
ææ°ã®äŒæ¥ITã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãå€ãã®ã·ã¹ãã ãšã³ã³ããŒãã³ãã§æ§æãããŠããŸãããããŠãããããåå¥ã«è¿œè·¡ããããšã¯éåžžã«é£ããå ŽåããããŸããäŒæ¥ã倧ãããªãã»ã©ããããã®ã¿ã¹ã¯ã¯ããé¢åã«ãªããŸãããã ããäŒæ¥ã€ã³ãã©ã¹ãã©ã¯ãã£å šäœã®éçšã«é¢ããã¬ããŒãã1ãæã«åéããããŒã«ããããŸããSIEMã·ã¹ãã ïŒã»ãã¥ãªãã£æ å ±ãšã€ãã³ã管çïŒã§ããç§ãã¡ã®ã¬ãã¥ãŒã§Gartnerã®å°éå®¶ã«ãããšããããã®è£œåã®æé«ã®ãã®ã«ã€ããŠèªã¿ãæ¯èŒè¡šã§äž»ãªæ©èœã«ã€ããŠåŠã³ãŸãã
äžèšã§èšãã°ãSIEMãã¯ãããžãŒã¯ã管çè ã«ãããã¯ãŒã¯äžã§èµ·ãã£ãŠããããšã®æŠèŠãæäŸããŸãããã®ãããªã·ã¹ãã ã¯ãã»ãã¥ãªãã£ã€ãã³ããããã³ããã€ã¹ãšãŠãŒã¶ãŒã®ã¢ã¯ãã£ããã£ã®ãªã¢ã«ã¿ã€ã åæãæäŸããŸããããã«ãããéå€§ãªæå·ãçºçããåã«ãããã«å¯Ÿå¿ã§ããŸãã
SIEMããã°ã©ã ã¯ããµãŒããŒããã¡ã€ã³ã³ã³ãããŒã©ãŒããã¡ã€ã¢ãŠã©ãŒã«ãããã³ãã®ä»ã®å€ãã®ãããã¯ãŒã¯ããã€ã¹ããæ å ±ãåéãã䜿ããããã¬ããŒãã®åœ¢åŒã§æäŸããŸãããã®ããŒã¿ã¯å¿ ãããã»ãã¥ãªãã£é¢é£ã§ã¯ãããŸãããããšãã°ã圌ãã®å©ããåããŠããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãã©ã®ããã«æ©èœããããçè§£ãããã®æé©åã®èšç»ãç«ãŠãããšãã§ããŸãããããããã¡ãããéèŠãªããšã¯ãæœåšçãªã®ã£ããã®æ€åºãšãæ¢åã®è åšã®ç¹å®ãšæé€ã§ãããã®ããŒã¿ã¯ããããã¯ãŒã¯ããã€ã¹ã®ãã°ããŒã¿ã®åéãšéçŽãéããŠæäŸãããŸãã
æ å ±ãåéããåŸïŒãã®æé ã¯æå®ãããééã§èªåçã«å®è¡ãããŸãïŒãã€ãã³ããèå¥ããã³åé¡ãããŸããæ¬¡ã«ïŒããã§ããæå®ãããèšå®ã«åŸã£ãŠïŒãæ©åšãããã°ã©ã ããŸãã¯ãŠãŒã¶ãŒã®ç¹å®ã®ã¢ã¯ã·ã§ã³ãæœåšçãªã»ãã¥ãªãã£åé¡ã§ããå¯èœæ§ããããšããã¢ã©ãŒããéä¿¡ãããŸãã
ã©ã®ãããªæ©äŒãéãããŠããŸããïŒ
SIEMã¯ãããŸããŸãªåé¡ã®è§£æ±ºã«åœ¹ç«ã¡ãŸãããã®äžã«ã¯ãæšçåæ»æããŠãŒã¶ãŒã«ããæå³ããªãæ å ±ã»ãã¥ãªãã£éåã®ã¿ã€ã ãªãŒãªæ€åºãéèŠãªã·ã¹ãã ããªãœãŒã¹ã®ã»ãã¥ãªãã£ã®è©äŸ¡ãã€ã³ã·ãã³ã調æ»ã®å®æœãªã©ããããŸãã
åæã«ãSIEMãã©ãããã©ãŒã ã«ã¯ããã€ãã®å¶éããããŸããããšãã°ã圌ãã¯ããŒã¿ãåé¡ããæ¹æ³ãç¥ããããã°ãã°é»åã¡ãŒã«ã§ããŸãæ©èœããã圌ãèªèº«ã®ã€ãã³ãã«é¢ããŠæ»è§ãæã£ãŠããŸãããããŠãã¡ãããäŒæ¥ã®æ å ±ã»ãã¥ãªãã£ã®åé¡ãå®å šã«ã«ããŒããããšã¯ã§ããŸããããããåæã«ããããã¯éèŠã§ã¯ãããŸããããäŒæ¥ã®é²è¡ã·ã¹ãã ã®éèŠãªéšåã§ããããã«ãSIEMãã©ãããã©ãŒã ã®éçºã¯åæ»ããŠããŸãããããšãã°ãäžéšã®ææ°ã®è£œåã«ã¯åææ©èœããããŸããã€ãŸããã¬ããŒããçºè¡ããŠæœåšçãªåé¡ã瀺ãã ãã§ãªããã€ãã³ãèªäœãåæããç¹å®ã®ã€ãã³ãã«é¢ããéç¥ã«ã€ããŠæ±ºå®ãäžãæ¹æ³ãç¥ã£ãŠããŸãã
