è åšã«é¢ããæ å ±ãåæããããã®ãã©ãããã©ãŒã ãã©ã®ããã«æ©èœãããã®åéã®é«åºŠãªãœãããŠã§ã¢ã«ãã£ãŠã©ã®ãããªæ©èœãæäŸãããããROI4CIOåæè¡šã«åºã¥ã補åã®æ¯èŒã
Advanced ThreatïŒAPTïŒã®æ°ã®ç°åžžãªå¢å ãšãæ»æãæ€åºããããã«åŠçããå¿ èŠã®ããããŒã¿ã®éã®å¢å ã«ãããã»ãã¥ãªãã£ã¢ããªã¹ãã®äœæ¥ã¯æ¥ã å°é£ã«ãªã£ãŠããŸããè¿å¹Žãæ å ±ã»ãã¥ãªãã£ãšã³ãžãã¢ã®ä»äºã¯ãå®éã®è åšãèŠã€ããããã«ãäœçŸãã®ã¢ã©ãŒããæåã§ãµããã«ãããããšã§ãããçµç¹ãçæããããŒã¿ã»ããã®ãããæåã®è åšæ€çŽ¢ããŒã ã¯ãã¯ã广çã§ã¯ãããŸããããã®åé¡ã«å¯ŸåŠããããã«ãªãœãŒã¹ãšãœãããŠã§ã¢ã䜿çšãããŸãããå€ãã®å Žåãçµç¹ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®çµ±åã«ãã£ãŠæ°ããããŒã«ã®å°å ¥ã劚ããããŸãã
Threat Intelligence Platformã¯ãåºæ¬çãªè åšã€ã³ããªãžã§ã³ã¹ã§ãããã£ãŒããèªååããŠã³ã³ããã¹ãã远å ããŸãããã£ãŒãã¯ãæœåšçãªè åšãç¹å®ããäŸµå®³ã®ææšãå«ãããŒã¿ã®ã¹ããªãŒã ã§ããæªæã®ãããã¡ã€ã«ãIPã¢ãã¬ã¹ãããã³ç¯çœªè¡çºã«é¢é£ãããã¡ã€ã³ã®ããã·ã¥ã§ããããã»ã¹ã®èªååã«ãããéè² è·ã®åŽååãè§£æŸãããè åšã«è¿ éãã€æ£ç¢ºã«å¯Ÿå¿ããããã®æ£ç¢ºãªãªã¢ã«ã¿ã€ã åæããŒã«ãæäŸãããŸãã
è åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ã¯ãçŸåšããã³æ°ãã«çºçããITã»ãã¥ãªãã£ã®è åšã«ã€ããŠãå éšããã³å€éšã®äž¡æ¹ã§å©çšå¯èœãªããŒã¿ã®éã®ããã«åºçŸããŸãããã¢ã³ããŠã€ã«ã¹è£œåã®æŽæ°ãªã©ã®è åšãç£èŠããäŒæ¥ã¯ãäœçŸäžãã®ã¯ã©ã€ã¢ã³ãã³ã³ãã¥ãŒã¿ãŒããã®ä»ã®ããã€ã¹ã§å®è¡ããããœãããŠã§ã¢ãšãŒãžã§ã³ãã§æ§æãããã°ããŒãã«è åšããŒã¿ããŒã¹ãäœå¹Žã«ãããã£ãŠç¶æããŠããŸããããã®ããŒã¿ã¯ãä»ã®ãœãŒã¹ããã®ãã£ãŒããšãšãã«ããã©ãããã©ãŒã ããŒã«ãæ§æããŸãã
è åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ãšã¯äœã§ããïŒ
è åšåæãã©ãããã©ãŒã ïŒThreat Intelligence PlatformãTIPïŒ-æ å ±ã»ãã¥ãªãã£ã«å¯Ÿããè åšã®æ€åºããããã¯ãããã³åé€ã®ããã«çµç¹ã䜿çšãããœãããŠã§ã¢ãœãªã¥ãŒã·ã§ã³ããã®ãã©ãããã©ãŒã ã¯ãè€æ°ã®è åšã€ã³ããªãžã§ã³ã¹ãã£ãã«ãçµã¿åããã以åã®ã€ãã³ããšæ¯èŒããã»ãã¥ãªãã£ããŒã ã«ã¢ã©ãŒããçæããŸãããã³ãã¯ãæ¢åã®ã»ãã¥ãªãã£æ å ±ããã³ã€ãã³ã管çïŒSIEMïŒãœãªã¥ãŒã·ã§ã³ãšçµ±åãããã¢ã©ãŒãã«å€ãå²ãåœãŠãç·æ¥åºŠã«å¿ããŠåªå é äœãä»ããŸãã
ãã®ãã©ãããã©ãŒã ã®å©ç¹ã¯ãæ å ±ã»ãã¥ãªãã£ããŒã ãããšã³ã¿ãŒãã©ã€ãºãµã€ããŒã»ãã¥ãªãã£ã«é¢ããæ å ±ãä»ã®éšéãå€éšã®ã»ãã¥ãªãã£å°éå®¶ãšå®å šã«å ±æã§ããããšã§ããã·ã¹ãã ã¯è åšããŒã¿ãåéããã³åæããå©å®³é¢ä¿è ã®æŠè¡ãšè¡åã調æŽããŸããã»ãã¥ãªãã£ããŒã ãè åšãæ€åºãããšãé¢é£ãããã¹ãŠã®éšéã調æ»ã«é¢äžããŸããã¢ã¯ã·ã§ã³ãåæããäœæ¥ã管çãããã®æ©èœã®ãããã§ããã©ãããã©ãŒã ã¯éèŠãªç¬éã«äžå¯æ¬ ã§ãã
ãªããã©ãããã©ãŒã ãå¿ èŠãªã®ã§ããïŒ
