å®åè è¦ç¹ã§èããè å¨ã¤ã³ããªã¸ã§ã³ã¹ï¼ç¬¬äºåï¼
1. ã¯ããã«
第ä¸åã®ã³ã©ã ã§ã¯ããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã¨ããè¨èã¯èãããã¨ããããå®æ ã¯ããããããªãã»ã»ã»ãã¨ããæ¹ã対象ã«ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æ¦è¦ï¼ç¨èªã®èª¬æï¼ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®ã¡ãªãããæ´»ç¨ã®ãµã¤ã¯ã«ã«ã¤ãã¦ãç´¹ä»ãã¾ããã第äºåã¨ãªãæ¬ç¨¿ã§ã¯ãçè ãã¤ã³ã·ãã³ã対å¿ã«å¾äºãã観ç¹ãããæ´»ç¨ã®ãµã¤ã¯ã«ã«ã¤ãã¦æ·±å ãã¦ããã¾ãã
2. ååã®ãããã
æ¬é¡ã«å ¥ãåã«ãååã®å 容ãç°¡åã«æ¯ãè¿ãã¾ããååãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã¨ã¯ããè å¨ã«ã¤ãã¦äººãããããããåæã»èç©ãããããã«ãã£ã¦æµãç¥ããã¨ãã§ããæ å ±ãã¨èª¬æãã¾ããããã®è å¨ã¤ã³ããªã¸ã§ã³ã¹ã¯ããã·ã³ãªã¼ããã«ãªIoCï¼Indicator of Compromiseï¼ãä¸å¿ã¨ããæ å ±ãæ ¸ã«ããä½ç³»ç«ã¦ãæ´çã人éã«ããåæãçµã¦å¾ããããã¥ã¼ãã³ãªã¼ããã«ãªæ å ±ã§ãï¼ä¸å³åç §ï¼ãä¸è¬çã«ããã¥ã¼ãã³ãªã¼ããã«å¯ãã®æ å ±ã«ãªãã»ã©ãå¹ççã«è å¨ã®èª¿æ»ãã§ããæ å ±ã¨ãªãã¾ãã
ä¸æ¹ã§ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®åéãæ´»ç¨ã¯ãç®çã誤ãã¨ä½¿ãç©ã«ãªããªãã£ããç¡é§ãªãªã½ã¼ã¹ãè²»ãããããããã¨ã«ãã¤ãªããã¾ãããããã£ã¦ãçµç¹ã«ããã¦æ´»ç¨ç®çãå®ãã¦ããã«å¿ããæ´»ç¨ãµã¤ã¯ã«ãåãå¿ è¦ãåºã¦ãã¾ãã
3. ã¤ã³ã·ãã³ã対å¿ã«å¾äºãã観ç¹ã§ã®æ´»ç¨ãµã¤ã¯ã«
3.1. â ç®æ¨é¸å®ï¼ã©ã®ããã«æ´»ç¨ãããï¼
ã©ã®ããã«è å¨ã¤ã³ããªã¸ã§ã³ã¹ãæ´»ç¨ããã®ãã¯ãçµç¹ãã¨ã«ç°ãªãã¾ããä½ã®ç®çã§ãã©ã®ããã«è å¨ã¤ã³ããªã¸ã§ã³ã¹ãæ´»ç¨ããã®ããå®ãã¦ãããã¨ãå¿ è¦ã§ããç°¡åãªä¾ãä¸è¨ã«ç¤ºãã¾ãã
- ã»äºé²ãã§ã¼ãºï¼éä¿¡æ¤ç¥ãé®æãªã©ï¼
