ãSOARããåºç¤ããå¾¹åºè§£èª¬ãã»ãã¥ãªãã£ãé ã ã¾ã§èªåå
ãµã¤ãã¼æ»æãå·§å¦åããä¸ã§ãä¼æ¥ã§ã¯ã¨ã«ãã人æãä¸è¶³ãã¦ãããããããä¸ã§ãã¤ã³ã·ãã³ãã®å¯¾å¿ã¾ã§èªååãããSOARãã¨å¼ã°ããã½ãªã¥ã¼ã·ã§ã³ã注ç®ãéãã¦ããã
ãµã¤ãã¼æ»æã¯å¹´ã ãã®æå£ãé«åº¦åã»å·§å¦åããæ»æéã®ã¿ãªãããæ»æãåããéã®å¯¾å¿ãè¤éåãå¢å ã®ä¸éããã©ã£ã¦ãã¾ãã
ãã¨ãã°è¦å¯åºãç·åçãçµæ¸ç£æ¥çã®çºè¡¨ã«ããã°ã令å2å¹´ã«ãããä¸æ£ã¢ã¯ã»ã¹è¡çºã®çºç件æ°ã¯2806件ã§ããã5å¹´åã®1840件ã¨æ¯ã¹ã¦5å²ä»¥ä¸å¢å ãã¦ãã¾ãï¼å³è¡¨1ï¼ã
å³è¡¨1ãä¸æ£ã¢ã¯ã»ã¹è¡çºã®èªç¥ä»¶æ°ã®æ¨ç§»ï¼éå»ï¼å¹´ï¼
ããããæ»æãåããä¼æ¥å´ã®è¦ç¹ã§ã¯ãæ»æã«å¯¾å¿ããã»ãã¥ãªãã£æè¡è ã確ä¿ã§ãã¦ããä¼æ¥ã¯éããã¦ãã¾ããIPAï¼æ å ±å¦çæ¨é²æ©æ§ï¼ã®ãIT人æç½æ¸2020ãã«ããã°ãååã«äººæã確ä¿ã§ãã¦ããã¨èãã¦ããçµç¹ã¯ããã10ï¼ ã»ã©ã«ããã¾ããã
ã¤ã¾ããå¤ãã®ä¼æ¥ã¯ã¾ãã¾ãå¢ããå¢ããµã¤ãã¼æ»æã«ãä¸è¶³ãã¦ãã人æã§å¯¾å¿ããªãã¦ã¯ãªããªãç¶æ³ä¸ã«ããã¾ããããã§ã注ç®ããã¦ãã対çããã»ãã¥ãªãã£ã«ç¹åããèªååã½ãªã¥ã¼ã·ã§ã³ã§ããSOARï¼Security Orchestration,Automation & Responseï¼ã§ãã
æ¬ç¨¿ã§ã¯SOARã®ä»çµã¿ã解説ããã¨ã¨ãã«ãä¼æ¥ã®ãµã¤ãã¼ã»ãã¥ãªãã£ã«ããã¦æ±ãã課é¡ãããã«è§£æ±ºããããå°å ¥ã®ã·ããªãªã示ããªãã解説ãã¾ãã
SOARã¨ã¯ä½ãï¼ãã対å¦ãã¾ã§èªåå
SOARã¨ã¯ç±³å½ã®èª¿æ»ä¼ç¤¾ã¬ã¼ããã¼ãæå±ããæ¦å¿µã§ãã»ãã¥ãªãã£ã«é¢ããéç¨ãçµ±åãã¦å¯¾å¿ãèªååã§ããã»ãã¥ãªãã£ã½ãªã¥ã¼ã·ã§ã³ç¾¤ã§ãã
