ãã㯠Akatsuki Advent Calendar 2019 20æ¥ç®ã®ãã¿ã§ãã
CTOå ¼ã»ãã¥ãªãã£ã®è²¬ä»»è ãæ å½ãã¦ããç°ä¸ã§ããæ ªå¼ä¼ç¤¾ã¢ã«ããã§ã¯ããããã¯ã¼ã¯ã¨ã¨ã³ããã¤ã³ãããã¤ã¹ãä¸é¨ã®ãã«ããµã¼ã以å¤ã®ãªã½ã¼ã¹ãå ¨ã¦ã¯ã©ã¦ãã«ç½®ãã¦ãã¾ãã
ãåºæ¥ãéãã¯ã©ã¦ããå©ç¨ãããã¨ããèãæ¹ã¯äºæ¥ã®æè»æ§ãéè¦ããã¤ã³ãã©ç®¡çã³ã¹ããä¸ãããä¼æ¥ã§ã¯ä¸è¬çã«ãªã£ã¦ãããã¨æãã¾ãã
ã¯ã©ã¦ããã¤ã³ãã©ã«ãããã¨ã§ãã¾ãã»ãã¥ãªãã£ãéè¦ãã¦ããªãä¼ç¤¾ãå¤ãã¨æãã¾ãï¼æã®ã¢ã«ãããããã§ããï¼ãããå人æ å ±ãæ±ãããã«ãªã£ãããäºæ¥ãæåãããã¨ãã£ãäºæ¥ç¶æ³ã®å¤åã«ãã£ã¦æ±ããããã»ãã¥ãªãã£ã¬ãã«ãå¤ãã£ã¦ãã¾ãã
ã»ãã¥ãªãã£ãæèããã«éçºãã¦ããæ代ããç¾å¨ã¾ã§ãæ§ã ãªã»ãã¥ãªãã£å¯¾çãæ¤è¨ããå®æ½ãã¦ãã¾ããã ã»ãã¥ãªãã£ã¯çµç¹ã»ããã»ã¹ã»è¦ç¯/æ³å¾ã»æè¡ã¨æ§ã ãªè¦³ç¹ãããã¾ããããã®è¨äºã§ã¯æè¡é¢ã®å¯¾çã«ç¦ç¹ãå½ã¦ã¦ãã©ã®ãããªå¯¾çããã¦ãããããã®ä¸é¨ãç´¹ä»ãããã¨æãã¾ãã
ID管çã¨SSO
大éæã«è¨ãã°ãã»ãã¥ãªãã£ã管çããã¨ãããã¨ã¯ãä½ãä¿¡ç¨ãããã管çãããã¨ã§ãã ã¯ã©ã¦ããå©ç¨ãã¦ããã¨ãããã¨ã¯ã誰ããèªè¨¼/èªå¯ã管çãã¦ããã¯ãã§ãããä¸å¤®é権çãªIDåºç¤ãç¡ãã¨éè·/ç°åã®æ¨©éè¨å®ã®æ¼ããçºçããããã¤ã³ã·ãã³ãçºçæã«è¿ éãªå¯¾å¿ãã§ããªãçã®åé¡ãçºçãã¾ãã
ID管çã«ã¯ Single source of truth (SSOT) ã¨ããèãæ¹ãã¨ã¦ãéè¦ã§ãã ã¢ã«ããã§ã¯ADãID管çã®SSOTã¨ãã¦ãã¾ããã·ã¹ãã æ§æã¯ä»¥ä¸ã®ã¤ã¡ã¼ã¸ã§ãã
ã·ã¹ãã | å½¹å² |
---|---|
AD | ID管çã®SSOT |
Azure AD | Office365ã©ã¤ã»ã³ã¹ã®èªè¨¼ |
OneLogin | SSO( Single Sign On )ã®ç®¡ç |
Active Directory (AD)
ID管çã®ä¸å¿ã¨ãªããã¼ã¿ã½ã¼ã¹ã§ããå人ãä¸æã«èå¥ããããã®æ å ±ã管çãã¦ãã¾ãã 以ä¸ã®æ å ±ãOUã¨ãã¦ã¡ã³ããã³ã¹ãã¦ããããããã¸ã§ãã³ã°ã®å±æ§ã¨ãã¦å©ç¨å¯è½ã«ãã¦ãã¾ãã
- æå±ä¼ç¤¾
- éç¨å½¢æ
- æå±çµç¹
- è·ä½
詳ããæ¹ã¯ãå ¨é¨ã¯ã©ã¦ããªãJumpCloudã®ãããªCloud Directoryã使ãã»ããè¯ãã®ã§ã¯ï¼ããOktaãOneLoginã®ãããªIdentity Provider (IdP)ãããã°ADã¯ä¸è¦ã§ã¯ï¼ãã¨æãããããã¾ããã å½æã¯ã以ä¸ã®çç±ããããã®æ§æã«ãªãã¾ããã