ãããã«ãããç¹å®ã®è£œåãéžæãããšãã¯ãå€ãã®ãã©ã¡ãŒã¿ãŒã«çŠç¹ãåœãŠãå¿ èŠããããŸãããã®äžã§ãæ å ±ã®éäžåéãåŠçãä¿åãã€ã³ã·ãã³ãã®éç¥ãããŒã¿åæïŒçžé¢ïŒãããã³äŒæ¥ãããã¯ãŒã¯ã®ç¯å²ã®å¹ ãéžã³åºããŸãããããŠãã¡ãããå¯èœã§ããã°ãè³Œå ¥ããåã«è©Šçšç/ãã¢çãå®è¡ããŠããããäŒç€Ÿã«ã©ã®ããã«é©ããŠãããã確èªããå¿ èŠããããŸãã
IBMQRadarã»ãã¥ãªãã£ã€ã³ããªãžã§ã³ã¹
ãã€ãã¯å€§æIBMã®SIEMãã©ãããã©ãŒã ã¯ãåžå Žã§æãå é²çãªãã©ãããã©ãŒã ã®1ã€ã§ããGartnerã®ãªãŒããŒã®è±¡éã§ããç«¶åä»ç€Ÿãäžåãã10幎é£ç¶ã§ååšããŠããŸãããã®è£œåã¯ããããã¯ãŒã¯ã§çºçããã€ãã³ããæå€§éã«ã«ããŒããè€æ°ã®çµ±åã·ã¹ãã ã§æ§æãããŠãããå€ãã®æ©èœãããã«æ©èœããŸãããã®ããŒã«ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã»ãã¥ãªãã£ããã€ã¹ãããŒã¿ããŒã¹ãã¢ããªã±ãŒã·ã§ã³ãªã©ãããŸããŸãªãœãŒã¹ããããŒã¿ãåéã§ããŸãã
QRadar Security Intelligenceã¯ãã€ãã³ããåªå 床ã§äžŠã¹æ¿ããæå€§ã®ã»ãã¥ãªãã£è åšãããããã€ãã³ãã匷調衚瀺ã§ããŸããããã¯ããªããžã§ã¯ãïŒäŒæ¥ãããã¯ãŒã¯å ã®ãŠãŒã¶ãŒãæ©åšããµãŒãã¹ãããã³ããã»ã¹ïŒã®ç°åžžãªåäœãåæããæ©èœã«ãããã®ã§ããããã«ã¯ãçãããIPã¢ãã¬ã¹ãŸãã¯ãããããã®èŠæ±ãžã®ã¢ã¯ã»ã¹ã«é¢é£ããã¢ã¯ã·ã§ã³ã®æ±ºå®ãå«ãŸããŸãããã¹ãŠã®çãããã¢ã¯ãã£ããã£ã«ã€ããŠè©³çްãªã¬ããŒããæäŸãããŸããããã«ãããããšãã°ãå€åæéå€ã®çãããã¢ã¯ãã£ããã£ãæ€åºã§ããŸãããã®ã¢ãããŒãã¯ããŠãŒã¶ãŒç£èŠæ©èœãšãããã¯ãŒã¯ã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®å¯èŠæ§ãšçµã¿åãããããšã§ãå éšã®è åšãšæŠãã®ã«åœ¹ç«ã¡ãŸããããã«ãåŸæ¥ã®ãµã€ããŒæ»æã§ã¯ãæ å ±ã¯éåžžã«è¿ éã«å°çãã以åã«é²æ¢ããããšãã§ããŸã圌ããã©ã®ããã«åœŒãã®ç®æšãéæããéå€§ãªæå®³ãåŒãèµ·ãããã
IBM QRadarã»ãã¥ãªãã£ã€ã³ããªãžã§ã³ã¹ã®éèŠãªæ©èœã®1ã€ã¯ãè³ç£ããŠãŒã¶ãŒããããã¯ãŒã¯ã¢ã¯ãã£ããã£ãæ¢åã®è匱æ§ãè åšã€ã³ããªãžã§ã³ã¹ãªã©ã®éã®é«åºŠãªåæãšçžé¢é¢ä¿ã䜿çšãããªã¹ã¯ããŒã¹ã®æ€åºãšåªå é äœä»ãã§ããIBMQradarã¯ãã€ãã³ããé£éãããŠäœæã§ããŸããã€ã³ã·ãã³ãããšã«åå¥ã®ããã»ã¹ããããŸãã
