èŠããã«ã空枯ããéèæ©é¢ãã¢ãã¥ãŒãºã¡ã³ãããŒã¯ãŸã§ãã»ãŒãã¹ãŠãæã£ããæ¬æ Œçã§ããªã倧ããªéœåžããšãã¥ã¬ãŒããããšèšããŸããããã«ãããæ»æè ã¯ãããã³ã°ã¹ãã«ãç€ºãæ©äŒãäžããããé²åŸ¡è ã¯è åšãæ€åºããŠæéããã¹ãã«ã身ã«ä»ããããšãã§ããŸãã
ã§ã¯ãæ å ±ã»ãã¥ãªãã£ã®èгç¹ãããã®æŠããã©ã®ããã«ã芳å¯ãã§ããã®ããšããçåãçããŸãããå®éããã®èšäºã¯ããã®ãããªèгå¯ããã»ã¹ã®æ§ç¯ã®è©³çްãšç§ãã¡ãåŸãçµæã«ã€ããŠã§ãã
ããªãŽã³ã®æäœã劚害ããŠã¯ãªãããã€ãã³ãã®åœ¢åŒã§ã¯æ»ææ€åºãããã¡ã€ã«ã®è©³çްãªèª¿æŽãè¡ãããšãã§ããªãããšãçè§£ãããããNTAã¯ã©ã¹ã®ãœãªã¥ãŒã·ã§ã³ïŒNTA-ãããã¯ãŒã¯ãã©ãã£ãã¯åæïŒãéžæããŸããããããã¯ããããã¯ãŒã¯ãã¬ã¡ããªãŒãåæããããšã§è åšãç¹å®ãããœãªã¥ãŒã·ã§ã³ã§ãã ããŸãã¯ç°¡åã«èšãã°ããããã¯ãŒã¯ãã©ãã£ãã¯ãããã¡ã€ã«ããã®ãããªã·ã¹ãã ã®å®è£ ã¯ãããšãã°ãåŸæ¥ã®äŸµå ¥æ€åºããã³é²æ¢ã·ã¹ãã ã®å®è£ ãããã¯ããã«åçŽã§ã·ãŒã ã¬ã¹ã§ããããã¯ããããã¯ãŒã¯ããããžã倿Žããå¿ èŠããªããšããäºå®ãšããã®ãããªã·ã¹ãã ã®ã³ã¢ãè åšã€ã³ããªãžã§ã³ã¹ããŒã¿ãšçµã¿åãããããã·ã³åŠç¿ã§ãããšããäºå®ã«ãããã®ã§ãããã®ã¢ãããŒãã«ãããã·ã¹ãã ã¯å žåçãªè åšããã°ããç¹å®ã§ããã ãã§ãªããç¹å®ã®æéã«ããã£ãŠãåŠç¿ãããããšãã§ããŸããæ¬¡ã«ãåŸãããç¥èã䜿çšããŠãç°åžžãªãŠãŒã¶ãŒãã·ã¹ãã ãããã³ã¢ããªã±ãŒã·ã§ã³ã®åäœãæ€åºããŸãããŸãããã®ãããªã·ã¹ãã ã¯ãåçŽã«ãã®ã¢ãããŒãã§ã¯ãããããçš®é¡ã®è åšã«é¢ããèŠåã®ç¹ã§ããã€ãºããå€§å¹ ã«å°ãªããå®éã®ã€ã³ã·ãã³ãã®èå¥ã®ç¹ã§ã¯ããã«æ£ç¢ºã§ãããã®ãããã¯ãžã®ãã®çãé è¶³ã§ãç§ã¯çµãããŸããããã«ã€ããŠãã£ãšèªã¿ãã人ã¯ã泚æãæãããšããå§ãããŸã
ãã®è³æã«ã
åœåãç§ã¯æåãªCisco Stealthwatch Enterprise補åã䜿çšããããšã«ããŸãããããã¯ãããŸããŸãªçµç¹ã®ååã®å€ãã«ãã£ãŠæ£åžžã«äœ¿çšãããŠããŸãããããŠãPositiveã®ååã«é»è©±ããŠãå¿ èŠãªããã»ããµããã£ã¹ã¯ã¹ããŒã¹ãä»®æ³ãã·ã³ãªã©ã®æ°ãäŒããããšããŠããŸããããã®ç¬éãå¥åŠãªèããæµ®ãã³ãŸããããã®ãµã€ããŒããªãŽã³ã®äœæã«ã人çããã³æè¡çãªãªãœãŒã¹ãããã€æå ¥ãããããæãåºããŸããããããŠãç§ããããã®ãªãœãŒã¹ã®ããã€ããèŠæ±ãããšã¯èª°ãäºæ³ããŠããªãã£ããšæããŸãããäžæ¹ãç§ã¯ãã®èãããããããããªãã£ãã®ã§ãæ å ±ã»ãã¥ãªãã£ã®çŸä»£çãªãã¬ã³ãã®æ çµã¿ã®äžã§ãã¹ãã«ã¹ãŠã©ããã¯ã©ãŠããšåŒã°ããã¯ã©ãŠããœãªã¥ãŒã·ã§ã³ã«åãæ¿ããããšã«ããŸããããã®ãœãªã¥ãŒã·ã§ã³ã¯ããã©ã€ããŒãã¯ã©ãŠãã®ãã¬ã¡ããªãåéããŠåæã§ãããããã¯ã©ãŠããšåŒã°ããŠãããšèšããããåŸãŸãããã¢ããªã±ãŒã·ã§ã³ããã°ã©ãã³ã°ã€ã³ã¿ãŒãã§ã€ã¹ïŒAPIïŒãä»ããŠãããªãã¯ã¯ã©ãŠãå ã§äœæãããŸããã€ãŸãããã®ãœãªã¥ãŒã·ã§ã³ã®å©ããåããŠãæ å ±ã»ãã¥ãªãã£ã®èгç¹ãããAmazon AWSãMicrosoft AzureãGoogle GCPãããã³Kubernetesã³ã³ããå ã§äœãèµ·ãã£ãŠããããåæã§ããŸãããããä»ãç§ã¯ãã®è£œåã®ããã®å¥ã®ã¢ããªã±ãŒã·ã§ã³ãã€ãŸããã©ã€ããŒããããã¯ãŒã¯ã®ç£èŠãå¿ èŠã§ããããã®å Žåãã»ã³ãµãŒïŒã»ã³ãµãŒïŒã¯ãã®ãããªã°ãªããã«ã€ã³ã¹ããŒã«ãããã ãã§ãã¯ã©ãŠãããŒã¹ã®ç£èŠããã³å¶åŸ¡ã³ã³ãœãŒã«ã«ãã¬ã¡ããªãŒãéä¿¡ããŸããåã®æã§ã¯ãã·ã³ãã«ããšããèšèã䜿çšããŸããããä»åºŠã¯ãããããã«è©³ãã説æããŠãããŸããKubernetesã³ã³ãããåæ§ã§ãããããä»ãç§ã¯ãã®è£œåã®ããã®å¥ã®ã¢ããªã±ãŒã·ã§ã³ãã€ãŸããã©ã€ããŒããããã¯ãŒã¯ã®ç£èŠãå¿ èŠã§ããããã®å Žåãã»ã³ãµãŒïŒã»ã³ãµãŒïŒã¯ãã®ãããªã°ãªããã«ã€ã³ã¹ããŒã«ãããã ãã§ãã¯ã©ãŠãããŒã¹ã®ç£èŠããã³å¶åŸ¡ã³ã³ãœãŒã«ã«ãã¬ã¡ããªãŒãéä¿¡ããŸããåã®æã§ã¯ãã·ã³ãã«ããšããèšèã䜿çšããŸããããä»åºŠã¯ãããããã«è©³ãã説æããŠãããŸããKubernetesã³ã³ãããåæ§ã§ãããããä»ãç§ã¯ãã®è£œåã®ããã®å¥ã®ã¢ããªã±ãŒã·ã§ã³ãã€ãŸããã©ã€ããŒããããã¯ãŒã¯ã®ç£èŠãå¿ èŠã§ããããã®å Žåãã»ã³ãµãŒïŒã»ã³ãµãŒïŒã¯ãã®ãããªã°ãªããã«ã€ã³ã¹ããŒã«ãããã ãã§ãã¯ã©ãŠãããŒã¹ã®ç£èŠããã³å¶åŸ¡ã³ã³ãœãŒã«ã«ãã¬ã¡ããªãŒãéä¿¡ããŸããåã®æã§ã¯ãã·ã³ãã«ããšããèšèã䜿çšããŸããããä»åºŠã¯ãããããã«è©³ãã説æããŠãããŸãã
ã§ã¯ãããã»ã¹ã¯ã©ã®ããã«èŠããŸããïŒ
ãã©ã€ã¢ã«ããªã¯ãšã¹ãããå¿ èŠããããŸããæ°åããããŸãã
ããã«ãªã³ã¯ããŸãã
ãã®åŸãæ°æ¥ä»¥å ã«ããŸããŸãªäŸ¿å©ãªæçŽãå±ãå§ããæåŸã«ããŒã¿ã«ãã¢ã¯ãã£ãåããããšããæçŽãå±ããŸãã
ãã®åŸãå人çšããŒã¿ã«ãååŸããŸãããªã³ã¯å ã¯