ããã«ãŒãå³åº§ã«å±å®³ãå ããæ ç»ãšã¯ç°ãªãã人çã§ã¯ãããã«ãŒã¯ãããã¯ãŒã¯äžã«é·æéé ããããšããããŸãããã®ç¹ã§ãã»ãã¥ãªãã£ã¯ãæ»æã®çµæãæé€ããã®ã§ã¯ãªããæå®³ãäžããåã«è åšãèŠã€ããŠæé€ããããã«ãä¿è·ãšå¯Ÿå¿ããäºé²æªçœ®ã«çŠç¹ãç§»ããŠããŸãããã©ãããã©ãŒã ãå®è¡ããã¿ã¹ã¯ã«ã€ããŠèããŠã¿ãŸãããã
æ¥åžžæ¥åã®èªååãšæéã®è§£æŸ
ITã»ãã¥ãªãã£æ åœè ã«å¯Ÿããæè¿ã®PonemonInstituteã®èª¿æ»ã«ãããšãåçè ã®84ïŒ ããè åšã€ã³ããªãžã§ã³ã¹ã¯åŒ·åãªã»ãã¥ãªãã£ã·ã¹ãã ã®äžæ žéšåã§ããå¿ èŠããããšèããŠããŸããåŸæ¥ã®ISã¹ããŒã ã«ããã°ãããŒã ã¯ã¢ã©ãŒã ãç¹°ãè¿ãæ€çŽ¢ããŠãå®éã®è åšãšèª€ã£ãã¢ã©ãŒã ãåºå¥ããŸããåæã«ããã©ãããã©ãŒã ã¯ãè åšã®ã¿ã€ããšé倧床ãå€å¥ããããã®ãã§ã«è±å¯ãªæ å ±ãããŒã ã«æäŸãã誀ã£ãã¢ã©ãŒããèªåçã«ç Žæ£ããŸãã
è åšã€ã³ããªãžã§ã³ã¹ã®ç²ŸåºŠã®åäž
人ã ãç¹°ãè¿ãã®æ¥åžžçãªã¿ã¹ã¯ãããŸãè¡ããªãçç±ã®1ã€ã¯ãããæç¹ã§ç®ããŒãããæçµçã«ã¯åŠçãšã©ãŒãçºçããããšã§ãããã©ãããã©ãŒã ã¯ããã®ãããªãšã©ãŒã®å¯èœæ§ãæé€ããŸãã
èªåã®è匱æ§ãèŠã€ãã
å€ãã®å Žåãã»ãã¥ãªãã£ããŒã ã¯ãå éšã®è åšãããå€éšã®è åšã«é¢å¿ãæã£ãŠããŸãã TIPã¯è匱æ§ãã¹ãã£ã³ããITã€ã³ãã©ã¹ãã©ã¯ãã£ãšãµãŒãããŒãã£ãšã³ã·ã¹ãã ã®åŒ±ç¹ãèŠåããŸããããã«ããã匱ç¹ã«ç©æ¥µçã«å¯ŸåŠããã·ã¹ãã ã匷åã§ããŸãã
ããŒã¿åŠçã®é«éå
æåã®ããŒã¿åŠçããã»ã¹ã¯ãæéãšæéãããããŸããããã¯ãçªç Žå£ãå°ã蟌ããããã«å³åº§ã®åå¿ãå¿ èŠãªæ»æã®éã®æ±ºå®çãªèŠå ã«ãªããŸãã
è åšãžã®äžè²«ãã察å¿ã®ç¢ºä¿
èªååããããã©ãããã©ãŒã ã¯ã瀟å ã®ãµã€ããŒé²åŸ¡ããã»ã¹ã«é¢äžãããã¹ãŠã®äººã«é¢é£ããã»ãã¥ãªãã£æ å ±ãæäŸããŸããããã¯ãããŒã å šäœãå¿ èŠãªæ å ±ãåæã«åãåãããšãæå³ããæŠç¥ãšã»ãã¥ãªãã£ããã»ã¹ã調æŽãããŸãã
åäœåç
è åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ã¯ã次ã®3ã€ã®äž»èŠãªæ©èœãæãããŸãã
- éçŽã¯ãè åšã«é¢ããæ å ±ãäžå åããããã£ãŒãã«éããããã£ãã«ã®ã³ã¬ã¯ã·ã§ã³ã§ãã
- åæ-ã»ãã¥ãªãã£ã®è åšãç¹å®ããã³ç¹å®ããããã®ææšã䜿çšããããŒã¿åŠçã
- ã¢ã¯ã·ã§ã³-è åšããŒã¿ã«ã€ããŠã€ã³ã·ãã³ã察å¿ããŒã ã«éç¥ããŸãã
ãããã®æ©èœã¯ãã»ãã¥ãªãã£ã·ã¹ãã ã®ã©ã€ããµã€ã¯ã«å šäœã®ã¯ãŒã¯ãããŒã®èªååãéããŠãã©ãããã©ãŒã ã«ãã£ãŠå®è£ ãããŸããè åšã€ã³ããªãžã§ã³ã¹ã»ãã¥ãªãã£ã®ã©ã€ããµã€ã¯ã«ã«é¢é£ããæ®µéïŒ
åé
STIXãXMLãJSONãOpenIOCãå«ãè€æ°ã®ãã£ãã«ããã®èŠçŽããŒã¿ããŠã§ããã°ãªã©ã®å éšãœãŒã¹ãããã³ã€ã³ã¿ãŒããããããŒã¯ãŠã§ããªã©ã®å€éšãœãŒã¹ããã®ããŒã¿ãå«ããããšãéèŠã§ãããã£ãŒããæ·±ããŠè¯ãã»ã©ããã©ãããã©ãŒã ã¯ãã广çã§ãã
çžé¢
èªååãããTIPããã»ã¹ã¯ãã¿ã°ã¡ã¿ããŒã¿ã䜿çšããŠããŒã¿ãäžŠã¹æ¿ããŠæŽçããç¡é¢ä¿ãŸãã¯åé·ãªæ å ±ãåé€ããŸããæ¬¡ã«ãç£èŠå¯Ÿè±¡ã®æ å ±ãšã®æ¯èŒãè¡ãããè åšãæ€åºããããã®ãã¿ãŒã³ãšå¯Ÿå¿ãèŠã€ãããŸãã
ã³ã³ããã¹ãå