æ å ±ãåéãããŠç»é¢ã«1ãæã«è¡šç€ºãããããã管çè ã¯ãã·ã¹ãã ã«ãã£ãŠæ€åºãããé¢é£ãããã¹ãŠã®çãããã¢ã¯ãã£ããã£ã確èªã§ããŸãããŸããæ°ããé¢é£ã€ãã³ãã1ã€ã®ãã§ãŒã³ã«è¿œå ããããããã¢ããªã¹ãã¯è€æ°ã®ã¢ã©ãŒããåãæ¿ããå¿ èŠããããŸãããããã«è©³çްãªèª¿æ»ãè¡ãããã«ãç¹å¥ãªããŒã«ã§ããIBM QRadar Incident Forensicsã䜿çšããŠãã€ã³ã·ãã³ãã«é¢é£ãããã¹ãŠã®ãããã¯ãŒã¯ãã±ããã埩å ããæ»æè ã®ã¢ã¯ã·ã§ã³ã段éçã«åçŸã§ããŸãã
Splunk Enterprise Security
æ¥çããªãŒããããã©ãããã©ãŒã ã®1ã€ã§ããã飿ºããå¹ åºãæ å ±ãœãŒã¹ãç¹åŸŽã§ããSplunk Enterprise Securityã¯ãåŸæ¥ã®ãããã¯ãŒã¯ã³ã³ããŒãã³ãïŒãµãŒããŒãã»ãã¥ãªãã£ããã€ã¹ãã²ãŒããŠã§ã€ãããŒã¿ããŒã¹ãªã©ïŒãã¢ãã€ã«ããã€ã¹ïŒã¹ããŒããã©ã³ãã©ããããããã¿ãã¬ããïŒãWebãµãŒãã¹ãããã³åæ£ãœãŒã¹ããã€ãã³ããã°ãåéã§ããŸããåéãããæ å ±ïŒãŠãŒã¶ãŒã¢ã¯ã·ã§ã³ããã°ã蚺æçµæãªã©ã®ããŒã¿ãããã«ãããèªåã¢ãŒããšæåã¢ãŒãã§ã®äŸ¿å©ãªæ€çŽ¢ãšåæãå¯èœã«ãªããŸãããã®ãœãªã¥ãŒã·ã§ã³ã«ã¯ãåéãããæ å ±ã«åºã¥ããŠæ¢åã®è åšãèŠåããæœåšçãªåé¡ãäºåã«å ±åãããã«ã¹ã¿ãã€ãºå¯èœãªããŸããŸãªéç¥ããããŸãã
ãã®è£œåã¯ã調æ»ã®å®æœãä¿è·ããããªãœãŒã¹ã®è«çå³ãããã³å€ãã®å€éšãµãŒãã¹ãšã®çµ±åãæ åœããããã€ãã®ã¢ãžã¥ãŒã«ã§æ§æãããŠããŸãããã®ã¢ãããŒãã«ãããããŸããŸãªãã©ã¡ãŒã¿ã«ã€ããŠè©³çްãªåæãå®è¡ããäžèŠãçžäºã«çžé¢ããªãã€ãã³ãéã®é¢ä¿ã確ç«ããããšãã§ããŸãã Splunk Enterprise Securityã䜿çšãããšãæéãå ŽæãçæãããèŠæ±ãããŸããŸãªã·ã¹ãã ãžã®æ¥ç¶ãããã³ãã®ä»ã®ãã©ã¡ãŒã¿ãŒã«ãã£ãŠããŒã¿ãçžäºã«é¢é£ä»ããããšãã§ããŸãã
ãã®ããŒã«ã¯å€§èŠæš¡ãªããŒã¿ã»ããã§ãæ©èœããæ¬æ Œçãªããã°ããŒã¿ãã©ãããã©ãŒã ã§ãã倧éã®ããŒã¿ã¯ããªã¢ã«ã¿ã€ã ãšå±¥æŽæ€çŽ¢ã¢ãŒãã®äž¡æ¹ã§åŠçã§ããåè¿°ã®ããã«ãèšå€§ãªæ°ã®ããŒã¿ãœãŒã¹ããµããŒããããŠããŸããSplunk Enterprise Securityã¯ã1æ¥ãããæ°çŸTBã®ããŒã¿ã«ã€ã³ããã¯ã¹ãä»ããããšãã§ãããããéåžžã«å€§èŠæš¡ãªãšã³ã¿ãŒãã©ã€ãºãããã¯ãŒã¯ã«ãé©çšã§ããŸããå°çšããŒã«ã®MapReduceã䜿çšãããšãã·ã¹ãã ãæ°Žå¹³æ¹åã«ãã°ããã¹ã±ãŒãªã³ã°ããè² è·ãåçã«åæ£ã§ãããããã·ã¹ãã ã®ããã©ãŒãã³ã¹ã¯åžžã«èš±å®¹ã¬ãã«ã«ä¿ãããŸããåæã«ãã¯ã©ã¹ã¿ãªã³ã°ãšçœå®³åŸ©æ§ã®æ§æããŠãŒã¶ãŒãå©çšã§ããŸãã