- ããªã³ã¿ã¼ã®èªè¨¼ãªã©ãADDSèªè¨¼ãã対å¿ãã¦ããªãæ©å¨ããããããADãå¿ è¦
- Microsoft ã©ã¤ã»ã³ã¹ã®ç®¡çã«AzureADãå¿ è¦
- AzureADã¯ç®¡çæ©è½ãä¸è¶³ãã¦ãããIdPã¨ãã¦ã¯OneLoginã®ãããªä¾¿å©ãªãã®ã使ããã
ADã¯å¤ãããããã®ã§ãå¨è¾ºãã¼ã«ãå å®ãã¦ãã¾ããæ¤è¨ããçµæãADManager Plusã¨ãããã¼ã«ã使ããããã£ãã®ã§ããããADã®éç¨ã«å©ç¨ãã¦ãã¾ãã
AzureAD
Azure AD Connect ãå©ç¨ãã¦ãADã§ç®¡çãã¦ããIDãAzure ADã¸åæãã¦ãã¾ãã Microsoft Office365 ã©ã¤ã»ã³ã¹ã®èªè¨¼ã«Azure ADãå¿ é ãªã®ã§ãOfficeã©ã¤ã»ã³ã¹ã®èªè¨¼ã®ããã«ãAzure ADã¨åæãã¦ãã¾ãã
2016å¹´ã«ã¯ã·ã³ã°ã«ãã©ã¬ã¹ããã¡ã¤ã³ãã対å¿ãã¦ããªãã£ãAzure ADããæè¿ã¯IDåºç¤ã¨ãã¦ååãªæ©è½ã¨ç®¡çæ©è½ãæã£ã¦ãã¾ãã ADDSé£æºãAzure ADDSé£æºã«ç½®ãæããAzure ADãID管çã®SSOTã¨ããéç¨ã§ããåé¡ãªããããªæ°ããã¦ãã¾ãã
OneLogin
AWSãGoogleã¢ã«ã¦ã³ããSlackãã©ã¯ã¹ã«ã®ãããªãµã¼ãã¹ã¾ã§ãæ§ã ãªã¯ã©ã¦ããµã¼ãã¹ã¸ã®SSOã«å©ç¨ãã¦ãã¾ãã ã¾ãããããã¯ã¼ã¯æ©å¨ã®ç®¡çç»é¢ããã¼ã«çã®èªç¤¾ã¢ããªã±ã¼ã·ã§ã³ãJenkinsã¸ã®ãã°ã¤ã³çã社å ã¡ã³ãã¼ã®IDãå ã«èªè¨¼ãããå ¨ã¦ã®ãã¼ã«ããOneLoginã§èªè¨¼ããããã«è¨å®ãã¦ãã¾ãã
OneLoginã¯æ©è½è¡¨ã§æ¯è¼ããã¨ãOktaã®ããã«é«ããªãããæ©è½ãå¤ãã¦é åçã§ããæ¡ç¨å½æã¯æ©è½ã®å¤ãã¨ãæ å½è ã®çµé¨ã«ãããOneLoginãé¸å®ãã¾ããã
éç¨ããã¦ãããã¡ã«ç®¡çç»é¢ãå¾®å¦ã«ä½¿ãã¥ããï¼ä¿åæã®ä½è¨ãªãã¤ã¢ãã°ã«ããä¿åã§ããªãã£ãã¨ããäºä¾ãå¤çºãã¦ããããã¼ã«ã®ãã£ã«ã¿ã¼ãã§ããªãããæä½å¯¾è±¡ãééããçï¼ãWebAPIã®APIãã¼ã¯ã³ãã»ã¼å ¨ã¦å¼·ã権éãæ±ããçã®ãç´°ããè¾ããæãã¦ãã¾ãã
ä»ã ã£ããã©ããªæ§æã«ãããï¼
Gartner Magic QuadrantãThe Forrester Waveãè¦ãã¨ãIdPã¨ãã¦ã¯Oktaãæé«è©ä¾¡ãåãã¦ãã¾ãã ãã£ããã¨OneLogin, Ping Identity, Oktaãæ¯è¼æ¤è¨¼ãã¾ãããã管çæ©è½ã®ä½¿ãããããã«ã¹ã¿ã ã¢ããªã®ãã£ã¼ã«ãã«ã¹ã¿ãã¤ãºã対å¿ã¢ããªã±ã¼ã·ã§ã³ã®å¤ããªã©ãOktaãä¸ã¤é ãæãã¦ããæè¦ãããã¾ãã