ã³ã³ããã¹ãã¯ãè åšã€ã³ããªãžã§ã³ã¹ã®éèŠãªãã©ã¡ãŒã¿ã§ããããããªããšãç°åžžãšè åšãæ··åããããããã®éãåæ§ã§ãå®éã®è åšãç¡èŠããããšãã§ããŸãããã®æç¹ã§ãTIPã¯ãœãŒããããããŒã¿ã«ã³ã³ããã¹ããæäŸãã仿§ïŒIPã¢ãã¬ã¹ããããã¯ãŒã¯ããã¡ã€ã³ãããã¯ãªã¹ãïŒã远å ããŠèª€æ€ç¥ãæé€ããæœåšçãªè åšã«ã€ããŠå¯èœãªéãå€ãã®æ å ±ãããŒã ã«æäŸããŸãã
è åšåæ
TIPã¯ãããŒã¿ã®é¢ä¿ã«ã€ããŠè åšææšããªã¢ã«ã¿ã€ã ã§åæããŸããããã«ããã®æ å ±ã¯ãã»ãã¥ãªãã£ã¢ããªã¹ããé ããè åšãèŠã€ããããã«ããæµéããããããšãã§ããŸãã
çµ±å
è åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ã¯ãæ å ±ã®æµããæå€§åããããã«çµç¹ã䜿çšããã»ãã¥ãªãã£ããŒã«ãšçµ±åãããŠããŸãããã®æ®µéã§ããã©ãããã©ãŒã ã¯åéããã³åæãããããŒã¿ãé©åãªéšéã«è»¢éããŠåŠçããŸãã
ãã©ãããã©ãŒã ãè åšãæ€åºãããšãã€ã³ã·ãã³ã察å¿ãéå§ããå¿ èŠããããšããèŠåãæ å ±ã»ãã¥ãªãã£ã°ã«ãŒãã«éä¿¡ãããŸãã
ã¢ã¯ã·ã§ã³
广çãªè åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ã¯å¿çæ§ããããŸããçµ±åTIPã¯ãæ å ±ã¯ãªã¢ããã³åæã»ã³ã¿ãŒïŒISACïŒããã³æ å ±äº€æããã³åæçµç¹ïŒISAOïŒãšææºããŠãã»ãã¥ãªãã£ããŒã«ããã³ã¢ããªã±ãŒã·ã§ã³ã®éçºã«å¿ èŠãªæ å ±ãæäŸããŸãã
ãã³ããŒé ä¿¡ã¢ãã«
è åšã€ã³ããªãžã§ã³ã¹ãµãŒãã¹ãããã€ããŒã¯ã»ãã¥ãªãã£åéã§ã¯æ¯èŒçæ°ãããããæäŸããããµãŒãã¹ã®çš®é¡ã¯äŸç¶ãšããŠå€§ããç°ãªããŸãã
ãããã®ãµãŒãã¹ã®äžéšã¯ã誀æ€ç¥ãé€å»ããããã£ãŒãã®ã¿ãæäŸããŸããæãäžè¬çãªææãµãŒãã¹ã¯ãéçŽããã³çžé¢ãã£ãŒãïŒ2ã€ä»¥äžïŒãã«ã¹ã¿ã ã¢ã©ãŒããããã³é¡§å®¢ã®ãªã¹ã¯ç¶æ³ã«åºæã®ã¢ã©ãŒããæäŸããŸãã
å¥ã®ã¿ã€ãã®è åšã€ã³ããªãžã§ã³ã¹ãµãŒãã¹ã¯ãããŒã¿ãéçŽããŠçžäºã«é¢é£ä»ããæ å ±ãã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ïŒãã¡ã€ã¢ãŠã©ãŒã«ãã»ãã¥ãªãã£æ å ±ãšã€ãã³ã管çãæ¥çã®è åšè©äŸ¡ãã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°ïŒã«èªåçã«çµã¿èŸŒã¿ãŸãã
åã¿ã€ãã®è åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ã¯ããµãã¹ã¯ãªãã·ã§ã³ãšããŠãéåžžã¯2ã€ãŸãã¯3ã€ã®äŸ¡æ Œåž¯ã§å©çšã§ããã¯ã©ãŠãçµç±ã§ããŸãã¯ãŸãã«ãªã³ãã¬ãã¹ãŸãã¯ãã€ããªããçµç±ã§é ä¿¡ãããŸãã
ãã®ãããªãã©ãããã©ãŒã ã®ã³ã¹ããé«ãããšãããã³ããŒã«ã«å±éçšã®æ©åšãå¿ èŠãªããšãããçŸåšããã®ãããªãµãŒãã¹ã¯å€§èŠæš¡ãªçµç¹ãäŒæ¥ã察象ãšããŠããŸãããã ããã¯ã©ãŠããµãŒãã¹ãããäœãåžå Žã»ã°ã¡ã³ãã«æ¡å€§ããã«ã€ããŠãè åšã€ã³ããªãžã§ã³ã¹ããŒã«ãããã¢ã¯ã»ã¹ãããããªããŸãã
ãã©ãããã©ãŒã ã®ã³ã¹ãã¯ãè åšã€ã³ããªãžã§ã³ã¹ãµãŒãã¹èªäœã®ã³ã¹ããšåããããç°ãªããŸããããŒã¿ãªã³ã¯ã ãã§ãæã«æ°åãã«ã®è²»çšããããå¯èœæ§ããããŸãããé¢é£ããè²»çšã«ã¯ãæè¡è ãã¢ããªã¹ããåžžé§ãã24æé幎äžç¡äŒã®ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒãç¶æããããã®è²»çšãå«ãŸããŸããããã«æ¯ã¹ãŠããããŒãžãã»ãã¥ãªãã£ãµãŒãã¹ã¯éåžžãæã«æ°äžãã«ã®è²»çšãããããŸããæãå®äŸ¡ãªãµãŒãã¹ã¯ãã¯ã©ã€ã¢ã³ãã®åŽã§ããå€ãã®äººçæéãšåŽåãå¿ èŠãšããŸãã