cisco-YOUR_CISCO_USERNAME.obsrvbl.comãäŸïŒ cisco-mkader.obsrvbl.comã§ãã
ããã«å ¥ããšãã¡ã€ã³ç»é¢ã衚瀺ããããããããã©ã€ããŒããããã¯ãŒã¯ãç£èŠããããã®ã»ã³ãµãŒä»®æ³ãã·ã³ãããŠã³ããŒãã§ããŸãããã®ä»®æ³ãã·ã³ã®èŠä»¶ã¯ããã»ã©å€§ãããããŸããã2ã€ã®vCPUã2ã®ã¬ãã€ãã®ã¡ã¢ãªãããã³32ã®ã¬ãã€ãã®ãã£ã¹ã¯ã¹ããŒã¹ã§ããäžè¬ã«ãã€ã³ã¹ããŒã«ããã»ã¹ã¯éåžžã«åçŽã§ãããã¹ã¯ããŒã«å¯èœãªé»åæžç±ã®åœ¢åŒã§äœæãããéåžžã«åçŽã§äŸ¿å©ãªããã¥ã¢ã«ã«èšèŒãããŠã ãŸãã
ã»ã³ãµãŒã«ã¯2ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ãããããšãããã«èšããªããã°ãªããŸããã1ã€ã¯ã³ã³ãããŒã«ã³ã³ãœãŒã«ãšã®éä¿¡ã«æ©èœããNetFlowãªã©ã®ãã¬ã¡ããªãããèªäœã§åéããåæã«ããã«å ¥ããã¹ãŠã®ãã©ãã£ãã¯ãç£èŠããŸãã 2ã€ç®ã¯ããã±ããããã£ããã£ããã¢ãŒãïŒç¡å·®å¥ã¢ãŒãïŒã§åäœãããã£ãããããã©ãã£ãã¯ã®ãã¬ã¡ããªãçæã§ããŸããç¹å®ã®ã±ãŒã¹ã§ã¯ãæåã®ã€ã³ã¿ãŒãã§ãŒã¹ã®ã¿ã䜿çšããŸããã
ã€ã³ã¹ããŒã«åŸãã»ã³ãµãŒã¯ã³ã³ãœãŒã«ãé 眮ãããŠããã¯ã©ãŠããŸã§å®è¡ãããŸããããã¯å®éã«ã¯AWSã§ãããçŸããã¡ãã»ãŒãžãçæããŸãã
{"error":"unknown identity","identity":"185.190.117.34"}
ããã¯ãã»ã³ãµãŒãå€ã®äžçã§èªåèªèº«ãèªèããŠãããšèŠãªãIPã¢ãã¬ã¹ãšåãã§ãããäŒæ¥ã®ãã¡ã€ã¢ãŠã©ãŒã«ãã¢ãã¬ã¹å€æãªã©ãçªç ŽããŸãã念ã®ãããã»ã³ãµãŒã«ã¯HTTPãšHTTPãå¿ èŠã§ãããDNSãèšå®ããå¿ èŠããããšããã«èšããŸãã aãäžèšã®ã¡ãã»ãŒãžãåä¿¡ãããããã®ã¢ãã¬ã¹ãååŸããŠãã³ã³ãœãŒã«ã®ã»ã³ãµãŒã®ãªã¹ãã«è¿œå ããå¿ èŠããããŸãã
ãã°ãããããšãã»ã³ãµãŒãç·è²ã«å€ãããŸããããã¯ãã»ã³ãµãŒãã³ã³ãœãŒã«ãžã®æ¥ç¶ã確ç«ããããšãæå³ããŸãã
ãããŠãäžè¬çã«ãã·ã¹ãã ã®ç«ã¡äžãã¯ããã§å®äºããŸããæ¬¡ã®ã¹ãããã¯ãã»ã³ãµãŒèªäœããªãã¹ã³ããããšã«å ããŠããã¬ã¡ããªãœãŒã¹ã远å ããããšã§ãã NetFlowãããã³ã«ã䜿çšããŠãã¬ã¡ããªãåä¿¡ãããå Žåããã®ãµã€ãã¯éåžžã«äŸ¿å©ã§ã ã
ãã®äžã§ãå¿ èŠãªãããã¯ãŒã¯ããã€ã¹ãéžæããããã€ãã®ãã©ã¡ãŒã¿ãå ¥åããŠãæ¢æã®æ§æãååŸã§ã
ãŸããåä¿¡ããæ å ±ããããã¯ãŒã¯ããã€ã¹ã«ã³ããŒããŸããããã§ãã·ã¹ãã ã®æºåãæŽããŸãããããããããã¯ãã§ã«æ©èœãå§ããŠããŸãã