â» The Forrester Waveã§Leaderã«é¸åºããã¦ããIdaptiveã¯è©¦ãã¦ããããå°ãæ°ã«ãªã£ã¦ãã¾ãã
ãã ãMicrosoft 365 E3 ã©ã¤ã»ã³ã¹ãä¸ã¤æã£ã¦ããã¨PREMIUM P1, Microsoft 365 E5 ã©ã¤ã»ã³ã¹ãä¸ã¤æã£ã¦ããã¨PREMIUM P2ã©ã¤ã»ã³ã¹ãæå¹ã«ãªãAzure ADã¯ã³ã¹ãã¨ããé¢ã§ã¯æé«ã§ãã
ä»ããID管çåºç¤ãæ§ç¯ãããªãã©ãããï¼ã¨åããããã以ä¸ã®ã©ã¡ããã®æ§æãæ¤è¨ãã¾ãã
- 管çé¢ã§ã®ã¹ãã¬ã¹ãæå°éã«ãããå ´åã¯OktaãID管çåºç¤ã¨ãã¦Azure ADã¨é£æºãã
- ã³ã¹ããæå°éã«ãããå ´åã¯Azure ADã ããID管çåºç¤ã¨ãã¦é å¼µã
CASB: Netskope
ã¯ã©ã¦ããæ¥åã®ä¸æ ¸ã¨ãã¦å©ç¨ãã¦ããã¨ãæ¥ã å©ç¨ãããã¯ã©ã¦ããµã¼ãã¹ãå¤ãã£ã¦ãã¦ãã¾ãã ã¢ã¯ã»ã¹å¶å¾¡ãã¦ã³ã³ããã¼ã«ãããã¨ã¯ãããã»ããè¯ãã§ããããæ¥åæ¹åã®ã¹ãã¼ããé ããªãã¾ãããèªç±ãã®é»å®³ã¯Shadow ITãçã¾ããåå ã«ããªãã¾ãã
ã¨ã¯ãããå±éºãªã¯ã©ã¦ãã®å©ç¨ãææ¡ããªãã»è¿½è·¡å¯è½æ§ãç¡ããã¨ããã®ã¯ã»ãã¥ãªãã£ç®¡çè ã®æ æ ¢ã§ãã ã¢ã«ããã§ã¯Netskopeãå©ç¨ãã¦ããªã¹ã¯ãé«ãã¯ã©ã¦ãã®å©ç¨ãç£è¦ããããDLPç£è¦ã¨ãã¦Confidentialãªè³æã社å¤ãããã¦ã³ãã¼ããããã¨ãã®ç£è¦ããã¦ãã¾ãã
ã¨ã³ããã¤ã³ãã»ãã¥ãªãã£
EPP/EDR: CrowdStrike Falcon
ãã®åéã«ã¯æ§ã ãªè£½åãããã¾ãããã¢ã«ããã§ã¯CrowdStrike Falconãå©ç¨ãã¦ãã¾ãã
EDRã®æ©è½ãå«ããã¨ãLinux, Mac, Windows åããç£è¦ãã§ãããã¨ãæ¤ç¥çãé«ããã¨ããããã¯ã¼ã¯é®æçã®å¯¾å¿ãã§ãããã¨ãã¤ã³ã·ãã³ãçºçæã«ãã©ãã§ãã©ããªããã»ã¹ãåãã¦ãããããé¡ã£ã¦æ¤ç´¢ã§ãããã¨ãçãé¸å®ã®çç±ã§ãã
端æ«ç®¡ç: Jamf / Intune
端æ«ãé å¸ããå¾ã«ãã¨ã³ããã¤ã³ãã»ãã¥ãªãã£è£½åãç¡å¹åããã¦ããããã»ãã¥ãªãã£è¨å®ãå¤æ´ããããã¨ãæ³å®ãã¦ããå¿ è¦ãããã¾ãã Macã¯JamfãWindowsã¯Intuneãå©ç¨ãã¦ãFalconãNetskopeãæå¹åããã¦ãããã¨ã確èªãã¦ãã¾ãã
ç£è¦
SIEM : SumoLogic
ADããããã¯ã¼ã¯æ©å¨ã®ãã°ãEDRã®ã¢ã©ã¼ããå種SaaSã®ãã°ããå ¨ã¦éç´ãã¦ãã¾ãã ä¸ç®æã«ãã°ãéç´ããã¦ãããã¨ã§ããOneLoginãã°ã¤ã³æã®ãªã¹ã¯ã¹ã³ã¢ãé«ãã¦ã¼ã¶ãä¸å¯©ãªè¡åããã¦ããªããï¼ãã®æ¤ç´¢ããå ¨ã¦ã®ãªãã£ã¹ããã®Emotetã¸ã®éä¿¡ãã¢ã©ã¼ããããã¨ãã£ãè¨å®ããæ°åã§å¯è½ã«ãªãã¾ãã
