INTELLILINK ãµã¤ãã¼æ¼ç¿ã·ã¹ãã CyberRange
CyberRangeã«ã¤ãã¦
ãµã¤ãã¼ã¬ã³ã¸ã¯ãä»®æ³åºç¤ä¸ã§å®éã®ä¼æ¥ãããã¯ã¼ã¯ã»ãã¹ãããã©ãã£ãã¯ãã¦ã¼ã¶ã¼ã®æåãåç¾ãããç°å¢ã§ãµã¤ãã¼ã»ãã¥ãªãã£äººæè²æã®ããã®ãã¬ã¼ãã³ã°ããããã¨ãã§ãã製åã§ãã
ãµã¤ãã¼ã¬ã³ã¸ã使ç¨ãããã¨ã§ãæ¼ç¿ã®ããã®ç°å¢ãã»ããã¢ããããæéãå¿
è¦ã¨ãããå®å
¨ãªä»®æ³ç°å¢ä¸ã§ãå¤ç¨®å¤æ§ãªã»ãã¥ãªãã£äººæãã¼ã«ã«å¯¾å¿ããè±å¯ãªæ¼ç¿ã·ããªãªã«åãçµããã¨ãã§ãã¾ãã
ããã«ãããå人ã®ã¿ãªããçµç¹ã®ã»ãã¥ãªãã£å¯¾å¿è½åãåä¸ããããã¨ãå¯è½ã§ãã
CyberRangeã¯ããã®ãããªèª²é¡ã解決ãã¾ã
æ¼ç¿ç°å¢ã®ã»ããã¢ããã大å¤
æ¼ç¿ã®ããã®ç°å¢ãä¸ããè¨å®ãããã¨ãªããå®éã®æ¥åã·ã¹ãã ã«å½±é¿ãåã¼ããªãå®å ¨ãªä»®æ³ç°å¢ãæä¾ãã¾ããCyberRangeã§ã¯ãå®å ¨ãªä»®æ³ã®ãµã¤ãã¼æ¼ç¿ç°å¢ä¸ã§ãå®è·µã«è¿ãå½¢ã§å¦ç¿ãããã¨ãã§ãã¾ãã
ãã¾ãã¾ãªã»ãã¥ãªãã£äººæãã¼ã«ã«å¯¾å¿ãããã¬ã¼ãã³ã°ãè¡ããã
ã¤ã³ã·ãã³ãå¯¾å¿æ å½è ã«éå®ãããå¹ åºããã£ãªã¢ãã¹ã«å¯¾å¿ããè±å¯ãªæ¼ç¿ã·ããªãªãç¨æããã¦ãã¾ããCTFãã¬ãããã¼ã ï¼ãã«ã¼ãã¼ã æ¼ç¿ãéãã¦ãå®éã®ãµã¤ãã¼æ»æãæ³å®ãããå®è·µçãªã¹ãã«ã身ã«çãããã¨ãã§ãã¾ãã
ç¹å®ã®åéãã¹ãã«ã«ç¹åãããã¬ã¼ãã³ã°ã宿½ããã
INTELLILINK ãµã¤ãã¼æ¼ç¿ã·ã¹ãã CyberRangeã¯ã夿§ãªãã¼ãºã«å¯¾å¿ãããããè¤æ°ã®æä¾å½¢æ ãããã¾ããSaaSå½¢å¼ã§ã¯ããµãã¹ã¯ãªãã·ã§ã³ã»ã·ããªãªåä½ãå¾é課éå¶ã§ã®ä½¿ç¨ãå¯è½ãªãããã³ã¹ããæãã¤ã¤ãç¹å®ã®åéãã¹ãã«ã®ãã¬ã¼ãã³ã°ã®ã¿ã宿½ãããã¨ãå¯è½ã§ãã
INTELLILINK ãµã¤ãã¼æ¼ç¿ã·ã¹ãã CyberRangeã®ç¹å¾´
INTELLILINK ãµã¤ãã¼æ¼ç¿ã·ã¹ãã CyberRangeã¯ãåãªãæ¼ç¿ã·ã¹ãã ã ãã§ãªããæ¼ç¿ã®ã«ã¹ã¿ãã¤ãºæ©è½ããåããçµ±åã·ã¹ãã ã¢ã¼ããã¯ãã£ã¼ã§æ§æããã¦ãã¾ããã¡ã³ããã³ã¹ãã·ã¹ãã 管çãã«ã¹ã¿ãã¤ãºãè¨å®ã ãã§ã¯ãªãINTELLILINK ãµã¤ãã¼æ¼ç¿ã·ã¹ãã CyberRange以å¤ã®æ©å¨ããããã¯ã¼ã¯ã¸ã®çµ±åã®ãããããªã©ã®æä½æ§ãæ¡å¼µæ§ã«ãåªãã¦ãã¾ãã
