Web/DB対çãSecureSphere
Webã·ã¹ãã /DBã«ãããç£è¦ã»ç£æ»ã»é²å¾¡ã®ããã®èªååã¢ãã©ã¤ã¢ã³ã¹ã§ã
SecureSphere®ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ã¸ã®æ»æãæ¤ç¥ã»é²å¾¡ãã¾ããããã«å¤é¨ã»å é¨ããã®ãã¼ã¿ãã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãç£è¦ã»ç£æ»ãããã¨ã§ãå é¨çµ±å¶ã«å½¹ç«ã¤ã¨å ±ã«ä¸æ£ã¢ã¯ã»ã¹ã«ããæ å ±æ¼æ´©ã鲿¢ãã¾ãã
æåã«ãã使¥ãæå°éã«ããèªååæè¡ã«ããã管çè è² æ ã®è»½æ¸ã¨å°å ¥ã»éç¨ã³ã¹ãã®åæ¸ãå®ç¾ãã¾ãã
Webã¢ããªã±ã¼ã·ã§ã³èå¼±æ§å¯¾çã®èª²é¡
Webã¢ããªã±ã¼ã·ã§ã³ã¸ã®æ»æã¯ãä¸è¬çã«å ¬éããã¦ããhttpãã¼ããå©ç¨ããããã徿¥ã®ãããã¯ã¼ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«ã§ã¯æ¤ç¥ã»é²å¾¡ãããã¨ãã§ãã¾ããããã®ãããOSããµã¼ãããã°ã©ã ã®è¨å®ãã»ãã¥ã¢ã«ããã»ãã¥ãªãã£ããããéæé©ç¨ãã¦ããã¨ãã¦ããWebã¢ããªã±ã¼ã·ã§ã³ã«èå¼±æ§ãããã°ããããæ å ±ãæ¼æ´©ãã¦ãã¾ãå¯è½æ§ãããã¾ãã
SecureSphereã®æ¦è¦ã¨æ©è½
SecureSphere製åã©ã¤ã³ããã
- Webã¢ããªã±ã¼ã·ã§ã³ã»ãã¡ã¤ã¢ã¦ã©ã¼ã«Web Application Firewallï¼WAFï¼
- Webãµã¼ãä¸ã§ç¨¼åããWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ãçã£ãæ»æãæ¤ç¥ã»é®æãã¾ãã
- Webãµã¼ãã®æåã§æ»æãé²å¾¡ãããããæ¹ä¿®ã¾ã§ã®æéãããã¯æ¹ä¿®å°é£ãªWebã·ã¹ãã ãè·ããã¨ãã§ãã¾ãã
-
- ãã©ãã¯ãªã¹ãã«ç¸å½ãããææ°æ»æãã¿ã¼ã³ãã¯ã¼ã ã®ã·ã°ããã£ãèªåæ´æ°ããæ¢ç¥ã®æ»æãé²å¾¡ãã¾ãã
- ãã¯ã¤ããªã¹ãã«ç¸å½ãããã¢ããªã±ã¼ã·ã§ã³ãã¨ã«ç°ãªãURLã»ãã©ã¡ã¼ã¿ã»ãã©ã¼ã ãã£ã¼ã«ããªã©ãèªåå¦ç¿ããããªã·ã¼ãèªåçæãã¾ããå®ç¾©ããããªã·ã¼ã«ããããªãéä¿¡ãæé¤ãããã¨ã§ãæªç¥ã®æ»æãé²å¾¡ãã¾ãã
- ãã¼ã¿ãã¼ã¹ç£æ»ã·ã¹ãã Database Activity Monitoringï¼DAMï¼