McAfee Enterprise Security Manager
McAfee ã®ãœãªã¥ãŒã·ã§ã³ã¯ããœãããŠã§ã¢ã ãã§ãªããç©çããã€ã¹ãšä»®æ³ããã€ã¹ã®äž¡æ¹ãšããŠæäŸãããŸããäžç·ã«ãŸãã¯å¥ã ã«äœ¿çšã§ããããã€ãã®ã¢ãžã¥ãŒã«ã§æ§æãããŠããŸãã Enterprise Security Managerã¯ãäŒæ¥ã®ITã€ã³ãã©ã¹ãã©ã¯ãã£ãç¶ç¶çã«ç£èŠããè åšãšãªã¹ã¯ã«é¢ããæ å ±ãåéããè åšã«åªå é äœãä»ããŠè¿ éã«èª¿æ»ãè¡ãããšãã§ããŸãããœãªã¥ãŒã·ã§ã³ã¯ããã¹ãŠã®åä¿¡æ å ±ã«ã€ããŠãããŒã¹ã©ã€ã³ã¢ã¯ãã£ããã£ã¬ãã«ãèšç®ãããã®ã¢ã¯ãã£ããã£ã®ç¯å²ã«éåããå Žåã«ç®¡çè ã«éä¿¡ãããäºåéç¥ãçæããŸãããã®ããŒã«ã¯ãã³ã³ããã¹ãã®æäœæ¹æ³ãèªèããŠãããããè åšã®åæãšæ€åºã®æ©èœãå€§å¹ ã«æ¡åŒµããã誀ã£ãã·ã°ãã«ã®æ°ãæžå°ããŸãã
McAfee ESMã¯ãAPIã䜿çšããã«ãµãŒãããŒãã£è£œåãšããŸãçµ±åã§ãããããä»ã®å€ãã®äžè¬çãªã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšäºææ§ããããŸãããŸããåŸæ¥ã®SIEMæ©èœãæ¡åŒµããMcAfee Global ThreatIntelligenceãã©ãããã©ãŒã ããµããŒãããŠããŸãããã®ãããã§ãESMã¯äžçäžããè åšã«é¢ããææ°ã®æ å ±ãçµ¶ããåãåããŸããå®éã«ã¯ãããã«ãããããšãã°ãçãããIPã¢ãã¬ã¹ã«é¢é£ä»ããããã€ãã³ããæ€åºã§ããŸãã
ã·ã¹ãã ããã©ãŒãã³ã¹ãåäžãããããã«ãéçºè ã¯é¡§å®¢ã«äžé£ã®McAfeeConnectããŒã«ãæäŸããŸãããããã®ããŒã«ã«ã¯ãè€éãªSIEMã®ãŠãŒã¹ã±ãŒã¹ãåŠçããã®ã«åœ¹ç«ã€æ¢è£œã®æ§æãå«ãŸããŠããŸããããšãã°ãUser Behavior Analysis Toolkitã䜿çšãããšãé ããè åšãããé©åãã€è¿ éã«èŠã€ããããšãã§ããã»ãã¥ãªãã£æäœãããæ£ç¢ºã«ãªããã€ã³ã·ãã³ãã®èª¿æ»æéãå€§å¹ ã«ççž®ãããŸããWindowsçšã®ããã±ãŒãžã䜿çšãããšããã®OSã®ãµãŒãã¹ãç£èŠããŠããããã®é©åãªäœ¿çšãè©äŸ¡ããè åšãæ€åºã§ããŸããããŸããŸãªã·ããªãªã補åãããã³æšæºãžã®æºæ ã®ããã«ãåèš50ãè¶ ããããã±ãŒãžãå©çšå¯èœã§ãã
AlienVaultçµ±åã»ãã¥ãªãã£ãã©ãããã©ãŒã
AlienVault ç€Ÿã¯æè¿ATïŒT Securityãšãããã©ã³ãã§ATïŒT Businessãšå䜵ããŸãããããã®äž»å補åã¯çŸåšå€ãååã§è²©å£²ãããŠããŸãããã®ããŒã«ã¯ãã¬ãã¥ãŒã®ä»ã®ã»ãšãã©ã®ãã©ãããã©ãŒã ãšåæ§ã«ãåŸæ¥ã®SIEMãããå€ãã®æ©èœãåããŠããŸãããã®ãããAlienVault USMã«ã¯ãè³ç£å¶åŸ¡ãå®å šãªãã±ãããã£ããã£ãªã©ãæ åœããããŸããŸãªã¢ãžã¥ãŒã«ããããŸãããã©ãããã©ãŒã ã¯ããããã¯ãŒã¯ã®è匱æ§ããã¹ãããããšãã§ããŸããããã¯ã1åéãã®ãã§ãã¯ãšç¶ç¶çãªç£èŠã®äž¡æ¹ã«ãªããŸããåŸè ã®å Žåãæ°ããè匱æ§ã®ååšã«é¢ããéç¥ã¯ããããã®åºçŸãšåæã«ã»ãŒåæã«åä¿¡ãããŸãã
