èå¼±æ§ç®¡çã«ç²å¼ãã¦ãã¾ãããï¼
ï½æåã«ããæ å ±çªåæ¹å¼ãããã¼ã«ã«ããèªååã¸ï½
1. ã¯ããã«
ä¼æ¥ã®ã»ãã¥ãªãã£å¯¾çãè«ããä¸ã§ãITè³ç£ã®é©åãªèå¼±æ§ç®¡çã¯å¤ããªãè¦ç´ ã¨ãªã£ã¦ããããªãããã®å½¢ã§èå¼±æ§ç®¡çã«åãçµã¾ãã¦ããä¼æ¥ã¯ããªãå¢ãã¦ããå°è±¡ã§ããä¸æ¹ã§ãæè¿å½ç¤¾ãç¸è«ãåããã±ã¼ã¹ã®å¤ãã¯ãæ§ææ å ±ã¨èå¼±æ§æ å ±ããããã人æã«ãã£ã¦åéããããããçªãåããã¦èå¼±æ§ã®æç¡ãå¤å®ããæ¹å¼ï¼ãããå¯é¡ã§ãæ å ±çªåæ¹å¼ãã¨å¼ãã§ãã¾ãï¼ã§è¡ã£ã¦ãããå·¥æ°ããããéãã¦ããã¨ãããã®ã§ããäºå®ãCVE IDâ»1ãä»ä¸ãããèå¼±æ§ã®æ°ã¯10å¹´åã®2012å¹´ã«ç´5,000ã ã£ãã®ã«å¯¾ããæ¨å¹´ã¯ç´20,000ã¨ç´4åã«å¢å ãã¦ããâ»2ã人æã«ãã管çã¯éçãè¿ãã¦ããããã«æããã¾ãã
ãã®ã³ã©ã ã§ã¯ãå¼ç¤¾ã§åãæ±ã£ã¦ããèå¼±æ§ç®¡çãã¼ã«ã§ãæ å ±çªåæ¹å¼ã®èª²é¡ãã©ã®ããã«è§£æ±ºå¯è½ã§ããããä¸ã¤ã®ã±ã¼ã¹ã¨ãã¦ä¾ç¤ºãã¦ã¿ããã¨æãã¾ãã
2. èå¼±æ§ç®¡çã®å®æ ã¨èª²é¡
ã¾ããæ å ±çªåæ¹å¼ã§èå¼±æ§ç®¡çãè¡ã£ã¦ããç¾å ´ã®ä¸ä¾ãæããã©ã®ãããªèª²é¡ãæ½ãã§ããã®ãæããã«ãã¦ã¿ã¾ãããã
å³1ã¯ãæ¶ç©ºã®çµç¹ã®èå¼±æ§ç®¡çããã»ã¹ã示ãããã®ã§ã以ä¸ã®ãããªä½å¶ã»ããã¼ã§è¡ã£ã¦ããã¨ãã¾ãã
- âä½å¶
çµç¹ã®ã»ãã¥ãªãã£ç¢ºä¿ã«è²¬ä»»ãæã¤æ å ±ã»ãã¥ãªãã£æ å½ã¨ãITè³ç£ã管çããã·ã¹ãã æ å½ãé£æºãã¦èå¼±æ§ç®¡çãå®æ½ãã¦ãã¾ãã - âæ§ææ
å ±ã®ç®¡ç
æ§ææ å ±ã¯CMDBâ»3ã§ç®¡çããã¦ãããã·ã¹ãã æ å½ãæä½æ¥ã§æ´æ°ãã¦ãã¾ãã - âèå¼±æ§æ
å ±ã®åé
æ å ±ã»ãã¥ãªãã£æ å½ãããã¤ãã®æ å ±ã½ã¼ã¹ããå®æçã«æ å ±åéãè¡ããèå¼±æ§æ å ±ãç¥å¾ããå ´åãCMDBã¨ç §åãã該å½ããã·ã¹ãã æ å½ã«èå¼±æ§ã®æç¡ã®ç¢ºèªããã³ä¿®æ£ãä¾é ¼ãã¾ãã - âèå¼±æ§ã®æ¤åºã»ä¿®æ£
ã·ã¹ãã æ å½ã¯ãé£æºãããèå¼±æ§æ å ±ã«åºã¥ããèªèº«ã管çããITè³ç£ã«å¯¾ãã¦å½è©²èå¼±æ§ãåå¨ãããã®ãã§ãã¯ãè¡ãã該å½ããã°ä¿®æ£ããæ å ±ã»ãã¥ãªãã£æ å½ã«åçãã¾ãã - âèå¼±æ§å¯¾å¦ã®ç®¡ç
