ããžã¿ã«ãªã¹ã¯ãšãã®çš®é¡ã調æ»ããããžã¿ã«ãªã¹ã¯ãã身ãå®ãæ¹æ³ãèŠã€ããŸããROI4CIOåæè¡šã«åºã¥ããŠãäžççã«èªããããŠãã6ã€ã®DRPïŒããžã¿ã«ãªã¹ã¯ä¿è·ïŒãœãªã¥ãŒã·ã§ã³ãæ€èšããæ©èœãšäŸ¡æ Œãæ¯èŒããŸãã
ããªãã®ãã©ã³ãã®æåãšèªç¥ã®ããã«ãªã³ã©ã€ã³ã®äžçã§åŒ·ãååšæã瀺ãå¿ èŠæ§ã¯ãäžè¬çãªçå®ã«ãªã£ãŠããŸãããããŠããã¯ãèžè¡çãªãã©ãããã©ãŒã ãæ¿æ²»å®¶ãã°ããŒãã«äŒæ¥ã®æ©ç¥ã«å¯ãã ãã£ããªã³ã°ã ãã§ã¯ãããŸãããå°å£²ãåºåãã«ã¹ã¿ããŒãµããŒãããªã³ã©ã€ã³ã¹ããŒã¹ã«ç§»è¡ããŠããŸããä»®æ³äžçãžã®ç§»è¡ã¯ãCOVID-19ã®å€§æµè¡ã«é¢é£ããŠå€ãã®åœã§æ€ç«ãå°å ¥ãããããšã«ç¹ã«é¢é£ããããã«ãªããŸããã
ã€ã³ã¿ãŒããããªãŒãã£ãšã³ã¹ã®ãªãŒããæ¡å€§ããããã«è²»ããããåªåãšæåãããªã³ã©ã€ã³ãã£ã³ããŒã³ã¯ããã®çµæã«é äºãããŠããŸããããããæ®å¿µãªããããªã³ã©ã€ã³ãã¬ãŒã³ã¹ãæåããèŠæš¡ã倧ãããªãã»ã©ããã®åœ±ã®åŽé¢ã§ããããžã¿ã«ãªã¹ã¯ãå¿ããã®ã¯å±éºã«ãªããŸããçµå±ã®ãšããããªãŒãã£ãšã³ã¹ãšã®ãªã³ã©ã€ã³ã€ã³ã¿ã©ã¯ã·ã§ã³ã¯ãå¿ èŠãªæ³šç®ãéããã ãã§ãªããããããçš®é¡ã®æ»æè ã«èŠããããã«ãªããŸããééçãªåæ©ãæã€ãµã€ããŒç¯çœªè ãç§å¯ãæŒããããšãã競åä»ç€Ÿãããã«ãŒãªã©ã§ãã
äœãè åšã§ããããããžã¿ã«ä¿è·ãæ§ç¯ããæ¹æ³ãéçšæ å ±ãåéããããã®æé©ãªãœãªã¥ãŒã·ã§ã³ãéžæããæ¹æ³ãããã³æ»æã«å¯Ÿããäºé²æªçœ®ãç解ããããšã¯ãè åšããããžãã¹ãä¿è·ããã®ã«åœ¹ç«ã¡ãŸãããã¡ãããæ¹æ³ã¯çµç¹ã®èŠæš¡ãšèŠæš¡ã«ãã£ãŠç°ãªããŸãããæ ä¿ã®éžæãå°ãããšãã§ããããžã¿ã«ãªã¹ã¯ä¿è·ã®ããã€ãã®åºæ¬çãªæŠå¿µããããŸãã
ããžã¿ã«ãªã¹ã¯ã®çš®é¡
ããžã¿ã«ãªã¹ã¯ä¿è·ã¯ãè åšæ å ±ç®¡çããã°ã©ã ã®1ã€ã®åŽé¢ã§ããããžã¿ã«ãªã¹ã¯ã«ããŽãªãæ§æããèŠçŽ ãæ€èšããŠãã ããã
äžæ£ãªé瀺ããã«
ã¯ãæ©å¯ããŒã¿ïŒå°å£²é¡§å®¢ã®å人çãªè²¡åæ å ±ããŸãã¯ãã¯ãããžãŒäŒæ¥ã®èªç€Ÿè£œåã®ãœãŒã¹ã³ãŒãïŒã®çé£ãŸãã¯æŒæŽ©ãå«ãŸããŸãã
è匱æ§ã®ç¹å®
Eã³ããŒã¹ãã©ãããã©ãŒã ãããŒã¯Webäžã®ç¯çœªãã©ãŒã©ã ãããã«ã¯ãªãŒãã³Webã¯ã匷åãªãªã¹ã¯æºã§ãã圱é¿ãäžããããšãã§ããªãã°ã«ãŒããŸãã¯å人ã«ãã£ãŠèå¥ãããè匱æ§ã¯ã圱é¿ãäžããããšãã§ãã誰ãã«ãã®æ¹æ³ãèŠã€ããŸããããã«ã¯ãæšçåæ»æãšéæšçåæ»æã®äž¡æ¹ã§ã®ãšã¯ã¹ããã€ãã®é åžãå«ãŸããŸãã
ãµãã©ã€ãã§ãŒã³ã®åé¡
çµç¹ãšçŽæ¥ããåãããããžãã¹ããŒãããŒããã³ãã¹ãŠã®ãã³ããŒã¯ãå¿ ãããããªããšåãã»ãã¥ãªãã£ã¬ã€ãã©ã€ã³ã«åŸããšã¯éããŸããã
ãã¯ãããžãŒãªã¹ã¯
ãã®å¹ åºãã«ããŽãªã«ã¯ãçµç¹ãäŸåãããã¯ãããžãŒãæ±ããšãã«èæ ®ããå¿ èŠã®ãããã¹ãŠã®ãªã¹ã¯ãå«ãŸããŸããããã«ã¯ä»¥äžãå«ãŸããŸãã
ç©çã€ã³ãã©ã¹ãã©ã¯ãã£ïŒSCADAãDCSããŸãã¯PLCã·ã¹ãã ã«ãã£ãŠéšåçãŸãã¯å®å šã«èªååãããç¡æ°ã®ç£æ¥ããã»ã¹ãæ®å¿µãªãããèªååã¯ãµã€ããŒæ»æã®ãããã¯ãŒã¯ãéããŸãããã®äžäŸã¯ãåœå šäœã®æ žèšç»ãæ··ä¹±ãããSTUXNETæ»æã§ãã
ITã€ã³ãã©ã¹ãã©ã¯ãã£ïŒãœãããŠã§ã¢ãšãââãŒããŠã§ã¢ã®ãã¹ãŠã®æœåšçãªè匱æ§ãå«ããããžã¿ã«ãªã¹ã¯ã®æãäžè¬çãªåå ããããã®ãªã¹ã¯ã¯ãã¢ãã®ã€ã³ã¿ãŒããããžã®æ¥ç¶ã«ããæ¥ã å¢å€§ããŠããŸãã
ã€ã³ã¿ãŒããããããªãã¯ãã¬ãŒã³ã¹ïŒé¡§å®¢ãã³ãã¥ããã£çµç¹ãšã®æ¥ç¹ïŒãœãŒã·ã£ã«ã¡ãã£ã¢ãé»åã¡ãŒã«ããŒã±ãã£ã³ã°ããŸãã¯ãã®ä»ã®ããŒã±ãã£ã³ã°æŠç¥ïŒã¯ãæœåšçãªãªã¹ã¯ã®åå ã§ãã
åŸæ¥å¡ããã®ãªã¹ã¯
æãå®å šã§äžæ£éå°é²æ¢ã®ããã¯ã§ãããéµãããã°ç°¡åã«éããããšãã§ããŸãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®åãçµã¿ãIDã®ç®¡çãšæäœãããã³äžæºãæã€åŸæ¥å¡ããã®æªæã®ããã€ã³ãµã€ããŒæ»æã«ãããæãä¿¡é Œã§ãããµã€ããŒã»ãã¥ãªãã£ããã°ã©ã ã§ãããããã«äžæãããå¯èœæ§ããããŸãã
ããžã¿ã«ãªã¹ã¯ä¿è·ã®10ã®ãŠãŒã¹ã±ãŒã¹
