MITRE ATT&CK ãã®5 ï½ ãã¼ã¸ã§ã³7ã¸ã®ãã¼ã¸ã§ã³ã¢ããã®æ¦è¦ ï½
MITRE ATT&CKã®è§£èª¬ã®ãã®1ãããã®4ã¾ã§å ¬éãã¦ããâ °ããããã®ã³ã©ã ã¯ãMITRE ATT&CK ãã¼ã¸ã§ã³6ãåºã«è§£èª¬ãããã2020å¹´7æ8æ¥ã«ãã¼ã¸ã§ã³7ãå ¬éããããæ¬å·ã§ã¯ãMITRE ATT&CKã®Enterpriseã«é¢ãããã¼ã¸ã§ã³6ã¨ãã¼ã¸ã§ã³7ã®ä¸»ãªå¤æ´ç¹ã«ã¤ãã¦è§£èª¬ããã
1. ãã¼ã¸ã§ã³ã¢ããã®çµç·¯
MITRE ATT&CK ãã¼ã¸ã§ã³6â ±ï¼ä»¥éããã¼ã¸ã§ã³6ã¨å¼ã¶ï¼ã2019å¹´10æ24æ¥ã«å ¬éããããã®å¾ãæ»æè ã°ã«ã¼ãã®è¿½å ã¨ã¨ãã«ãæ°ããæ»æææ³ãæ»æã®ã½ããã¦ã§ã¢ãçºè¦ããããã®å¯¾å¦æ¹æ³ãå ¬éããã¦ããã2020å¹´7æ8æ¥ã«ãMITRE ATT&CK ãã¼ã¸ã§ã³7â ²ï¼ä»¥éããã¼ã¸ã§ã³7ã¨å¼ã¶ï¼ãå ¬éããããã¨ã³ã¿ã¼ãã©ã¤ãºï¼ä¼æ¥ï¼ã対象ã¨ãããã¼ã¸ã§ã³7ã§ã¯ãå¾æ¥ã®ãã¯ããã¯ã156ã®ãã¯ããã¯ï¼266ããåæ¸ï¼ã¨272ã®ãµããã¯ããã¯ã«åé¡ããä½ç³»ãè¦ç´ããã®ã大ããªå¤æ´ç¹ã§ãããæ¬ã³ã©ã ã§ã¯ãã¨ã³ã¿ã¼ãã©ã¤ãºï¼ä¼æ¥ï¼åãã®MITRE ATT&CKã«çç®ãã¦è§£èª¬ããã
2. MITRE ATT&CKã®å¤æ´ç¹
2.1 主ãªå¤æ´ç¹
ãã¼ã¸ã§ã³7ã®Matrixãå³1示ãã
å³1ããã¼ã¸ã§ã³ï¼ã®Matrix
ãã¼ã¸ã§ã³7ã§ã¯ãæ¦è¡ããã¯ããã¯ãã½ããã¦ã§ã¢ãæ»æè ã°ã«ã¼ããç·©åçã«ã¤ãã¦ã次ã®ãããªå¤æ´ãè¡ã£ãã
- â æ¦è¡(Tactics)
- ã¨ã³ã¿ã¼ãã©ã¤ãºï¼ä¼æ¥ï¼ç¨ã®ãã¼ã¸ã§ã³7ã§ã¯ãæ¦è¡(Tactics)ã®å¤æ´ã¯ãªãã
- â¡ ãã¯ããã¯(Technique)
-
ãã¼ã¸ã§ã³6ã®ãã¯ããã¯ã§ã¯ãç²åº¦ã¬ãã«ã®ç°ãªããã¯ããã¯ãæ··å¨ãã¦ã¨ããææãããã¦ããããã¯ããã¯(Technique)ã®å¤§ããªå¤æ´ç¹ã¯ããµããã¯ããã¯ã追å ããããã¯ããã¯ã¨ãµããã¯ããã¯ã«ååé¡ãããç¹ã§ããããã¯ããã¯ã«å¯¾ãã¦ã次ã®ãããªå¤æ´ãè¡ã£ãã
- ãã¯ããã¯ã®ã¾ã¾ç¶ç¶
- ãã¯ããã¯ããµããã¯ããã¯ã«å¤æ´
- è¤æ°ã®ãã¯ããã¯ãçµ±åãã¦æ°ãããµããã¯ããã¯ã«å¤æ´
- 1ã¤ä»¥ä¸ã®ãã¯ããã¯ãçµ±åãã¦æ°ãããã¯ããã¯ã«å¤æ´
- æ¢åã®ãã¯ããã¯ã«çµ±å
- éæ¨å¥¨
- è¤æ°ã®ãµããã¯ããã¯ã«åå²
ãªãããã¯ããã¯ã¯ãæ»æè ãæ¦è¡çãªç®æ¨ãéæããããã«åãåºç¯ãªè¡åã表ãã®ã«å¯¾ãããµããã¯ããã¯ã¯ããå ·ä½çãªæ»æè ã®è¡åã表ãããã«è¦ç´ããè¡ã£ããä¾ãã°ããã¼ã¸ã§ã³6ã®åæã¢ã¯ã»ã¹(Initial Access)ã§ã¯ã3種é¡ã®ãã£ãã·ã³ã°æ»æããã¯ããã¯ã¨ãã¦è¨å®ããã¦ãã¾ããããã¼ã¸ã§ã³7ã§ã¯ããã£ãã·ã³ã°ã¨ãããã¯ããã¯ãè¨å®ãããã®ãã¯ããã¯ã«ã3種é¡ã®ãã£ãã·ã³ã°æ»æããµããã¯ããã¯ã¨ãã¦è¨å®ããã
