ãããã¯ãŒã¯äŸµå ¥ãæ€åºãã
åŠç¿ã®ç®ç
ãã®åå ãå®äºãããšã次ã®ããšãã§ããããã«ãªããŸãã
- å
æ¬çãªãããã¯ãŒã¯ã»ãã¥ãªãã£ç£èŠã®éèŠæ§ãæããã
- 䟵å
¥æ€ç¥ããã³é²æ¢æ¹æ³ã«ã€ããŠèª¬æããã
- æµå¯Ÿçãã¹ãã®éèŠæ§ã説æããã
å æ¬çãªãããã¯ãŒã¯ã»ãã¥ãªãã£ç£èŠãå®è£ ãã
çæ§ããåã®ãããã§å¯ãŠãããšãããæ³åããŠãã ãããçåœã®åšå²ã«ã¯æ»ãèŸŒãæ©äŒã窺ã£ãŠããå€ãã®æµãããŸããã ãåã¯é äžãªåå£ãšåºãå ã§å®ãããŠãããããçæ§ã¯å®å¿ããŠç ãããšãã§ããŸãããŸãããåã®æ£éã«ã¯èŠåŒµããé ããåŒäœ¿ããæ£é¢ã®å£ãããããŒã«ããŠããŸãããšãããããæ©ãçæ§ãå¯ãŠããéã«çåããã£ãããšãåã®è£å£ã«ããå°ãããã¢ããæãåºããæ©ãæž¡ã£ãŠé£çºã®ç女ã«äŒãã«è¡ã£ãã®ã§ããçåã¯è£å£ã®ãã¢ã®éµãéãããŸãŸã«ããããããã®äžéšå§çµãèŠãŠããéããããã®æªäººãããã£ãããšãåã«å¿ã³èŸŒãã§ããŸããŸããããããŠãçåãç çã®äžã«çœ®ããŠè¡ã£ãå®é£Ÿåãæã¡å»ã£ãã®ã§ãã

ãã®ã話ã¯ãå æ¬çãªç£èŠã®éèŠæ§ã瀺åããŠããŸãããã®æªäººãšåãããã«ãããã«ãŒãçµç¹ã®ã»ãã¥ãªãã£ãã§ãŒã³ã«ãããŠæã匱ããªã³ã¯ãæªçšããããšããŸãããããã¯ãŒã¯ãä¿è·ããããã«ã¯ã匷åãªå¢çé²åŸ¡ã ãã§ã¯äžååã§ãããã¹ãŠã®åºå ¥ããã€ã³ããç£èŠããå€å±€é²åŸ¡ (倧åãªããŒã¿ãæ å ±ãé²åŸ¡ããããã®å€å±€åãããäžé£ã®é²åŸ¡ã¡ã«ããºã ) ããããã¯ãŒã¯æ¥ç¶éã®ç£èŠãæ¡çšããŠãããã«ãŒã貎éãªãªãœãŒã¹ã«äŸµå ¥ããŠæ¹ãããããçã¿åºãããã§ããªãããã«ããããšãéèŠã§ãããããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã¯ãç£èŠããŒã¿ãåéããŠåæããäŸµå ¥ã®åœ¢è·¡ãããã°ãšã¹ã«ã¬ãŒã·ã§ã³ããŸãããããã¯ãŒã¯å šäœãç£èŠããããšããŠããå€§èŠæš¡ãªçµç¹ã§ã¯å°é£ã§ãã
ãšã³ãžãã¢ã¯ããããã®ç£èŠã容æã«ããããã«ãæªæ¿èªã®ããŒããŠã§ã¢ã«ãããããã¯ãŒã¯ãžã®æ¥ç¶ãæ€ç¥ããŠã¢ã©ãŒããçæããäžå åããããã¯ãããžãŒããŒã«ã䜿çšããŸãããããã®ããŒã«ã¯ãããã¯ãŒã¯ã¢ã¯ã»ã¹å¶åŸ¡ (NAC) ãšåŒã°ããŸããNAC ã¯ãæ¥ç¶ã ID ããã³ã¢ã¯ã»ã¹ç®¡çã·ã¹ãã ãšç §åããããšã§èªèšŒããŸãããããŠãäžé£ã®ãã©ã¡ãŒã¿ãŒãšããªã·ãŒã«åºã¥ããŠã¢ã¯ã»ã¹ãåãå ¥ãããæåŠããããæ±ºå®ããŸããããšãã°ãã²ã¹ããäŒç€Ÿã®ãããã¯ãŒã¯ã«ãã°ãªã³ããããšãããšãNAC ã¯å¥ã®ç»é²ããã³èªèšŒããŒã¿ã«ã«ã²ã¹ãã転éããŠãäŒç€Ÿã®æãéèŠãªãªãœãŒã¹ãžã®å¿åã¢ã¯ã»ã¹ã鲿¢ããŸãã