æ å ±ã»ãã¥ãªãã£æ å½ã¯ä¸è¨ã®åçã以ã¦ãèå¼±æ§ç®¡çå°å¸³ã®æ´æ°ï¼çºè¦ãããèå¼±æ§ã®ä¿®æ£ãå®äºããæ¨ã®è¨é²ï¼ãè¡ãã¾ãã
å³1ï¼èå¼±æ§ç®¡çããã»ã¹ã®ä¸ä¾
ãã®ãããªããã»ã¹ã«ããã課é¡ã¨ãã¦ä»¥ä¸ã®ãããªãã®ãèãããã¾ãã
- âæ§ææ
å ±ãæ£ç¢ºã§ãªããèå¼±æ§æ¤åºãä¸æ£ç¢ºã¨ãªã
CMDBãæä½æ¥ã§æ´æ°ãã¦ããå ´åãæ å ±ã®é®®åº¦ã»ç²¾åº¦ã®åé¡ã¯å¸¸ã«ä»ãã¾ã¨ãã¾ããæ§ææ å ±ãä¸æ£ç¢ºã ã¨ãèå¼±æ§æ¤åºã®ç²¾åº¦ãä¸ãããèå¼±æ§ãè¦éãã¦ãã¾ã£ãããèå¼±æ§ããªãã®ã«èå¼±æ§ãããã¨å¤å®ããã¦ãã¾ã£ãããã¾ãã - âæ
å ±çªåæ¹å¼ã§ã¯æ¤åºã§ããªãèå¼±æ§ããã
èå¼±æ§ã«ãã£ã¦ã¯ãåç´ã«ç¹å®ã®ã½ããã¦ã§ã¢ã®ç¹å®ã®ãã¼ã¸ã§ã³ã§å¿ ãçºç¾ãããã®ãããã°ãããã«å ãã¦ç¹å®ã®è¨å®ãæ¡ä»¶ã§çºç¾ãããã®ãããã¾ãããããã®ç¢ºèªã«ã¯é«ãæè¡ã¹ãã«ã¨å·¥æ°ãå¿ è¦ã¨ãã¾ããåé ã§ãæããã¨ãããè¿å¹´ãèå¼±æ§ã®æ°ãå¢å ãã¦ãããç¾å ´ã®è² æ ã¯å¢ãç¶ããä¸æ¹ã§ãã - âå®ã¯å¯¾å¦ãå®äºãã¦ããªãã±ã¼ã¹ãè¦éãã¦ãã¾ã
æ å ±ã»ãã¥ãªãã£é¨éã対象ã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ããªãã±ã¼ã¹ã§ã¯ãã·ã¹ãã æ å½ããã®å®äºå ±åãéµåã¿ã«ããããå¾ããæ¢ã«å¯¾å¦å®äºæ¸ã¿ã§ããã¯ãã®èå¼±æ§ãæªç¨ããã¦ã¤ã³ã·ãã³ãã«çºå±ããå¯è½æ§ã¯ååã«èãããã¾ãã - âæ
å ±ã®é£æºãè² æ
ã¨ãªã£ã¦ãã¾ã
æ å ±ã»ãã¥ãªãã£æ å½ã¨æ å ±ã·ã¹ãã æ å½ã®æ å ±é£æºã«ã¡ã¼ã«çã使ç¨ãã¦ããå ´åãé£çµ¡æ¼ããçºçãããæ´çããå·¥æ°ãããããªã©ã®å¼å®³ãããã¾ãã
3. èå¼±æ§ç®¡çãã¼ã«Tenable.ioã«ããèªåå
ä¸è¨ã§æãã課é¡ã®å¤§é¨åã¯èå¼±æ§ç®¡çãã¼ã«ã«ããèªååã§è§£æ¶ã¾ãã¯å¤§ããç·©åãããã¨ãå¯è½ã§ããæ¬ç¨¿ã§ã¯ãå½ç¤¾ã§åãæ±ã£ã¦ããTenable.ioã使ç¨ããä¾ãæããã©ã®ããã«èå¼±æ§ç®¡çããã»ã¹ãæ¹åãããããè¦ã¦ããã¾ãããã
3.1. Tenable.ioã¨ã¯
Tenable.ioã¯ç±³å½Tenable社ãéçºãããçµ±åèå¼±æ§ç®¡çãã©ãããã©ã¼ã ã§ããPCããµã¼ããNWæ©å¨ãªã©ã«åå¨ããèå¼±æ§ãã¹ãã£ã³ããçµ±åçã«ç®¡çãããã¼ã«ã§ã以ä¸ã®ç¹å¾´ãæã£ã¦ãã¾ãã
- â精度ã®é«ãèå¼±æ§ã¹ãã£ã³