è åšã®ç¶æ³ã¯çµ¶ããæ¡å€§ããŠããŸããã€ãŸãããµã€ããŒã»ãã¥ãªãã£ããŒã ã¯çµç¹ãä¿è·ããããã«ãŸããŸãåªåããããšãäœåãªããããŠããŸãããªã¹ã¯ä¿è·ãµãŒãã¹ã®ç¯å²ã瀺ãããã«ã12ã®ã±ãŒã¹ã¹ã¿ãã£ããŸãšããŸããã
ãã£ãã·ã³ã°ã®æ€åº
ãã£ãã·ã³ã°ã¯é°æ¹¿ãªåé¡ã§ããããµã€ããŒç¯çœªè ã¯ãããå¹æçã§ããããã«ãããæããŠããŸããDRPã«ã¯ãæ»æã害ãåãŒãåã«æ»æãç¹å®ããŠé»æ¢ããäºé²æªçœ®ãå«ãŸããŠããŸãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãç»é²æžã¿ãã¡ã€ã³ãMXã¬ã³ãŒãã®å€æŽãDNSã¬ãã¥ããŒã·ã§ã³ãªã©ãããŸããŸãªäž»èŠãªãã£ãã·ã³ã°ã¡ããªãã¯ã远跡ããããšã§ãæªæã®ãããã¡ã€ã³ãèå¥ãããªãããŸããµã€ãããã°ããæé€ããŸãã
è匱æ§ã®åªå é äœä»ã
è åšã€ã³ããªãžã§ã³ã¹ãçµç¹ã®è匱æ§ãšæåã§é¢é£ä»ããããšã¯ããã¯ãçŸå®çã§ã¯ãããŸããã䜿çšãããã¯ãããžãŒãå€ãããããŒã¿ãå€ãããŸãã DRPã¯ãã©ãããã§ãããŒã¿ãæªçšããèªååãããè匱æ§ã³ã¬ã¯ã·ã§ã³ã§ãã次ã«ããããã®é åã¯ãªã¢ã«ã¿ã€ã ã§æ§é åãããäœãæ倧ã®ãªã¹ã¯ããããããã確èªã§ããŸãã
ããŒã¯ãããã®å¯èŠæ§
æ»æè ã¯è³¢ãå¿åã§ãããããã§ãç®ã«èŠããŸãã DRPã¯ãã€ã³ã¿ãŒãããå šäœã§ã®ã¢ã¯ãã£ããã£ãç£èŠããŸããã¿ãŒã²ãããåµå¯ããçãããããŒã«ã䜿çšããä»ã®ããã«ãŒãšååããæ¹æ³ã§ããé«åºŠãªDRPãœãªã¥ãŒã·ã§ã³ã¯ããµã€ããŒç¯çœªè ã®èãæ¹ãšè åšã®é²åãç解ããç©æ¥µçã«è¡åããæ©äŒãæäŸããŸããã¡ãªã¿ã«ãããŒã¯ãããã§ã®Webã¢ã¯ãã£ããã£ã®ç£èŠãšè¿œè·¡ã¯ãè åšãéåžžæ€åºããã³è»œæžãããæ¹æ³ã®éèŠãªéšåã§ãã
ãã©ã³ãä¿è·
ããªãã¯ããªãã®ãã©ã³ããæ§ç¯ãæ§ç¯ããããã«å€ãã®æéãšãéãè²»ãããŸãããæ²ããããªãããã«ãŒã¯ãããã©ãã»ã©äŸ¡å€ãããããç¥ã£ãŠããŸãã DRPãœãªã¥ãŒã·ã§ã³ã¯ããã©ã³ãã®äžæ£äœ¿çšã«ã€ããŠå€éšãœãŒã¹ãã¹ãã£ã³ããããã«èšèšãããŠããŸãããã¡ã€ã³ãIPã¢ãã¬ã¹ãã¢ãã€ã«ã¢ããªããœãŒã·ã£ã«ã¡ãã£ã¢ããŒãžãç£èŠããŠãäŸµå ¥è ãç¹å®ããŸãããŸããçãããã¢ã¯ãã£ããã£ãæ€åºããããšãçµç¹ãããŒã±ãã£ã³ã°ãã³ã³ãã©ã€ã¢ã³ã¹ãITãããã³ã»ãã¥ãªãã£å šäœã«ã¢ã©ãŒããå³åº§ã«éä¿¡ããŸãã
äžæ£æ€åº
ãã¡ã€ã¢ãŠã©ãŒã«ãã²ãŒããŠã§ã€ãIDS / IPSããã«ãŠã§ã¢æ€åºã·ã¹ãã ãªã©ãããããçš®é¡ã®å¢çé²åŸ¡ãã€ã³ã¹ããŒã«ãããŠããããããã®ã·ã¹ãã ãçµ±åããŠåŒ·åããããã®æªçœ®ãè¬ããŠããå ŽåããããŸããã«ãã³ããïŒåé¡ã¯ãããã«ãŒã代ããã«è©æ¬ºã䜿çšããŠãã®ä¿è·ããã€ãã¹ããããšã§ãããããã£ãŠãDRPãœãªã¥ãŒã·ã§ã³ã¯ããã£ãã·ã³ã°ãµã€ããäœæããããæŒæŽ©ããè³æ Œæ å ±ã顧客ãåŸæ¥å¡ã®éè¡å£åº§æ å ±ã販売ãããããè©Šã¿ãç£èŠããå¿ èŠããããŸããã€ã³ã¹ã¿ã³ããªã¢ã«ã¿ã€ã ã¢ã©ãŒãã¯ããã®ãããªã¢ã¯ã·ã§ã³ãçºçããåã«é²æ¢ããã®ã«åœ¹ç«ã¡ãçµç¹ã®ã³ã¹ããæ¯å¹ŽäœçŸäžãç¯çŽããŸãã
æªæã®ããã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®èå¥
ã¢ãã€ã«ããã€ã¹ãšã¢ããªã¯ãèŠèŽè ã®ãªãŒããæ¡å€§ããŸãããã ããæ»æè ã¯ãããŒã±ãã£ã³ã°ããŒã ã远跡ãŸãã¯èªèããŠããªãå¯èœæ§ãé«ãäžæ£ãªã¢ãã€ã«ã¢ããªããã§ã«äœæããŠããå¯èœæ§ããããŸãã DRPã¯ãåæ³ããã³æµ·è³çã®äž¡æ¹ã®ããŸããŸãªã¢ããªã¹ãã¢ããã§ãã¯ããŠãçãããã¢ããªãæ€åºãããããã®ééãéå§ããå¿ èŠããããŸããããã¯ããœãªã¥ãŒã·ã§ã³ãã¢ããªã¹ãã¢ãšææºããŠããå Žåã«å¯èœã§ãã
ãªãŒããŒã·ããã®ä¿è·
以åã¯ãå¹¹éšã¯ç©ççãªå®å šã®ã¿ãå¿ èŠãšããŠããŸããããã®ç®çã®ããã«ãã¢ã©ãŒã ãšã»ãã¥ãªãã£ããªãã£ã¹ã«èšçœ®ãããŠãããæã«ã¯ããã£ã¬ãŒããããããããžã¡ã³ãã«å²ãåœãŠãããŠããŸããçŸåšãé«å®ã¯æ·±å»ãªãµã€ããŒã»ãã¥ãªãã£ã®è åšã«çŽé¢ããŠããŸããæè³å®¶ãåç· åœ¹äŒã¡ã³ããŒãã¢ããã€ã¶ãŒãããã§ãã DRPããã°ã©ã ã¯ããªã³ã©ã€ã³ãœãŒã¹ãã¹ãã£ã³ããŠãIDãšããŒã¿ãæ¹ãããŸãã¯äŸµå®³ããè©Šã¿ãèŠã€ããŠåæ¢ããå¿ èŠããããŸãã
èªååãããè åšã®è»œæž
