOSæ»æã人çºçãšã©ãŒããŸãã¯ãµã€ããŒæ»æã®æ¡æ£ã鲿¢ãããŸãã
æ©èœïŒ
ããã€ã¹ã€ã³ãã³ããªïŒããã
ãŒããã€è åšæ€åºïŒããã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒã¯ã
çµ±åïŒ IT / OT
ãµããŒããããã·ã¹ãã ïŒ N / A
æ©èœïŒãµãŒããŒã¬ããªã±ãŒã·ã§ã³ãç£æ¥çšããã€ã¹ãšãã¥ã¬ãŒã·ã§ã³ãç£æ¥çšããŒã¿ã¯ã©ãŠã倿
ã®ãã¿ãããã¯ãŒã¯ã¹ã¬ãŒãã£ã¢ã³
Nozomi Networksã¯ããªã¢ã«ã¿ã€ã ã®ãµã€ããŒãªã¹ã¯ç®¡çã®ããã®ã¯ã³ã¹ããããœãªã¥ãŒã·ã§ã³ãæäŸããŸãã人工ç¥èœã𿩿¢°åŠç¿ã®é©æ°çãªäœ¿çšã«ãããé«ç²ŸåºŠãšæå°éã®èª€æ€ç¥ãå®çŸãããŸããNozomi Networks Guardianã®
ãã¯ãããžãŒã«ãããè³ç£ãæ¥ç¶ããããã³ã«ãå«ãç£æ¥ãããã¯ãŒã¯å šäœãèªåçã«ãããã³ã°ããã³èŠèŠåã§ããŸãããã®ãœãªã¥ãŒã·ã§ã³ã¯ããããã¯ãŒã¯éä¿¡ãšåäœã®ãªã¹ã¯ãç£èŠããè¿ éã«å¯Ÿå¿ããããã«å¿ èŠãªæ å ±ãæäŸããŸãã çµ±åã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¯ãè³ç£ç®¡çã·ã¹ãã ããã±ããããã³ID管çã·ã¹ãã ãSIEMã®çµ±åãçµã¿èŸŒãŸããŠããŸããæ©èœïŒããã€ã¹ã€ã³ãã³ããªïŒã¯ã
ãŒããã€è åšæ€åºïŒã¯ã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒã¯ã
çµ±åïŒ IT / OTãSOC
ãµããŒããããŠããã·ã¹ãã ïŒ N / A
æ©èœïŒã¹ã±ãŒã©ããªãã£ããããã¯ãŒã¯ã®å¯èŠæ§ãé«åºŠãªç°åžžãšè åšã®èªèãèªå·±åŠç¿
Indegy Industrial Cyberââsecurity Suite
Indegy ããŒã ã¯ãç£æ¥çšãããã¯ãŒã¯ã®ä¿è·ãç®çãšããŠèšç«ããããµã€ããŒã»ãã¥ãªãã£ã®å°éç¥èãšå®è·µçãªç£æ¥çšå¶åŸ¡ã®ç¥èã®ç¬èªã®çµã¿åãããèªã£ãŠããŸãã
å瀟ã®ãªãŒããŒã·ããããã³ç ç©¶ããŒã ã«ã¯ãã€ã¹ã©ãšã«ã®ãšãªãŒããµã€ããŒã»ãã¥ãªãã£ãŠãããã®åæ¥çãå«ããã»ãã¥ãªãã£ãç£æ¥éå¶ãé²è¡ã®å°éå®¶ãå«ãŸããŠããŸãã
ãããã¯ãŒã¯ãŸãã¯ä»®æ³ã¢ãã©ã€ã¢ã³ã¹ãšããŠå±éãããIndegyIndustrial Cyberââsecurity Suitã¯ãæ å ±ã»ãã¥ãªãã£æ åœè ãšOTãšã³ãžãã¢ã«å æ¬çãªã»ãã¥ãªãã£ããŒã«ãæäŸããŸãã
ãã®ãã©ãããã©ãŒã ã¯ãè³ç£ã®è¿œè·¡ãè åšã®æ€åºãšè»œæžãè匱æ§ã®ç®¡çãããã³ããã€ã¹ã®æŽåæ§ãæäŸããŸããæªæã®ããå¹²æžããã ãã§ãªããæå³ããªã人çãšã©ãŒããããããã¯ãŒã¯ãä¿è·ããããšãã§ããŸãã
æ©èœïŒ
ããã€ã¹ã€ã³ãã³ããªïŒã¯ã
ãŒããã€è åšæ€åºïŒããã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒ
çµ±åïŒ CMDBãSIEM
ãµããŒããããã·ã¹ãã ïŒ DCSãPACãPLCãRTU
æ©èœïŒãšãŒãžã§ã³ãã¬ã¹ãããã¯ãŒã¯æ¥ç¶ãã«ã¹ã¿ã ããªã·ãŒã¢ã©ãŒãããã³ã¡ãŒã«ãããã€ã¹ã®æŽåæ§ã確ä¿ããããã®ã¢ã¯ãã£ãæ€åºãã¯ãããžãŒ
ICSCyberââVision
Sentryoã¯ãæ å ±ã»ãã¥ãªãã£æ¥çã®2人ã®èµ·æ¥å®¶ãšããã©ã³ã«ãã£ãŠèšç«ãããŸããã圌ãã¯çŸåšããœãããŠã§ã¢ããããã³ã°ããµã€ããŒã»ãã¥ãªãã£ç°å¢ã§ã®é·å¹Žã®çµéšãç£æ¥çšãµã€ããŒã»ãã¥ãªãã£ã®äžçã«å¿çšããŠããŸãã