- ãã¼ã¿ãã¼ã¹ã·ã¹ãã ã»ã¤ã³ãã©ã®èå¼±æ§ãè©ä¾¡ãããã¼ã¿ãã¼ã¹ã¸ã®ã¢ã¯ã»ã¹è¡çºãç£è¦ã»è¨é²ãã¾ãã
- ç£æ»ãã°ãé©åã«ç®¡çã»ä¿ç®¡ãããã¨ãã§ããå é¨çµ±å¶ã«ãæå¹ã§ãã
-
- DBã¸ã®ã¢ã¯ã»ã¹ããã³ã¬ã¹ãã³ã¹ãå ¨ã¦ç£è¦ã»è¨é²ãã¾ãã
- ã¢ã¯ã»ã¹ããã¢ããªã±ã¼ã·ã§ã³ã®ã¿ãªããããã¤èª°ãã©ã®ãã¼ã¿ã«ã¢ã¯ã»ã¹ããããç¹å®ãè¨é²ãããã¨ãã§ãã¾ãã
- å é¨é¢ä¿è ã®TelnetãSSHã¢ã¯ã»ã¹ã¾ã§ãæ¥å¸¸ã®å é¨ã»å¤é¨ã¢ã¯ã»ã¹ãèªåå¦ç¿ããèªå使ããããããã¡ã¤ã«ããã¨ã«ãç°å¸¸ã¢ã¯ã»ã¹ãå¦ããå¤æãæ¤ç¥ã»éç¥ãã¾ãã
- ç±³å½SOXãPCIDSSãHIPAAæºæ ã¬ãã¼ããè¦ååæã¬ãã¼ããªã©70種é¡ä»¥ä¸ã®ã¬ãã¼ãåºåãå¯è½ã§ãã
- ç£æ»ãã°ã¯ãã¡ã¼ã«é ä¿¡ãHTMLå½¢å¼ãCSVå½¢å¼ãPDFå½¢å¼ã«ããåºåãå¯è½ã§ãã
- ãã¼ã¿ãã¼ã¹é²å¾¡ã·ã¹ãã Database Firewallï¼DBFï¼
- Webã¢ããªã±ã¼ã·ã§ã³ãçµç±ããå¤é¨ããã®æ»æã¨ãå é¨ããã®ä¸æ£ã¢ã¯ã»ã¹ã«ããæ å ±æ¼æ´©ãããã¼ã¿ãã¼ã¹ãè·ãã¾ãã
- ç£è¦ã»ç£æ»æ©è½ã«å ãã䏿£ã¢ã¯ã»ã¹ãæ£ç¢ºã«å³æé®æããé²å¾¡æ©è½ãæä¾ãã¾ããï¼WAFã¨DAMã®æ©è½ãå å«ï¼
-
- SQLãããã³ã«ç°å¸¸æ¤ç¥ãæ¢ç¥ã®æ»æãç¶²ç¾ ãããã©ãã¯ãªã¹ãã¨ãèªåçæãããã¦ã¼ã¶ãããã¡ã¤ã«ã«ãããã¯ã¤ããªã¹ããããã«è¤æ°ã¤ãã³ããçµ±åçã«ç¸é¢åæãããã¨ã§ãã¦ã¼ã¶ã®ç¡å®³ãªè¡çºãå¦ããç¬æã«å¤æãã䏿£ã¢ã¯ã»ã¹ã峿鮿ãã¾ãã
- èªåã¦ã¼ã¶ãããã¡ã¤ã«ã«ããããªã·ã¼è¨å®ã«å ãã管çè ãä»»æã«ã«ã¹ã¿ã ããªã·ã¼ã使ããæ©å¯ãã¼ã¿å©ç¨è ãèå¥ãã¢ã¯ã»ã¹å¶å¾¡ããäºãå¯è½ã§ãã(ãã¡ã¤ã«ã«å¯¾ããã¢ã¯ã»ã¹å¶éã»IDã®ä¸æ£ä½¿ç¨é²æ¢ã»å¤é¨ãããã¯ã¼ã¯ããã®ä¸æ£ä¾µå ¥é²æ¢ãªã©)
SecureSphereã®æ ¸ã¨ãªãä¸»ãªæ©è½
- ãã¤ãããã¯ãããã¡ã¤ãªã³ã°æè¡
-
- ã¦ã¼ã¶ã¨Webãµã¼ããããã³ãã¼ã¿ãã¼ã¹éãã¹ã¦ã®ç¸äºéä¿¡ãèªåçã«ã¢ãã¿ãªã³ã°ããã¢ããªã±ã¼ã·ã§ã³ã®æ§æãããã³æ£å¸¸ãªãµãã¾ãããããã¡ã¤ã«ã¨ãã¦æ§ç¯ãã¾ãã