æœåšçãªè åšã®èŠæš¡ãšãããã軜æžããããã®å°éç¥èã®æ¬ åŠãèãããšã軜æžããã»ã¹ãèªååããããšãéèŠã§ãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãããŒã¿ãã€ã³ããªãžã§ã³ã¹ã«ãã€ã³ããªãžã§ã³ã¹ãã¢ã¯ã·ã§ã³ã«å€ããå¿ èŠããããŸããè åšã®ãããã¯ãšæé€ãè³æ Œæ å ±ã®ã¯ã©ãã·ã¥ãªã»ãããã»ãã¥ãªãã£ããªã·ãŒã®äœæã§ãã
ãªãŒã¯ãšæ©å¯ããŒã¿ã®ç£èŠ
顧客ããŒã¿ãšç¥ç財ç£ãä¿è·ããããšã¯éèŠã§ãã DRPã¯ãçãŸããè³æ Œæ å ±ãšæ©å¯ããŒã¿ããã¹ã¯ãŒããæ€çŽ¢ãããããã®æ€åºã«ã€ããŠéç¥ããŸãã DRPãææ°ã®è³æ Œæ å ±ã«åŸã£ãŠæ©èœããŠããããšã確èªããæè¯ã®æ¹æ³ã¯ããœãªã¥ãŒã·ã§ã³ãActiveDirectoryããã³MicrosoftExchangeãšçµ±åããããšã§ãããããã£ãŠããªãŒã¯ãæ€åºããããšãã¢ã¯ãã£ããªè³æ Œæ å ±ããªã»ãããããŸãã
第äžè
èªåã®ã·ã¹ãã ãä¿è·ããã®ã¯ååã«é£ããããšã§ã¯ãªããã®ããã«ãå€éšãœãŒã¹ã«ã€ããŠãå¿é ããå¿ èŠããããŸããå€éšãœãŒã¹ãå¶åŸ¡ãå°é£ã§ãããããã¯ãããžã¿ã«ãããããªã³ãã®äžéšã§ãããµãã©ã€ã€ãŒãããŒãããŒãæè³å®¶ã§ãã圌ãã®ãµã€ããŒãªã¹ã¯ãããªãã®ãã®ã§ãããããã£ãŠãDRPã¯ããµãã©ã€ãã§ãŒã³ãå¹æçã«ç®¡çã§ããããã«ããµãŒãããŒãã£ãçŽé¢ããè åšãè©äŸ¡ããå¿ èŠããããŸãã
ããžã¿ã«ãªã¹ã¯ä¿è·ãã³ã¹ãã§ã¯ãªãæè³ã§ããçç±
ããžã¿ã«ãªã¹ã¯ä¿è·ã¯ãäºé²çãªé²åŸ¡æŠç¥ã§ããããã«ãããè åšã«å¯ŸæããäžèŠãªã³ã¹ããåé¿ããå¹çãåäžãããæ倱ãå埩ããããšãã§ããŸãã DRPãROIãæäŸããã®ã¯ãããã4ã€ã®é åã§ããããèŠãŠã¿ãŸãããã
ROI 1ïŒãªã¹ã¯ã®åé¿
ãµã€ããŒã»ãã¥ãªãã£æŠç¥ã®ä»ã®ã»ãšãã©ã®èŠçŽ ãšåæ§ã«ããœãªã¥ãŒã·ã§ã³ãžã®æè³ã¯ãã»ãã¥ãªãã£éåãçºçããå¯èœæ§ã®ããäžèŠãªã³ã¹ããšã®é¢é£ã§æ€èšããå¿ èŠããããŸããããããããã¯ã¡ãªããã®äžéšã«ãããŸããã DRPã®æã䟡å€ã®ããåŽé¢ã®1ã€ã¯ãçµç¹èªäœã®ããžã¿ã«ãããããªã³ãã®èŠèŠåã§ããããã¯ãããžãã¹ãšè©å€ãä¿è·ããããã«äžå¯æ¬ ãªèŠçŽ ã§ãã
ROI 2ïŒäœã³ã¹ã
DRPãœãªã¥ãŒã·ã§ã³ã¯ãããžã¿ã«è åšã®æ€åºãšç£èŠã«é¢é£ããå€ãã®ã¿ã¹ã¯ãèªååããŸããç¹å¥ã«èšèšããã絶ããæŽæ°ããããœãªã¥ãŒã·ã§ã³ãšæ¯èŒããå Žåãå°äžã§ã®èªäž»çãªãµã€ããŒé²åŸ¡ã¯ããã®ãããªã¿ã¹ã¯ãéšåçã«ããã«ããŒããŸããããããDRPãµãŒãã¹ã¯ãã·ã£ããŠITïŒITéšéã«éç¥ããã«äœæãŸãã¯äœ¿çšãããç¡èš±å¯ã®ãã¡ã€ã³ãã¢ããªã±ãŒã·ã§ã³ããŸãã¯ããã€ã¹ïŒãšå¿ããããITïŒå€ãWebãµã€ãã®ã©ã³ãã£ã³ã°ããŒãžãã¢ãŒã«ã€ããããã³ã³ãã³ããªã©ïŒãã«ããŒããè¿œå ã®ã³ã¹ãåæžãæäŸããŸã..ã
ROI 3ïŒå¹çã®åäž
ããžã¿ã«ãªã¹ã¯è»œæžãœãªã¥ãŒã·ã§ã³ã«åºæã®èªååã«ãããè匱æ§ãããè¿ éãã€ç°¡åã«ç¹å®ããããã»ã¹å¹çãåäžãããŸããShadow and Forgotten ITã®ç¹å®ãšæé€ã«ãããäŒæ¥ã®ããžã¿ã«ã¹ããŒã¹ãããã«æé©åããããªãœãŒã¹ãç¯çŽãããŸãã
ROI 4ïŒåçã®çæ
çµç¹ã®ãµã€ããŒæ»æããã£ãã·ã³ã°ã¡ãŒã«ãåœã®ãµã€ãã®æåã¯ãåçã«çŽæ¥çãªæªåœ±é¿ãåãŒãããã¡ããè©å€ã«ãæªåœ±é¿ãåãŒããŸããããžã¿ã«ãªã¹ã¯ä¿è·ãœãªã¥ãŒã·ã§ã³ã¯ããããã®ãªã¹ã¯ã軜æžããã®ã«ã圹ç«ã¡ãéæ³ãŸãã¯è è¿«çãªæŽ»åãè¿ éã«ç¹å®ããŠä¿®æ£ããã®ã«åœ¹ç«ã¡ãŸãã
ä¿è·æ¹æ³
Forresterã¯ãããžã¿ã«ãªã¹ã¯ãåæžããããšããŠããçµç¹ã«ãšã£ãŠã2ã€ã®äž»èŠãªèª²é¡ãç¹å®ããŸãããŸããååšãããªã¹ã¯ãç¹å®ãã次ã«ãããããæé€ããŸããç§ãã¡ã¯ããªãã«åæããŸã-äžèŠãããšãããç®æšã¯æçœã§ãããããå®éã«ã¯ã圌ãã¯ã»ãã¥ãªãã£ã«é¢ããŠäžå®ã®ã¹ã¿ã³ã¹ããšã£ãŠããŸã-ã€ã³ã·ãã³ã察å¿ãããç©æ¥µçã§ãããã®ããã¢ã¯ãã£ããªã¢ãããŒãã¯ãããžã¿ã«ãªã¹ã¯ä¿è·ãè åšã€ã³ããªãžã§ã³ã¹æŠç¥ã«çµã¿èŸŒã¿ãŸãã
è¡ã®åšãã«å£ãäœã£ãŠäžèŠãªãã®ã«è¿ã¥ããªãããã«ããã®ã§ã¯ãªããåšå²ã®ãã¹ãŠãç¥ã£ãŠããäžçäžãèªç±ã«æ©ãåãããšãå®å šã ãšæããããšã§ãã
Forresterã¬ããŒãã¯ãDRPãœãªã¥ãŒã·ã§ã³ã«åºæã®ããã€ãã®éèŠãªå質ãèå¥ããŸãã
- . . -, , .