å瀟ã¯ãç£æ¥è³ç£ã«é¢ããå®å šãªæ å ±ãæäŸããããã«ç¬èªã®AIã¢ã«ãŽãªãºã ãéçºããŸããã圌ãã®äººå·¥ç¥èœã¯ãè匱æ§ãç¹å®ããç°åžžããªã¢ã«ã¿ã€ã ã§æ€åºããITããŒã ãšååããŠãµã€ããŒæ»æããããããšãã§ããŸãã
ICS CyberââVisionã¯ãç¬èªã®OTèšèªã䜿çšããŠããã¹ãŠã®è³ç£ãšãããã¯ãŒã¯ã¢ã¯ãã£ããã£ã«èªåçã«ã©ãã«ãä»ããŸããããã«ãããããã€ã¹ã®æ©èœãã·ã¹ãã ãã©ã³ãã䜿çšãããŠãããããã³ã«ãOTãŸãã¯ITã®åäœãããã³ãããã¯ãŒã¯æ å ±ãããã«ç¢ºèªã§ããŸãã
ãã®ãœãªã¥ãŒã·ã§ã³ã§ã¯ãè³ç£ãã°ã«ãŒãåãããããã®ãæ¥çãžã®åœ±é¿ããå®çŸ©ã§ãããããã»ãã¥ãªãã£ç®æšã«å¯ŸããŠã¢ã¯ã·ã§ã³ã«åªå é äœãä»ããããšãã§ããŸãã
æ©èœïŒ
ããã€ã¹ã€ã³ãã³ããªïŒã¯ã
ãŒããã€è åšæ€åºïŒããã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒããã
çµ±åïŒãã¡ã€ã¢ãŠã©ãŒã«ãCMDBãSIEMãSOC
ãµããŒããããŠããã·ã¹ãã ïŒ N / A
æ©èœïŒã·ã¹ãã ã«åœ±é¿ãäžããªãããã·ãã¢ãã¿ãªã³ã°ãã³ã³ããã¹ãåãããã€ãã³ããã°ã«ãŒãåãåªå é äœä»ãã»ãã¥ãªãã£ãžã®åœ±é¿ã«ãããããã¯ãŒã¯å ã®è³ç£
Forescoutãã©ãããã©ãŒã
2000幎ã«èšç«ãããForescoutã¯ãããããã¿ã€ãã®ãããã¯ãŒã¯ããã€ã¹ã®ããã€ã¹ã®å¯èŠæ§ãåäœå¶åŸ¡ããµã€ããŒã»ãã¥ãªãã£ã®ããã®ç¬èªã®ã©ããœãªã¥ãŒã·ã§ã³ãéçºããŠããŸãã圌ãã®ããŒã ã¯ãæ¡å€§ãç¶ããããã€ã¹ã®ãšã³ã·ã¹ãã ããã®è åšãç¹å®ãçè§£ã管çããçµç¹ã®èœåã®åäžã«åãçµãã§ããŸãã
Forescout Platformã¯ãäŒæ¥ç°å¢ã®å®å šãªç¶æ³èªèãååŸãããªã¹ã¯ã軜æžããããã®ã¢ã¯ã·ã§ã³ãæŽçã§ããçµ±åã»ãã¥ãªãã£ãã©ãããã©ãŒã ã§ãã
ãã®è£œåã䜿çšãããš
ãæ¢åã®ç©çããã³ä»®æ³ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããŠãé©å¿æ§ã®ãããã现ããããªã·ãŒãé©çšããçµæããã°ãã衚瀺ã§ããŸãã
ãã©ãããã©ãŒã ã¯ããšã³ã¿ãŒãã©ã€ãºã€ã³ãã©ã¹ãã©ã¯ãã£ãããŒã¿ã»ã³ã¿ãŒãã¯ã©ãŠããããã³OTãããã¯ãŒã¯å šäœã®å±éããšã«200äžå°ã®ããã€ã¹ã«æ¡åŒµã§ããŸãã
æ©èœïŒ
ããã€ã¹ã€ã³ãã³ããªïŒã¯ã
ãŒããã€è åšæ€åºïŒããã
ç°åžžæ€åºïŒã¯ã
ãã©ãã£ãã¯åæïŒããã
çµ±åïŒ CMDB
ãµããŒããããã·ã¹ãã ïŒ N / A
æ©èœïŒã¹ã±ãŒã©ããªãã£ãåçããã€ã¹ã»ã°ã¡ã³ããŒã·ã§ã³ãæ¥ç¶äžã®äºææ§ã®ãªãããã€ã¹ã®ä¿®æ£
ãã¹ãŠã®è£œåã確èªããåŸãæ¡ä»¶ä»ãã§ç¢ºèªã§ããŸããã®ãããªã°ã«ãŒãïŒ
- , â CyberX OT, Indegy Industrial Cybersecurity Suite, ICS CyberVision, Cyberbit SCADASchield;
- , â Forescout Platform;
- , Nozomi Networks Guardian Veracity Cerebellum;
- , â Dragos Industrial Cybersecurity Platform, Claroty Platform;
- ããŒããŠã§ã¢å¢çä¿è·-ãŠã©ãŒã¿ãŒãã©ãŒã«åæ¹åã»ãã¥ãªãã£ã²ãŒããŠã§ã€ã
æ¯èŒè¡š ã§åãœãªã¥ãŒã·ã§ã³ã®æ©èœã®ãã詳现ãªãªã¹ãã確èªããããã§é¢å¿ã®ãããœãªã¥ãŒã·ã§ã³ã䜿çšããŠç¬èªã®æ¯èŒè¡šãäœæã§ããŸãã
èè ïŒRoI4CIOã®Natalka Chekh