- ⢠ã½ããã¦ã§ã¢(Software)
- ã½ããã¦ã§ã¢(Software)ã«ããã¦ã¯ãæ»æè ã°ã«ã¼ãã«ãã£ã¦æ»æã«ç¨ããããã½ããã¦ã§ã¢ã®è¿½å ãè¡ã£ãã
- ⣠æ»æè ã°ã«ã¼ã(Groups)
- æ»æè ã°ã«ã¼ã(Groups)ã«ããã¦ã¯ãæ°ãã«åºç¾ããã°ã«ã¼ãã®è¿½å ãè¡ã£ãã
- ⤠緩åç(Mitigations)
- ç·©åç(Mitigations)ã«ããã¦ã¯ãæ°è¦è¿½å ã¯ãªããç·©åçã®æ´æ°ãåç §ãããã¯ããã¯ã¾ãã¯ãµããã¯ããã¯ã®çªå·ãªã©å¤æ´ãè¡ã£ãã
ãããã®å¤æ´ã®æ¦è¦ããUpdates - July 2020â ³ããåºã«æ´çãããåé¡ã¨ãã¦ãæ°è¦è¿½å ãå¤æ´ã軽微ãªå¤æ´ãéæ¨å¥¨çï¼å¤æ´ã«ãã使ç¨ããªããªã£ãé ç®ãå«ãï¼ã¨ãã¦æ´çããçµæã表1ã«ç¤ºãã
ãã¼ã¸ã§ã³6ãããã¼ã¸ã§ã³7ã¸ã®å¤æ´æ° | è¨å®æ° | |||||
---|---|---|---|---|---|---|
æ°è¦è¿½å (addition) |
å¤æ´ (change) |
軽微ãªå¤æ´ (minor change) |
éæ¨å¥¨ç (Deprecate) |
ãã¼ã¸ã§ã³6 | ãã¼ã¸ã§ã³7 | |
æ¦è¡ (Tactics) |
V6ããã®å¤æ´ã¯ãªã | 12 | 12 | |||
ãã¯ãã㯠(Technique) |
302 ãã¯ããã¯ã»ãµããã¯ããã¯ãå«ã |
91 ãã¯ããã¯ã»ãµããã¯ããã¯ãå«ã |
14 ãã¯ããã¯ã»ãµããã¯ããã¯ãå«ã |
140 | 266 | 156/272(*) |
ã½ããã¦ã§ã¢ (Software) |
47 | 317 | 0 | 0 | 414 | 477 |
æ»æè
ã°ã«ã¼ã (Groups) |
14 | 80 | 2 | 1 | 94 | 107 |
ç·©åç (Mitigations) |
0 | 20 | 4 | 0 | 41 | 41 |
*ï¼ãã¯ããã¯æ°/ãµããã¯ããã¯æ°
大ããªå¤æ´ã¯ããµããã¯ããã¯ã®å°å ¥ã§ããããã¼ã¸ã§ã³6ã¨ãã¼ã¸ã§ã³7ã®æ¦è¡ã«å¯¾ãããã¯ããã¯ã¨ãµããã¯ããã¯ã®æ°ã表2ã«ç¤ºãã
表2ãè¨å®ãããã¯ããã¯ããã³ãµããã¯ããã¯æ°
åæã¢ã¯ã»ã¹(Initial Access)ãä¾ã«ããã¼ã¸ã§ã³6ã¨ãã¼ã¸ã§ã³7ã®å¯¾å¿ãå³2ã«ç¤ºãã1対1ã«å¯¾å¿ãããã¯ããã¯ãè¤æ°ã®ãã¯ããã¯ããµããã¯ããã¯ã«ãã¦æ°ãã«ãµããã¯ããã¯åãä»ä¸ãããã¼ã¸ã§ã³7ã¨ãã¦è¨å®ããã
å³2ããã¼ã¸ã§ã³6ã¨ãã¼ã¸ã§ã³7ã®ãã¯ããã¯ã®å¯¾å¿é¢ä¿ã®ä¾
2.2 å¤æ´ã¸ã®å¯¾å¿æ¹æ³