ã¡ãªã¿ã«ããã®ãµã€ãã®Netflowèšå®ã®äŸã¯ãSteathwatchã ãã§ãªãããã®ãããªãã¬ã¡ããªã䜿çšã§ããä»ã®è£œåïŒCisco TetrationãIBM QRadarãªã©ïŒã«ã䜿çšã§ããŸãã
ããã§ãã·ã¹ãã ã®åŸ®èª¿æŽãè¡ãããšãã§ããŸããããŸããŸãªCiscoæ å ±ã»ãã¥ãªãã£è£œåããåäžã®CiscoSecureXç£èŠããã³å¿çã³ã³ãœãŒã«ã§çºçãããã¹ãŠã®ããšã«ã€ããŠç§ã«ã©ã®ããã«éç¥ããããæ¬åœã«èŠãããšæããŸããå®éãSecureXã¯éåžžã«è峿·±ããã®ã§ãããå¥ã®èª¬æã«å€ããŸããäžèšã§èšãã°ãããã¯ã¯ã©ãŠãããŒã¹ã®æ å ±ã»ãã¥ãªãã£ç£èŠã·ã¹ãã ïŒSIEMïŒã調æ»ïŒThreat HuntingïŒã調æ»ãšã€ã³ã·ãã³ããžã®å¯Ÿå¿ããããŠåæã«ããã»ã¹èªååïŒSOARïŒã§ãããã®ã·ã¹ãã ã«ã€ããŠè©³ããçè§£ããããšã匷ããå§ãããŸãããã®ã·ã¹ãã ã¯ãããã©ã«ãã§ãã¹ãŠã®Ciscoæ å ±ã»ãã¥ãªãã£è£œåã«ãæ¥ç¶ããããŠããŸããããŠãããã§ãã®ãããã¯ã«é¢ããå°ãã®ããŒã±ãã£ã³ã° ã
ããã§ããŸãããã®çµ±åãèšå®ããŸããã
åæã«ãã»ãã¥ãªãã£ãµãŒãã¹Cisco UmbrellaãæäŸããããã®ã¯ã©ãŠããã©ãããã©ãŒã ãšã®çµ±åãèšå®ããŸããïŒhttpsïŒ //habr.com/ru/company/jetinfosystems/blog/529174/ã
åãç«ãŠå°ã®äžã§æãè峿·±ãããšããã¹ãŠèµ·ãããšä¿¡ããŠãç§ã¯ããã«ç¹å¥ãªåžæãåºå®ããŸããã§ããããããŠãã®åãç«ãŠå°ãä¿è·ããããšã¯ç§ã®ä»äºã§ã¯ãããŸããã§ããã
ãã®åŸãSecureXã§æ°ããç£èŠã³ã³ãœãŒã«ãèªåã§äœæããŸãããããã¯ãã¹ãŠåèš5åããããããã以äžã§ããã以äžã®ç§ã®SecureXããã®ããã€ãã®åçïŒ
ãã®åŸãèå³ã®ãªãéç¥ããªãã«ããèå³ã®ããéç¥ããªã³ã«ããããšã«ããŸããããããè¡ãããã«ãSWCã³ã³ãœãŒã«ã«æ»ããåãéç¥ãèšå®ããŸã
ããéç¥ããšã«ãéç¥ã®å 容ã察å¿ããè åšãæ€åºããããã«å¿ èŠãªé éæž¬å®æ å ±ã®å鿥æ°ãããã³è åšãããŠã³ããå Žåã®ç¶æ³ã確èªã§ããããšãããã«èª¬æããŸãã MITER ATTïŒCKçšã
ãœãªã¥ãŒã·ã§ã³èªäœãé²åããã«ã€ããŠãæ€åºãããè åšãšé¢é£ããéç¥ã®æ°ã¯çµ¶ããå¢å ããŠããŸããããããç§ã¯ããã«ã€ããŠæ¬åœã«èããå¿ èŠã¯ãããŸãã-圌ããäœãæ°ãããã®ã远å ããã®ã§ãã¯ã©ãŠãã¯ããã«ç§ã®èªç±ã«äœ¿ããããã«ãªããŸãã