ã端æ«ããã¤ã³ã¿ã¼ãããã¸ã®ä¸å¯©ãªéä¿¡ãæ¢ããããã¨ããã¦ã¼ã¹ã±ã¼ã¹ã§ããC2ãµã¼ãã¼ï¼Command and Control serverï¼ããã£ãã·ã³ã°ãµã¤ããªã©ã®æªæ§ãªéä¿¡å ãåéããã»ãã¥ãªãã£æ©å¨ãªã©ã«é©ç¨ãããã¨ã«ç¹åããæ´»ç¨æ¹æ³ã§ãã - ã»å¯¾å¿ãã§ã¼ãºï¼ã¤ã³ã·ãã³ã調æ»ã対å¦ãªã©ï¼
ãã»ãã¥ãªãã£æ©å¨ãªã©ã§æ¤ç¥ããæ å ±ã®è©³ç´°èª¿æ»ãããããã¨ããã¦ã¼ã¹ã±ã¼ã¹ã§ãã調æ»ã®ç³¸å£ã¨ãªãããã«åºãå¤æ°ã®IoCãåéãããã¨ãæ±ãããã¾ãããIoCã®æ å ±ã ãã§ã¯ä»®ã«ãã°çã§åè´ãã¦ãããªãã®è å¨ããã¯ãããã¾ããããã®ãããè å¨ãç¹å¾´ã¥ããæ å ±ãåéãããã®æ å ±ãIoCã«ä»ä¸ãã¦è å¨ã¤ã³ããªã¸ã§ã³ã¹ãè²ã¦ã¦ããä½æ¥ãæ±ããããæ´»ç¨æ¹æ³ã§ãã
以éã¯ãä¸è¨ã®ã対å¿ãã§ã¼ãºãã§ã®æ´»ç¨ãä¾ã«ã¨ããªãã説æãé²ãã¾ãã
3.2. â¡åéï¼ã©ã®ãããªè å¨ã¤ã³ããªã¸ã§ã³ã¹ãå ¥æãããï¼
ï¼â ç®æ¨é¸å®ï¼ã«æ²¿ãIoCãéãã¦ããã¾ãã対å¿ãã§ã¼ãºã§ã®æ´»ç¨ã«ããã¦ã¯ã調æ»ã®ç³¸å£ã¨ãªãããåºãå¤æ°ã®IoCãåéãã¤ã¤ã極åè å¨ãç¹å¾´ã¥ããæ å ±ãå«ã¾ãããã®ãåå¾ããã¨å¹æçã§ããä¸è¨ã«ãåèã¨ãªãæ å ±å ãæ å ±ã®é¸å®åºæºãè¨è¼ãã¾ãã
æ å ±ã®ç²åº¦ | æ å ±å | 説æ |
---|---|---|
ãã·ã³ãªã¼ããã«å¯ã | OSINT Feed | 主ã«ãéä¿¡å
ãããã·ã¥å¤ãªã©ã®IoCã®ãªã¹ããæä¾ãã¦ããå
¬éãµã¤ãã§ããæåãªæä¾ãµã¤ãã¨ãã¦ä¸è¨ãããã¾ãã
|
ã³ãã¥ããã£ï¼ISAC/ã°ã«ã¼ãä¼ç¤¾éï¼ | ç¹å®ã®æ¥çãä¼æ¥ã«é¢é£ããéå
¬éã®IoCãæä¾ããã¾ãã NTTãã¼ã¿ã°ã«ã¼ãã§ã¯ãMISPãç¨ãã¦ç¬èªã®IoCãå ±æããè å¨ã®æ¤ç¥/é®æã«ç¨ãã¦ãã¾ãã |
|
æåFeed | ã¤ã³ããªã¸ã§ã³ã¹ãã³ãçãæä¾ããè
å¨ã¤ã³ããªã¸ã§ã³ã¹ã§ããIoCã«éãããå°éã®ã¢ããªã¹ãã«ããåææ¸ã¿ã®æ
å ±ï¼æ»æè
ãæ»æææ³ãªã©ï¼ãä»ä¸ããã¦ãããã¨ãããã¾ãã å½ç¤¾ã§åãæ±ã£ã¦ãããEclecticIQ Platformãã®ãªãã·ã§ã³ãµã¼ãã¹ã¨ãã¦ãFusionCenterããããã¾ãã |
|