è åšã€ã³ããªãžã§ã³ã¹ãµãŒãã¹ã¯äºãã«å€§ããç°ãªããããæ å ±ãã©ã®ããã«äœ¿çšãããããçè§£ãããã®ãµãŒãã¹ãé©åã«äœ¿çšããããã«å¿ èŠãªäººå¡ãé 眮ããããšããéžæã®å€§ããªèª²é¡ã«ãªããŸãã
次ã®ç¹æ§ã«åºã¥ããŠã 6ã€ã®ROI4CIOè åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ãæ¯èŒããŸããã
- ç¬èªã®é£ŒæäŸçµŠæ¥è ãŸãã¯é£ŒæååŠçåæã»ã³ã¿ãŒã
- ç®±ããåºããŠããã«äœ¿ãã飌æäŸçµŠæ¥è ã®æ°ããã£ãŒããåãåãããã®ãµããŒããããŠããæ¹æ³ã
- å€éšãœãŒã¹ïŒããšãã°ãWHOisãPassiveDNSãVirusTotalãªã©ïŒããã®ããŒã¿ã匷åããå¯èœæ§ã
- SIEMã€ãã³ãã§äžèŽãããã®ãæ€çŽ¢ããŸãã
- ãµãŒãããŒãã£ã®æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ãšçµ±åããããšã«ãããã€ã³ã·ãã³ãã«çŽæ¥å¯Ÿå¿ããŸãã
- è€éãªã¢ã«ãŽãªãºã ïŒãã¬ã€ããã¯ïŒã䜿çšããã€ã³ã·ãã³ã察å¿ã
- RESTAPIãä»ããŠçµ±åããæ©èœã
- ãã£ãŒããªããžã§ã¯ããšå éšã¢ãŒãã£ãã¡ã¯ãéã®ãªã³ã¯ã®ã°ã©ããäœæããæ©èœã
ThreatQuotinetã«ããThreatQ
ThreatQã¯ãã»ãã¥ãªãã£ãåäžãããè åšã®è»œæžãšç®¡çãæåãããããã«å¿ èŠãªã³ã³ããã¹ããšé«åºŠãªã«ã¹ã¿ãã€ãºãã»ãã¥ãªãã£ããŒã ã«æäŸããããªãŒãã³ã§æ¡åŒµå¯èœãªè åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ã§ãã
2013幎ã«èšç«ãããããžã¿ã«ã»ãã¥ãªãã£äŒç€Ÿã§ããThreatQuotientã®è£œåã¯ãè åšã«åªå é äœãä»ããããã»ã¹ãèªååããŠãéããããªãœãŒã¹ãæå€§éã«æŽ»çšããªããæææ±ºå®ããµããŒãããŸããå瀟ã¯ãã€ã³ã·ãã³ã察å¿ãè åšãã³ãã£ã³ã°ããã£ãã·ã³ã°å¯Ÿçãã¢ã©ãŒããœãŒããããã³è匱æ§ç®¡çãå°éãšããŠããŸãã
ThreatQãã©ãããã©ãŒã ã¯ãThreatQuotientã®äž»åãœãªã¥ãŒã·ã§ã³ã§ãããã®ãã©ãããã©ãŒã ã¯ãSOCã¢ããªã¹ããã€ã³ã·ãã³ã察å¿ã¹ãã·ã£ãªã¹ããããã³ã¢ããªã¹ãã«ãã³ã³ããã¹ããæäŸããããŒã¿ãææ°ã®ç¶æ ã«ä¿ã€ããšã«ãããæè»æ§ãå¯èŠæ§ãããã³å¶åŸ¡ãæäŸããŸãã
ä»çµã¿
SolutionThreat Libraryã¯ãç¬èªã®ããžãã¹ç°å¢ã«åãããŠã«ã¹ã¿ãã€ãºãããææ°ã®ã³ã³ããã¹ãæ å ±ã®ããã®å éšè åšããã³ã€ãã³ãããŒã¿ã§åŒ·åããã³åŒ·åããããå€éšè åšã€ã³ããªãžã§ã³ã¹ã®äžå€®ãªããžããªã§ãã
çµ±åãããThreatLibraryãAdaptive WorkbenchãOpen ExchangeãThreatQInvestigationsã䜿çšãããšãè åšã¢ããªã¹ãã¯ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒãããè¿ éã«æ€åºã調æ»ãããã³è¡åã§ããŸãã
ThreatQã¯ãæ¢åã®ããã»ã¹ããã³ãã¯ãããžãŒãšé£æºããŠãæ¢åã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å¹çãåäžãããŸãããã®ãã©ãããã©ãŒã ã«ããã顧客ã¯ã»ãã¥ãªãã£ãªãœãŒã¹ã«ã€ããŠããå€ãã®æŽå¯ãåŸãããšãã§ããŸãã Open Exchange ThreatQã©ã€ãã©ãªã¯ãã«ã¹ã¿ãã€ãºãããŒã«ãã³ãã³ããããã³ã¯ãŒã¯ãããŒã®çµ±åã®ããã®æ¥çæšæºã®ã€ã³ã¿ãŒãã§ã€ã¹ãšSDK / APIã䜿çšããŠãæ¢åã®ã»ãã¥ãªãã£æè³ã«äŸ¡å€ãä»å ããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ã®
ç¹æ§