å½ç¤¾ã§ã¯15年以ä¸ã«ããã£ã¦ãã©ãããã©ã¼ã ã®èå¼±æ§è¨ºæä½æ¥ã®ä¸é¨ã«Nessusï¼Tenable.ioå ã§åä½ããã¢ã¸ã¥ã¼ã«ï¼ãæ´»ç¨ãã¦ãããèå¼±æ§ã¹ãã£ãã¨ãã¦ã®å質ãé«ãè©ä¾¡ãã¦ãã¾ãã - âå¹
åºãITè³ç£ã«å¯¾å¿
ãµã¼ããPCããããã¯ã¼ã¯ã¢ãã©ã¤ã¢ã³ã¹ãªã©å¹ åºã対象ã«å¯¾ãã¦ã¹ãã£ã³ãè¡ããã¨ãã§ãã¾ããTenable.ioã§ãååãªã«ãã¬ã¼ã¸ãæä¾ãã¦ãã¾ããããªãã·ã§ã³ã®Tenable.ioãTenable.adãçµã¿åããããã¨ã«ãããå·¥å ´ã®å¶å¾¡ç³»ã·ã¹ãã ãActive Directoryã®ã¹ãã£ã³ãå®æ½ãããã¨ãã§ãã¾ãã - â対å¦ã®åªå
度決å®ãå¼·åã«æ¯æ´ããVPRï¼Vulnerability Priority Ratingï¼æ©è½
VPRã¯èå¼±æ§ã«å¯¾ãã対å¦åªå 度ã示ãTenableç¬èªã®ã¹ã³ã¢ãªã³ã°æ©è½ã§ããCVSSï¼ãã¼ã¹ï¼ã¹ã³ã¢ã¯èå¼±æ§ã®æ§è³ªããæºä¸ã§ç®åºããéçãªã¹ã³ã¢ã§ããã®ã«å¯¾ããTenableã®VPRã¯ç¾å¨ã®ç¶æ³ï¼å®éã®æ»æã³ã¼ãã®æµéããã¼ã¯ã¦ã§ãã§ã®è°è«ã®æ´»çºåº¦åããªã©ï¼ãåæ ãããåçãªã¹ã³ã¢ã§ããã対å¦ã®é çªã決å®ããä¸ã§é常ã«åèã¨ãªãå¤ã§ãã - âè±å¯ãªAPIã¨ãµã¼ããã¼ãã£ã¼è£½ãã¼ã«ã¨ã®é£æºæ©è½
Tenable.ioã®ã¹ãã£ã³ã«ãã£ã¦å¾ãããèå¼±æ§æ å ±ãã精度ã®é«ãæ§ææ å ±ãä»ã®è³ç£ç®¡çã·ã¹ãã ããã±ãã管çã·ã¹ãã ã«åãè¾¼ããã¨ãã§ãã¾ãã
3.2. Tenable.ioã«ããèå¼±æ§ç®¡çããã»ã¹ã®èªåå
å ã«ä¾ç¤ºããç°å¢ã«Tenable.ioãå°å ¥ããå ´åã®ã¤ã¡ã¼ã¸ãå³2ã«ç¤ºãã¾ãã
å³2ï¼Tenable.ioã«ããèªååå¾ã®èå¼±æ§ç®¡çããã»ã¹
æ§ææ å ±ãèå¼±æ§æ å ±ã¯Tenable.ioãèªåçã«åéããITè³ç£ã«å¯¾ããèå¼±æ§ã¹ãã£ã³ãå®æ½ãã¾ããæ å ±ã»ãã¥ãªãã£æ å½ã¯èå¼±æ§ç®¡çç¶æ³ã®ææ¡ãããªã·ã¼ã®æ¹åã«æ³¨åãããã¨ãã§ãã¾ããã¾ããã·ã¹ãã æ å½ã¯ç ©éãªæ§ææ å ±ã¨èå¼±æ§æ å ±ã®çªåãã解æ¾ãããåè¿°ã®VPRæ©è½ãä½µç¨ãããã¨ã«ãããé«ãªã¹ã¯ã®èå¼±æ§ã®ä¿®æ£ä½æ¥ã«éä¸ãããã¨ãã§ãã¾ããåç« ã§ç¤ºããèå¼±æ§ç®¡çããã»ã¹ã¯ä»¥ä¸ã®ããã«æ¹åããã¾ãã
- âä½å¶
æ å ±ã»ãã¥ãªãã£æ å½ã¨ã·ã¹ãã æ å½ã¯ãåãTenable.ioã®UIãä»ãã¦æ å ±ãå ±æãé©å®é£æºãè¡ããªããèå¼±æ§ã管çãããã¨ãã§ãã¾ãã - âæ§ææ