ãã¥ã¼ãã³ãªã¼ããã«å¯ã | ã»ãã¥ãªãã£ãã³ãã®ããã° SNS ãã¼ã¯ã¦ã§ã ãªã© |
ãã«ã¦ã§ã¢è§£æçµæãæ»æäºä¾ãªã©ããã¥ã¼ãã³ãªã¼ããã«ãªæ å ±ãIoCã¨ã»ããã§å ¬éããã¦ããå ´åãããã¾ããååããããã®æ å ±ã¯äººã確èª/ç解ããä¸ã§IoCã«ä»ä¸ãã¦ããã¾ãã |
é¸å®åºæº | 説æ |
---|---|
æ°é ï¼ç²¾åº¦ã¨ã®ãã¬ã¼ããªãï¼ |
äºåã«å®ããç®çã«å¿ããIoCãå¿
è¦ãªåã ãåãè¾¼ãã¨ãã観ç¹ã§ããIoCãã·ã¹ãã ã«åãè¾¼ãå ´åçã¯ããã®éããµã¤ã¸ã³ã°ãããã©ã¼ãã³ã¹ã¸ã©ã®ç¨åº¦å½±é¿ãããã確èªãã¾ãã 対å¿ãã§ã¼ãºã§ã®æ´»ç¨ã«ããã¦ã¯ã調æ»ã®ç³¸å£ã¨ãªãããåºãå¤æ°ã®IoCãåéãããã¨ã§ãæ»æã®çè·¡ã®æãæ¼ããæ¸ãããå¾ç¶ã®èª¿æ»ã«ãã¤ãªããã¾ãã |
ä¸èº« | åå¾ããIoCãéä¿¡å
ãªã®ãéä¿¡å
ãªã®ããããã·ã¥å¤ãªã©ã®éä¿¡å
/éä¿¡å
以å¤ã®æ
å ±ãããã®ããã¾ãã¯ã¿ã°ãåæçµæãªã©ã®ãã¥ã¼ãã³ãªã¼ããã«ãªæ
å ±ãããã ã¨ãã観ç¹ã§ãã ç¹ã«ãã¥ã¼ãã³ãªã¼ããã«å¯ãã®æ å ±ãæã«å ¥ãã¨ã人ã«ãã対å¿ã®éã«æçã§ãã |
精度 | åå¾ããIoCãã©ã®ç¨åº¦ä¿¡é ¼ã§ããããæ£ããæ å ±ã§ãããã¨ãã観ç¹ã§ããåºæ¬çã«ã¯ãä¿¡é ¼ã§ããçµç¹ããIoCãéãããã¨ãæ±ãããã¾ãããã以å¤ã®å ´æããIoCãéããå ´åã¯ãè¤æ°åæããåå¾ãããã¨ã§ãåä¸ã®IoCã横並ã³ã§è©ä¾¡ã§ãã精度ãåä¸ãã¾ãã |
鮮度 | IoCã¯ç¾å¨ãæå¹ãã¨ãã観ç¹ã§ããæ»æè ãç¨ããIPã¢ãã¬ã¹ããã«ã¦ã§ã¢ã®ããã·ã¥å¤ã¯é »ç¹ã«å¤ããå¾åãé«ããã¨ãããIoCã®è¦³æ¸¬ããæ¥æãªã©ããåæ¨é¸æãã¾ãã |
å½¢å¼ | æ§é åãããIoCãã¨ãã観ç¹ã§ããIoCãCSVãJSONãSTIXï¼â»ï¼ã§è¨è¿°ããã¦ããã¨ãã¼ã«çã§ã®å¤§éå¦çãèªååã«æçã§ãã â»è å¨æ å ±å°ç¨ã®è¨è¿°ãã©ã¼ããã |
æã
CSIRTã®ã¡ã³ãã¼ã¯ãIoCã調æ»ã®ç³¸å£ã¨ãªããããæ°éãéè¦ï¼è¤æ°ã®Feedããå¤æ°ã®IoCãåå¾ï¼ãã¦ãã¾ããçµ±è¨çã«IoCã®æ¯æ°ãå¢ãããã¨ããæ©æ¢°çã«æ¤ç¥/æä¾ãããï¼äººã«ããåæãè¡ãããªãï¼IoCãåå¾ãããã¨ã«ãªãã精度ï¼èª¤æ¤ç¥çï¼ã¯è¥å¹²æªããªãã¾ããã調æ»ã§ã¯äººã«ããIoCã®ç²¾æ»ãä½µãã¦è¡ãããã調æ»çµæã®ç²¾åº¦ã«ã¯å½±é¿ãã¾ããã