ãã£ãŒãååŠççšã®ç¬èªã®ãã£ãŒããµãã©ã€ã€/åæã»ã³ã¿ãŒïŒçŸåš
ããã«äœ¿çšã§ãããã£ãŒããµãã©ã€ã€ã®æ°ïŒ 100以äž
ãµããŒããããŠãããã£ãŒãåä¿¡æ¹æ³ïŒ CSVãJSON
å€éšãœãŒã¹ïŒWHOisãPassiveDNSãVirusTotalãªã©ïŒããã®ããŒã¿ã匷åããå¯èœæ§ã ãïŒïŒpresent
SIEMã€ãã³ãã§ã®äžèŽã®æ€çŽ¢ïŒ present
ãµãŒãããŒãã£ã®æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ãšã®çµ±åã«ããã€ã³ã·ãã³ããžã®çŽæ¥å¿çïŒ present
è€éãªã¢ã«ãŽãªãºã ïŒãã¬ã€ããã¯ïŒã䜿çšããã€ã³ã·ãã³ããžã®å¿çïŒ present
REST APIãä»ããçµ±åã®
å¯èœæ§ïŒ presentãã£ãŒããªããžã§ã¯ããšå éšã¢ãŒãã£ãã¡ã¯ãéã®ãªã³ã¯ã®ã°ã©ããäœæããå¯èœæ§ïŒçŸåš
Anomaliã«ããThreatStream
Anomaliã¯ãSIEMããã³ãã®ä»ã®ãã°ãœãŒã¹ãšçµ±åããããã°ãéè€ããããšãªãå±¥æŽã®å¯èŠæ§ãç¶æããŸããéåã®å åãç¹å®ããããã«ãå±¥æŽããŒã¿ãåžžã«åæãããæ°èŠããã³æ¢åã®è åšããŒã¿ãšæ¯èŒãããŸãã
Anomali ThreatStreamã¯ãä»®æ³ãã·ã³ãšããŠããŒã«ã«ã«å±éããããšãã§ããSaaSè åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ã§ãããã®ããŒã«ã«ã¯140ãè¶ ãããªãŒãã³ãœãŒã¹ãã£ãã«ãå«ãŸããŠãããAnomali APPStoreãéããŠåçšãã£ãã«ãç°¡åã«çµã¿èŸŒãããšãã§ããŸãã
ThreatStreamãã©ãããã©ãŒã ã®éèŠãªæ©èœã¯ã調æ»ããã·ã¥ããŒãã§ããããã¯ãé¢å¿ã®ããè åšã«æ²¡é ããããã«äœ¿çšãããŸããããã§ã¯ãå¿ èŠãªç£èŠå¯Ÿè±¡ã远å ãããšãã«ãæ°ãã調æ»ãç°¡åã«äœæã§ããŸãããããããŠãŒã¶ãŒãŸãã¯ã¯ãŒã¯ã°ã«ãŒãã«å²ãåœãŠãå¿ èŠã«å¿ããŠãThreatStreamãšServiceNowã®çµ±åã䜿çšããŠãã±ãããå²ãåœãŠãŸãã
äœæ¥ã®ã¹ããŒã
ThreatStreamã«ã¯ããã¡ã€ã«ã®ã¢ããããŒããšåæãå¯èœã«ããçµã¿èŸŒã¿ã®ãµã³ãããã¯ã¹ãå«ãŸããŠããŸããã€ã³ããªãžã§ã³ã¹ã¬ããŒããŸãã¯IoCãªã¹ããã€ã³ããŒãããããšãã§ããŸãããã®è£œåã¯ãå€ãã®äžè¬çãªSIEMãšçµ±åãããç ç©¶ã¿ã¹ã¯ãå²ãåœãŠãããã®ã±ãŒã¹ç®¡çæ©èœãã¢ããªã¹ãã®ã¯ãŒã¯ãããŒã®ãµããŒããå«ã¿ãä¿¡é Œã§ããããŒãããŒãšã®ã³ã©ãã¬ãŒã·ã§ã³ãå¯èœã«ããŸãã ThreatStream Linkã䜿çšãããšãäŒæ¥å ã®ããã€ã¹ãšããŒã¿ãçŽæ¥äº€æã§ããŸãã
ç¬èªã®ç£èŠã€ã³ãžã±ãŒã¿ã«å ããŠããã©ãããã©ãŒã ã¯ãã£ãŒããåãåããç¬èªã®ãœãŒã¹ããã®æ å ±ã§ãã£ãŒãã匷åããæ å ±ãèŠèŠåããçè§£ãæ·±ããããã«æ§æèŠçŽ ã«åè§£ããŸãã
調æ»ã¬ããŒãã¯ãSTIXãKill ChainããŸãã¯Diamond圢åŒã§çºè¡ãããŸãããã©ãããã©ãŒã ã¯Splunkãšçµ±åããã远å ã®äŸ¿å©ãªããŒã«ãæäŸããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ã®
ç¹æ§
ç¬èªã®ãã£ãŒããµãã©ã€ã€/ãã£ãŒãååŠçåæã»ã³ã¿ãŒïŒçŸåš
ããã«äœ¿çšã§ãããã£ãŒããµãã©ã€ã€ã®æ°ïŒ 100以äž
ãµããŒããããŠãããã£ãŒãåä¿¡æ¹æ³ïŒ CSVãJSONãHTTP
å€éšãœãŒã¹ããã®ããŒã¿ã匷åããå¯èœæ§ïŒäŸïŒWHOisãPassiveDNSãVirusTotalãã®ä»ïŒïŒçŸåš
SIEMã€ãã³ãã§è©Šåãæ€çŽ¢ïŒçŸåš
ãµãŒãããŒãã£ã®æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ãšã®çµ±åã«ãããäºä»¶ãžã®çŽæ¥ã®å¿çïŒååš
è€éãªã¢ã«ãŽãªãºã ïŒãã¬ã€ããã¯ïŒã䜿çšããã€ã³ã·ãã³ããžã®å¯Ÿå¿ïŒ N / A
REST APIçµ±åã®
å¯èœæ§ïŒååšãã£ãŒããªããžã§ã¯ããšå éšã¢ãŒãã£ãã¡ã¯ãã®ãªã³ã¯ã®ã°ã©ããäœæããå¯èœæ§ïŒååš
EclecticIQãã©ãããã©ãŒã
EclecticIQã¯ãã¢ããªã¹ãããã·ã³ã®é床ã§ã€ã³ããªãžã§ã³ã¹ãåºããªãããããéããããè¯ããããæ·±ã調æ»ã宿œã§ããããã«ãããã©ãããã©ãŒã ã§ãã
EclecticIQãã©ãããã©ãŒã ã¯ããªãŒãã³ãœãŒã¹ãæ¥çããŒãããŒãããã³å éšãªãœãŒã¹ããã®æ§é åããã³éæ§é åè åšããŒã¿ã®äž¡æ¹ãåŠçãããããã1ã€ã®ããã·ã¥ããŒãã«çµåããŸãããã©ãããã©ãŒã ã¯ãã¯ã©ãŠããšãªã³ãã¬ãã¹ã®äž¡æ¹ã«å±éã§ããŸãã
EclecticIQã¯ããŒã¿åéæ¹æ³ã䜿çšããŸããã代ããã«ãå瀟ã¯ãè åšãç¶ç¶çã«èª¿æ»ããŠæ§é åããã圢åŒã§ãã¹ãŠã®ã€ã³ããªãžã§ã³ã¹ãåéããå®çšçãªãœãªã¥ãŒã·ã§ã³ãåããå æ¬çãªæŠèŠãæäŸããã¢ããªã¹ãã®ããŒã ãæ¡çšããŠããŸãã
äœæ¥ã®ã¹ããŒã
ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãæ¶è²»è ãšçç£ã®äž¡æ¹ã®ãã©ãããã©ãŒã ã§ããããã§ãã¢ããªã¹ãã¯åã ã®ã€ã³ã·ãã³ãã®ã¯ãŒã¯ã¹ããŒã¹ãäœæã§ããŸãããã®ã¯ãŒã¯ã¹ããŒã¹ã«ã¯ãããã«é¢é£ãããã¹ãŠã®èª¿æ»ãå«ãŸããŸããå®äºãããšãçµç¹ã¯ã¯ãŒã¯ã¹ããŒã¹ãã¢ãŒã«ã€ãããã€ã³ã·ãã³ããåçºããå Žåã«åã³ã¢ã¯ãã£ãã«ããããšãã§ããŸãã
ã»ãã¥ãªãã£ããŒã ã¯ãçŸåšç£èŠãããŠããè åšã®åºçŸã«äŒŽããã£ã¹ã«ããªã¢ã©ãŒããèšå®ã§ããŸãããŸããç¹å®ã®ãšã³ãã£ãã£ïŒãã«ãŠã§ã¢ãã¡ããªãè åšã¢ã¯ã¿ãŒãªã©ïŒããã³ãããã¢ã©ãŒãã®èšå®ãšããããã®ãšã³ãã£ãã£ã«é¢é£ããçä¿¡è åšããªã¢ã³ãã®ã·ã°ããªã³ã°ãèŠå¶ããŸãã
ã¬ããŒããã«ããŒæ©èœã¯ãEclecticIQå®çšŒåç°å¢ã瀺ããŠããŸãã圌女ã¯ç¹å®ã®ãªãã·ã§ã³ã«åºã¥ããŠã¬ããŒããäœæã§ããã¢ããªã¹ãã¯ã¬ããŒãã«æ å ±ãšã³ã³ããã¹ããç°¡åã«è¿œå ã§ããŸãããã®ãœãªã¥ãŒã·ã§ã³ã§ã¯ãTLPã䜿çšããŠããã©ãããã©ãŒã å€ãžã®æ å ±ã®æ¡æ£ãé²ããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ã®
ç¹æ§
ç¬èªã®ãã£ãŒããµãã©ã€ã€/ãã£ãŒãååŠçã·ã³ã¯ã¿ã³ã¯ïŒçŸåš
ããã«äœ¿çšã§ãããã£ãŒããµãã©ã€ã€ã®æ°ïŒ 20-100
ãã£ãŒããåä¿¡ãããµããŒããããŠããæ¹æ³ïŒ CSVãJSONãHTTP
å€éšãœãŒã¹ããã®ããŒã¿ã匷åããå¯èœæ§ïŒäŸïŒWHOisãPassiveDNSã VirusTotalãªã©ïŒïŒ present
SIEMã€ãã³ãã§äžèŽãããã®ãæ€çŽ¢ããŸãïŒ present
ãµãŒãããŒãã£ã®æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ãšã®çµ±åã«ããã€ã³ã·ãã³ããžã®çŽæ¥å¯Ÿå¿ïŒçŸåš
è€éãªã¢ã«ãŽãªãºã ïŒãã¬ã€ããã¯ïŒã䜿çšããã€ã³ã·ãã³ããžã®å¯Ÿå¿ïŒ N / A
REST APIãä»ããçµ±åã®å¯èœæ§ïŒçŸåš
ãã£ãŒããªããžã§ã¯ããšå éšã¢ãŒãã£ãã¡ã¯ãéã®ãªã³ã¯ã®ã°ã©ããäœæããå¯èœæ§ïŒçŸåš
ThreatConnectãã©ãããã©ãŒã
ThreatConnectãã©ãããã©ãŒã ã¯ãæµã®èãæ¹ãçè§£ããã¯ãŒã¯ãããŒãèªååããã€ã³ããªãžã§ã³ã¹ã䜿çšããŠè åšã軜æžããããã«èšèšãããŠããŸãã ThreatConnectã¯ãåæèªåãã©ãããã©ãŒã äžã«æ§ç¯ãããäžé£ã®è£œåãæäŸããŸãã