ã»ãã¥ãªãã£ã¤ã³ã·ãã³ãçºçæã¯ååã®èª¿æ»é度ãã¨ã¦ãéè¦ãªã®ã§ãSoC/CSIRTã®éç¨ãããä¸ã§ãSIEMã¸ã®ãã°é£æºã¯å¿ é ã ã¨èãã¦ãã¾ãã
ãããã¯ã¼ã¯
ãã¡ã¤ã¢ã¼ã¦ã©ã¼ã«
ãªãã£ã¹ãããã¯ã¼ã¯ã®ãã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã«ã¯FortiGateãå©ç¨ãã¦ãã¾ãã ã¢ã³ãã¦ã£ã«ã¹æ©è½ãIPSã«ããä¾µå ¥é²å¾¡ãWebã³ã³ãã³ããã£ã«ã¿ãªã³ã°ã«ããã»ãã¥ãªãã£ä¸åé¡ã®ãããµã¤ãã®ãããã¯ãæå¹åãã¦ãã¾ãã
ã¾ãããã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã®è¨å®å¤æ´ããã£ãéã«ã¯SumoLogicããSlackã«ã¢ã©ã¼ããé£ã°ãããã«è¨å®ãã¦ãããæå³ãã¬ã»ãã¥ãªãã£ãã¼ã«ãçºçããªãããã«ç£è¦ãã¦ãã¾ãã
ãããã¯ã¼ã¯ç£è¦: Verizon NDR
æ¯çµ¦ç«¯æ«ã«ååãªã»ãã¥ãªãã£å¯¾çãæ½ãã¦ããããã¨ãã£ã¦ããããã¯ã¼ã¯ç£è¦ãããªãã¦è¯ãã¨ããçç±ã«ã¯ãªãã¾ããã LANã±ã¼ãã«ã«ããä¸ç¨æã«æ¥ç¶ãããããã¤ã¹ã®åå¨ãããããã¯ã¼ã¯æ©å¨ã®èå¼±æ§ã¸ã®æ»æãèæ ®ããå¿ è¦ãããã¾ãã
ã¢ã«ããã§ã¯ããããã¯ã¼ã¯ã¬ã¤ã¤ã®ç£è¦ã¨ãã¦ãVerizon NDRãå©ç¨ãã¦ãã¾ãã ãªãã£ã¹ãããã¯ã¼ã¯ã ãã§ãªããAWS/GCPã®IaaSç°å¢ãç£è¦å¯¾è±¡ã¨ãããã¨ã§ãéç¨ç°å¢ãæ»æãããéã«æ¤ç¥ã§ããããã«ãã¦ãã¾ãã
ããªã¢ã¼ã¸ã¾ã§ã¯ ããã³ã´ç¤¾ ã«ãé¡ããã¦ãã¾ãã ã¢ã©ã¼ãæ å ±ãæµãã¦ããSlack channelãããã³ã´ç¤¾ã¨ã®å ±æãã£ã³ãã«ã¨ãã¦ãã¾ãã é«ãæè¡åãæã£ãããã³ã´ç¤¾ã®ã¡ã³ãã¼ã«ããã24æé365æ¥ è¿ éãªå¯¾å¿ããã¦ããã ãã¦ãããã¨ã¦ãå©ãã£ã¦ãã¾ãã
ç§å¿æ å ±ãæ±ãã¯ã©ã¦ããµã¼ãã¹
å ¨ã¦ã®æ¥åãã¯ã©ã¦ãã§ç®¡çãã¦ãããããå©ç¨ããã¦ããã¯ã©ã¦ãã¢ããªã±ã¼ã·ã§ã³ã¯200ç¨åº¦ããã¾ãã éè¦ãªæ å ±ãæ±ããµã¼ãã¹ãæ»æãåããã¨ãã®å½±é¿ã大ãããµã¼ãã¹ãææ¡ãã常ã«ã»ãã¥ãªãã£å¯¾çãæ¹åãã¦ãããã¨ãéè¦ã ã¨èãã¦ãã¾ãã
å©ç¨ãã¦ããä¼ç¤¾ãå¤ãã§ããããµã¼ãã¹ãããã¯ã¢ãããã¦ãã¢ã«ããã§ã®å¯¾çã®å·¥å¤«ãç´¹ä»ãã¾ãã
AWS
AWSã®ã»ãã¥ãªãã£ã¯èãããã¨ãããããããã¾ãããã¯ã©ã¹ã¡ã½ããããã® AWSã§ã®ã»ãã¥ãªãã£å¯¾çå ¨é¨çã åç´ããä¸ç´ã¾ã§ ã¨ããè³æãã¾ã¨ã¾ã£ã¦ãã¦æé«ã§ãã