å å®ããã»ãã¥ãªãã£äººæè²æã®ãã©ãããã©ã¼ã
ç¾å®ã®ã»ãã¥ãªãã£å±æ©ã«è¿ éãã¤å°éçã«å¯¾å¿ããããã®ã¹ãã«ãçµé¨ããã¼ã ã§ã®å¯¾å¿ãå¦ç¿ããããã®åºç¤ããµã¤ãã¼ã»ãã¥ãªãã£ãæ¯ããå°éå®¶ã¨ãã¦å¿ è¦ã¨ãããç¶ç¶çæ¹åã¡ã«ããºã ããæé«ã¬ãã«ã®æç度ã«éããã¾ã§ã®æè²ç°å¢ãæä¾ãã¾ãã
å人åããã³ãºãªã³ã¨ä¸ç´è ã対象ã¨ãããã¼ã ãã¼ã¹ã®ãã¬ã¼ãã³ã°ç°å¢
å人æ¼ç¿ã§ã¯ã4段éã®é£æåº¦ã®ä¸ããèªåã«åã£ãã¬ãã«ã®å 容ãèªåã®ãã¼ã¹ã§é²ãããã¨ãå¯è½ã§ããã¾ãä¸ç´è åãã«ããã¼ã ãã¼ã¹ã®ãã¤ãããã¯æ¼ç¿ããç¨æãã¦ãã¾ããæ»æãã¼ã ã¨é²å¾¡ãã¼ã ã«åããããã¼ã«ã使ç¨ãããªã¢ã«ã¿ã¤ã ã®æ»é²æ¦ãè¡ãã¾ãã
å¹çæ§ã®é«ããç¾å®çãªæ¼ç¿ã®ã«ã¹ã¿ãã¤ãº
åä¸ã®ãµã¼ãã¼ããé åå
ã®ãããã¯ã¼ã¯å
¨ä½ã¾ã§ãä»®æ³ç°å¢ãç°¡åã«ã»ããã¢ããããæ©è½ãæä¾ãã¾ãã
ãã®æ©è½ã使ããå¤ç¨®å¤æ§ãªç¨éã«å¯¾å¿å¯è½ã§ãã
- ç£æ¥å¶å¾¡ã·ã¹ãã (SCADA)ãéèä¼ç¤¾ã黿°éä¿¡äºæ¥è ã¾ãã¯é»åä¼ç¤¾ãªã©ã®ã¤ã³ãã©ãåç¾ãããã¬ã¼ãã³ã°
- CTF(Capture The Flag)æ¼ç¿
- ãã©ãã£ãã¯ã·ãã¥ã¬ã¼ã¿ã¼ãç¨ããé«åº¦ãªãããã¯ã¼ã¯æ»æã®åç¾
- æªæã®ãããã©ãã£ãã¯ã«ããæ¼ç¿ãã·ãã¥ã¬ã¼ã·ã§ã³
CyberRangeã¯ã¤ã³ã·ãã³ã対å¿ããããã¬ã¼ã·ã§ã³ãã¹ãã ãã§ãªããå¤ç¨®å¤æ§ãªã»ãã¥ãªãã£äººæãã¼ã«ã«å¯¾å¿ããè±å¯ãªæ¼ç¿ã·ããªãªãæä¾ãã¦ãããã¨ã大ããªç¹é·ã§ããåã¦ã¼ã¶ã¼ã®å¦ç¿æç¸¾ã¯ãç±³å½å½ç«æ¨æºæè¡ç ç©¶æï¼NISTï¼ãçå®ãããµã¤ãã¼ã»ãã¥ãªãã£äººæè²æã®ããã®æ¨æºãã¬ã¼ã ã¯ã¼ã¯ã§ããNIST NICEãã¬ã¼ã ã¯ã¼ã¯â»1ã«åºã¥ãã¦è©ä¾¡ããããããå人ããã¼ã ã®ã¹ãã«ã¬ãã«ã客観çã«ææ¡ãããã¨ãå¯è½ã§ãã
CyberRangeã¯GUIãã¼ã¹ã®ã·ããªãªä½ææ©è½ãåãã¦ãããããçµç¹ã®ç¹æ§ããã¼ãºã«å¿ããã«ã¹ã¿ã ã·ããªãªã容æã«è¨è¨ãããã¨ãã§ãã¾ãããã®æ©è½ãæ´»ç¨ãããã¨ã§ãçµç¹åºæã®ã·ã¹ãã æ§æãç¹å®ã®æ¥çãç´é¢ããè å¨ãæ³å®ãããããå®è·µã«è¿ããªã¢ã«ãªæ»æã·ããªãªãåç¾ãããã¨ãã§ãã¾ãã