AWSãAzureãGCPã¯ã©ãŠããžã®æ»æã«é¢é£ããéç¥ã®ã»ãšãã©ã¯ããã®ããªãŽã³å ã§äœ¿çšãããŠããªãããç¡å¹ã«ãããã©ã€ããŒããããã¯ãŒã¯ãžã®æ»æã«é¢é£ãããã¹ãŠã®éç¥ããªã³ã«ããŸããã
ãŸããå¶åŸ¡ãããããŸããŸãªãµããããã®ç£èŠããªã·ãŒã管çã§ããŸãããŸããç¹ã«é¢å¿ã®ããåœã®ç£èŠãåå¥ã«æå¹ã«ããããšãã§ããŸã
ããã®æç¹ã§ãäžèšã®ããã¹ããèªãã§ããã¹ãŠã®çµ±åãå«ããã·ã¹ãã ã®æ§æã«ãããæéãããã¯ããã«é·ãæéããããããšã«æ°ä»ããŸããã
ä»ãç§ãã¡ã¯äœãèŠãŸãããïŒ
ã¹ã¿ã³ããªãã®åæã«ã¯ãããã€ãã®ä»®æ³ASAvãã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠãã¬ã¡ããªãŒãæäŸãããŠããŸãããããã®åŸããœãŒã¹ã®æ°ããããã«å¢å ããŸããããã¡ã€ã¢ãŠã©ãŒã«ã远å ãããäžå€®ã®ãã©ãã£ãã¯ãããŒã«ãŒããã®Netflowã远å ãããŸããã
æåã®éç¥ã¯éåžžã«è¿ éã«å±ãããæ³åã®ãšããã倿°ã®ã¹ãã£ã³ã«é¢é£ä»ããããŠããŸãããããŠãããããæ¯æããã»ã¹ãèŠãããšãããé¢çœããªããŸãããããã§ã¯ã芳å¯ããã»ã¹å šäœã«ã€ããŠã¯èª¬æããŸããããããã€ãã®äºå®ã«ã€ããŠèª¬æããŸãã第äžã«ããã¹ããµã€ãã§äœãäœã§ãããã«ã€ããŠã®è¯ãæ å ±ãåéããããšãã§ããŸããã
第äºã«ãã€ãã³ãã®èŠæš¡ãè©äŸ¡ããããã«-ã©ã®åœãæã掻çºãªäº€é亀æã§ãããïŒ
å®éããã®ããŒã¿ã衚瀺ããããã®ãã䟿å©ãªåœ¢åŒããããŸãããããã§ã¯ãã詳现ã衚瀺ããããšã«ããŸããã
ãããã£ãŠããã·ã¢ä»¥å€ã®äž»ãªãå€éšãã®åãç«ãŠå°ã®ãŠãŒã¶ãŒã¯ãç±³åœããã€ãããªã©ã³ããã¢ã€ã«ã©ã³ããã€ã³ã°ã©ã³ãããã©ã³ã¹ããã£ã³ã©ã³ããã«ããã§ããããåã¢ã¡ãªã«ãã¢ããªã«ããªãŒã¹ãã©ãªã¢ã®åœã ãå«ãã»ãŒãã¹ãŠã®åœãšã®äº€æµããããŸããã
ãã¡ãããç§ãã¡ã¯èŠãã¢ãã¬ã¹ã®ææè ã確èªã§ããŸãã
ãŸããå¿ èŠã«å¿ããŠãä»ã®æçšãªåæãœãŒã¹ããã¢ãã¬ã¹ ã«ã€ããŠè³ªåããŸãã
ããã«ãããããšãã°ãå€ãã®åœã§MicrosoftãªãœãŒã¹ãšã®æŽ»çºãªããåãã確èªã§ããŸããã
ããã«ãæãã¢ã¯ãã£ããªçžäºäœçšã®è¡šã¯ãæ¥ç¶ã®åçãªå³ã®åœ¢ã§èŠãããšãã§ãããã詳现ãªåæãå¯èœã§ãã
ããããæ»æã®èгç¹ããæ£ç¢ºã«äœãåéããã®ã§ããããã
éç¥ã®ãªã¹ãã¯ããã«ã€ããŠæããŠãããŸãã