å¾æ¥ããã¯ããã¯ã¯T1055ã®ããã«ãT****ã®å½¢å¼ã§çªå·ãããããã®ãã¯ããã¯ã«ä»ä¸ããã¦ããããµããã¯ããã¯ã«ã¯ãå
ã¨ãªããã¯ããã¯ã«æçªå·ãä»ä¸ããã¦è¡¨ããã¦ãããä¾ãã°T1055.001ã®ããã«ãT****.***ã®å½¢å¼ã§çªå·ããµããã¯ããã¯ãä¸æã«èå¥ã§ããããã¼ã¸ã§ã³6ãããã¼ã¸ã§ã³7ã¸ã®å¤æ´ã§ã¯ãçªå·ã®å¤æ´ãæ°è¦å²å½ãªã©ãããããããã®å¯¾å¿é¢ä¿ãcsvãã¡ã¤ã«ï¼zipå½¢å¼â
´ï¼ã§å
¬éãã¦ããããã®å¯¾å¿é¢ä¿ã¯ã12ã®æ¦è¡(Tactics)ãã¨ã«ãã¼ã¸ã§ã³6ã§ä½¿ããã¦ãããã¯ããã¯ã¨ãã¼ã¸ã§ã³7ã§ã®ãã¯ããã¯ã¾ãã¯ãµããã¯ããã¯çªå·ãããã³æ°ãã追å ããããã¯ããã¯ããã³ãµããã¯ããã¯ãã¨ã«ãæ°ãã追å ããããã¯ããã¯ã¾ãã¯ãµããã¯ããã¯ã®çªå·ãæ´çããã¦ããããããã®ãã¡ã¤ã«ãåç
§ãã¦ããã¼ã¸ã§ã³7ã¸ã®å¯¾å¿ãåããã
表3ã«åæã¢ã¯ã»ã¹(Initial Access)ã®å¯¾å¿é¢ä¿ã表ããã¡ã¤ã«ã®æç²ã示ããTIDããã¼ã¸ã§ã³6ãNew IDããã¼ã¸ã§ã³7ã®IDã示ãã
表3ãåæã¢ã¯ã»ã¹(Initial Access)ã®ãã¯ããã¯ã®å¯¾å¿è¡¨
3. MITRE ATT&CK Navigator ã®å¤æ´ç¹
3.1 主ãªå¤æ´ç¹
ãã¼ã¸ã§ã³7ã¸ã®å¤æ´ã«ä¼´ããMITRE ATT&CK Navigatorãããã¯ããã¯ããã³ãµããã¯ããã¯ã¸ã®å¯¾å¿ãæ»æè
ã°ã«ã¼ããã½ããã¦ã§ã¢ã®å¤æ´ã«å¯¾å¿ããã
MITRE ATT&CK Navigatorã®ã¡ãã¥ã¼ã«å¤æ´ã¯ãªãããã ããè¤æ°é¸æ(multi-selector)ã¯ããã¼ã¸ã§ã³6ã®MITRE ATT&CK Navigatorâ
µã§ã¯æ»æè
ã°ã«ã¼ã(Groups)ã¨ã½ããã¦ã§ã¢(Software)ã®é¸æãã§ããããã¼ã¸ã§ã³7ã®MITRE ATT&CK Navigator ã§ã¯ãæ»æè
ã°ã«ã¼ã(Groups)ã¨ã½ããã¦ã§ã¢(Software)ã«å ãã¦ãç·©åç(Mitigations)ãé¸æãããã¨ãã§ããããã«ãªã£ããå³3ã«å¤æ´ã®å
容ã示ãã
å³3ãè¤æ°é¸æ(multi-selector)ã®å¤æ´ã®æ¦è¦
3.2 å¤æ´ã¸ã®å¯¾å¿æ¹æ³
MITRE ATT&CK Navigatorã®ãã¼ã¸ã§ã³ã¢ããã§ã¯ããã¯ããã¯ããã³ãµããã¯ããã¯ã¸ã®å¯¾å¿ãæ»æè ã°ã«ã¼ããã½ããã¦ã§ã¢ã®å¤æ´ãè¡ãããããã«ãå度ããã¼ã¸ã§ã³7ã®MITRE ATT&CK Navigatorã使ã£ã¦ãã·ããªãªã®ä½æãæ¤ç´¢ãè¡ããã¨ã«ãªãã
4. ã¾ã¨ã
ãµã¤ãã¼ã»ãã¥ãªãã£ã®åéã«ããã¦ããã¯ããã¯ã®å¤æ´ãæ°è¦ã®æ»æè ã°ã«ã¼ãã®åºç¾ãæ»æã«ä½¿ç¨ããããã®ã½ããã¦ã§ã¢ã®è¿½å ãªã©ãé »ç¹ã«çºçããããã«ãMITRE ATT&CKãå®æçã«æ´æ°ããããä»å¾ããMITREã®ãã¼ã ãã¼ã¸ããã§ãã¯ãã¦ããã®å¤æ´ã«æ³¨æããå¿ è¦ãããã