â»éä¿¡é®æãªã©æ©æ¢°çã«IoCãæ´»ç¨ããå ´åã¯ã精度ã鮮度ãéè¦ããã®ãè¯ãã§ããããçã«é®æãã¹ãIoCãæ©å¨ã«è¨å®ãããã¨ã§èª¤æ¤ç¥ãæ¸ãããã·ã¹ãã ç/人çãªã½ã¼ã¹ã®æ¸å°ã«ãã¤ãªããã¾ãã
3.3. â¢å¦çï¼ã©ããã£ã¦è å¨ã¤ã³ããªã¸ã§ã³ã¹ãããè¾¼ããï¼
ï¼â¡åéï¼ã§éããIoCãæ´å½¢ãããããã¼ã¿ãã¼ã¹ã«èç©ãããããä½æ¥ã§ããIoCã®æ´»ç¨ç®çãéã«ãã£ã¦å°ç¨ã®ãã¼ã«ã使ãã®ãè¯ãã§ãããã
- ã»å°éã®ã¤ã³ããªã¸ã§ã³ã¹ãåéãã
- ã»Proxyã¸ã®ãã©ãã¯ãªã¹ãé©ç¨ã¯æåã§è¡ã
âExcelãCSVãã¡ã¤ã«ãèç©åªä½ã¨ãã人/å°ç¨ã®ã¹ã¯ãªããã§è¨å ¥ãã¦ããã¾ããããããä¸è¨ã®ãããªé«åº¦ãªä½¿ãæ¹ã«ã¯ãã¾ãé©ãã¦ãã¾ããã
- ã»è¤æ°ã®Feedããå¤æ°ã®ã¤ã³ããªã¸ã§ã³ã¹ãåéããã
- ã»ã¢ããªã¹ãã«ããè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®åæãè¡ããã
- ã»ã»ãã¥ãªãã£æ©å¨ã¨ã®é£æºãèªååãããããªã©
âãã®ãããªã¦ã¼ã¹ã±ã¼ã¹ã®å ´åã¯ãè
å¨ã¤ã³ããªã¸ã§ã³ã¹ãéããå°ç¨ã®ãã¼ã«ãTIPï¼Threat Intelligence Platformï¼ããç¨ããã®ãè¯ãã§ããããæå®ããFeedããå®æçãªIoCã®åéæ©è½ããWebUIãAPIãç¨ããæ¤ç´¢æ©è½ãç¹å®ã®IoCã®ã¿ã®æ½åºæ©è½ãä»æ©å¨ã¨ã®é£æºãã©ã°ã¤ã³ãªã©ãåãã£ã¦ãããã®ãã»ã¨ãã©ã§ããæåã©ããã§ã¯ãªã¼ãã³ã½ã¼ã¹ã®MISPãæåã®EclecticIQ Platformï¼ä»¥éãEIQï¼ãªã©ã®ãã¼ã«ãããã¾ãã
å½ç¤¾CSIRTã§ã¯ã2013å¹´ããç¬èªã·ã¹ãã ã«ããIoCã®åé/èç©ãè¡ã£ã¦ãããæ¨ä»ã§ã¯MISPã¨EIQãä½µç¨ãã¦ãã¾ãã
3.4. â£åæï¼æ å ±ã®æ´çã追å æ å ±ã®ä»ä¸
IoCã®ãããªãã·ã³ãªã¼ããã«ãªæ
å ±ã ãã§ã¯ãä»®ã«ãã°çã§è©²å½ãã¦ãããä½ã®è
å¨ããã¯ãããã¾ãããåæä½æ¥ã¯ãIoCã«æ
å ±ãä»å ããã¥ã¼ãã³ãªã¼ããã«ãªæ
å ±ï¼è
å¨æ
å ±ãè