ãã®äžéšã以äžã«ç€ºããŸãã åèš117ã®æ»æãç¹å®ãããå€ãã®èŠ³æž¬ã«ãã£ãŠç¢ºèªãããŸããïŒObservablesïŒããã§ã¯ããããã¯ãŒã¯ã¹ãã£ã³ãçãããé·ãã»ãã·ã§ã³ãSMBã®åé¡ããããã¯ãŒã¯ããŒããšãµãŒãã¹ã®èª€ã£ã䜿çšãå¥åŠãªåäœãèŠãããŸãããããã¯ãŒã¯ããŒãããããã®åäœã®äºæããªã倿Žãããã³æ å ±ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã«èŠåããå¿ èŠããããã®ä»ã®ç°åžžã
é¢å¿ã®ããã€ãã³ãããšã«ããããäœã§ããããäœãæªãããäºé²ã®ããã®æšå¥šäºé ãªã©ãè©³çŽ°ãªæ å ±ãåãåãããšãã§ããŸãããã®ãããªè峿·±ãã€ãã³ããããã€ã以äžã«ç€ºãããŠããŸããWindowsã¯ãŒã¯ã¹ããŒã·ã§ã³ã§ã®SSHãµãŒããŒã®äºæããªãèµ·åãšãéæšæºã®ããŒãç¯å²ã®äœ¿çšã§ãããŸããæ§æãããçµ±åã«ãããã€ãã³ãã®èª¬æããSecureX Treat Response調æ»ã³ã³ãœãŒã«ã«çŽæ¥ç§»åããŠããã®ã€ã³ã·ãã³ãã®è©³çްãªåæãè¡ãããšãã§ãããšããäºå®ã«ã泚æãæãããšãã§ããŸãã
ãããã£ãŠããã®å°ãããŠé¢çœããã€ãããã®çµæã«åºã¥ããŠãããã€ãã®çãçµè«ãåºããŸãã
ãŸããPositive Technologiesã¯åªãããµã€ããŒæŒç¿ã宿œããŸãããããããããå åŽãããå°ã芳å¯ããããšã¯éåžžã«è峿·±ãã䟿å©ã§ãç°¡åã§ãã·ã³ãã«ã§ããã
2ã€ç®ã¯ãã¯ã©ãŠãã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯é«éã§ã·ã³ãã«ãã€äŸ¿å©ã§ãããããŠããããããŸã ããããããããããã®éã®çµ±åãèšå®ã§ããå Žåããããéåžžã«å¹æçã§ãã
第äžã«ããã¹ããµã€ãã®åå è ã¯ãMicrosoftã®ãµãŒãã¹ãªã©ã®ã¯ã©ãŠããµãŒãã¹ãç©æ¥µçã«äœ¿çšããŠããŸããã
第4ã«ãããŸããŸãªãããã¯ãŒã¯ãã¬ã¡ããªã®èªååããããã·ã³åæã«ãããäŸµå ¥è ã®èšç»ãããæŽ»åãå«ããæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ããç°¡åã«ç¹å®ã§ããŸãããŸããæ å ±ã»ãã¥ãªãã£ã®ããŒãºã«å¯ŸããŠCisco Stealthwatchãœãªã¥ãŒã·ã§ã³ã广çã«äœ¿çšããããã®ååã«éçºãããã·ããªãªããã§ã«å€æ°ãããšããäºå®ã«æ³šæãæãããšããå§ãããŸããèªè ã®ããããã¯ãããã§åœŒãã®å¥œã¿ã«åã£ãã¹ã¯ãªãããèŠã€ããããšãã§ããŸã ã
ããŠããããŠå°ããªæåŸã®ã³ã¡ã³ã-ãã®èšäºã§ã¯ãIPã¢ãã¬ã¹ããã¡ã€ã³ãã€ã³ã¿ã©ã¯ã·ã§ã³ã®è©³çްãªã©ã®åä¿¡ãªã¹ããæå³çã«è©³çްã«ãªã¹ãããŸããã§ãããPositiveTechnologiesããã®ããªãŽã³ãçµã¿ç«ãŠãã®ã«ã©ãã ãã®åŽåãè²»ãããããçè§£ããäœåºŠã圹ç«ã€ããšãæåŸ ããŠããŸããå°æ¥çã«ç§ãã¡ããããŠãå°æ¥ã®æ»æè ã®çæŽ»ãæ¥œã«ããããšã¯ãããŸããã