ä¸è¬çã«ãã»ãã¥ãªãã£ã¤ã³ã·ãã³ããçºçããéã«ã¯ãè¤æ°ã®ã·ã¹ãã ã»ãã¼ã«ã§æ¤ç¥ã»åæãããæ å ±ããå¤é¨æ å ±ãçµ±åï¼Orchestrationï¼ãã¦å¤æãã対å¦ï¼Responseï¼ãé²ããå¿ è¦ãããã¾ããSOARã¯ããã®ãããªä¸é£ã®ã¤ã³ã·ãã³ã対å¿ã®ããã»ã¹ãèªååï¼Automationï¼ãããã¨ãã§ããã½ãªã¥ã¼ã·ã§ã³ç¾¤ã§ãï¼å³è¡¨2ï¼ã
å³è¡¨2ãSOARã®æ¦è¦
èªååã«ããè²´éãªã»ãã¥ãªãã£äººæã®åç´ä½æ¥ã代è¡ããé«åº¦ãªåæã»å¤æã«éä¸ãããã¨ãã§ããããã«ãªãã¾ãã
ã¾ããè¿å¹´ã¯æ»æå´ã®é度ãä¸ãã£ã¦ããããã¨ãã°ãã«ã¦ã§ã¢ã«ææãã端æ«ãä¼æ¥ãããã¯ã¼ã¯ããéé¢ãããªã©ã®æªç½®ãè¿ éã«å®è¡ããå¿ è¦ãããã¾ãããããã§ãèªååã«ãã対å¿é度åä¸ãæå¹ãªå¯¾ææ段ã¨ãªãã¾ãã
SOARã®å ·ä½çãªè¦ç´ ã¨ãã¦ã¯ãåºå¹¹ã³ã³ãã¼ãã³ãã¨ãªãèªååãã¼ã«ãä¸å¿ã¨ãã¦ãã»ãã¥ãªãã£è£½åããµã¼ãã¼çãé£æºããè¤æ°ã®ã³ã³ãã¼ãã³ãããæ§æããã¾ããã¦ã¼ã¶ã¼ã¯èªååãã¼ã«ã«ã¦ããªãã¬ã¼ã·ã§ã³ã¨ãããå®è¡ããæ¡ä»¶ãè¨ãããã¬ã¤ããã¯ã¨å¼ã°ããèªååã·ããªãªãä½æãããã¨ãã§ãã¾ããèªååãã¼ã«ã¯ãã¬ã¤ããã¯ã®å 容ã«åºã¥ãã»ãã¥ãªãã£è å¨ã¬ãã«ãèªåã§å¤å¥ããã¬ãã«ã«å¿ãã対å¦ãå®è¡ãããã¨ãã§ãã¾ãã
ããã«ãå¤é¨ã¤ã³ããªã¸ã§ã³ã¹ã¨ã®ã¤ã³ãã°ã¬ã¼ã·ã§ã³ãèªçµç¹å ããã¤ã¹ã®éè¦åº¦ãè¨å®ãããã¨ã§ãè å¨ã¬ãã«å¤å¥åºæºãå©ç¨è ã®ç°å¢ã«åããããã¨ããã¬ãã«å¤å®ã®ç²¾åº¦ãåä¸ãããã¨ãå¯è½ã¨ãªãã¾ãã
SOARã«ããèªååã®ä¾ãè¦ã¦ããã¾ãããããµã³ãããã¯ã¹ã¨æ§ææ å ±ãå¤é¨ã¤ã³ããªã¸ã§ã³ã¹ãæ å ±ã½ã¼ã¹ã¨ãã¦èªååãã¼ã«ãã¤ã³ãã°ã¬ã¼ã·ã§ã³ãããèªååã«ã¤ãã¦å³è¡¨3ã«ç¤ºã解説ãã¾ãã
å³è¡¨3ãSOARã«ããèªååä¾
ãµã³ãããã¯ã¹ã§ã¯æ確ã«ãã«ã¦ã§ã¢ã¨å¤å®ãããããçããããã¡ã¤ã«ã§ããã¨ããå¤å®ã§ããªãã±ã¼ã¹ãããã¾ããå¾æ¥ããã®ãããªãã¡ã¤ã«ã¯ã»ãã¥ãªãã£æè¡è ã調æ»ã»å¯¾å¦ããããªãå¿ è¦ãããã¾ããã