ããã«ãããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ã®ç£èŠã容æã«ããããã«ãã»ãã¥ãªãã£æ å ±ã€ãã³ã管ç (SIEM) ã·ã¹ãã ãæŽ»çšããŸããSIEM ã¯ä»¥äžã®æ©èœãåããŠããŸãã
- è€æ°ã®ãœãŒã¹ããã®åºåãçµã¿åãããŠã¢ã©ãŒããçæãããããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã®æ³šæãç°åžžãªãããã¯ãŒã¯ã¢ã¯ãã£ããã£ã«åããããŸãã
- 䟵å
¥æ€ç¥ã»é²æ¢ã·ã¹ãã (IDPS ãšåŒã°ããŸãã詳现ã¯åŸã»ã©åŠç¿ããŸã)ããã¡ã€ã¢ãŠã©ãŒã«ãããã³ãããã¯ãŒã¯äžã®ä»ã®ããã€ã¹ããã®ãã° (ãã©ã³ã¶ã¯ã·ã§ã³ãã€ãã³ãã®ã¬ã³ãŒã) ãéèšããŸãã
- ã€ã³ã¿ãŒããããããã³ã« (IP) ãã©ãã£ã㯠(ã€ã³ã¿ãŒãããäžã®ããŒã¿ãããŒ) ã®ããããããŒã®ç£èŠã詳现ãªãã±ããæ€æ»ãè¡ããããããã«ãããŒã¿ãã±ãããææããŠåæå¯èœã«ããŸãã
- ãã®æ
å ±ãè
åšã€ã³ããªãžã§ã³ã¹ (æ»æè
ãšæ¢ç¥ã®æ»æã«é¢ããæ
å ±) ãšçµã¿åãããŠããšã³ãžãã¢ãããŒã¿ãåæããŠäŸµå
¥ãæ€ç¥ããããããã«ããŸãã
- å¢çã ãã§ã¯ãªããããã¯ãŒã¯å
šäœã«ç£èŠãé
眮ããŠãå€å±€é²åŸ¡ãå®è£
ã§ããããã«ããŸãã
次ã®ã»ã¯ã·ã§ã³ã§ã¯ããããã®ããŒã«ã® 1 ã€ã§ãã IDPS ã«ã€ããŠè©³ãã説æããŸãã
äŸµå ¥æ€ç¥ããã³é²æ¢ã䜿çšãã
äŸµå ¥æ€ç¥ãšäŸµå ¥é²æ¢ã¯ãå¥ã ã§å®è£ ããããšãã飿ºããŠå®è£ ããããšãã§ããŸããã©ã¡ããç£èŠæ©èœãæäŸããŸãããããã§éãã確èªããŠãããŸãããã
äŸµå ¥æ€ç¥ã·ã¹ãã (IDS) ã¯ããããã¯ãŒã¯ãžã®ãã«ãŠã§ã¢ã®äŸµå ¥ãšãã£ãã€ã³ã·ãã³ãã®å åãç£èŠããŸããIDS ã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã«äœãããããããšããããšãã¢ã©ãŒãã§ç¥ãããŸããIDS ã¯ãããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®ã©ã¡ãã§ãå®è£ ã§ããŸãããéåžžã¯åž¯åå€ã«é 眮ãããŸããã€ãŸããIDS ã¯ããŒã¿ãã¹ã®å€éšã«ååšãããããã¯ãŒã¯äžã®ãã¹ãŠã®ãã±ããã調æ»ããã®ã§ã¯ãªããããŒã¿ãã±ããã®ã³ããŒã䜿çšããŠãããŒã¿ããµã³ããªã³ã°ããããšã§äŸµå ¥ã調æ»ããŸããã»ãã¥ãªãã£ããµãã«ãŒãªã©ã®ã¹ããŒãã€ãã³ãã«äŸããŠã¿ãŸããããIDS ã¯ãèã«ç«ã£ãŠèг客ãç£èŠããŠããèŠåå¡ã®ãããªãã®ã§ããæªãã人ç©ãã€ãã³ãã«ä¹±å ¥ãããã«ãªããšãèŠåå¡ã¯ç¡ç·ã§å¿æŽãåŒã³ãŸãã
äŸµå ¥é²æ¢ã·ã¹ãã (IPS) ã¯ãIDS ã®äžæ©å ãè¡ããã€ã³ã·ãã³ããæ€åºããã ãã§ã¯ãªããã€ã³ã·ãã³ããæ¢ããŸããããŒã¿ãããŒã«åå¿ããŠå¶åŸ¡ããã®ã§ããããšãã°ãIPS ãæªæã®ããããŒã¿ãã±ãããç¹å®ããå Žåã¯ããã®ãã±ãããç Žæ£ããŠãåä¿¡è ãŸã§å±ããªãããã«ããŸãããŸãããããã¯ãªã¹ãã«ç»é²ãããŠããæå®³ãª IP ã¢ãã¬ã¹ããããã¯ããŸããIPS ã¯éåžžã¯ãã¡ã€ã¢ãŠã©ãŒã«ã®èåŸã«é 眮ãããã€ã³ã©ã€ã³ä¿è·ãè£å®ããŸãã
ã€ã³ã©ã€ã³ä¿è·ãšã¯ãããã€ã¹ãåãåã£ãããŒã¿ãã±ãããæ£åžžã§ããã°ç®çã®å®å ã«è»¢éããæªæãããã°ç Žæ£ãããšããåŠçã§ããããã¯ããµãã«ãŒã¹ã¿ãžã¢ã ã®å ¥å£ã§è©Šåã®èгæŠãã±ããã確èªããåœé ãã±ãããæã£ãŠãã人ã¯å ¥å Žãããªãã®ãšäŒŒãŠããŸãã
ãããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã¯ãæ£åœãªããŒã¿ãç®çã®åä¿¡è ã«å±ãããšãä¿èšŒãã€ã€ãã¹ã«ãŒããããžã®åœ±é¿ãæããªããããããã¯ãŒã¯ãä¿è·ããããã«ååãªç£èŠãå®è¡ããªããã°ãªããŸãããIPS ã¯çããããã±ãããäºèŠçã«åæããŠãããã¯ãããããé å»¶ãçºçããããæ£åœãªãã±ãããééã£ãŠç Žæ£ããããããããšããããŸããIDPS ãé©åã«å®è£ ããã«ã¯ãã»ãã¥ãªãã£ãªã¹ã¯ãšããžãã¹ããŒãºã®ãã©ã³ã¹ãåãå¿ èŠããããŸããã¹ããŒãã€ãã³ãã®èŠåå¡ããã±ããããã¡ãã¡ç¢ºèªããŠå ¥å Žãèš±å¯ããã®ã¯é¢åã«èŠããŸãããèŠåå¡ã¯ãèš±å¯ããã人ã ããå ¥å Žã§ããããã«ããŠãã€ãã³ãã®å®å šãä¿éãããšããéèŠãªåœ¹å²ãæ ã£ãŠããŸãã
ãããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã¯ãçµ±åè åšç®¡ç (UTM) ãšãããã¯ãããžãŒãå©çšããŸãããã®ãã¯ãããžãŒã¯ããã¡ã€ã¢ãŠã©ãŒã« (èš±å¯ãããªãç¹å®çš®å¥ã®ãããã¯ãŒã¯ãã©ãã£ãã¯ããããã¯ããæ©èœ)ããŠã€ã«ã¹å¯ŸçãIDPS ã®å¹ åºãæ©èœãçµ±åããŸããUTM ã¯ãããŒã¿ãã±ãããæ€æ»ããŠç¹å®çš®å¥ã®ãã©ãã£ãã¯ããããã¯ããåŸæ¥ã®ãã¡ã€ã¢ãŠã©ãŒã«ãããäžæ©å ã«é²ããŠããŸãããã¡ã€ã¢ãŠã©ãŒã«ãIPS ããã€ã¹ããŠã€ã«ã¹/ãã«ãŠã§ã¢å¯Ÿçããã®ä»ã®æ©èœãå¥ã ã«ç®¡çããã®ã§ã¯ãªãããããã 1 ã€ã®ã»ãã¥ãªãã£ã¹ã¿ãã¯ã«ãŸãšãã UTM ã¯ãç¹ã«å°èŠæš¡ã®çµç¹ã«é©ããŠããŸãã