ThreatConnectãã©ãããã©ãŒã ã¯ãè åšã€ã³ããªãžã§ã³ã¹ãœãŒã¹ã®éçŽãèªååããæ©èœãæäŸããããŒã¿åéã®ç ©ãããããããŒã ãè§£æŸããŸãã ThreatConnectã¯ãããŒã¿éçŽæ©èœã«åºã¥ããŠãããŸããŸãªåæããŒã«ããã³ãµãŒãã¹ãšçµ±åããŠãããŒã äœæ¥ãããã«åçåããã³èªååããŸããã¯ã©ãŠããŸãã¯ãªã³ãã¬ãã¹ãžã®å±éãå¯èœã§ããè€æ°ã®ç°å¢ã«ã·ã¹ãã ãå±éããããšããŠãã人ã®ããã®ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãªãã·ã§ã³ããããŸãã
äœæ¥ã®ã¹ããŒã
ThreatConnect ResearchGroup-æ°ããã€ã³ããªãžã§ã³ã¹ãç¶ç¶çã«æäŸããäžççã«æåãªãµã€ããŒã»ãã¥ãªãã£ã¢ããªã¹ãããã®ã°ã«ãŒãã«ã¯ãè«å ±æ©é¢ã®æ¥çæé«ã®ã¢ããªã¹ããšæãæ å ±ã«éããåæãµãŒã¯ã«ãå«ãŸããŠããŸãã圌ãã¯ã100ãè¶ ãããªãŒãã³ãœãŒã¹ããã®æ€èšŒæžã¿ã®è åšã€ã³ããªãžã§ã³ã¹ãšæ°åã®ã³ãã¥ããã£ããã®ã¯ã©ãŠããœãŒã¹ããŒã¿ãæäŸããæ å ±ãœãŒã¹ãTCIdentifyããã¥ã¬ãŒãããŸãã
ThreatConnectã䜿çšãããšãã»ãã¥ãªãã£ããŒã ã¯ç¹å®ã®ããŒãºã«åãããŠããã·ã¥ããŒããäœæããã³ã«ã¹ã¿ãã€ãºã§ããã¡ã€ã³ããã·ã¥ããŒãã§ã¯ãæè¿èгå¯ãããã¡ããªãã¯ãšãã¬ã³ããããã¯ããã°ããèŠèŠåã§ããŸãã
ãã©ãããã©ãŒã ã®ãã¬ã€ããã¯ããã«ã«ã¯ãã»ãŒãã¹ãŠã®ã¢ã¯ã·ã§ã³ã®åŠçãèªååããããã®äœçŸãã®ã¢ããªã±ãŒã·ã§ã³ãªãã·ã§ã³ãçšæãããŠããŸããã客æ§ã¯ãç¬èªã®ã¢ããªã±ãŒã·ã§ã³ãäœæããããæ¢åã®ã¢ããªã±ãŒã·ã§ã³ã倿Žãããã§ããŸãããã®ãã©ãããã©ãŒã ã¯ãã¿ã°ã䜿çšããé«åºŠãªãã£ã«ã¿ãªã³ã°ããµããŒãããŠãåäœãå°çãããã³ãã®ä»ã®ããŸããŸãªç¹æ§ã«ãã£ãŠèŠçŽ ãåé¡ããŸããã¢ããªã¹ãã¯ãã€ã³ã·ãã³ãã¬ããŒãã®è©³çްããŒãžå ã®ã³ã©ãã¬ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããŸãã
ãã©ãããã©ãŒã ã¯è€æ°ã®SIEMçµ±åãç¹ã«SplunkããµããŒãããThreatConnectãšSplunkéã®åæ¹åéä¿¡ãäœæãããããè åšæ å ±ã¯Splunkã«çŽæ¥éä¿¡ãããããŒã ã¯è åšã®æŠèŠããã®ä»ã®æ å ±ã衚瀺ã§ããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹
æ©èœ
ç¬èªã®ãã£ãŒããµãã©ã€ã€/ãã£ãŒãååŠçåæã»ã³ã¿ãŒïŒpresent
ããã«äœ¿çšã§ãããã£ãŒããããã€ããŒã®æ°ïŒ 100以äž
ãµããŒããããŠãããã£ãŒãã®åä¿¡æ¹æ³ïŒ CSVãJSONãHTTP
å€éšãœãŒã¹ïŒWHOisãPassiveDNSãVirusTotalãªã©ïŒããã®ããŒã¿ã匷åããå¯èœæ§ïŒ present
SIEMã€ãã³ãã§äžèŽãããã®ãæ€çŽ¢ïŒ present
DirectãµãŒãããŒãã£ã®æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ãšçµ±åããããšã«ããã€ã³ã·ãã³ã察å¿ïŒçŸåš
è€éãªã¢ã«ãŽãªãºã ïŒãã¬ã€ããã¯ïŒã䜿çšããã€ã³ã·ãã³ã察å¿ïŒ N / A
REST APIãä»ããçµ±åã®å¯èœæ§ïŒçŸåš
ãã£ãŒããªããžã§ã¯ããšå éšã¢ãŒãã£ãã¡ã¯ãéã®ãªã³ã¯ã®ã°ã©ããäœæããå¯èœæ§ïŒçŸåš
R-Visionã«ããè åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã
R-Vision TIPã¯ãç¡æããã³åçšã®äž¡æ¹ã®äº€æãã£ãã«ããã®äŸµå®³ã®ææšã®åéãèªååããããããåŠçããæ å ±ãå å®ãããè åšã®ã¿ã€ã ãªãŒãªæ€åºãšã€ã³ã·ãã³ãã®èª¿æ»ã®ããã«å éšã»ãã¥ãªãã£ã·ã¹ãã ã§äœ¿çšã§ããããã«ãããã©ãããã©ãŒã ã§ãã