å¨ã¤ã³ããªã¸ã§ã³ã¹ï¼ã«è¿ã¥ããä½æ¥ã§ãã
対å¿ãã§ã¼ãºã§ã®æ´»ç¨ã«ããã¦ã¯ãIoCã¨ãã¦å
¥æããæªæ§ãªéä¿¡å
ã«å¯¾ãã¦ãããã«ã¦ã§ã¢Aãã¨ããã¿ã°ãä»ä¸ãããããã«ã¦ã§ã¢Aã®æ¤ä½ããã·ã¥å¤ãéä¿¡å
ã®é¢é£IoCã¨ãã¦ã°ã«ã¼ãã³ã°ãããããã«ã¦ã§ã¢è§£æãªã©ããå¾ãæ»æè
ãæ»æææ³ãªã©ãIoCã«ã³ã¡ã³ãã¨ãã¦è¨å
¥ããããã¾ãã
ãã®ä½æ¥ã¯ãè¨ãæããã°ãè
å¨ã«é¢ããã¬ãã¼ãããä½æãããããªã¤ã¡ã¼ã¸ã§ããåºæ¬çã«ã¯äººãå®æ½ããä½æ¥ã§ãããæéã¨æéã¯ãããã¾ããããã°èª¿æ»ã端æ«ãã©ã¬ã³ã¸ãã¯ãªã©ãå¹ççã«é²ããããããã«ãªãã¾ãã
MISPãEIQãªã©ã®TIPã§ã¯ããã®ãããªä½æ¥ãæ¯ããæ©è½ãæ¨æºæè¼ããã¦ãã¾ãï¼ä¸å³åç
§ï¼ã
MISPã«ãããåæä½æ¥ã®ä¾
EclecticIQ Platformã«ãããåæä½æ¥ã®ä¾
3.5. â¤å©ç¨ï¼ç«¯æ«èª¿æ»ãéä¿¡é®æ
åé/åæããIoCãå®éã«å©ç¨ãã¦ããã¾ãã対å¿ãã§ã¼ãºã§ã®æ´»ç¨ã«ããã¦æãå ¸åçãªå©ç¨ä¾ã¯ã端æ«ã®ãã«ã¦ã§ã¢æææç¡èª¿æ»ãæãããã¾ãã
ã¾ãã¯èª¿æ»ã®ç³¸å£ã¨ãã¦ããããã¯ã¼ã¯æ©å¨ãProxyãµã¼ãã¼ãªã©ã®ãã°ããç¹å®æéå
ã®éä¿¡å
ä¸è¦§ãæ½åºãããããTIPå
ã«èç©ããå¤æ°ã®IoCã¨ç
§åããããã¨ã§ãæªæ§ãªéä¿¡å
ã¸ã®ã¢ã¯ã»ã¹ããã£ããã®ç¢ºèªã«å©ç¨ã§ãã¾ããã¾ããIDS/IPSçã®ã»ãã¥ãªãã£æ©å¨ã§æªæ§ãªéä¿¡ãæ¤ç¥ããå ´åã¯ããã®æ¤ç¥çµæãTIPã§æ¤ç´¢ãããã¨ã«ãããIDS/IPSã§ã®æ¤ç¥çµæã®æªæ§åº¦åãã第ä¸è
çã«æ¸¬ãã¨ãã使ãæ¹ãã§ãã¾ãã
ï¼â£åæï¼ã§æªæ§ãªéä¿¡å
ã¨é¢é£ããIoCã¨ã®ç´ã¥ããã§ãã¦ããå ´åã¯ãéä¿¡å
ãããã«ã¦ã§ã¢ã®ããã·ã¥å¤ããã«ã¦ã§ã¢åãªã©ã®è¿½å æ
å ±ãæã«å
¥ãããã¨ãå¯è½ã§ããããã«ããã端æ«ã®ããã·ã¥å¤ãããã«ã¦ã§ã¢åãæ»æææ³ãªã©ãã端æ«ã®ã¢ããªã±ã¼ã·ã§ã³å®è¡å±¥æ´ãªã©ãä»ã®è¦³ç¹ãç¨ãã調æ»ã«ãã¤ãªããã¾ãã
ãªããåè´ããIoCã¯éä¿¡é®æã«ãå©ç¨ã§ãã¾ãããã ãããåè´ãããã®ãä½ã§ãããã§ãé®æããã°ãããã¨ããããã§ã¯ããã¾ãããä¸è¨ã®ãããªã±ã¼ã¹ã«ããé®æã®å¹æãå¾ãããªãå¯è½æ§ãèãããããããå¿ ã人ã®ç®ã«ããç²¾æ»ãä»ã®ã»ãã¥ãªãã£æ©å¨ã§ã®æ¤ç¥çµæãåèã«ããªãããé®æãè¡ãã¾ãã