MITRE ATT&CKâ»2ãã¬ã¼ã ã¯ã¼ã¯ããã³ææ°ã®è å¨ã«å¯¾å¿
æ°è¦ã·ããªãªãå¹´éè¤æ°å追å ãããæ°ãã«çºè¦ãããèå¼±æ§ã«å¯¾å¿ãã¾ããã¤ã³ã·ãã³ã対å¿ããããã¬ã¼ã·ã§ã³ãã¹ãã®ã¿ãªãããå¤ç¨®å¤æ§ãªã»ãã¥ãªãã£äººæãã¼ã«ã«å¯¾å¿ãã¦æ¼ç¿ã·ããªãªãåãã¦ãããMITRE ATT&CK Defenderãè å¨ã¤ã³ããªã¸ã§ã³ã¹ãã³ãã¼ã¨ã®é£æºã«ããã·ããªãªãéçºããã¦ãã¾ãããã®ãããå¸¸ã«ææ°ã®ãµã¤ãã¼æ»æã«å¯¾å¿ããã·ããªãªã§å¦ç¿ããããã¨ãå¯è½ã§ãã
夿§ãªæä¾å½¢æ
CyberRangeã§ã¯ã夿§ãªãã¼ãºã«å¯¾å¿ããããã以ä¸ã®4ã¤ã®æä¾å½¢æ ããç¨æãã¦ãã¾ããã客æ§ãæ±ãããã¼ã¿ã®æ©å¯æ§ãã«ã¹ã¿ãã¤ãºæ§ãç¨éã«å¿ãã¦ãæé©ãªå½¢æ ããé¸ã³ããã ãã¾ãã
SaaSåï¼Cyber Range As a Serviceï¼
ã¤ã³ã¿ã¼ããããä»ãã¦æè»½ã«ãå©ç¨ããã ããå½¢å¼ã§ãããåæè¨å®ãã¡ã³ããã³ã¹ã®æéã軽æ¸ã§ãã¾ããã·ã¹ãã æ§ç¯ãä¸è¦ã§ãããããã³ã¹ããæãã¤ã¤ãä½ããã¼ãã«ã§ãµã¼ãã¹ãéå§ãããã¨ãå¯è½ã§ãã
Hostedåï¼ã客æ§å°ç¨ã®ã¯ã©ã¦ãããã³ãï¼
ãã©ã¤ãã¼ãã®ãµã¤ãã¼ã¬ã³ã¸ç°å¢ã¨ãã¦ã¯ã©ã¦ãä¸ã«ã客æ§å°ç¨ã®ããã³ããè¨ç½®ãããµã¼ãã¹ãæä¾ãã¾ããé«ãã»ãã¥ãªãã£ã確ä¿ããªãããçµç¹ç¬èªã®ã·ããªãªã®æä¾ãåãããã¨ãã§ãããããã«ã¹ã¿ãã¤ãºæ§ã«ãåªãã¦ãã¾ãã
ãªã³ãã¬ãã¹
ãªã³ãã¬ãã¹ã¯ãã客æ§ã®ç°å¢ã«å°ç¨ã®ãã¼ãã¦ã§ã¢ãè¨ç½®ãã¦ãã·ã¹ãã ãæ§ç¯ããå½¢æ ã§ããã»ãã¥ãªãã£ã¬ãã«ãããããã¯ã¼ã¯ã¸ã®æè»ãªå®è£ ãå¯è½ã§ãã
ãã¼ã¿ãã«
èè¡ææ§ã®ããæ©å æã¡è¾¼ã¿å¯è½ãªå°ç¨ã®ã¹ã¼ãã±ã¼ã¹ã«ãCyber Rangeã¤ã³ã¹ãã¼ã«æ¸ã¿ç¹å¥ä»æ§ãã¼ããã½ã³ã³ãªã©ããã¬ã¼ãã³ã°ã«å¿ è¦ãªãã¼ã«ãå ¨ã¦æ ¼ç´ãã¦æä¾ããå½¢æ ã§ããã¤ã³ã¿ã¼ãããã¸ã®ã¢ã¯ã»ã¹ãè¡ããªãç¹æ®ãªç°å¢ã«ããã¦ãããããã¯ã¼ã¯æ©å¨ã追å ãããã¨ãªããå ´æãé¸ã°ãã«ãã¬ã¼ãã³ã°ãã·ãã¥ã¬ã¼ã·ã§ã³ã宿½ãããã¨ãå¯è½ã§ãã