- , . , , - ; , ; .
- - . â , . â , .
DRPãå®è£ ããããšã®ãã¹ãŠã®å©ç¹ãæ€èšãããœãªã¥ãŒã·ã§ã³ã«äœãæåŸ ã§ããããç解ããã®ã§ã次ã«6ã€ã®äž»èŠãªè£œåãçžäºã«æ¯èŒããŸããæ©èœãæ©èœãç°¡åã«èŠãŠã¿ãŸããããROI4CIOåæããŒãã«ã«åºã¥ããŠãäŸ¡æ Œãšãã©ã¡ãŒã¿ãŒïŒIPã¢ãã¬ã¹ãURLãTTPã«ããŽãªã®è åšããã¡ã€ã«ã®ããã·ã¥åèšããã¡ã€ã³ãã¬ãžã¹ããªããŒãã«ãŒãçªå·ãé»è©±çªå·ããœãŒã·ã£ã«ïŒã®ä¿è·ãšæ€èšŒãæ¯èŒããŸãããããã¯ãŒã¯; ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ãšãã©ã³ãã®ä¿è·ãããŒã¿æŒæŽ©ã®çºèŠ; ããŒã¿ã®åŒ·åïŒè åšã®è©äŸ¡ãè åšã®ã¿ã°ä»ããè¿œå æ å ±ïŒ; çžäºäœçšã®æ¹æ³; ããŒã¿åœ¢åŒã
ZeroFOXãã©ãããã©ãŒã
ZeroFOXã¯ãã°ããŒãã«ãªããŒã¿åéãšã³ãžã³ãAIã掻çšããåæãèªå修埩ã·ã¹ãã ãåããŠããããœãŒã·ã£ã«ã¡ãã£ã¢ãããžã¿ã«ãã©ãããã©ãŒã ã§ã®ãµã€ããŒããã©ã³ããç©ççãªè åšããä¿è·ããŸãã
ããžã¿ã«ã®å¯èŠæ§ãšã»ãã¥ãªãã£ã®ããŒã±ãããªãŒããŒã§ããZeroFOXã¯ãä»æ¥ã®çµç¹ãããœãŒã·ã£ã«ãã¢ãã€ã«ãWebãã©ãããã©ãŒã äžã®åçãªããžã¿ã«ãªã¹ã¯ãšç©ççãªã¹ã¯ããä¿è·ããŸãã
ZeroFOXã¯ãæšçåãã£ãã·ã³ã°æ»æãã¢ã«ãŠã³ãã®äŸµå®³ãããŒã¿ã®ååãããã³å Žæã®è åšãæ€åºããŠæé€ããŸããç¹èš±ååŸæžã¿ã®ZeroFOXSaaSãã¯ãããžãŒã¯ãLinkedInãFacebookãSlackãTwitterãInstagramãPastebinãYouTubeãã¢ãã€ã«ã¢ããªã¹ãã¢ã®äœçŸäžãã®ã¡ãã»ãŒãžãšã¢ã«ãŠã³ããæ¯æ¥åŠçããŠä¿è·ããŸãã
ãã©ãããã©ãŒã ã§ã®äœæ¥ã¯ãããšã³ãã£ãã£ãã®èšå®ããå§ãŸããŸããããã¯ããœãŒã·ã£ã«ã¡ãã£ã¢ãããžã¿ã«ãã£ãã«ã§çµç¹ã«ãšã£ãŠéèŠãªãã¹ãŠã®ãã®ã§ãããã©ã³ããåŸæ¥å¡ããšã°ãŒã¯ãã£ããVIPã補åãå ŽæãäŒæ¥ããŒãžãªã©ã§ãããšã³ãã£ãã£ã«ã¯ããããã¡ã€ã«ãååãããŒã¯ãŒããç»åããã¡ã€ã³ãããã·ã¥ã¿ã°ãªã©ã§æ§æããããµãã»ã¯ã·ã§ã³ããããŸãããšã³ãã£ãã£æ§æã¯ãZeroFOXãããŒã¿ãåéããå Žæãšæ¹æ³ãå¶åŸ¡ããŸããã«ã¹ã¿ãã€ãºã«ãããçµç¹ã«é¢é£ããããŒã¿ã®ã¿ã衚瀺ãããããã«ãªããŸãã
次ã«ãããããã®ãŠãŒã¹ã±ãŒã¹ã«åºã¥ããŠåãšã³ãã£ãã£ã«å¯ŸããŠå®è¡ãããåæã決å®ããŸãïŒããšãã°ããã©ã³ãã«ã¯åŸæ¥å¡ãšã¯ç°ãªãèŠä»¶ããããŸãïŒãéåãæ€åºããããšãZeroFOXã¯ã¢ã©ãŒããéä¿¡ããŸãããããã¯ããªã¹ã¯è©äŸ¡ãè åšã®çš®é¡ãã¿ã€ã ã¹ã¿ã³ãã§ãœãŒãããããã£ã«ã¿ãŒå¯èœãªããŒãã«ã«è¡šç€ºãããŸã...