- ã»IoCã®é®®åº¦ãè½ã¡ã¦ãã
æ°ãæåã¾ã§ã¯æ»æã§ç¨ãããã¦ããIPã¢ãã¬ã¹/ãã¡ã¤ã³ã§ãã£ã¦ããæ»æè ãæ»æç°å¢ãä¹ãæããç¾å¨ã¯ä½¿ããã¦ããªãå¯è½æ§ãããã¾ãã - ã»ãã¹ãã£ã³ã°ãµã¼ãã¹ãå
¬éProxyãªã©ã®IPã¢ãã¬ã¹/ãã¡ã¤ã³
ãã¼ã«ãããã¢ãã¬ã¹ãè¤æ°ã®å©ç¨è ï¼æ»æè ãå«ãï¼ãææãã¦ããå¯è½æ§ããããæã ã«å¿ãã¦ãã®ç´ æ§ã¯ç°ãªãå ´åãããã¾ãã - ã»æ£è¦ãµã¤ããææããIPã¢ãã¬ã¹/ãã¡ã¤ã³
ãã«ã¦ã§ã¢ã®ä¸ã«ã¯ãGitHubãOneDriveãªã©ã®æ£è¦ãµã¼ãã¹ãããã¤ãã¼ãããã¦ã³ãã¼ãããå ´åãããã¾ããããã®ãããªãµã¼ãã¹ãä¸æ¬é®æãã¦ãã¾ãã¨ãçµç¹å ã§ã®æ£è¦å©ç¨ã«å½±é¿ãåã¼ãå¯è½æ§ãããã¾ãã
3.6. â¥ãã£ã¼ãããã¯ï¼åä½æ¥ã®æ¹å
ï¼â¤å©ç¨ï¼ã®çµæãå ã«ãåä½æ¥ã®æ¹åãè¡ã£ã¦ããã¾ããä¸è¨ã«ä¸ä¾ã示ãã¾ãã
- â¡åé
å®éã«å©ç¨ãã¦ã¿ã¦æçãªFeedã§ãã£ãããå ã«ãæ¢åã®Feedã®åé¤ãæ°ããªFeedã®è¿½å ãæ¤è¨ãã - â¢å¦ç
ã·ã¹ãã ã®ãªã½ã¼ã¹å©ç¨ç¶æ³ã調æ»ã§ã®å©ç¨å®ç¸¾ãå ã«ãIoCã®åãè¾¼ã¿é »åº¦ã対象ãè¦ç´ã
IoCã®æä¾å½¢å¼ã«å¤æ´ã¯ãªãããå¿ è¦ã«å¿ãã¦ã¹ã¯ãªãããTIPã®è¨å®ãå¤æ´ãã
Feedéã§éè¤ããIoCãç¹å®æéãçµã£ãIoCãåé¤ãã - â£åæ
IoCã«ä»ä¸ããã¿ã°ãã³ã¡ã³ãçã®è¨è¿°æ¹æ³ãçµ±ä¸åãã
IoCã«å¯¾ãã¦ã¤ã³ã·ãã³ãã®èª¿æ»çµæãªã©ãè¨é²ããå¥ã®ã¤ã³ã·ãã³ã対å¿ã®éã®å¹çåã«ã¤ãªãã - â¤å©ç¨
ã¿ã°/ã³ã¡ã³ãã®è¨è¿°çµ±ä¸åãè¡ããIoCã®æ¤ç´¢æ¹æ³ãè¦ç´ã
TIPãç¨ãã¦IoCç §åãªã©ã®å¦çã®èªååãæ¤è¨ãã
調æ»ã§å©ç¨ãããã®çµæãè¨é²ããIoCãèªçµç¹/ä»çµç¹ã¸å ±æãã
4. ã¾ã¨ã
æ¬ç¨¿ã§ã¯ãè å¨ã¤ã³ããªã¸ã§ã³ã¹ã®æ´»ç¨ãµã¤ã¯ã«ã«ã¤ãã¦æ·±å ãã¾ããã調æ»ã§ç¨ããããã®IoCãã©ã®ããã«åéããã©ã®ããã«å©ç¨ãã¦ããããçããã®åèã«ãªãã°å¹¸ãã§ãã