ç¿åŸåºŠãã§ãã¯
ã§ã¯ããããŸã§ã«åŠãã å 容ã埩ç¿ããŠãããŸãããããã®ç¿åŸåºŠãã§ãã¯ã¯ç°¡åãªèªå·±èšºæãã¹ãã§ãæ¡ç¹å¯Ÿè±¡ã§ã¯ãããŸãããå·ŠåŽã®æ©èœãå³åŽã®å¯Ÿå¿ããã«ããŽãªã«ãã©ãã°ããŠãã ãããå šé ç®ãçµã³ä»ãããã[éä¿¡] ãã¯ãªãã¯ããŠç¿åŸåºŠããã§ãã¯ããŸããæåããããçŽãã«ã¯ [ãªã»ãã] ãã¯ãªãã¯ããŸãã
ãèŠäºã§ããæ¬¡ã¯ãæµå¯Ÿçãã¹ããçµç¹ã®ã»ãã¥ãªãã£æŠç¥ã«ã©ã®ããã«é©åãããã«ã€ããŠèª¬æããŸãã
æµå¯Ÿçãã¹ãã䜿çšãã
éåžžããããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã¯ãã«ãŒããŒã ã«æå±ããŸãããã«ãŒããŒã ãšã¯ãæ¯æ¥ãããã¯ãŒã¯ã管çããŠãã¢ã»ãããšãŠãŒã¶ãŒãä¿è·ããäŸµå ¥ãæ€ç¥ããã»ãã¥ãªãã£ãããã§ãã·ã§ãã«ã®éãŸãã§ãããããã®ãããã§ãã·ã§ãã«ã¯æ¯æ¥ãããã¯ãŒã¯ã®å®å šãå®ãããšã«éäžããŠããŸãããçµç¹ã§ã¯ãå¥ã®ããŒã ã䜿çšããŠãæ»æè ã®èгç¹ãããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ããã¹ãããå ŽåããããŸãããããã®ããŒã ã¯ã瀟å ã§çµç¹ãããããšãã倿³šãããããšããããŸããæäŸããããµãŒãã¹ã¯ãäŸµå ¥ãã¹ããã¬ããããŒã ã®ç·šæããããŸãã以äžã«è©³ãã説æããŸãã
äŸµå ¥ãã¹ãã§ã¯ãã»ãã¥ãªãã£ãããã§ãã·ã§ãã«ã®ããŒã ãããããã¯ãŒã¯äžã®ã·ã¹ãã ãæ±ããŠãããªã¹ã¯ãšè匱æ§ãç¹å®ããŸããããŒã ã¯ãå€éšãããããã¯ãŒã¯ã芳å¯ããäžæ£ã¢ã¯ã»ã¹ãå¯èœãªè匱æ§ãèŠã€ããŠå©çšããŠãæš©éãææ ŒãããŠãéèŠãªããŒã¿ãçã¿åºããŸãã
éåžžã®äŸµå ¥ãã¹ãã§ã¯ãç¹å®ã®é«äŸ¡å€ã·ã¹ãã ã®ã»ãã¥ãªãã£ããã¹ãããããšã«äž»çŒã眮ãããŸãããã¹ãã®æåŸã§ã¯ãå®è¡ããã¹ããããå©çšã§ããè匱æ§ãã»ãã¥ãªãã£äžã®åŒ±ç¹ãæšå¥šãããç·©åçãã¿ã€ã ã©ã€ã³ã説æããã¬ããŒããäœæããŸãããã«ãŒããŒã ã¯ããããã®æšå¥šäºé ã«åºã¥ããŠã·ã¹ãã ã®ã»ãã¥ãªãã£ã匷åãããããã¯ãŒã¯äžã®ä»ã®ã·ã¹ãã ã«ãåæ§ã®è匱æ§ããªããã確èªããŸãã