ã¢ã«ããã§ã¯ä¸è¨ãªã³ã¯ã«ãããããªåºæ¬çãªå¯¾çã«å ãã¦ã
- AWSã¢ã«ã¦ã³ããæãåºããã¿ã¤ãã³ã°ã§ååãªã»ãã¥ãªãã£å¯¾çï¼AWS Config, CloudTrail, SIEMã¸ã®é£æºãªã©ï¼ãæ½ããã¦ããç¶æ ã«ãã
- éç¨ãè¡ãå±ããªãå¤ãAWSã¢ã«ã¦ã³ãã¯çãããã¡ãªã®ã§ãä¸è¦ã«ãªã£ãããªãã¹ãæ©ãã¢ã«ã¦ã³ããã¨åé¤ãã
ã¨ãã¦ãããèå¼±æ§ãçºçããããããªæä½ãè¡ãããå ´åã«ãããã«æ°ä»ããããã«ãã¦ãã¾ãã
ãããAWSã®ã»ãã¥ãªãã£èå¼±æ§ã«è§¦ãã¦ã¿ãã人ã¯ã以ä¸ã®"crackme"ãµã¤ãã«ææ¦ãã¦ã¿ã¦ä¸ãããèå¼±ãªç°å¢ã¯ããã«ç°¡åã«çã¾ãããã¨ããã®ããå®æåºæ¥ãã¨æãã¾ãã
ã¡ã¼ã«: Gmail
Emailã¯ã³ãã¥ãã±ã¼ã·ã§ã³ã®å ¥ãå£ã§ãã®ã§ãæ»æè ã¯ããEmailãéã£ã¦ä¾µå ¥ãå³ãã¾ãã
Gmailã«ã¯ã»ãã¥ãªãã£ãµã³ãããã¯ã¹ã«ããä¸æ£ãªã½ããã¦ã§ã¢ãçºè¦ããæ©è½ãããã¾ãã®ã§ãæå¹åãã¦ãã¾ãã
ã¹ãã¬ã¼ã¸: Google Drive
ä¸è¬å ¬éãã¡ã¤ã«ã¨ãã¦ãªã³ã¯å ±æãããã¨ã¯ã§ããªãè¨å®ã«ãã¦ãã¾ãã ããããããã¡ã¤ã³å ã¸ã®ãªã³ã¯å ±æãã¯æ°è»½ã«ã§ãã¦ãã¾ãã®ãGoogle Driveã®æãã¨ããã§ãã ç¹å®ã®æååãã¿ã¤ãã«åã«å«ããã¡ã¤ã«ããç¹å®ã®å ±æãã©ã¤ãã«å¯¾ãã¦ãå ±æè¨å®ã®ç£è¦ããã¦ãã¾ãã
SIEMã§ç£è¦ãã¦ãè¯ãã®ã§ãããç£æ»ãã°ã®ãã¤ãã¼ãã大ãããã¦ãã¼ã¹ã§ããªãå ´åãããã®ã§ãG Suiteã®ç£æ»ãã°ç»é¢ãããã¢ã©ã¼ããä½æãã¦ãã¾ãã
ã¢ã©ã¼ãã¯ã¡ã¼ã«ã®è»¢éã«ã¼ã«ã§Slackã«éç¥ãããããè¨å®ãã¦ãã¾ãã
GitHub
GitHubã¯å¼·åãªéçºæ¯æ´ãã¼ã«ã§ããã大ããªã»ãã¥ãªãã£ãã¼ã«ã§ãããã¾ãã AWS, GCP, GitHub, Slack çã®APIãã¼ã¯ã³ãGitHub Publicãªãã¸ããªã«æ稿ãã¦ãã¾ãã¨ãããã«ä»äººã«ç¥ããã¦ãã¾ãã¾ãã ä¾ãã°ãhttps://shhgit.darkport.co.uk/ ã¨ãããµã¤ãã§ã¯ãGitHub ã«å ¬éããããã¼ã¯ã³ããªã¢ã«ã¿ã¤ã ã«çºè¦ãããã¨ãã§ãã¾ãã
Publicãªãã¸ããªã¸ã®Pushã«ã ãæ°ãã¤ããã°è¯ããã¨ããã¨ããã§ããªããGitHub Personal Access Tokenãä¸ç¨æã«å ¬éãã¦ãã¾ã£ãããPrivateãªãã¸ããªã¸ã®Collabolatorã®ç»é²ééãã¨ãã£ããã¨ã§ããæ¼æ´©å¯è½æ§ãããã¾ããã¾ããGitHubã¸ã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¯CI/CDç°å¢ã«ä¿åããã¦ãããã¨ãå¤ããJenkinsç°å¢ãã¿ã¼ã²ããã¨ãã¦æ»æãããã¢ã¯ã¿ã¼ãåå¨ãã¾ãã