ãã®ä»ã®ãã©ãããã©ãŒã æ©èœã«ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®è匱æ§è©äŸ¡ãå«ãŸããŸããããã¯ããããã¯ãŒã¯ã®å®å šæ§ãšãã»ãã¥ãªãã£åºæºãæºããããã«æ§æãããŠããããšã瀺ããŸãããã©ãããã©ãŒã ã¯ããããã¯ãŒã¯ãžã®æ»æãæ€åºããã¿ã€ã ãªãŒã«éç¥ããæ¹æ³ãç¥ã£ãŠããŸãããã®å Žåã管çè ã¯ãäŸµå ¥ãã©ãããæ¥ãŠãããããããã¯ãŒã¯ã®ã©ã®éšåãæ»æãããããæ»æè ãã©ã®æ¹æ³ã䜿çšããŠããããããã³æåã«äŸµå ¥ãæéããããã«äœããã¹ããã«ã€ããŠã®è©³çްæ å ±ãåãåããŸããããã«ãã·ã¹ãã ã¯ãããã¯ãŒã¯å ããã€ã³ãµã€ããŒæ»æãæ€åºããŠå ±åããããšãã§ããŸãã
ç¬èªã®AlienAppsãœãªã¥ãŒã·ã§ã³ã«ãããUSMãã©ãããã©ãŒã ã¯ãå€ãã®ãµãŒãããŒãã£ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšçµ±åãã广çã«è£å®ããããšãã§ããŸãããããã®ããŒã«ã¯ãAlienVaultUSMã®ã»ãã¥ãªãã£ã«ã¹ã¿ãã€ãºããã³è åšå¯Ÿå¿èªååæ©èœã匷åããŸãããããã£ãŠãäŒæ¥ãããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã¹ããŒã¿ã¹ã«é¢ããã»ãšãã©ãã¹ãŠã®æ å ±ã¯ããã©ãããã©ãŒã ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠçŽæ¥å©çšã§ããããã«ãªããŸãããããã®ããŒã«ã¯ãè åšãæ€åºããããšãã®å¯Ÿå¿ã¢ã¯ã·ã§ã³ãèªååããã³æŽçããæ©èœãæäŸããã€ã³ã·ãã³ãã®æ€åºãšå¯Ÿå¿ãããç°¡åãã€è¿ éã«ããŸããããšãã°ããã£ãã·ã³ã°ãµã€ããžã®ãªã³ã¯ãèŠã€ãã£ãå Žåã管çè ã¯ãµãŒãããŒãã£ã®DNSä¿è·ãµãŒãã¹ã«ããŒã¿ãéä¿¡ããŠããã®ã¢ãã¬ã¹ãèªåçã«ãããã¯ã§ããŸããçµç¹å ã®ã³ã³ãã¥ãŒã¿ãŒããã¯ã¢ã¯ã»ã¹ã§ããªããªããŸãã
Micro Focus ArcSight Enterprise Security Manager
SIEMãã©ãããã©ãŒã ã®Micro Focus 2017幎ãŸã§HPEã«ãã£ãŠéçºããããããçºèŠåæãããªã¢ã«ã¿ã€ã ã§ã®ã¯ãŒã¯ãããŒã管çããããã®å æ¬çãªããŒã«ã§ãããã®ããŒã«ã¯ããããã¯ãŒã¯ã®ç¶æ ãšãããã¯ãŒã¯ã§çºçããããã»ã¹ã«é¢ããæ å ±ãåéããããã®ååãªæ©äŒãšãæ¢è£œã®ã»ãã¥ãªãã£ã«ãŒã«ã®å€§èŠæš¡ãªã»ãããæäŸããŸããè åšã®æ€åºãåªå é äœä»ããªã©ãArcSight Enterprise SecurityManagerã®å€ãã®æ©èœãèªååãããŠããŸãã調æ»ã®ããã«ããã®ããŒã«ã¯å¥ã®ç¬èªã®ãœãªã¥ãŒã·ã§ã³ã§ããArcSightInvestigateãšçµ±åã§ããŸããæªç¥ã®è åšãæ€åºããé«éã§ã¹ããŒããªæ€çŽ¢ãå®è¡ããããŒã¿ãèŠèŠåã§ããŸãã