ç¬èªã®ããã»ã¹ãéããŠãZeroFOXã¯ã¯ã©ã€ã¢ã³ãã«ä»£ãã£ãŠæ©èœãããœãŒã·ã£ã«ã¡ãã£ã¢äžã®äžé©åãªã³ã³ãã³ãã«ãã©ã°ãä»ããŸãããã®è£œåã¯ãç¹å®ã®éåã«é¢ããèŠæ ãèªåçã«ãœãŒã·ã£ã«ã»ãã¥ãªãã£ã»ã³ã¿ãŒã«çŽæ¥éä¿¡ããŠåé€ããŸãããªã¢ã«ã¿ã€ã ã§ãäŒæ¥ããŒãžããäžé©åãªã³ã³ãã³ããåé€ããããšãã§ããŸãã
æè¿ã®ã¢ããããŒãã§ããZeroFOXEnterprise Remote Workforce Protectionã¯ãåŸæ¥ã®ãµã€ããŒã»ãã¥ãªãã£ããŒã«ã«ã¯ãªãã³ã©ãã¬ãŒã·ã§ã³ãã©ãããã©ãŒã ã®è åšã«ã»ãã¥ãªãã£ãšã€ã³ããªãžã§ã³ã¹ããããããŸãã
補åã¬ãã¥ãŒãã¹ãã¬ãŒãžäŒç€Ÿã®ã»ãã¥ãªãã£éšéã®è²¬ä»»è ïŒ
ä»ã®èª°ããã®æ±ºå®ãããããšãããªãã®ã§ãZeroFOXã®ç·æ¥ã®å¿ èŠæ§ããããŸããZeroFOXã§ã®äœæ¥ã¯ãç§ãã¡ã®ç®ãæ¬åœã«éããŸãããç§ãäžããããšãã§ããæé«ã®è€ãèšèã¯ããã©ãããã©ãŒã ã§äœæ¥ããããã»ã¹ã宣èšããã説æã«å®å šã«å¯Ÿå¿ãããã¹ãŠãæ©èœããããšã§ãã
ã€ã³ã¿ãŒãã§ã€ã¹ã¯
IPã¢ãã¬ã¹ã§ãïŒã¯ã
URLã¢ãã¬ã¹ïŒã¯ã
è åšã«ããŽãªTTPSïŒã¯ã
ãã¡ã€ã«ã®ããã·ã¥åèšïŒã¯ã
ãã¡ã€ã³ïŒã¯ã
ã¬ãžã¹ããªããŒïŒã¯ã
ã«ãŒã以å€ïŒã¯ã
é»è©±ïŒã¯ã
ãœãŒã·ã£ã«ãããã¯ãŒãã³ã°ã®ã€ã³ãžã±ãŒã¿ïŒã¯ã
ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®
ä¿è·ïŒã¯ããã©ã³ãä¿è·ïŒã¯ã
ããŒã¿æŒæŽ©ïŒ N / A
ããŒã¿åŒ·åïŒè åšã®è©äŸ¡ãè åšã®ã¿ã°ä»ããè¿œå ããã³ãã®ä»ã®è¿œå æ å ±ïŒïŒã¯ã
çžäºäœçšæ¹æ³ïŒ API
ããŒã¿åœ¢åŒïŒ JSONãSTIXãTAXII
äŸ¡æ ŒïŒ æé¡390ãã«ãã
IntSightsè åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ïŒTIPïŒ
IntSights Threat Intelligence PlatformïŒTIPïŒã¯ãçµç¹ãè€æ°ã®æ å ±ãœãŒã¹ããã®ããŒã¿ãäžå åããŠããããã¯ãªã¹ããææ°ã®ç¶æ ã«ä¿ã€ã®ã«åœ¹ç«ã¡ãŸãã
IntSightsã¯ãå æ¬çãªå€éšè åšé²åŸ¡ãã©ãããã©ãŒã ã掻çšããŠãµã€ããŒæ»æãç¡ååããããšã«ããããµã€ããŒã»ãã¥ãªãã£éçšã«é©åœããããããŠããŸãããµã€ããŒã€ã³ããªãžã§ã³ã¹æ©èœã䜿çšãããšããããã¯ãŒã¯äžã®äŒæ¥ã®å€éšããžã¿ã«ãããã¡ã€ã«ãšããŒã¯ããããç¶ç¶çã«ç£èŠããŠãæ°ããªè åšãç¹å®ããããã¢ã¯ãã£ãã«å¯Ÿå¿ã§ããŸãã
ã³ã¢ã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ãšçµ±åãããã®ãããªç¹æ®ãªè åšã€ã³ããªãžã§ã³ã¹è£œåã®äœæã«ãããIntSightsã¯äžçã§æãæ¥éã«æé·ããŠãããµã€ããŒã»ãã¥ãªãã£äŒæ¥ã®1ã€ã«ãªããŸããã
IntSights Threat Intelligence PlatformïŒTIPïŒã¯ãæ°åã®ã€ã³ããªãžã§ã³ã¹ãœãŒã¹ãäžå åããŠäžèŠ§è¡šç€ºããæŽç¶ãšãã調æ»ãšè¿ éãªè åšã®ãããã¯ãå®çŸããŸããè åšã¯ãéä¿¡ãã£ãã«ã«ã³ã³ããã¹ããããããããšã«ãããé倧床ãåªå ãããŸãã IntSightsã¯ããã«ãçµç¹ã«ç¹åããéç¥ãã¢ã©ãŒããããã³ã¬ããŒããæäŸããŸãã
èŠèŠåãããè åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã 調æ»ããã·ã¥ããŒãã䜿çšãããšãæ¢ç¥ã®æªæã®ããè³ç£ã«é¢é£ãããã£ã³ããŒã³ãç£èŠããã³ç®¡çãã察å¿ã調æŽã§ããŸããå éšã®æ€åºãšå¿çã®ããã«ããã©ãããã©ãŒã ã¯ãã¡ã€ã¢ãŠã©ãŒã«ãWebãããã·ãActive Directoryãªã©ã®ãªã³ãã¬ãã¹ã»ãã¥ãªãã£ã·ã¹ãã ãšçµ±åãããã»ãã¥ãªãã£ããŒã ã«è åšãšèªå修埩æ©èœãèªåçã«éç¥ããŸãã
çµç¹å€ïŒã€ã³ã¿ãŒããããšããŒã¯ãŠã§ãïŒã§èµ·ãã£ãŠããããšãšçµç¹å ã§èµ·ãã£ãŠããããšïŒã»ãã¥ãªãã£ããã€ã¹ããããã¯ãŒã¯ãã·ã¹ãã ãããã€ã¹ãããã³ãŠãŒã¶ãŒããã®å éšããŒã¿ïŒãæ¥ç¶ããæ©èœã«ãããåºç¯ãªãã¬ãŒãã³ã°ãäžèŠã«ãªããã»ãã¥ãªãã£ããŒã å šäœãããããç解ã§ããããã«ãªããŸããããã»ã¹ã
. , SOC , Teva:
IntSights . , , , .