-
ï¼æ¬ææ¸ä¸ã®ç¿»è¨³ææ¸ã¯ãNTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾ã«ããæ
å ±æä¾ããã¦ãã¾ãã
ããã¯ãæ¬é ã主ãªåèæç®ãã«ã¦å ¬éãããæç« ã®ãéå ¬å¼ã®ç¿»è¨³ãå«ã¿ã¾ãã
è±æãå ¬å¼çã§ããã¨ã¿ãªããã翻訳æã¨è±æã«ããã¦ã®ææ§ããä¸æçãã«ã¤ãã¦ã¯ãè±æãåªå ããã¾ãã
NTTãã¼ã¿å 端æè¡æ ªå¼ä¼ç¤¾ã¯ãæ¬ç¿»è¨³ææ¸ã«å«ã¾ããé失ã«å¯¾ãã責任ãè² ãã¾ããã
主ãªåèæç®
- *â
°ï¼MITRE ATT&CKã®ã³ã©ã
http://www.intellilink.co.jp/column/security/2020/060200
http://www.intellilink.co.jp/column/security/2020/061700
http://www.intellilink.co.jp/column/security/2020/070800
http://www.intellilink.co.jp/column/security/2020/073100 - *â
±ï¼MITRE ATT&CK ãã¼ã¸ã§ã³6
https://attack.mitre.org/versions/v6/ - *â
²ï¼MITRE ATT&CK ãã¼ã¸ã§ã³7
https://attack.mitre.org/ - *â
³ï¼Updates - July 2020
https://attack.mitre.org/resources/updates/updates-july-2020/ - *â
³ï¼ãã¼ã¸ã§ã³6ã¨ãã¼ã¸ã§ã³7ã®é¢ä¿ã®å¯¾å¿ã®ãã¡ã¤ã«
https://attack.mitre.org/docs/subtechniques/subtechniques-csv.zip - *â
³ï¼ãã¼ã¸ã§ã³6ã®MITRE ATT&CK Navigator
https://mitre-attack.github.io/attack-navigator/v2/enterprise/ - *â
³ï¼ãã¼ã¸ã§ã³7ã®MITRE ATT&CK Navigator
https://mitre-attack.github.io/attack-navigator/enterprise/
Writer Profile
ã»ãã¥ãªãã£äºæ¥æ¬é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨ ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½
ã¨ã°ã¼ã¯ãã£ãã³ã³ãµã«ã¿ã³ã
å
é£ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ éè¦ã¤ã³ãã©å°é調æ»ä¼ å§å¡
æ¾ç° æ ä¹
ã»ãã¥ãªãã£äºæ¥æ¬é¨
ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨ ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½ èª²é·
æ¸ç° åä¹ï¼CISSPãCEHãCISAï¼
Tweet