SOARã§ã¯ãµã³ãããã¯ã¹ã§çããããã¡ã¤ã«ã§ããã¨å¤å®ããããã¡ã¤ã«ã«å¯¾ããå¤é¨ã¤ã³ããªã¸ã§ã³ã¹ããåå¾ããè å¨æ å ±ãã»ã«ã³ããªãããªã³ã¨ãã¦å©ç¨ããå±éºæ§ãå¤æããããã¨ãã§ãã¾ãã
ãã®çµæãå±éºåº¦ãé«ãã¨å¤æããå ´åããã¡ã¤ã¢ã¦ã©ã¼ã«ãæä½ã該å½ã®æ©å¨ããããã¯ã¼ã¯ããåãé¢ããåæã«åä¸ã»ã°ã¡ã³ãã®æ©å¨ã«å°å ¥ãããEDR製åãæä½ããæ¤ç¥ããããã«ã¦ã§ã¢ãè延ãã¦ããªããèªåã§æ¤ç´¢ãããããã¨ãå¯è½ã§ãããã®ãããªèª¿æ»ã»å¯¾å¦ã®èªååãè¡ããã¨ãã§ãã¾ãã
SOARã®å°å ¥ã·ããªãªãé±ã«250ååæ¸ã3å¹´ã§æè³åå
ããã§ã¯ãå ·ä½çãªå°å ¥ã®ã·ããªãªãèãã¦ããã¾ãã
å°å ¥ã«ããã£ã¦ã¯ã¾ããç¾å¨ã®ã»ãã¥ãªãã£æ¥åãå®éåããèªååããç¯å²ãå 容ãè¨ç»ãã¾ããèªååç¯å²ã»æ¹æ³ãå®ããã¨ããã§å°å ¥ã®åå¾ã§å®éã«ã©ããããä½æ¥ãå¹çåã§ããããå·¥æ°ã«æç®ãã¦å²ãåºãã¾ããä½æ¥ã®å¹çåã«ããåæ¸ã§ããè¦è¾¼ã¿ã®å·¥æ°ã¨SOARã®å°å ¥ã³ã¹ãã»ã©ã³ãã³ã°ã³ã¹ããæ¯è¼ãããã¨ã§è²»ç¨å¯¾å¹æã確èªãã¾ãã
å®éã®æ¥åãèªååããå ´åã®ä¾ãè¦ã¦ããã¾ãããã
ã¨ããä¼æ¥ã®ã»ãã¥ãªãã£æ å½ã¯ãµã³ãããã¯ã¹ã®ã³ã³ã½ã¼ã«ãæ¯æ¥ç¢ºèªããã¤ãã³ããæ¤åºããã¦ããå ´åã«ã»ãã¥ãªãã£ãµã¤ããæ¤ç´¢ãã¦æ å ±ãéããã·ã¹ãã æ§ææ å ±ããå½±é¿ç¯å²ã確èªãã対å¦æç¡ãå¤å¥ãã¦ããã¨ãã¾ããè å¨ã¨å¤æãããå ´åã®å¯¾å¦ã¯ããã¡ã¤ã¢ã¦ã©ã¼ã«ã¸è©²å½ç«¯æ«ã®IPãè¨å®ãããã¨ã«ãããããã¯ã¼ã¯ããã®é®æã¨ãªãã¾ãããã®å¾ãåä¸ã»ã°ã¡ã³ãã®å ¨ã¦ã®æ©å¨ã«ãã°ã¤ã³ããå°å ¥ãããEDR製åããã¹ãã£ã³ãå®æ½ãã¦ãã¾ããç¾å¨ã®æ¥åéã¯å³è¡¨4ã«ç¤ºãããã®ã¨ãã¾ãã
å³è¡¨4ãSOARã®å°å ¥ã«ãã£ã¦èªååã§ããè¦è¾¼ã¿ã®æ¥å
SOARå°å ¥ã«ããã£ã¦èªååãã¼ã«ã®ä»æ§ã確èªããã¨ããããµã³ãããã¯ã¹ã®ã¤ãã³ããã»ãã¥ãªãã£ãµã¤ãããã®æ å ±åéããã³ã·ã¹ãã æ§ææ å ±ã¸ã®åç §ãèªååãã¼ã«ã«ã¦è¡ããã¨ã確èªã§ãã¾ããã
ããã«ãæ§ææ å ±ãã»ãã¥ãªãã£ãµã¤ãããã®æ å ±ããã¨ã«ãè å¨ã¬ãã«ã®è¨ç®ãèªååãã¼ã«ã«ã¦è¨å®ãããã¨ãå¯è½ã§ãããè¨ç®æ¹å¼ã¯è³ç£ã®éè¦åº¦ãã»ãã¥ãªãã£ãµã¤ãã«ããè å¨ã¹ã³ã¢ãçµã¿åããã¦ä½æãã¾ãã対å¦ï¼Responseï¼ã®ãã§ã¼ãºã«ããã¦ã¯ãèªååãã¼ã«ããã¡ã¤ã¢ã¦ã©ã¼ã«ãEDR製åã¨é£æºãããªãã¬ã¼ã·ã§ã³æ示ãè¡ãããã¨ã確èªã§ãã¾ããã
æå¾ã«ãå®éã«èªååãã¼ã«ãç¨ãã¦èªååã®æ¤è¨¼ãå®æ½ããã¨ãããå ¨ã¦ã®æ¥åãèªååãããã¨ã確èªã§ãã¾ãããå ¨ã¦ã®æ¥åãèªååããå ´åãé±ã«250åã®æéãåæ¸ããããã¨ãäºæ³ããããã®å¤ã¨èªååãã¼ã«ã®ã¤ãã·ã£ã«ã³ã¹ãã»ã©ã³ãã³ã°ã³ã¹ãã¨æ¯è¼ããæã3å¹´ç®ä»¥éã§æ¥åå ¨ä½ã®ã³ã¹ãã®åæ¸ãè¦è¾¼ãã¾ããããããã®å 容ããå ¨ã¦ã®æ¥åãèªååããã¨ããè¨ç»ãçå®ãããå®è¡ããã¾ããã
SOARå°å ¥å¾ã®ã¡ãªãããã¨ã³ã¸ãã¢ã¯é«åº¦ãªæ¥åã«
ãã®ããã«SOARãç¨ãã¦ã»ãã¥ãªãã£å¯¾å¦ãèªååããã¨ãããã¨ã«ãããã¤ã³ã·ãã³ãã«æ¼ããªãè¿ éã«å¯¾å¿ãããã¨ãã§ãã¾ããã¤ã³ã·ãã³ãã®åæã®èªååã«ã¯ãã¾ãããã«ã¦ã§ã¢ã«ææçãã®ããæ©å¨ã®èªåéé¢ã¨ãã対å¦ã¾ã§èªååå¯è½ã§ãããã»ãã¥ãªãã£æè¡è ã¯ããé«åº¦ãªæ¥åã«éä¸ãããã¨ãã§ãã¾ãã
ã¾ãã対å¿ãèªååãããã¨ã§ã¤ã³ã·ãã³ãã«å¯¾ãã¦å¸¸ã«åä¸ã®å¯¾å¦ãå®æ½ãããã¨ãã§ããè¤éåããç¾ä»£ã®ã»ãã¥ãªãã£å¯¾å¿ã«ããã課é¡ã§ãããå±äººçãªå¯¾å¿ãããã«ä¼´ãåå¥ã®å ±åä½æã»ç¢ºèªæ¥åãåæ¸ãããã¨ãã§ãã¾ãã
ãã®ä»ã®ã¡ãªããã¨ãã¦ã¯ããã¡ã¤ã¢ã¦ã©ã¼ã«ã¸ã®è¨å®ããããã¯ãã®ç¥èãæã£ãã¨ã³ã¸ãã¢ã§å¯¾å¿ããå¿ è¦ãç¡ããªãããããã¯ãã«å¯¾ããã¹ãã«ãç¡ãã¨ã³ã¸ãã¢ã§ãã»ãã¥ãªãã£éç¨ãå®ç¾ãããã¨ãã§ããããã«ãªãã¾ãã
æ¢åã½ãªã¥ã¼ã·ã§ã³ã¨ã®éããSIEMãRPAã¨ãå ±å
æ¢åã®ã»ãã¥ãªãã£æ å ±ã®çµ±ååæãã¼ã«ã¨ãã¦ã¯ãSIEMï¼Security Information and Event Managementï¼ãªã©ã®ã½ãªã¥ã¼ã·ã§ã³ã代表çã§ããè¤æ°ã®ã»ãã¥ãªãã£è£½åãããã°ãåéãã¦ç¸é¢åæãè¡ããã¨ã§é«ç²¾åº¦ãªæ¤ç¥ãå¯è½ã¨ãã¾ããããããSIEMã«ããç£è¦ã»åæå¾ã®ã¤ã³ã·ãã³ã対å¿ã«ã¤ãã¦ã¯ãã»ãã¥ãªãã£æè¡è ãããã®ç¥è¦ããã£ã¦å¯¾å¿ããå¿ è¦ãããã¾ããã
èªååãã¼ã«ã¨ãã¦ã¯RPAï¼Robotic Process Automationï¼ãããã¾ãããã¨ã³ãã¦ã¼ã¶ã¼ã®ç«¯æ«ã§ç¹°ãè¿ãä½æ¥ãå¿ è¦ã¨ãªãå¸³ç¥¨å ¥åçã端æ«æä½æ¥åãèªååãããã¨ã主ç®çã¨ãã¦ãããã»ãã¥ãªãã£å¯¾å¦ã®èªååã¨ãã観ç¹ã¨ã¯ç°ãªãã¾ãã
SOARã¯SIEMãRPAã¨ç°ãªããã»ãã¥ãªãã£éç¨ã§å¿ è¦ã¨ãªã追å 調æ»ãåéããå¤é¨æ å ±ãçµ±åãã¦å¤æããã»ãã¥ãªãã£ããã¤ã¹ãæä½ããä¸é£ã®éç¨ãèªååãããã¨ã«ä¸»ç¼ãç½®ãã¦ãã¾ãã
ãããã決ãã¦ãããã®ã½ãªã¥ã¼ã·ã§ã³ã¨ã¯ç«¶åãããã®ã§ã¯ããã¾ãããæ å ±ã®åæã¨ãã¦SIEMã¨ã®é£åãè¡ãå ´åããã»ãã¥ãªãã£ã®å¯¾å¦ãã§ã¼ãºã§ç«¯æ«ã®æä½ãå¿ è¦ãªå ´é¢ã§ã¯RPAã¨é£åããã±ã¼ã¹ãåå¨ãã¾ãã
ç ©éåã®ä¸éããã©ãã»ãã¥ãªãã£éç¨ã«ããã¦ãèªååã«ããçååãå®ç¾ããä¸ã«ãéãæ£ç¢ºãªå¯¾å¿ãã§ããSOARã¯ãä»å¾ã¾ãã¾ãå°å ¥ãé²ãã¨èãããã¾ããã¾ããå©ç¨å¯è½ãªãã¬ã¤ããã¯ã®å ±æãé²ãã«ã¤ãã¦æ´»ç¨ã®å ´ãåºããã¨äºæ³ãããã¾ãã¾ãç®ãé¢ããªãã½ãªã¥ã¼ã·ã§ã³ã¨ãªãã¨èãããã¾ãã
â»ãªãã¯ãã¬ã³ã 社ã®ãæåã³ãã¥ãã±ã¼ã·ã§ã³ããbusiness network.jpãã«å¯ç¨¿ããã³ã©ã ãæ²è¼ãã¦ãã¾ãã
-
ãSOARããåºç¤ããå¾¹åºè§£èª¬ãã»ãã¥ãªãã£ãé
ã
ã¾ã§èªåå
https://businessnetwork.jp/Detail/tabid/65/artid/8418/Default.aspx