ã¢ã«ããã§ã¯ãPrivateãªãã¸ããªãææ»ãããã¼ã«ãä½æãã¦ãcommitããã¦ãããã¼ã¯ã³ãæ¢ãåºãã¦ãã¾ãã
Slack
Slackã¯ã¤ã³ãã°ã¬ã¼ã·ã§ã³ãè±å¯ãªãããæ»æè ã«çããããããã¼ã«ã§ãããã¾ãã ç¹ã«Slackã®ã¡ãã»ã¼ã¸å 容ãèªã¿åããã¨ãåºæ¥ãAPIãã¼ã¯ã³ã¯æ éã«ãªãã¹ãã§ãã Slackã¢ããªã¯æ¿èªãå¿ é ã¨ãã¦ããã以ä¸ã®ããªã·ã¼ãå ã«æ¿èªå¯å¦ãå¤æãã¦ãã¾ãã
APIãã¼ã¯ã³ãã¢ããªã®ç¨®é¡ã«ã¤ãã¦ã¯ãhttps://slack.com/intl/ja-jp/help/articles/215770388 ãåèã«ãã¦ä¸ããã aktsk ãä¼ç¤¾åä½ã®ã¯ã¼ã¯ã¹ãã¼ã¹ã«å¯¾ããã¢ããªã¯ã以ä¸ã®æ§ã«å¤æãã¾ãããã®ä»ã¯ã¼ã¯ã¹ãã¼ã¹ã¯ãã¯ã¼ã¯ã¹ãã¼ã¹ç®¡çè ã®å¤æã«ãã¾ãããã¦ãã¾ãã ## å¤é¨ã¢ããªã±ã¼ã·ã§ã³ ### ã¡ãã»ã¼ã¸å 容ãåå¾ã§ããå¤é¨ã¢ã㪠以ä¸ã¹ã³ã¼ããè¦æ±ããå¤é¨ã¢ããªã±ã¼ã·ã§ã³ã¯ååæå¦ãã¾ãã ã¡ãã»ã¼ã¸ãèªããã¹ã³ã¼ãã®ä¸è¦§: bot channels:history conversations:history groups:history im:history mpim:history search:read stars:read ã¡ãã»ã¼ã¸å 容ãåå¾ããå¤é¨ã¢ããªã¯ãä¿¡é ¼ã§ããçºè¡å ãã¤ãé£æºããªããã°ãªããªãçç±ãããå ´åã«éãæ¿èªãã¾ãã®ã§ãç³è«çç±ã詳ãããè¨è¼ä¸ããã ### ãã£ã³ãã«åãDMã®ãªã¹ããåå¾ãããã¨ãã§ããå¤é¨ã¢ã㪠以ä¸ã¹ã³ã¼ããè¦æ±ããã¢ããªã±ã¼ã·ã§ã³ã¯ãå©ç¨ç¨éã«å¿ãã¦æ¿èªå¯å¦ãæ¤è¨ãã¾ããç³è«çç±ã詳ãããè¨è¼ä¸ããã ãã£ã³ãã«ãåå¾ãããã¨ãã§ããã¹ã³ã¼ãã®ä¸è¦§: channels:read groups:read mpim:read im:read ### Slack社ã«ããã¬ãã¥ã¼ãéã£ã¦ããªãå¤é¨ã¢ã㪠Slack社ã«ããã¬ãã¥ã¼ãå®æ½ããã¦ããªãã¢ããªã±ã¼ã·ã§ã³ã«ã¤ãã¦ã¯ãååæ¿èªãã¾ãããã©ããã¦ãå¿ è¦ãªå ´åã¯ãç³è«çç±ããè¨è¼ä¸ããã ## å é¨ï¼èªä½ï¼ã¢ããªã±ã¼ã·ã§ã³ ååã¨ãã¦ãIPå¶éãå¿ é ã¨ãã¾ãã ãã®ä»ã¯å¤é¨ã¢ããªã±ã¼ã·ã§ã³ã®å¤æåºæºã«å¾ãã¾ãã ## Slackã¢ããªä»¥å¤ã®Integration ### ã¬ã¬ã·ã¼ãã¹ããã¼ã¯ã³ ã©ããªçç±ããã£ã¦ããå©ç¨ç¦æ¢ã§ããã¯ã¼ã¯ã¹ãã¼ã¹è¨å®ã§ä¸è¨±å¯ã¨ãã¦ãã¾ãã ### Outgoing Webhook åå¾å ã®ãã£ã³ãã«å¶éãå¿ é ã¨ãã¾ãã ### Bot ã«ã¹ã¿ã ã¤ã³ãã°ã¬ã¼ã·ã§ã³ãããã®ã¦ã¼ã¶ã¼ãã¼ã¯ã³ ã¯éæ¨å¥¨ã§ãã èªä½ã®ãããã¯ãã¹ã³ã¼ããæå°éã«ããå é¨ã¢ããªã±ã¼ã·ã§ã³ã¸ç½®ãæãã¦ä¸ããã ### Slash command, Incoming Webhook ç¹ã«å¶éãã¾ãããç³è«ããã£ããæ¿èªãã¾ãã
ã¾ããSlack Enterprise Gridã®ç£æ»ãã°ãã¢ã¯ã»ã¹ãã°ãSIEMã«é£æºãã¦ãããã¤ã³ã·ãã³ãçºçæã«è¿½è·¡ã§ããããã«ãã¦ãã¾ãã
ãã¼ã¯ã³ã®ç®¡ç
ãã§ãã¯
æ¨çåæ»æã«ãããCyber Kill Chainãå ã«æè¡ç対çãåé¡ãã¦ã¿ã¾ããã ã¯ã©ã¦ãä¸å¿ã«ã·ã¹ãã ãéç¨ãã¦ããä¼ç¤¾ã«ã¨ã£ã¦ã以ä¸ã®ãã§ãã¯é ç®ããåèã«ãªãã°å¹¸ãã§ãã
åµå¯
ä¾µå ¥ã«ä½¿ããããªæ å ±ãåéããè¡çºã§ããä¼æ¥ãµã¤ããSNSãå ¬éãµã¼ããªã©ã調æ»å¯¾è±¡ã«ãªãã¾ãã
[対ç]
ç£è¦ãã¦ããªããéç¨ããã¦ããªãå ´æãããã¨ãä¾µå ¥ãããå±éºæ§ãé«ããªãã¾ããä¸è¦ãªãµã¼ããã¯ã©ã¦ããµã¼ãã¹ã¯åé¤ãã¾ãããã
- ä¸å¤®é権çID管çãã§ãã¦ãããï¼éè·ãç°åã«ã¤ãã¦ãå³æ¥å¯¾å¿ã§ãã¦ãããï¼
- éçºç¨ã®ãµã¼ãçãä¸å¿ è¦ã«ãã¼ãå ¬éãã¦ããªããï¼
- å¤ããµã¼ãã»éç¨ããã¦ããªããµã¼ãã¯ãªããï¼
- CASBã«ãã£ã¦èª°ãã©ã®ãããªã¯ã©ã¦ããµã¼ãã¹ãå©ç¨ãã¦ãããææ¡ãããªã¹ã¯ã管çã§ãã¦ãããï¼
æ¦å¨å
ã¨ã¯ã¹ããã¤ãã³ã¼ãããã«ã¦ã§ã¢ãä½æããã¡ã¼ã«ãSNSã使ã£ã¦éä»ãã¾ãã URLãã¯ãªãã¯ããã¨ãBeEF ãå®è¡ãããå é¨ãããã¯ã¼ã¯ã®èå¼±æ§ãææ¡ããã¨ãã£ãæ»æææ³ãããã¾ãã æè¿ã¯ Emotetã®è¢«å®³ã主ã«Wordãã¡ã¤ã«ã«ãã£ã¦æ¡å¤§ãã¦ããããã¾ãã
[対ç]
ã¡ã¼ã«ã¯ãµã¤ãã¼æ»æã®å ¥ãå£ã¨ãã¦ã¾ã å¤ãå©ç¨ããã¦ãã¾ãã®ã§ã対çãã¾ããããæ»æææ³ã«é¢ããæ å ±ãå¾ã¦ãããã¨ãéè¦ã§ãã
- JPCERTãªã©ä¿¡é ¼ã§ããã³ãã¥ããã£ããã注æåèµ·æ å ±ãå¾ã¦ãããï¼
- ã¡ã¼ã«ã®ãµã³ãããã¯ã¹æ©è½çã«ããããã«ã¦ã§ã¢ããã¦ã³ãã¼ããããåã«éé¢ãã対çãã§ãã¦ãããï¼
- C&Cãµã¼ãããã£ãã·ã³ã°ãµã¤ãã®Webãã£ã«ã¿ãªã³ã°ã¯è¨å®ããã¦ãããï¼
ããªããªã¼