ã€ã³ã¿ãŒãã§ã€ã¹ã¯
IPã¢ãã¬ã¹ã§ãïŒã¯ã
URLã¢ãã¬ã¹ïŒã¯ã
è åšã«ããŽãªTTPSïŒã¯ã
ãã¡ã€ã«ã®ããã·ã¥åèšïŒ N / A
ãã¡ã€ã³ïŒã¯ã
ã¬ãžã¹ããªããŒïŒ N / A
ã«ãŒãçªå·ïŒã¯ã
é»è©±ïŒã¯ã
ãœãŒã·ã£ã«ãããã¯ãŒãã³ã°ã®ã€ã³ãžã±ãŒã¿ïŒã¯ã
ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®ä¿è·ïŒ N / A
ãã©ã³ãä¿è·ïŒã¯ã
ããŒã¿æŒæŽ©ïŒ N / A
ããŒã¿åŒ·åïŒè åšã®è©äŸ¡ãè åšã®ã¿ã°ä»ããè¿œå ããã³ãã®ä»ã®è¿œå æ å ±ïŒïŒã¯ã
çžäºäœçšæ¹æ³ïŒ API
ããŒã¿åœ¢åŒïŒ N / A
äŸ¡æ ŒïŒ å¹Žé10äžãã«ãã
Kasperskyè åšã€ã³ããªãžã§ã³ã¹
Kaspersky Labã¯ãKaspersky Threat IntelligenceïŒKTIïŒããŒã¿ã«ãéçºããŸããããã®ããŒã¿ã«ã¯ãäŒç€Ÿã®20幎以äžã®çµéšã§èç©ããããã¹ãŠã®ç¥èãžã®ã¢ã¯ã»ã¹ãæäŸããŸããããã«ãããã»ãã¥ãªãã£ã»ã³ã¿ãŒã«ææ°ã®è åš
ã€ã³ããªãžã§ã³ã¹ãæäŸãããŸããè åšã€ã³ããªãžã§ã³ã¹ã¯ãã¯ã©ã€ã¢ã³ãã«å¯Ÿããæ»æã®çŸç¶ã®å šäœåãåéãããããã¯ãŒã¯å¢çã®åŒ±ç¹ããµã€ããŒç¯çœªã®è åšãæªæã®ããã¢ã¯ãã£ããã£ãããã³ããŒã¿äŸµå®³ãç¹å®ããKasperskyã®å°é家ã®å°éç¥èã«åºã¥ããŠæ§ç¯ãããŠããŸãã
ãã®ãµãŒãã¹ã¯ããµã€ããŒæ»æã«é¢ããããŒã¿ãžã®åäžã®ã¢ã¯ã»ã¹ãã€ã³ãã§ããKaspersky Threat IntelligencePortalã§å©çšã§ããŸãããã®ããŒã¿ã«ã䜿çšããŠãSOCã¹ãã·ã£ãªã¹ãã¯ãè åšã«é¢ããææ°æ å ±ã ãã§ãªããæšçåæ»æã®ãœãŒã¹ã«é¢ããã°ããŒãã«ãªèª¿æ»çµæãžã®ã¢ã¯ã»ã¹ãåãåããŸããããã«ãããæªç¥ã®è åšã«é¢ããå éšã·ã¹ãã ããã®ä¿¡å·ã«åªå é äœãä»ããã€ã³ã·ãã³ãã®å¿çæéãæå°éã«æããã·ã¹ãã ã®äŸµå®³ãé²ãããšãã§ããŸãã
ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãéäŸµå ¥åã®æ¹æ³ã䜿çšããŠãããã¯ãŒã¯ã€ã³ãã³ããªãå®è¡ãããªã¢ãŒã管çãµãŒãã¹ãæå³ããã«éããŠèª€ã£ãŠæ§æããããµãŒãã¹ããããã¯ãŒã¯ããã€ã¹ãªã©ã顧客ã®ãããã¯ãŒã¯å¢çã®éèŠãªã³ã³ããŒãã³ããèå¥ããŸããå©çšå¯èœãªãµãŒãã¹ã®å°éçãªåæã«ãããè匱æ§ã®ã©ã³ã¯ä»ããšãå€ãã®ãã©ã¡ãŒã¿ãŒïŒããŒã¹ã©ã€ã³CVSSè©äŸ¡ããããªãã¯ãšã¯ã¹ããã€ãã®å¯çšæ§ïŒã«åºã¥ãå æ¬çãªãªã¹ã¯è©äŸ¡ãè¡ãããŸãã
ãã®ãµãŒãã¹ã«ã¯ãè åšããŒã¿ã¹ããªãŒã ãã«ã¹ã¿ãã€ãºãããè åšã¬ããŒããäŒæ¥åºæã®è åšã€ã³ããªãžã§ã³ã¹ã¬ããŒããåœåºæã®è åšã€ã³ããªãžã§ã³ã¹ã¬ããŒããéèæ©é¢ã®è åšã€ã³ããªãžã§ã³ã¹ã¬ããŒããAPTè åšã€ã³ããªãžã§ã³ã¹ã¬ããŒããè åšã«ãã¯ã¢ãããµãŒãã¹ããµãŒãã¹ãå«ãŸããŸããã¯ã©ãŠããµã³ãããã¯ã¹ãCyberââTraceãµãŒãã¹ã
ãã®ãµãŒãã¹ã¯ããªã³ã©ã€ã³ã³ã³ãã³ããã¹ãã£ã³ã°ãµãŒãã¹ããããªãã¯ãã©ãŒã©ã ããœãŒã·ã£ã«ãããã¯ãŒã¯ããã£ãã«ãšã¡ãã»ã³ãžã£ãŒãéå ¬éã®ã¢ã³ããŒã°ã©ãŠã³ããªã³ã©ã€ã³ãã©ãŒã©ã ãšã³ãã¥ããã£ãä»ããèªåããŒã¿åéãéããŠã䟵害ãããåŸæ¥å¡ã¢ã«ãŠã³ããããŒã¿äŸµå®³ãèšç»ãŸãã¯è°è«ãããæ»æã«é¢ãã詳现æ å ±ãæäŸããŸããçµç¹ã
Digital Footprint Intelligenceã¬ããŒãã¯ã顧客ã ãã§ãªãã顧客ãããŒãããŒãããã³ãµãã©ã€ã€ãŒã€ã³ãã©ã¹ãã©ã¯ãã£ã«å¯Ÿãããµã€ããŒç¯çœªè ã匷調ããå°åããã³æ¥çå šäœã®çŸåšã®ãã«ãŠã§ã¢ãŸãã¯APTæ»æã®æŠèŠãæäŸããŸãããã®æ å ±ã䜿çšããŠã顧客ã¯æ»æè ã®èŠ³ç¹ããããžãã¹ãèŠãŠãITã€ã³ãã©ã¹ãã©ã¯ãã£ãšäŒç€Ÿã®åŸæ¥å¡ã«ã€ããŠäœãåŠã¶ããšãã§ããããç解ã§ããŸãã
. , :
Kaspersky Intelligence Reporting â , . , -. IOC .ã€ã³ã¿ãŒãã§ã€ã¹ã¯
IPã¢ãã¬ã¹ã§ãïŒã¯ã
URLã¢ãã¬ã¹ïŒã¯ã
è åšã«ããŽãªTTPSïŒã¯ã
ãã¡ã€ã«ã®ããã·ã¥åèšïŒã¯ã
ãã¡ã€ã³ïŒã¯ã
ã¬ãžã¹ããªããŒïŒã¯ã
ã«ãŒã以å€ïŒã¯ã
é»è©±ïŒ N / A
ãœãŒã·ã£ã«ãããã¯ãŒã¯ã®ã€ã³ãžã±ãŒã¿ïŒ N / A
ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®ä¿è·ïŒ N / A
ãã©ã³ãä¿è·ïŒ N / A
ããŒã¿ãªãŒã¯ïŒ N / A
ããŒã¿ãšã³ãªããã¡ã³ãïŒè åšã®è©äŸ¡ãè åšã®ã¿ã°ä»ããè¿œå ããã³ãã®ä»ã®è¿œå æ å ±ïŒïŒã¯ã
察話æ¹æ³ïŒ https
ããŒã¿åœ¢åŒïŒ JSONãSTIXãCSVãOpenIoC
äŸ¡æ ŒïŒ å¹Žé10äžãã«ãã
ã°ã«ãŒãIBè åšã€ã³ããªãžã§ã³ã¹
Group-IB Threat Intelligenceã¯ãçµç¹ãããŒãããŒãããã³é¡§å®¢ã«å¯Ÿããè åšãç£èŠãåæãããã³äºæž¬ãããµãã¹ã¯ãªãã·ã§ã³ãµãŒãã¹ã§ãã