éçºè ã«ãããšããã®ãã©ãããã©ãŒã ã¯ããŸããŸãªçš®é¡ã®ããã€ã¹ããã®æ å ±ãåŠçã§ãã500ãè¶ ããããã€ã¹ãããããã®ã¡ã«ããºã ã¯ãã¹ãŠã®äžè¬çãªã€ãã³ã圢åŒããµããŒãããŠããŸãããªã³ã©ã€ã³ãœãŒã¹ããåéãããæ å ±ã¯ããã©ãããã©ãŒã ã§äœ¿çšããããã«ãŠãããŒãµã«åœ¢åŒã«å€æãããŸãããã®ã¢ãããŒãã«ããã調æ»ãŸãã¯å³æã®ã¢ã¯ã·ã§ã³ãå¿ èŠãªç¶æ³ããã°ããç¹å®ã§ãã管çè ãæãç·æ¥ã§ãªã¹ã¯ã®é«ãè åšã«éäžã§ããããã«ãªããŸãã
ArcSight ESMã¯ããªãã£ã¹ãéšéã®åºç¯ãªãããã¯ãŒã¯ãæã€äŒæ¥ã®å Žåããªã¢ãŒãã»ãã¥ãªãã£ããŒã ãçµ±åãããã¬ããŒããããã»ã¹ãããŒã«ãããã³æ å ±ããªã¢ã«ã¿ã€ã ã§äº€æã§ããå Žåã«ãSecOpsã¢ãã«ã®éçšãå¯èœã«ããŸãããããã£ãŠããã¹ãŠã®éšéãšãªãã£ã¹ã«å¯ŸããŠãäžå åãããèšå®ãããªã·ãŒãããã³ã«ãŒã«ã®ã»ãããé©çšãã圹å²ãšã¢ã¯ã»ã¹æš©ã®çµ±äžããããããªãã¯ã¹ã䜿çšã§ããŸãããã®ã¢ãããŒãã«ãããè åšã瀟å ã®ã©ãã«çŸããŠãè¿ éã«å¯Ÿå¿ã§ããŸãã
RSANetWitnessãã©ãããã©ãŒã
RSAïŒDellã®éšéã®1ã€ïŒ ã®ãã©ãããã©ãŒã ã¯ããšã³ããã€ã³ããNetFlowãã»ãã¥ãªãã£ããã€ã¹ãéä¿¡ããããã±ããããã®æ å ±ãªã©ãããŸããŸãªãããã¯ãŒã¯ãœãŒã¹ããã®ããŒã¿ã«åºã¥ããŠè åšã®å¯èŠæ§ãæäŸããã¢ãžã¥ãŒã«ã®ã»ããã§ãããã®ããã«ãæ å ±ããªã¢ã«ã¿ã€ã ã§åŠçããããã«åºã¥ããŠã¢ã©ãŒããçºè¡ããå°æ¥ã®èª¿æ»ã®ããã«ããŒã¿ãä¿åããè€æ°ã®ç©çããã€ã¹ããã³/ãŸãã¯ä»®æ³ããã€ã¹ãããã«ãéçºè ã¯ãå°èŠæš¡äŒæ¥ãšå€§èŠæš¡ãªåæ£ãããã¯ãŒã¯ã®äž¡æ¹ã«ã¢ãŒããã¯ãã£ãæäŸããŸãã
NetWitnessãã©ãããã©ãŒã ã¯ãå éšã®è åšãèå¥ããç¹å®ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«é¢ããã³ã³ããã¹ãæ å ±ãåŠçããŸããããã«ãããã¢ã©ãŒãã«åªå é äœãä»ããçµç¹ã®è©³çްã«åŸã£ãŠäœæ¥ãæé©åã§ããŸãããã©ãããã©ãŒã ã¯ãåã ã®ã€ã³ã·ãã³ãã«é¢ããæ å ±ãæ¯èŒããããšãã§ããŸããããã«ããããããã¯ãŒã¯ã«å¯Ÿããæ»æã®å šäœçãªèŠæš¡ã倿ããå°æ¥åæ§ã®ãªã¹ã¯ãæå°éã«æããããã«æ§æã§ããŸãã
éçºè ã¯ããšã³ããã€ã³ãã®æäœã«å€ãã®æ³šæãæããŸãããã®ãããRSA NetWitnessãã©ãããã©ãŒã ã«ã¯ããã®ããã®åå¥ã®ã¢ãžã¥ãŒã«ãããããŠãŒã¶ãŒã¬ãã«ãšã«ãŒãã«ã¬ãã«ã®äž¡æ¹ã§å¯èŠæ§ãæäŸããŸãããã®ããŒã«ã¯ãç°åžžãªã¢ã¯ãã£ããã£ãæ€åºããçãããããã»ã¹ããããã¯ããç¹å®ã®ããã€ã¹ã®è匱æ§ãè©äŸ¡ã§ããŸãããŸããåéãããããŒã¿ã¯ã·ã¹ãã å šäœã®éçšã§èæ ®ããããããã¯ãŒã¯ã»ãã¥ãªãã£ã®å šäœçãªè©äŸ¡ã«ã圱é¿ãäžããŸãã
FireEyeHelixã»ãã¥ãªãã£ãã©ãããã©ãŒã
FireEyeã® ã¯ã©ãŠãããŒã¹ã®ãã©ãããã©ãŒã ã«ãããçµç¹ã¯ã€ã³ã·ãã³ãã®å ±åããç¶æ³ã®ä¿®æ£ãŸã§ãããããã€ã³ã·ãã³ããå¶åŸ¡ã§ããŸããå€ãã®ç¬èªã®ããŒã«ãçµã¿åããããµãŒãããŒãã£ã®ããŒã«ãšçµ±åã§ããŸãã Helix Security Platformã¯ãåºç¯ãªãŠãŒã¶ãŒè¡ååæãæ¡çšããŠãå éšã®è åšãšéãã«ãŠã§ã¢æ»æãèªèããŸãã
è åšã«å¯Ÿæããããã«ããã®ããŒã«ã¯ç®¡çè ããã®éç¥ã䜿çšããã ãã§ãªããäºåå®çŸ©ãããã«ãŒã«ã»ããïŒçŽ400ïŒãé©çšããŸããããã«ããã誀æ€ç¥ã®æ°ãæå°éã«æãããã管çè ã¯è åšã¡ãã»ãŒãžãåžžã«ã¹ãã£ã³ããå¿ èŠããªããªããŸããããã«ããã®ã·ã¹ãã ã¯ãè åšã®èª¿æ»ãšæ€çŽ¢ãè¡ååæãæ å ±ãååŸããããã®è€æ°ã®ãªãœãŒã¹ã®ãµããŒããããã³ã»ãã¥ãªãã£ã³ã³ãã¬ãã¯ã¹å šäœã®ç°¡åãªç®¡çãæäŸããŸãã
ãã®ããŒã«ã¯ãé«åºŠãªè åšãããŸãæ€åºããŸããHelix Security Platformã«ã¯ãFireEyeãšãµãŒãããŒãã£ãã³ããŒã®äž¡æ¹ã®300ãè¶ ããã»ãã¥ãªãã£ããŒã«ãçµ±åããæ©èœããããŸãããããã®ããŒã«ã¯ãä»ã®ã€ãã³ãã®ã³ã³ããã¹ããåæããããšã«ãããé ããæ»æãåœè£ ãããæ»æãé«ã¬ãã«ã§æ€åºããŸãã
Rapid7 InsightIDR
Rapid7 瀟ã¯ãåäœã®åæã«ãã£ãŠç£šãããã¯ã©ãŠãSIEMãã©ãããã©ãŒã ãé¡§å®¢ã«æäŸããŸããã·ã¹ãã ã¯ããã°ãšãã°ã®è©³çްãªåæãå®è¡ãããããã¯ãŒã¯ãžã®äžæ£ãªäŸµå ¥ãæ€åºããããã®ç¹å¥ãªãã©ãããèšå®ããŸããInsightIDRããŒã«ã¯ããŠãŒã¶ãŒã¢ã¯ãã£ããã£ãç¶ç¶çã«ç£èŠãããããããããã¯ãŒã¯ã€ãã³ããšé¢é£ä»ããŸããããã¯ãå éšé¢ä¿è ãç¹å®ããã®ã«åœ¹ç«ã€ã ãã§ãªããæå³çãªã»ãã¥ãªãã£éåãé²ããŸãã
Rapid7 InsightIDRã¯ããšã³ããã€ã³ããç¶ç¶çã«ç£èŠããŸããããã«ãããç°åžžãªããã»ã¹ãç°åžžãªãŠãŒã¶ãŒã®åäœãå¥åŠãªã¿ã¹ã¯ãªã©ã確èªã§ããŸãããã®ãããªã¢ã¯ã·ã§ã³ãæ€åºãããå Žåãã·ã¹ãã ã§ã¯ãããããä»ã®ã³ã³ãã¥ãŒã¿ãŒã§ç¹°ãè¿ãããŠããããããŒã«ã«ã®åé¡ã®ãŸãŸã§ãããã確èªã§ããŸãããŸããåé¡ãçºçããŠã€ã³ã·ãã³ãã調æ»ãããå Žåãæéã®çµéãšãšãã«èç©ãããããŒã¿ã䟿å©ã«äœç³»åãã調æ»ãå€§å¹ ã«ç°¡çŽ åããããžã¥ã¢ã«ããŒã«ã䜿çšãããŸãã