INTELLILINK ãµã¤ãã¼æ¼ç¿ã·ã¹ãã CyberRangeã®ãã¬ã¼ãã³ã°ãã©ãããã©ã¼ã
INTELLILINK ãµã¤ãã¼æ¼ç¿ã·ã¹ãã CyberRangeã使ç¨ãã3ã¤ã®ãã¬ã¼ãã³ã°ç°å¢ã«ã¤ãã¦ããç´¹ä»ãã¾ãã
1. ãµã¤ãã¼ã»ãã¥ãªãã£ãã¬ã¼ãã³ã°
è¬ç¾©è³æã¨ä»®æ³ã³ã³ãã¥ã¼ã¿ã¼ï¼ãããã¯ã¼ã¯ç°å¢ã§æ§æãããè¬ç¾©å½¢å¼ã§ã®ãã¬ã¼ãã³ã°ãæä¾ãã¾ããã»ãã¥ãªãã£ã®åºæ¬æè¡ã«ã¤ãã¦å¹ççã«å¦ç¿ãããã¨ãå¯è½ã§ãã
2.ãµãã¹ã¯ãªãã·ã§ã³ã³ã³ãã³ãã«ããèªç¿å½¢å¼ã®å¦ç¿
å人åãã®ãã³ãºãªã³ãã¬ã¼ãã³ã°ç°å¢ãæä¾ãã¾ããåè¬è ã¯ã4段éã®é£æåº¦ã®ä¸ããèªåã«åã£ãã¬ãã«ã®å 容ãèªåã®ãã¼ã¹ã§é²ãããã¨ãå¯è½ã§ãã
å³1. ãã¬ã¼ãã³ã°åé¡ã®ä¸è¦§
3. ã¬ãããã¼ã ï¼ãã«ã¼ãã¼ã æ¼ç¿
ã¬ããï¼æ»æè å´ï¼ãã¼ã ã¨ãã«ã¼ï¼é²å¾¡å´ï¼ãã¼ã ã«åããã両æ¹ã®æè¡ãå¦ç¿ããããå®éçãªã¤ã³ã·ãã³ã対å¿ãã·ãã¥ã¬ã¼ã·ã§ã³ãããã¨ãã§ãã¾ãã
INTELLILINK ãµã¤ãã¼æ¼ç¿ã·ã¹ãã CyberRangeå°å ¥ï¼éç¨ã®æµã
å½ç¤¾ã§ã¯ãå°å ¥ããéç¨ã¾ã§ä¸è²«ãããµã¼ãã¹ãæä¾ãããã¨ã§ããµã¤ãã¼ã»ãã¥ãªãã£äººæã®è²æããæ¯æ´ãã¾ãã
SaaSåï¼Cyber Range As a Serviceï¼
Hostedåï¼ãªã³ãã¬ãã¹
- â»1NIST NICEãã¬ã¼ã ã¯ã¼ã¯
NIST NICEãã¬ã¼ã ã¯ã¼ã¯ã¨ã¯ããµã¤ãã¼ã»ãã¥ãªãã£ã®è·åãå¿ è¦ãªã¹ãã«ãä½ç³»åãã人æè²æãè·åå®ç¾©ã«æ´»ç¨ãããå½å®¶ã¬ãã«ã®æ¨æºåãããæ çµã¿ã§ãã
https://www.nist.gov/itl/applied-cybersecurity/nice/nice-framework-resource-center - â»2MITRE ATT&CK
MITRE ATT&CKã¯ãããã¤ã¿ã¼ã¢ã¿ãã¯ãã¨èªã¿ã¾ããç±³å½ã®é£é¦æ¿åºãè³éãæä¾ããéå¶å©çµç¹ MITREã«ããå ¬éããã¦ãããèå¼±æ§ãæªç¨ããå®éã®ãµã¤ãã¼æ»æã«ã¤ãã¦ãæ¦è¡ã»æè¡ã»ææ³ã®è¦³ç¹ã§åé¡ãããã¬ãã¸ãã¼ã¹ã§ãã
https://attack.mitre.org/
- â»åååãä¼ç¤¾åãå£ä½åã¯ãä¸è¬ã«å社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã