â æ¦è¦ 2021å¹´3æ3æ¥ãå¾ã«ProxyLogonã¨ã®é称ãèå¼±æ§çºè¦è ããå ¬è¡¨ãããExchange Serverã®èå¼±æ§CVE-2021-26855ã¨ãããã«é¢é£ããããã¤ãã®èå¼±æ§ï¼CVE-2021-26857ãCVE-2021-26858ãCVE-2021-27065ï¼ããã§ã«æ»æè ã«ããæªç¨ããã¦ããç¶æ³ã観測ãããå½å å¤ã®å¤ãã®æ©é¢ãã注æåèµ·ãè¡ããã¦ãã¾ãã æ¬èå¼±æ§ãæªç¨ããããã®Attack Surface/æ»æ対象é¢ã§ããExchange Serverã®OWAã®ç»é¢ã«ã¤ãã¦ã¯ããã®æ§è³ªä¸ã¤ã³ã¿ã¼ãããå´ã«ã¢ã¯ã»ã¹å ãå¶éããã«å ¬éããã¦ãã¦ãããã¨ãå¤ããããã¯ä¸çä¸ã®æ»æè ããã¤ã§ãèå¼±ãªãµã¼ããæ»æã§ããã¨ãããã¨ã«ãªãã¾ãããã¤ã¯ãã½ãã社ããæ å ±ãå ¬éãããå½åãæ»æã¯è¦³æ¸¬ããã¦ãããã®ã®éå®çãªãã®ã§ãããã¨ã®è¦æ¹ãããã¾ãããããã®å¾ããªãåºç¯å²ã§ãã§ã«
AlienVault Open Threat Exchange is ä½ï¼ AlienVaultã®Open Threat eXchangeï¼OTXï¼ã¯ãã³ãã¥ããã£ã¼ã§IoC(Indicator of Compromise)ãã®ä»ã®è å¨æ å ±ã交æããããã®ãªã¼ãã³ãªã³ãã¥ããã£ãã¼ã¹ã®ãã©ãããã©ã¼ã ã§ãã¢ã«ã¦ã³ãç»é²ãããã°èª°ã§ãç¡æã§ä½¿ç¨ãããã¨ãã§ããã AlienVaultã¯ãOTXã®ãã©ãããã©ã¼ã 以åããç¡åã§ä½¿ç¨ã§ããSIEMçãªä½ç½®ã¥ãã®OSSIMãã¾ããã®åç¨çã®USMãã¾ããªã¼ãã³ã½ã¼ã¹ã®ãã¹ãåIDSå ¼ãã°IDSã¨ããããOSSECã®ãµãã¼ããªã©æåºãã½ãªã¥ã¼ã·ã§ã³ãæä¾ãã¦ããã ãããç¥ã£ãã®ã¯OSSECããã§ããªãã ãæãååã®ä¼æ¥ãOSSECã®åç¨ãµãã¼ããã¦ããããã ãã¨ããã¨ãããSIEMã¿ãããªãã®ãæã£ã¦ããã¿ããã ããã¨ããã¨ããã§ããã¡ãã使ã£ã¦ã¿
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}