ã¬ããããŒã ãå®è¡ããã®ã¯äŸµå ¥ãã¹ãã ãã§ã¯ãããŸãããã¬ããããŒã ã¯ãå šç¯å²ã§ã®å€å±€åæ»æã宿œããåŸæ¥ã®ã·ã¹ãã ã»ãã¥ãªãã£ã®ãã¹ãã«å ããŠãçµç¹å ã®ãŠãŒã¶ãŒãããã»ã¹ãæ»æã«å¯ŸããŠã©ã®ãããæµæã§ããããæž¬å®ããŸããäŸµå ¥ãã¹ãããŒã ã¯ããã£ãã·ã³ã°ã¡ãŒã«ãéä¿¡ããããäžè¬å ¬éãããŠããã·ã¹ãã ãã¹ãã£ã³ããŠé倧ãªè匱æ§ãæ¢ãããããã»ãããã«ãŠã§ã¢ã«ææããã USB ãã©ã€ããåä»ã«æž¡ãããã建ç©å ã®ä¿è·ãããŠããªãããŒãã«æ»æçšã®ããã€ã¹ãæ¥ç¶ããããããŸãããã¹ãã®æåŸã«ã¯ãæè¡çãªä¿®æ£ã«å ããŠãããªã·ãŒãæé ã®æŽæ°ããã¬ãŒãã³ã°ã«é¢ããæšå¥šäºé ãªã©ããŸãšãããã¹ãã®ãµããªãŒãäœæããŸãã
ãã®æµå¯Ÿçãã¹ãã¯ãã»ãã¥ãªãã£ãå®ãããã®éèŠãªã³ã³ããŒãã³ãã§ããè匱æ§ã¹ãã£ã³ãªã©ã®æ©èœã¯ããã«ãŒããŒã ãã»ãã¥ãªãã£äžã®åŒ±ç¹ãèŠã€ããŠããããé©çšããã®ã«åœ¹ç«ã¡ãŸãããæµå¯Ÿçãã¹ãã¯ãå€éšã®èгç¹ããã·ã¹ãã ããããã¯ãŒã¯ããããŠçµç¹ã®ã»ãã¥ãªãã£ã確èªããŸããããŒã ã¯ããã¹ãåã«ãããã¯ãŒã¯ãã·ã¹ãã ã®æ å ±ããããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã«èŠæ±ããããšããããŸãããŸããçºèŠãã匱ç¹ã修埩ããŠããããªãã»ãã¥ãªãã£ã®æ¹åããšã³ãžãã¢ã«æšå¥šããããšããããŸãããããã®ãã¹ãã¯ãæ€èšŒæžã¿ã®ãµãŒãããŒãã£ã«ããçºèŠç¹ãè£ä»ããšããŠãæ¹åã®å¿ èŠæ§ãäžå±€éšã«ã¢ããŒã«ãããœãªã¥ãŒã·ã§ã³å®è£ ãžã®è³åãåŸãããã®éèŠãªææ®µã§ãã
ãŸãšã
äŸµå ¥ãæ€ç¥ããããã®å æ¬çãªã»ãã¥ãªãã£ç£èŠã®éèŠæ§ãšããããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ããã®ç®æšãéæããããã«äœ¿çšããäžè¬çãªããŒã«ã«ã€ããŠåŠç¿ããŸãããã§ã¯ãæ€ç¥ãããäŸµå ¥ã«å¯Ÿå¿ããå Žåã«ããããã¯ãŒã¯ã»ãã¥ãªãã£ãšã³ãžãã¢ã¯ã©ã®ãããªè²¬ä»»ãè² ãã®ã§ãããã? ããã«ã€ããŠã¯ã次ã®åå ã§èª¬æããŸãããµã€ããŒã»ãã¥ãªãã£ã«é¢ãã詳ããæ å ±ã«é¢å¿ãããæ¹ã¯ã Trailhead ã®ãµã€ããŒã»ãã¥ãªãã£ã®åŠç¿ãããåç §ããŠãã ããã
ãªãœãŒã¹
- å€éšãµã€ã: CIS Critical Security Control 3 (CIS Critical Security Control 3: ããŒã¿ä¿è·)Â
- å€éšãµã€ã: CIS Critical Security Control 18: Penetration Testing (CIS Critical Security Control 18: äŸµå ¥ãã¹ã)