- å®éã®ãã©ãã£ãã¯ã¨ãããã¡ã¤ã«ã®æ¯è¼ã«ãããæ½å¨çã«æªæã®ããæ§ã ãªç¨®é¡ã®è¡çºãèå¥ãé²å¾¡ãã¾ãã
- ç¶ç¶çãªå¦ç¿ã¢ã«ã´ãªãºã ã«ãããã¢ããªã±ã¼ã·ã§ã³ã®å¤æ´ãèªåçã«æ¤ç¥ã§ãããããæåã«ãã調æ´ãè¨å®å¤æ´ã¯æä½éã§æ¸ã¿ã¾ãã
- ã¦ããã¼ãµã«ã¦ã¼ã¶ãã©ããã³ã°æè¡
-
- Webéä¿¡ã¨DBéä¿¡ãç¸é¢åæããWebã¢ããªã±ã¼ã·ã§ã³ã®ãã°ã¤ã³IDã¨DBã¸ã®ã¢ã¯ã»ã¹ãé¢é£ä»ãã¾ãã
- 徿¥ãWebã¢ããªã±ã¼ã·ã§ã³ã¾ã§ã®è¿½è·¡ã®ã¿å¯è½ã ã£ãDBã¸ã®ã¢ã¯ã»ã¹ã«ã¤ãã¦ãã¦ã¼ã¶ã¾ã§ç¹å®ãããã¨ãã§ãã¾ãã
- 主è¦ãªãã¼ã¿ãã¼ã¹ããã³Oracle EBSãSAPãå«ãæ§ã ãªWebã¢ããªã±ã¼ã·ã§ã³ããµãã¼ããã¦ãã¾ãã
- WAF Web Application Firewall
- DAM Database Activity Monitoring
- DBF Database Firewall
SecureSphereè¨ç½®ä¾
ãã³ã¤ã³ã©ã¤ã³ã»ã¹ããã¡æ§æï¼DAMã«å¯¾å¿ï¼
- ãããã¯ã¼ã¯ã忢ããã«ã¹ããã¡é ç½®å¯è½
- æ¢åç°å¢å¤æ´ä¸è¦ï¼IPã¢ãã¬ã¹ä¸è¦ï¼
- æ¤è¨¼æãå°å ¥åæã«æé©
- è¤æ°ã»ã°ã¡ã³ããä¸å
管ç
â» ã¿ãããã¹ã¤ãããªã©SPANãã¼ããå¿ è¦
ã¤ã³ã©ã¤ã³ã»ããªãã¸æ§æï¼WAFï¼DBFã«å¯¾å¿ï¼
- æ¢åç°å¢å¤æ´ä¸è¦ï¼IPã¢ãã¬ã¹ä¸è¦ï¼
- æ¤ç¥ã®ã¿ã®ã·ãã¥ã¬ã¼ã·ã§ã³ã¢ã¼ãã«ããæ¤è¨¼ãå¯è½
- æ¤è¨¼å¾ãé²å¾¡ã¢ã¼ãã«åãæ¿ã鮿éå§
- ãã§ã¤ã«ãªã¼ãã³æ©è½ã«ããå¯ç¨æ§ç¶æ
SecureSphereå°å ¥ã®æµã
äºåãã¢ãªã³ã° | 試é¨å°å ¥ | æ¬çªå°å ¥ |
---|---|---|
ã客æ§ã®ã»ãã¥ãªãã£ç¶æ³ããã¢ãªã³ã°ãã¾ããåå¥ã®ç£è¦æ å ±ãåéã»åæãã¾ãã | ã»æ¤ç¥ã®ã¿ã®ã¢ã¼ãã§è©¦é¨çã«å°å
¥ãã¾ãã ã»èªåå¦ç¿ã«ãããããã¡ã¤ã«ã使ãã¾ããï¼1ã2é±éç¨åº¦ï¼ |
ã»è©¦é¨çµæãåºã«ããªã·ã¼ãçå®/è¨å®ãã¾ãã ã»é²å¾¡ã¢ã¼ãã«åãæ¿ãéç¨ãéå§ãã¾ãã |
â» SecureSphereã¯ãImperva社ã®ç»é²åæ¨ã§ãã
â» ãã®ä»ãè¨è¼ããã¦ããä¼ç¤¾åã製ååããµã¼ãã¹åçã¯ãä¸è¬ã«å社ã®åæ¨ã§ãã