ã¡ã¼ã«ã®æ·»ä»ãã¡ã¤ã«ããã¬ã¸ã¥ã¡ã«ã«ã¢ãã©ã¼ã¸ã¥ããURLçã«ãã£ã¦ããã«ã¦ã§ã¢ã«ææããã¾ãã ãã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ãVPNã«èå¼±æ§ãããã°ãããããä¾µå ¥ãããã®æ®µéã¾ã§é²ã¾ãã¾ãã
[対ç]
ã¨ã³ããã¤ã³ãã»ãã¥ãªãã£ãéè¦ã§ãã
- ã¨ã³ããã¤ã³ãããã¤ã¹ã«EDR製åï¼æä½ã§ãEPP製åï¼ãã¤ã³ã¹ãã¼ã«ããã¦ãããï¼
- ã¨ã³ããã¤ã³ãããã¤ã¹ã®EDR稼åç¶æ³ããJamf/Intuneçã®ããã¤ã¹ç®¡çã½ããã¦ã§ã¢ã§ãã§ãã¯ã§ãã¦ãããï¼
- VPNã¯ç¡å¹åããã¦ãããï¼VPNãå©ç¨ãã¦ããå ´åã¯ãé©åã«éç¨ãããç£è¦ã§ãã¦ãããï¼
ã¨ã¯ã¹ããã¤ã/ä¾µå ¥
ä¾µå ¥ã«æåããPCãããå é¨ãããã¯ã¼ã¯ã®æ§é ãææ¡ããæ©å¯æ å ±ãä¿åããã¦ããå ´æãæ¢ããã¢ã¯ã»ã¹æ¨©éãçã¿åãã¾ãã
[対ç]
å é¨ãããã¯ã¼ã¯ã®æ»æãé²æ¢/æ¤ç¥ããããã®å¯¾çããèå¼±æ§èª¿æ»ãè¡ãã¾ãããã
- IPS/IDSãéç¨ããã¦ãããï¼
- ãã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã¯é©åã«è¨å®ããã¦ãããï¼
- ãããã¯ã¼ã¯ã®ç£è¦ï¼ä¾: C&Cãµã¼ããã©ã³ãµã ã¦ã§ã¢ãç½®ããã¦ãããã¹ãã¸ã®ã¢ã¯ã»ã¹ï¼ãã§ãã¦ãããï¼
- NDRçã®ãããã¯ã¼ã¯ç£è¦ã®è£½åã«ãããã¨ã³ããã¤ã³ãããã¤ã¹ããã®ä¸å¯©ãªéä¿¡ãç£è¦ã§ãã¦ãããï¼
- å®æçãªå é¨ãããã¯ã¼ã¯è¨ºæã«ããã社å ãããã¯ã¼ã¯ããã®èå¼±æ§ãçºè¦ã§ãã¦ãããï¼
- å©ç¨ãã¦ãããããã¯ã¼ã¯æ©å¨ãã½ããã¦ã§ã¢ã®ãã¼ã¸ã§ã³ãææ¡ãã¦ãããè¿ éã«ã»ãã¥ãªãã£ããããé©ç¨ã§ãã¦ãããï¼
æ½ä¼/ç®çã®å®è¡
æ å ±ã®çã¿åºããã·ã¹ãã ã®æ¹ããããã°ã®æ¶å»ãè¡ãã¾ãã
[対ç]
ããã¾ã§Kill chainãé²ãã§ãããäºé²ã¯é£ããã®ã§ãç´ æ©ãæ»æãçºè¦ã§ãããã¨ãéè¦ã§ãã ã¾ãããã°ã®æ¶å»ãé£ããããããã«ãSIEMã«é£æºãã¦ãããã¨ãéè¦ã§ãã
- éè¦ãªæ å ±ãæ±ããã¼ã«ã®ã¢ã¯ã»ã¹ãã°ã¯å ¨ã¦SIEMã«é£æºããã¦ãããï¼
- SIEMã®ã¢ã¯ã»ã¹ãã°ç£è¦ã¯ãç¶ç¶çã«ã¢ãããã¼ãããã¦ãããï¼
- åãã¼ã«ã®ç¹æ¨©ã¦ã¼ã¶ã®ã¢ã¯ãã£ããã£ãS3ã®å ¬éè¨å®ã®å¤æ´ãªã©ãç¹ã«éè¦ãªæä½ãã¢ã©ã¼ãã§ãã¦ãããï¼
- éçºç°å¢ãå¤é¨ããã¢ã¯ã»ã¹å¯è½ãªæ¬çªç°å¢ã«ããEDRåã³ãããã¯ã¼ã¯ç£è¦ãé©ç¨ããã¦ãããï¼
- AWSãGCPã®ç£æ»ãã°ãç£è¦ã§ãã¦ãããï¼ï¼IAMã¦ã¼ã¶ã®ä½æãå½å¤ããã®ã³ã³ã½ã¼ã«ã¢ã¯ã»ã¹ãªã©ãä¸å¯©ãªã¢ã¯ãã£ããã£ãç£è¦ã§ãã¦ãããï¼ï¼