Group-IBã¯ãInterpolãEuropolãããã³å°åã®æ³å·è¡æ©é¢ã®å ¬åŒããŒãããŒã§ãã Group-IBã¯ã15幎以äžã®çµéšãšé«åºŠãªè³æ Œãæã€å°é家ãæããç¬èªã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãšç¬èªã®å€éšè åšæ€çŽ¢ã·ã¹ãã ã䜿çšããŠããŸãããã©ãããã©ãŒã ã¯ã倧éã®ããŒã¿ããªã¢ã«ã¿ã€ã ã§åéããç¬èªã®ã¢ã«ãŽãªãºã ãšæ©æ¢°åŠç¿ã䜿çšããŠãããŒã¿ããã°ããé¢é£ä»ããŸãã
ããŒã¿åéã®åéã§ã®Group-IBã®ç 究掻åã¯ãéèã»ã¯ã¿ãŒã«åããããè åšã®ã»ãšãã©ã¯ãäŒç€Ÿã®æŽ»åã®ç¹å®ã®é åã§ãããã·ã¢èªã話ãç¯çœªè ããæ¥ãŠãããšäž»åŒµããŠããŸãããœãªã¥ãŒã·ã§ã³ã®çŠç¹ã¯ã䟵害ã®ææšã®ç®¡çã§ã¯ãªããåæ»æã®èåŸã«ãã人ç©ã«é¢ããæ å ±ã«åºã¥ããŠããŸãã
ãã©ãããã©ãŒã ã®[䟵害ãããããŒã¿]ã»ã¯ã·ã§ã³ã«ã¯ããœãŒã¹ãè åšããã¡ã€ã³ããããŒãã¥ãŒã«ãªã©ã®èŠçŽ ã衚瀺ãããŸãããã®ããã·ã¥ããŒãã§ãã¢ããªã¹ãã¯ãç¹å®ã®ãã£ãã·ã³ã°ããŒãžã䟵害ã«ã©ãã»ã©å¹æçã§ããããããã³ããŒãžãæ€åºããããšãã«ã©ã®ããã«èŠãããã確èªã§ããŸãã
Group-IBãµã³ãããã¯ã¹ã¯ãæ©é¢ã®ã¯ãŒã¯ã¹ããŒã¹ããšãã¥ã¬ãŒãããããã«èšèšãããŠããŸããæªæã®ãããã¡ã€ã«ã®å²åãæšå®ãããµã³ãããã¯ã¹ã§ã®ãã¡ã€ã«ã®åäœã®ãããªãè¿ããŸããã¢ããªã¹ãã¯ããã¡ã€ã«ãšããã»ã¹ããªãŒãã©ã®ããã«æ©èœãããã瀺ãããã«å¿ èŠãªåäœæ©èœã®ç°¡åãªèª¬æãåãåããŸãã
æè¿è¿œå ãããæ»ææ©èœã¯ãå ã®ãã£ãã·ã³ã°ããŒãžã®èŠçŽ ããä»ã®ãã¡ã€ã³ãIPã¢ãã¬ã¹ãSSL蚌ææžãé»åã¡ãŒã«ãé»è©±çªå·ãããã³ãã¡ã€ã«ãŸã§ã®ãã¹ãŠã®äº€å·®ç¹ã®æ確ãªã°ã©ããæäŸããŸãã
Advanced Threatsã¯ã説æä»ãã®ã«ãŒãã®åªå é äœä»ãã®æŠèŠãéå§ããæ¥ä»ãŸã§ã®ç¯çœªãã£ã³ããŒã³ã®ã¿ã€ãã³ã°ãããã³ã¢ã¯ãã£ããã£æ å ±ãæäŸããããšã«ãããã¢ããªã¹ããæäŸãããèšå€§ãªéã®æ å ±ãç°¡åã«åŠçã§ããããã«ããŸãã
補åã¬ãã¥ãŒããªãŒã¹ãã©ãªã¢ã®éèäŒç€ŸïŒ
Group-IBãä»ã®ãã³ããŒãšäžç·ãç»ãã®ã¯ãç¬èªã®ããŒã¿ãœãŒã¹ãšç¬èªã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã§ããã¢ããªã¹ãã®å°éããŒã ã¯ãè åšã®ç¶æ³ã«åããããªãŒããŒã¡ã€ãã®èª¿æ»ãè¿ éã«å®è¡ããããšã§ãç§ãã¡ã®æåŸ ãäžåããŸãããThreat Intelligenceãã©ãããã©ãŒã ã¯ãã»ãã¥ãªãã£ã·ã¹ãã ã«ã·ãŒã ã¬ã¹ã«çµ±åãããŠããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ã¯
IPã¢ãã¬ã¹ã§ãïŒã¯ã
URLã¢ãã¬ã¹ïŒã¯ã
è åšã«ããŽãªTTPSïŒã¯ã
ãã¡ã€ã«ã®ããã·ã¥åèšïŒã¯ã
ãã¡ã€ã³ïŒã¯ã
ã¬ãžã¹ããªããŒïŒ N / A
ã«ãŒãçªå·ïŒ N / A
é»è©±çªå·ïŒ N / A
ãœãŒã·ã£ã«ãããã¯ãŒãã³ã°ã®ã€ã³ãžã±ãŒã¿ïŒã¯ã
ä¿è·ã¢ãã€ã«ã¢ããªïŒ N / A
ãã©ã³ãä¿è·ïŒã¯ã
ããŒã¿æŒæŽ©ïŒ N / A
ããŒã¿åŒ·åïŒè åšã®è©äŸ¡ãè åšã®ã¿ã°ä»ããè¿œå ããã³ãã®ä»ã®è¿œå æ å ±ïŒïŒã¯ã
察話æ¹æ³ïŒ API
ããŒã¿åœ¢åŒïŒ STIX
äŸ¡æ ŒïŒå¹Žé15äžãã«ãã
ããžã¿ã«ã·ã£ããŠãµãŒãã©ã€ã
äžèŠãªé²åºãç¹å®ããå€éšã®è åšããä¿è·ããããšã«ãããããžã¿ã«ãªã¹ã¯ãæå°éã«æããŸããããŒã¿ã®æ倱ãæ€åºãããªã³ã©ã€ã³ãã©ã³ããä¿è·ããæ»æé¢ãæžãããŸãã
Digital Shadowsã¯ãã€ã³ã¿ãŒãããããã³ããŒã¯Webäžã®æãå¹ åºãããŒã¿ãœãŒã¹ã«ããã£ãŠãçµç¹ã®ããžã¿ã«ãªã¹ã¯ã远跡ããã³ç®¡çããããã®ãœãªã¥ãŒã·ã§ã³ã®äžççã«æåãªãããã€ããŒã§ãã
å瀟ã®äž»å補åã§ããDigitalShadows SearchLightã¯ãæ¥çã§æãå æ¬çãªããŒã¿åæãšäž»èŠãªã»ãã¥ãªãã£å°é家ãçµã¿åããããã®ã§ãã SearchLightã¯ããªãŒãã³ãœãŒã¹ããœãŒã·ã£ã«ãããã¯ãŒã¯ããã®è åšã«é¢ããæ å ±ãæäŸããŸãããŠãŒã¶ãŒã¯ãRESTful APIãé»åã¡ãŒã«éç¥ããªã¯ãšã¹ããããã³æ¯é±ã®ã€ã³ããªãžã§ã³ã¹ãµããªãŒãéããŠãã®æ å ±ã«ã¢ã¯ã»ã¹ã§ããŸãã
æœåšçãªå±å®³ãç¹å®ããããã«ããã®ãœãªã¥ãŒã·ã§ã³ã¯ããŒã¯ãŠã§ãã«å®å šã«æ²¡é ããŸããããã¯ãããŒã¯ãŠã§ãã§è²©å£²ãããŠããäŒæ¥ã®æ©å¯ããŒã¿ã補åããã®ä»ã®è³ç£ã®çºèŠã§ãã䜿çšããã調æ»ããã³åæããŒã«ã¯ãè³ç£ãšããŒã¿ãä¿è·ããããã«å¿ èŠãªåæãæäŸããŸãã
䟵害ãããåŸæ¥å¡ã®è³æ Œæ å ±ãšãããã¯ãŒã¯ã®æãç©Žãæ€åºããç¹èš±æè¡ãšåæããŒã«ã䜿çšãããšããªãŒã¯ããã¡ã€ã³ã¹ããŒãã£ã³ã°ãããã³äŸµå®³ãããé»åã¡ãŒã«ãå³åº§ã«èŠã€ããããšãã§ããŸãã
SearchLightã®ã¯ã©ãŠãããŒã¹ã®ãšã³ã·ã¹ãã ã«ãããä»ã®SIEMãã©ãããã©ãŒã ãšçµ±åããŠãå æ¬çãªã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ãäœæã§ããŸãã
補åã¬ãã¥ãŒã Norm LaudermilchãSophosã®CISOïŒ
Digital Shadows , . , , , Sophos.