è åšã«å¯Ÿæããããã«ãéçºè ã®å°éå®¶ã¯ãæ©åšããçŸåšã®ããã»ã¹ãããªã·ãŒã«è³ããŸã§ãäŒæ¥ç°å¢ã®ã»ãã¥ãªãã£ã®çšåºŠãç¬èªã«è©äŸ¡ã§ããŸããããã«ãããRapid7 InsightIDRã䜿çšããŠæé©ãªãããã¯ãŒã¯ä¿è·ã¹ããŒã ãæåããæ§ç¯ããããæ¢åã®ã¹ããŒã ãæ¹åãããã§ããŸãã
Fortinet FortiSIEM
Fortinetã® å æ¬çã§ã¹ã±ãŒã©ãã«ãªãœãªã¥ãŒã·ã§ã³ã¯ãFortinet SecurityFabricãã©ãããã©ãŒã ã®äžéšã§ãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãç©çããã€ã¹ã®åœ¢åŒã§æäŸãããŸãããã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ã«åºã¥ããŠããŸãã¯ä»®æ³ããã€ã¹ãšããŠäœ¿çšããããšãã§ããŸãããã®ããŒã«ã¯ãå¹ åºãæ å ±ãœãŒã¹ãæäŸããŸããä»ã®ã¡ãŒã«ãŒã®400ãè¶ ããããã€ã¹ããµããŒããããŠããŸãããããã«ã¯ããšã³ããã€ã³ããIoTããã€ã¹ãã¢ããªã±ãŒã·ã§ã³ãã»ãã¥ãªãã£ããŒã«ãªã©ãå«ãŸããŸãã
ãã©ãããã©ãŒã ã¯ããã¡ã€ã«ã®æŽåæ§ãã¬ãžã¹ããªã®å€æŽãã€ã³ã¹ããŒã«ãããããã°ã©ã ããã®ä»ã®çãããã€ãã³ããªã©ããšã³ããã€ã³ãããæ å ±ãåéããŠåŠçããããšãã§ããŸããFortiSIEMã«ã¯ããªã¢ã«ã¿ã€ã ããã³éå»ã®ã€ãã³ãæ€çŽ¢ã屿§ããã³ããŒã¯ãŒãæ€çŽ¢ãé倧ãªéåã®æ€åºã«äœ¿çšãããåçã«å€æŽããããŠã©ãããªã¹ããªã©ãå«ã詳现ãªåæããŒã«ããããŸãã
ãã®ããŒã«ã¯ãã·ã¹ãã ã®äœ¿ãããããåçã«åäžããããå®å šã«æ©èœããã«ã¹ã¿ãã€ãºå¯èœãªããã·ã¥ããŒãã管çè ã«æäŸããŸããã¹ã©ã€ãã·ã§ãŒãåçããŠã·ã¹ãã ããã©ãŒãã³ã¹ãå®èšŒããããŸããŸãªã¬ããŒããšåæãçæããè²åãã䜿çšããŠéèŠãªã€ãã³ãã匷調ããããšãã§ããŸãã
åŸæžãã®ä»£ããã«
åžå Žã«ã¯éåžžã«å€ãã®SIEMãœãªã¥ãŒã·ã§ã³ãããããã®ã»ãšãã©ã¯éåžžã«æ©èœçã§ããå€ãã®å Žåããããã®æ©èœã¯æšæºã®SIEMå®çŸ©ãè¶ ããŠãããã¯ã©ã€ã¢ã³ãã«ããŸããŸãªãããã¯ãŒã¯ç®¡çããŒã«ãæäŸããŸããããã«ãå€ãã¯ç®±ããåºããŠããã«äœæ¥ã§ãããããã€ã³ã¹ããŒã«ããã³åææ§ææã«æå°éã®ä»å ¥ã§æžã¿ãŸããããããèœãšã穎ããããŸãããããã¯ã1ã€ã®ã¬ãã¥ãŒå ã§è©±ãããšãã§ããªããæ°åã®å°ããªãã©ã¡ãŒã¿ãŒãç°ãªãå¯èœæ§ããããŸãããããã£ãŠãããããã®ç¹å®ã®ã±ãŒã¹ã§ã¯ãäŒæ¥ã®äž»ãªããŒãºã«åºã¥ããŠãœãªã¥ãŒã·ã§ã³ãéžæããã ãã§ãªããçµç¹ã®çްéšãå°æ¥ã®æé·ãèæ ®ã«å ¥ããå¿ èŠããããŸãã
äž»ãªãã€ã³ãã«æ³šç®ãã補åã®è©Šçšçããã¹ãããããšã§ãè€éãããã¥ã¢ã³ã¹ãç¶¿å¯ã«çè§£ããããšãã§ããŸãã幞ããªããšã«ãã»ãšãã©ãã¹ãŠã®ãã³ããŒããã®ãããªæ©äŒãæäŸããŠããŸãã
èè ïŒããããªãŒãªãã·ã§ã³ã³