R-Visionã¯ãã·ã¢ã®ãµã€ããŒã»ãã¥ãªãã£ã·ã¹ãã éçºè ã§ããã2011幎以æ¥ãçŸåšã®ãµã€ããŒè åšã«å¯Ÿæããä¿¡é Œæ§ã®é«ãæ å ±ã»ãã¥ãªãã£ç®¡çã確ä¿ããããã®ãœãªã¥ãŒã·ã§ã³ãšãµãŒãã¹ãéçºããŠããŸããã
å瀟ã®ãã©ãããã©ãŒã ã§ããR-VisionTIPã¯ãäŸµå®³ã®ææšã®èªååéãæ£èŠåã匷åãåŠçãããããŒã¿ã®å éšã»ãã¥ãªãã£å¯Ÿçãžã®è»¢éãã»ã³ãµãŒã䜿çšããçµç¹ã®ã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ææšã®æ€çŽ¢ãšæ€åºãæäŸããŸãã
è åšã«é¢ãããµããŒããããŠããæ å ±æºã«ã¯ããã·ã¢é£éŠäžå€®éè¡ã®FinCERTãKasperskyãGroup-IBãIBM X-Force ExchangeãATïŒTCyberââsecurityããã®ããŒã¿ãå«ãŸããŸããäžé£ã®ã»ã³ãµãŒã«ããããã©ãããã©ãŒã ã¯ãªã¢ã«ã¿ã€ã ã§ç£èŠããçµç¹ã®ã€ã³ãã©ã¹ãã©ã¯ãã£å ã®æªæã®ããã¢ã¯ãã£ããã£ã®çè·¡ãé¡åçã«æ€çŽ¢ãããªã¹ã¯ãçºçããå Žåã«ã»ãã¥ãªãã£ã¢ããªã¹ãã«éç¥ã§ããŸãã
R-Vision TIPã¯ãåäžã®ããŒã¿ããŒã¹ã«å€ãã®ãœãŒã¹ããããŒã¿ãåéãæ£èŠåãããã³ä¿åããããšã§è åšããŒã¿ã®åŠçãç°¡çŽ åããã»ã³ãµãŒã䜿çšããŠSIEMãsyslogãããã³DNSã¯ãšãªã®é¢é£ã€ã³ãžã±ãŒã¿ãŒãç£èŠããããšã§æœåšçãªè åšã®èå¥ã容æã«ããŸãã
äœæ¥ã®ã¹ããŒã
TIPã䜿çšãããšãåŠçãããããŒã¿ãå éšé²åŸ¡ã«çŽæ¥èªåçã«ã¢ããããŒãããããšã§ãè åšãæéå ã«ãããã¯ã§ããŸããååŠçã«ãããçããŒã¿ã®äœ¿çšæã«çºçãã誀æ€ç¥ã®æ°ãæžå°ããŸãã CiscoãPaloAlto NetworksãCheckPointã®æ©åšãžã®ã€ã³ãžã±ãŒã¿ãŒã®èªåã¢ããããŒãããµããŒãããŸãã
R-Vision Threat Intelligence Platformã䜿çšãããšãã€ã³ãžã±ãŒã¿ãŒãæäœããããã«å¿ èŠãªã·ããªãªãå®è£ ããã³èªååã§ããŸããã·ããªãªã«ã¯ãæ¿çž®ãæ€åºãä¿è·ãžã®é åžãéç¥ãå«ãŸããå ŽåããããŸãã
補åã®æ°ãããªãªãŒã¹ã§ã¯ããªã³ã¯ã°ã©ãããŒã«ãå°å ¥ãããŠããŸããæªæã®ããã€ã³ãžã±ãŒã¿ãŒãšä»ã®ãšã³ãã£ãã£ãšã®é¢ä¿ã衚瀺ããè åšãèŠèŠçã«è¡šçŸããŸããã°ã©ãã«ã¯ãããŸããŸãªå±æ§ã«ãã£ãŠãªããžã§ã¯ããã¹ã±ãŒãªã³ã°ããã£ã«ã¿ãªã³ã°ãããã³ã¯ã©ã¹ã¿ãªã³ã°ããããã®ããŒã«ãå«ãŸããŠããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ã®
ç¹æ§
ç¬èªã®ãã£ãŒããµãã©ã€ã€/ãã£ãŒãåæã»ã³ã¿ãŒïŒ N / A
ç®±ããåºããŠããã«äœ¿çšã§ãããã£ãŒããµãã©ã€ã€ã®æ°ïŒ 20-100
ãµããŒããããŠãããã£ãŒãã®åä¿¡æ¹æ³ïŒ CSVãJSONãHTTP
å€éšãœãŒã¹ããã®ããŒã¿ãå å®ãããå¯èœæ§ïŒäŸïŒWHOisã PassiveDNSãVirusTotalãªã©ïŒïŒ present
SIEMã€ãã³ãã§äžèŽãããã®ãæ€çŽ¢ããŸãïŒ present
ãµãŒãããŒãã£ã®æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ãšã®çµ±åã«ããäºæ ã«çŽæ¥å¿çïŒæ¬
è€éãªã¢ã«ãŽãªãºã ã䜿çšããŠãã€ã³ã·ãã³ãã«å¯Ÿããå¿çïŒãã¬ã€ããã¯ïŒïŒ N / A
REST APIãä»ããŠçµ±åã®å¯èœæ§ïŒæ¬
ãã£ãŒããªããžã§ã¯ããšå éšäººå·¥ç©ãšã®éã®ãªã³ã¯ã®ã°ã©ãæ§ç¯ããå¯èœæ§ïŒ N / Aã
-
ROI4CIOã®NatalkaChech