ã€ã³ã¿ãŒãã§ã€ã¹ã¯
IPã¢ãã¬ã¹ã§ãïŒã¯ã
URLã¢ãã¬ã¹ïŒã¯ã
è åšã«ããŽãªTTPSïŒã¯ã
ãã¡ã€ã«ã®ããã·ã¥åèšïŒã¯ã
ãã¡ã€ã³ïŒã¯ã
ã¬ãžã¹ããªããŒïŒã¯ã
ã«ãŒã以å€ïŒã¯ã
é»è©±ïŒã¯ã
ãœãŒã·ã£ã«ãããã¯ãŒãã³ã°ã®ã€ã³ãžã±ãŒã¿ïŒã¯ã
ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®
ä¿è·ïŒã¯ããã©ã³ãä¿è·ïŒã¯ã
ããŒã¿æŒæŽ©ïŒã¯ã
ããŒã¿åŒ·åïŒè åšã®è©äŸ¡ãè åšã®ã¿ã°ä»ããè¿œå ããã³ãã®ä»ã®è¿œå æ å ±ïŒïŒã¯ã
çžäºäœçšæ¹æ³ïŒ API
ããŒã¿åœ¢åŒïŒ JSONãXMLãSTIXãCSV
äŸ¡æ ŒïŒæé¡5600ãã«ãã
RiskIQã€ã«ãããŒã·ã§ã³
RiskIQãã©ãããã©ãŒã ã¯ããšã¯ã¹ããã€ããæ»æã®å¯èŠæ§ãç解ãããã³å¶åŸ¡ãæäŸããå€éšã®è åšã®æ€åºãèªååããŠãæšçåæ»æããä¿è·ããŸãã
RiskIQã¯ããããã¯ãŒã¯äžã®çµç¹ã®ããžã¿ã«ãã¬ãŒã³ã¹ã«é¢é£ããè åšã®å®å šãªæ€åºãã€ã³ããªãžã§ã³ã¹ãããã³ä¿®åŸ©ãæäŸããããžã¿ã«è åšç®¡çã®ãã1ã€ã®ãªãŒããŒã§ããéå»10幎éã®RiskIQã®ããžã§ã³ãšäœ¿åœã¯ãã€ã³ã¿ãŒãããã€ã³ãã©ã¹ãã©ã¯ãã£å ã®é¡§å®¢ã®ããžã¿ã«ãããããªã³ãããã£ããã£ãçžé¢ãåæããããšã§ããã RiskIQã®ãœãªã¥ãŒã·ã§ã³ã䜿çšãããšãã€ã³ã¿ãŒãããããœãŒã·ã£ã«ãããã¯ãŒã¯ãã¢ãã€ã«ããã€ã¹ã«é¢é£ããè åšãçµ±äžçã«è¡šç€ºããã³å¶åŸ¡ã§ããŸãã
RiskIQ Illuminateãã©ãããã©ãŒã ã¯ãäœåãã®ã»ãã¥ãªãã£ã¢ããªã¹ããã»ãã¥ãªãã£ããŒã ãããã³CISOããä¿¡é ŒãããŠããŸãããããã³ã°ã®æé©ãªèªèãšèªååãã€ã³ã¿ãŒãããæ»æã«ãããããè¡šé¢ã®ç£èŠãæ»æã®åœ±é¿ã®è»œæžãå€éšã®è åšã®èª¿æ»ã®å éã®ããã«ãæãå¹ åºãããŒã¿ã»ããã«åºã¥ããŠæ§ç¯ãããŠããŸãã
ãã®ãã©ãããã©ãŒã ã¯ãã€ã³ã¿ãŒãããæ»æã«é¢ãã10幎ã®çµéšã«æ¯ããããŠãããããŒã¯Webãããããã¯ãŒã¯ã®è¡šå±€ãããã«ã¯ç©ççãªäžçãŸã§ããã¹ãŠã®è åšã枬å®ããŸãã Illuminateã¯ãå®çšçãªã¢ã©ãŒãããªã¢ã«ã¿ã€ã ã§ååŸããããã«å¿ èŠãªåæãçæããŸãã
補åã¬ãã¥ãŒã PBB IT Security StandardBankã®ã»ãã¥ãªãã£è²¬ä»»è ã§ããRobinBarnwellïŒ
, RiskIQ, , .
IPã¢ãã¬ã¹ã€ã³ã¿ãŒãã§ã€ã¹ïŒã¯ã
URLïŒã¯ã
è åšã«ããŽãªTTPïŒ N / A
ãã¡ã€ã«ããã·ã¥ïŒã¯ã
ãã¡ã€ã³ïŒã¯ã
ã«ãŒãçªå·ïŒã¯ã
é»è©±çªå·ïŒ N / A
ãœãŒã·ã£ã«ãããã¯ãŒã¯ããã®ã€ã³ãžã±ãŒã¿ãŒïŒã¯ã
ã¢ãã€ã«ã¢ããª
ä¿è·ïŒã¯ããã©ã³ãä¿è·ïŒã¯ã
ããŒã¿æŒæŽ©ïŒã¯ã
ããŒã¿åŒ·åïŒè åšè©äŸ¡ãè åšã¿ã°ä»ããè¿œå ããã³ãã®ä»ã®è¿œå æ å ±ïŒïŒã¯ã
çžäºäœçšæ¹æ³ïŒ API
ããŒã¿åœ¢åŒïŒ JSONãXMLãSTIXãCSV
äŸ¡æ ŒïŒ N / A
äœæè ïŒNatalka CechãROI4CIO