å ±ã®ç®¡ç
æ§ææ å ±ã¯Tenable.ioãä¸å çã«å¯¾è±¡è³ç£ãã¹ãã£ã³ãã¦ä¿æãæåã«ããæ´æ°ã®å¿ è¦ã¯ããã¾ããã - âèå¼±æ§æ
å ±ã®åé
Tenable社ã®ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ãæ¥ã æ å ±åéãããã©ã°ã¤ã³ãã¢ãããã¼ããã¦ãã¾ãããªãªã¼ã¹ã®ãªã¼ãã¿ã¤ã ã¯æ¨æºã§ç´ï¼æ¥ã¨çããèªçµç¹ã§ã®ç¬èªã®æ å ±åéã¯å¤ãã®å ´åä¸è¦ã¨ãªãã¾ãã - âèå¼±æ§ã®æ¤åºã»ä¿®æ£
èå¼±æ§ã®æ¤åºã¯ãã¹ã¦Tenable.ioãé«ç²¾åº¦ã«å®æ½ãã¾ããçºç¾æ¡ä»¶ãè¤éãªèå¼±æ§ã«ã¤ãã¦ããå¤é¨ããã®ããã¼ããã±ããã«å¯¾ããæ»ãå¤ã§å¤å®ãããªã©ãé«åº¦ãªãã¸ãã¯ãçµã¿è¾¼ã¾ãã¦ãã¾ãããããã£ã¦ãã·ã¹ãã æ å½ã¯æ¬å½ã«ä¿®æ£ãã¹ãèå¼±æ§ã«ãªã½ã¼ã¹ãéä¸ããããã¨ãã§ãã¾ããã¾ãããã±ãã管çã·ã¹ãã ã¨ã®é£æºã«ãããä¿®æ£ããã»ã¹ãã·ã¹ãã ä¸ã§ç®¡çãããã¨ãã§ãã¾ãã - âèå¼±æ§å¯¾å¦ã®ç®¡ç
ä¿®æ£ã®å®äºã¯æ¬¡åã®ã¹ãã£ã³çµæã§å®éã«å½è©²èå¼±æ§ãæ¤åºãããªããã¨ã§æè¡çãªæ¤è¨¼ãå¯è½ã§ããããã§å¯¾å¿æ¼ããé²æ¢ãããã¨ãã§ãã¾ãã
4. ãããã«
èå¼±æ§ã®æ¥æ¿ãªå¢å ã«ä¼´ã£ã¦ã人æã«ããä½æ¥ã極åæããå¹ççãªèå¼±æ§ç®¡çãæ±ãããã¦ãã¾ããä»åã¯èå¼±æ§ç®¡çããã»ã¹ã«ããã課é¡ã¨ãTenable.ioã«ããèªååä¾ã«ã¤ãã¦ãç´¹ä»ãã¾ãããå½ç¤¾ã§ã¯ãçµ±åèå¼±æ§ç®¡çãã©ãããã©ã¼ã ã¨ãã¦Tenable.ioã®ä»ã«QualysGuardãåãæ±ã£ã¦ããããè¦ä»¶ã«ããé©åãªè£½åã¨å°å ¥å½¢æ ããææ¡ãã¦ããã¾ããã¾ããä»å¸¯ãµã¼ãã¹ã¨ãã¦ã製åã®å°å ¥æ¯æ´ãServiceNowã¨ã®é£æºã«ããè³ç£ç®¡çã»æ§æ管çã¨ã®èåã®ãæ¯æ´ãGRCS社ã®CSIRT MT.mssã¨ã®é£æºã«ããä¿®æ£ä½æ¥ã®ã·ã¹ãã åã®ãæ¯æ´ãªã©ã®ãç¨æããããã¾ããæ¥ã ã®èå¼±æ§ç®¡çã«æ©ã¾ããã¦ããçãã¾ããã®ãåãåããããå¾ ã¡ãã¦ããã¾ãã
- â»1ç±³å½æ¿åºã®æ¯æ´ãåããéå¶å©å£ä½ã®MITRE社ãæ¡çªãã¦ããèå¼±æ§ã®èå¥å
- â»2www.cvedetails.comããç®åº
- â»3Configuration Management Databaseï¼æ§æ管çãã¼ã¿ãã¼ã¹
â»æç« ä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã