倧äŒæ¥ã¯ãŸããŸããããžãã¹ã«äžå¯æ¬ ãªãµãŒããŒãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããã³ç£èŠããããšãèããŠããŸãã 誰ãå
¥ã£ãŠæ¥ãŠãäœãããã®ïŒ çµã¿èŸŒã¿ã®ãã®ã³ã°ã¯åžžã«äŸ¿å©ã§ãèªã¿ãããããšã¯éããããç¹æš©ãŠãŒã¶ãŒã³ã³ãããŒã«ãåãã®è£œåãåŸã
ã«ãã·ã¢åžå Žã«åå
¥ãå§ããŸããã ãã®ã·ãªãŒãºã®2ã€ã®ãäž»èŠãªã補åãã€ãŸãBalabit Shell Control BoxãšWallix Admin Bastionãæ¯èŒããã®ã¯èå³æ·±ãããã«æããŸããã
泚ïŒèšäºã®éãæžããããã«ãæ¯èŒã¯rdpãããã³ã«ãšå
šäœãšããŠã®æ©èœã®ã³ã³ããã¹ãã§ã®ã¿è¡ãããŸãããã®çµæãæ¯èŒçäžè¬çã§ãã sshãããã³ã«ããããã®è£œåã§ãµããŒããããŠããŸããããã®èšäºã§ã¯ãã1ã€ã®ããŒãå
ãã®ãã¹ãŠã«å¹²æžããªãããã«èæ
®ãããŠããŸããã管çå¶åŸ¡ã·ã¹ãã ãå¿
èŠãªã®ã¯èª°ã§ããïŒ
ç§ãã¡ã®ã³ã³ãã¥ãŒã¿ãŒåãããæ代ã®ã·ã¹ãã 管çè
ã¯ãã»ãšãã©äŒç€Ÿã®itã¹ããŒã¹ã®ãçãšç¥ãã«ãªããŸããã ãã®çµæã管çè
ã¯ç¹ã«ç«¶åããªãããšã奜ã¿ãå¯èœã§ããã°è²æ©ããŸãããæªãæ¹æ³ã§ãæŸçœ®ãããšãå
ã®ç®¡çè
ãããžãã¹ã«å€§ããªæ害ãäžããå¯èœæ§ãããããã§ãã ãããã£ãŠãå€ãã®äžäœ5人ã®åŸæ¥å¡ã«ãšã£ãŠãã管çè
ã³ã³ãããŒã«ããšãããã¬ãŒãºã¯ãããªã±ãŒããªåé¡ãšåªãã解決çãåãé€ãããã«èŠãããããããŸããããããã¯åçŽã§ããïŒ ãã¡ããéããŸãã ãããã£ãŠããŸãæåã«ã
æ¬åœã«äŒŒããããªè£œåãäœããã®è¯å®çãªæ¶èãããããããšãã§ããäŒæ¥ãç°¡åã«æŠèª¬ããããšæããŸãã ãã®ãªã¹ãã¯ç§ãã¡èªèº«ã®çµéšã«åºã¥ããŠäœæããããã®ã§ããã究極ã®çå®ã§ãããšäž»åŒµãããã®ã§ã¯ãããŸããã æåã¯äž»èŠ³çã§ãã
ãã®ããããã³ã³ãããŒã«ç®¡çè
ãã圹ç«ã¡ãŸãã
- ã·ã¹ãã 管çè
æ°ã7ã10人ãè¶
ããäŒæ¥ã
- ITãµããŒããå€éšçµç¹ã«ãã£ãŠæäŸãããŠããäŒç€ŸïŒã¢ãŠããœãŒã·ã³ã°ïŒã
- ãã³ããŒ/ãã£ã¹ããªãã¥ãŒã¿ãŒã®ã¹ãã·ã£ãªã¹ããã¿ãŒã²ãããµãŒããŒã«éä¿¡ããå¿
èŠãããç¹å®ã®ãœãããŠã§ã¢ãæã€äŒæ¥ã
- èŠå¶åœå±ã«èŠãããããããŸããŸãªåºæºã«æºæ ããããšãèŠæ±ããäŒæ¥ïŒééããŠããªãããé€å€ããŠããªãïŒã
ä»ã®å Žåã§ã¯ã管çå¶åŸ¡ã®ããã®ãœãããŠã§ã¢ã®äœ¿çšã¯éåžžãå§ãã§ããŸããã
以äžã§èª¬æããã·ã¹ãã ã¯äž¡æ¹ãšããããã€ãã®å€æŽãããUNIXã·ã¹ãã ã«åºã¥ããããŒããŠã§ã¢ãŸãã¯ä»®æ³ã¢ãã©ã€ã¢ã³ã¹ã§ããWallixã¯DebianãBalabit-ZorpOSã«åºã¥ããŠãããã€ãããŸãã å¿
èŠãªããŒããŠã§ã¢å®¹éã¯ãã¢ã¯ãã£ããªãŠãŒã¶ãŒã®æ°ãšä¿è·ãããŠãããµãŒããŒã®æ°ã«ãã£ãŠç°ãªããŸãã
ä»çµã¿-Wallix Admin Bastion
Wallixã¯ãOSIã¢ãã«ã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ãèŠå¡ãã¢ãŒãã§ã®ã¿æ©èœããŸãã 管çè
ãã©ãŒã ã«è¡šç€ºãããæ瀺çãªãããã¯ãŒã¯ãã¬ãŒã¯ã«é
眮ãããŸãã WallixãµãŒããŒã§ã«ãŒã«ãæ§æãããŸãïŒè©³çŽ°ã¯ä»¥äžãåç
§ïŒãããã«åºã¥ããŠã管çè
ã®æ¥ç¶ãã¹ããã/ãããã¯ããŸãã 管çè
ã¯ãrdpãããã³ã«ïŒæšæºããŒãïŒã䜿çšããŠwallixãµãŒããŒã«æ¥ç¶ããäœæãããããŒã«ã«ã¢ã«ãŠã³ãïŒãŸãã¯ADããã€ã³ããŒããããïŒã䜿çšããŠãã°ã€ã³ããŸãã ãã®åŸããµãŒããŒ+æçµã¢ã«ãŠã³ãã£ã³ã°ãã¢ã®ã¢ã¯ã»ã¹å¯èœãªãªã¹ããæäŸãããç®çã®ãµãŒããŒãéžæããŸãã Wallixã¯æçµçãªã¢ã«ãŠã³ããã¹ã¯ãŒãèªäœãèšå®ã§ããŸããã管çè
ã«ãã®ãã¹ã¯ãŒããèŠæ±ããããšãã§ããŸãã æ確ã«ããããã«ãæ¥ç¶å³ã以äžã«ç€ºããŸãã
Wallixãä»ããŠç®¡çè
ãä¿è·ããããµãŒããŒã«æ¥ç¶ããè«çå³Wallixã®èšå®ã¯ãWalixèªäœã®ã¢ã«ãŠã³ãã®ã°ã«ãŒãïŒADããã€ã³ããŒããããã¢ã«ãŠã³ãã«çœ®ãæããããšãã§ããŸãïŒãšãµãŒããŒã®ã°ã«ãŒããšæçµçãªã¢ã«ãŠã³ãã®ãã¢ã®2çš®é¡ã®ã°ã«ãŒãéã®ãã€ããªïŒtrue-false \ possible-impossibleïŒãããã³ã°ã§ãã
ä¿è·ããããµãŒããŒãšæçµçãªã¢ã«ãŠã³ãã£ã³ã°ãè¿œå /ç·šéããããã®ãã©ãŒã ãã®ãããªæ¯èŒã®æ°ãããã³ã°ã«ãŒãèªäœã¯å¶éãããŠãããããããã«åºã¥ããŠã誰ãã©ãã§æ¥ç¶ã§ãããã«ã€ããŠã¢ã¯ã»ã¹ãããªãã¯ã¹ãæ§ç¯ãããŸãã
Wallixã¯rdpã¬ã³ãŒãããããªã¯ãªããã®åœ¢åŒã§ïŒãã¡ã€ã«åœ¢åŒã§ïŒæ ŒçŽããŸããããã¯ãçµã¿èŸŒã¿ã®ããã¹ãèªèïŒocrïŒãä»ããŠå®è¡ã§ããã¿ã€ãã«ã§æ€çŽ¢ããŸãïŒæ¬¡ã®ããŒãžã§ã³ã®1ã€ã®ãããªã ãã§ãªãããã¬ãŒã ã¯ãŒã¯å
ã§ã¿ã€ãã«ã®æ€çŽ¢ãé«éåããããšãçŽæãããŸããïŒã
RDPã»ãã·ã§ã³ã®ä¿åããããããªé²ç»ã®ãªã¹ã管çè
ãwallixçµç±ã§å¿
èŠãªãµãŒããŒã«ã匷å¶ã移åãããã«ã¯ã©ãããã°ããã§ããïŒ- çµç¹çæ段ãåããã³ã³ããŒãã¡ã³ãå
ã®ãããã¯ãŒã¯ã¬ãã«ã§ã®ã«ãŒãã®ééã
- ç¹å¥ã«äœæããããã¡ã€ã³ã¢ã«ãŠã³ãã®äžã§ã®ã¿ä¿è·ããããµãŒããŒãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸããWallixã1æé\æ¥\é±\æã«å€æŽãããã¹ã¯ãŒãïŒãã¹ã¯ãŒãã¯æå®ãããã¡ãŒã«ããã¯ã¹ã«æå·å圢åŒã§éä¿¡ãããŸããGPG蚌ææžãšãã¹ã¯ãŒããå¿
èŠã§ãïŒã
補åã®å©ç¹- ã·ã³ãã«ã§ç°¡åãªã»ããã¢ããã
- å®å®ããåäœã¢ãŒããèŠå¡ããäºéèªèšŒã®å¯èœæ§ãããã³ããã«åºã¥ãé©åãªã¢ã¯ã»ã¹ãããªãã¯ã¹ã®ç·šéã
- è€æ°ã®ADãšçµ±åããæ©èœã
補åã®çæ- å®å®ãã ãééãã¢ãŒãã¯ãããŸããã 宣èšãããŠãããã®ã¯ãã¿ã³ããªã³ããã³åãæ ªãããã§åäœãããããŸã£ããåäœããŸããã
- æŸèæãšå®è¡äžã«ã«ããŒããå¿
èŠãããçç£äžã®åŸ®åŠãªéãïŒããŒãžã§ã³4.2ïŒããããŸãã
ä»çµã¿-Balabit Shell Control Box
Balabitããã®ã£ãããã«çœ®ãããŸãããç°ãªãOSIã¢ãã«ã®ããã€ãã®ã¢ãŒãã§åäœã§ããŸãã åæã«ããéæã\ãäžéæãã¢ãŒãã®èšå®ã¯æ¥ç¶èªäœã§çŽæ¥è¡ãããŸããããã¯ãæ¥ç¶ã®ã现ãããèšå®ã®èŠ³ç¹ããéåžžã«äŸ¿å©ã§ãã
ééã¢ãŒã
Balabitã®äž»ãªå©ç¹ã¯ã管çè
ã«ã¯èŠããªã圢ã§ãããã¯ãŒã¯äžã«é
眮ãããŠãããééãã¢ãŒãã§åäœã§ããããšã§ãã IPã¹ããŒãã£ã³ã°ã䜿çšãããšãFWããã³ã«ãŒã¿ãŒã«å¯ŸããŠããèŠããªããããã«ãªããPC管çè
ã®IPã¢ãã¬ã¹ãip-srcã«çœ®ãæããããšãã§ããããããããã¯ãŒã¯æ©åšã«åå¥ã®ã¢ã¯ã»ã¹èš±å¯ãèšå®ããå¿
èŠããããŸããã
balabitãééã¢ãŒãã§åäœããããã«ã察å¿ããã«ãŒããã«ãŒã¿ãŒã«ç»é²ãããŸãïŒãµããããNãããã¹ãŠã®ãã©ãã£ãã¯ãBalabit IPã¢ãã¬ã¹ã«éä¿¡ããŸãïŒã åæã«ãbalabitãèªèã§ããªãïŒå¶åŸ¡ããããããã³ã«ãæ€åºããïŒãã©ãã£ãã¯ã¯ãå€æŽãªãã§ïŒæå®ãããã²ãŒããŠã§ã€ã«ïŒæž¡ãããŸãã
泚ïŒééã¢ãŒãã§ã¯ãèš±å¯ã¯balabitãµãŒããŒã§å®è¡ãããŸããããã·ã¹ãã ã¯ç®¡çè
ãä¿è·ããããµãŒããŒã«ãã°ãªã³ããã¢ã«ãŠã³ããèšé²ããŸããããã«ãããå¿
èŠãªãã£ã«ã¿ãŒãèšå®ããç®çã®ãããªã¯ãªãããèŠã€ããããšãã§ããŸããBalabitã®èšå®ã¯ãä¿è·ããããµãŒããŒéã§åæãããŸã-åãµãŒããŒã«ã¯ãç¬èªã®ã€ã³ã¹ã¿ã³ãèšå®ãšã¢ã¯ã»ã¹æš©ããããŸãïŒééã¢ãŒãã®å ŽåïŒä¿è·ããããµãŒããŒã«æ¥ç¶ã§ãããããã¯ãŒã¯ããïŒã èšå®ãªãã·ã§ã³ã¯æ¬¡ã®ãšããã§ãã
balabitãä»ããä¿è·ããããµãŒããŒãžã®ã¢ã¯ã»ã¹ã®èšå®ééã¢ãŒãã§ã¯ãèšå®ã®ã¡ã€ã³ã¬ã€ã€ãŒã¯ããã©ãã£ãã¯ã®ã«ãŒãã£ã³ã°ãšãããã¯ãŒã¯æ©åšã®æ§æã«äŸåããŸãã balabitèªäœã®èšå®ã¯æå°éã§ãããWallixã§å®è£
ãããŠããããã«ããŠãŒã¶ãŒãšãã®æš©éã§ã¯ãªããä¿è·ããããµãŒããŒã«ã¢ã¯ã»ã¹ããIPã¢ãã¬ã¹ã§åäœããŸãã
èŠå¡ã¢ãŒã
èŠå¡ã¢ãŒãã«ã¯ããã€ãã®å®è£
ããããŸãã
- TSã²ãŒããŠã§ã€ã¢ãŒãã ãã®ã¢ãŒãã§ã¯ãbalabitãµãŒããŒã®DNSåã¯ããªã¢ãŒããã¹ã¯ãããã²ãŒããŠã§ã€ãµãŒããŒãšããŠrdpã¯ã©ã€ã¢ã³ãã«ç»é²ãããŸãã ãã®ã¢ãŒãã§ã¯èšŒææžã䜿çšããTS GWãŸã§ã®ãã©ãã£ãã¯ïŒbalabitãµãŒããŒèšŒææžïŒãšbalabitaããä¿è·ããããµãŒããŒãžã®ãã©ãã£ãã¯ïŒãã®å Žã§çæããã蚌ææžãŸãã¯balabitã«ã¢ããããŒãããã蚌ææžïŒãæå·åããŸãã ãã®ãããªæ¥ç¶ã§ã¯ããã©ããããµãŒããŒã«äºåã«èšå®ãããæçµã¢ã«ãŠã³ãã®ãã¹ã¯ãŒãã眮ãæããããšãã§ããããã管çè
ã¯ä¿è·ããããµãŒããŒã«æ¥ç¶ããããã®è³æ Œæ
å ±ãç¥ãããšãã§ããŸããã ãã ããbalabitèªäœã¯ãã¹ã¯ãŒãã®å€æŽæ¹æ³ãèªåçã«èªèãããäœããã®æ¹æ³ã§ãã¹ã¯ãŒããã管çãããŸããã å¥ã®Thycotic Secret Server SSOã·ã¹ãã ãšçµ±åããŸãã
泚ïŒãã®ã¹ããŒã ã¯ããã©ãŒãã³ã¹ãéåžžã«æ°ãŸããã§ãã ããã«ã¯ãããªãé©åãªéã®åŸ®èª¿æŽãšãæ§æãããŠãããã®ãšãã®çç±ã®ç解ãå¿
èŠã§ãã äºæž¬ã§ããªããã®ã£ã°ããçºçããå ŽåããããŸãïŒããšãã°ããã©ãŠã¶ã®ããããã£ã§ãããã·ãæå®ãããŠããå Žåãrdpã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒã®ãã©ãããDNSåã®è§£æ±ºãæåŠããŸããïŒã
- GWã¢ãŒãã§ã®æ¿èªã ãã®ã¢ãŒãã§ã¯ã管çè
ã«
2ã€ã®ã¢ãã¿ãŒãå¿
èŠã§ããæ¥ç¶ãåæåããåŸãä¿è·ããããµãŒããŒãžã®æ¥ç¶ãéå§ããBalabit Webã€ã³ã¿ãŒãã§ã€ã¹ã«ãã°ã€ã³ããŠãæ¥ç¶ããèš±å¯ãããå¿
èŠããããŸãã ãã®æ¥ç¶ãªãã·ã§ã³ã§ã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ã®ã«ãŒãã£ã³ã°ãšã«ãŒã¿ãŒã®å¯Ÿå¿ããèšå®ãå¿
èŠã§ãã - 4ç®ã¢ãŒãã åäœã®åçã¯ãã©ã°ã©ã2ãšåãã§ãããããã§ã¯å¥ã®äººããã§ã«ãèš±å¯ãããå¿
èŠããããŸãã
åã¢ãŒãã«ã¯ç¬èªã®èšå®ããããŸãããããã§ã¯è©³ãã説æããŸããã æã«ã¯ç®ããã£ãŒã«ãã®æ°ããæ£ä¹±ãããšããããšã§ååã§ã:)ïŒ
ãŸããã·ã¹ãã ã¯ãã¹ãŠã®ã»ãã·ã§ã³ããããªã¯ãªããã®åœ¢åŒã§ä¿åããŸãã OCRã¯1åå®è¡ãããŸãã ãã¹ãŠã®ãããªã§èªèãããããã¹ãã®æ€çŽ¢ã¯ãã§ã«ååšããŠããŸãã ã»ãã·ã§ã³ã衚瀺ããã«ã¯ãã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ïŒAudit PlayerïŒãå¿
èŠã§ããããã¯ãé
åžãããã«ä»å±ããŠãããMS OSãæèŒãããããªãã¬ãŒã¿ãŒãã®PCã«ã€ã³ã¹ããŒã«ãããŠããŸãã
RDPã»ãã·ã§ã³ã®ä¿åããããããªé²ç»ã®ãªã¹ã補åã®å©ç¹- ãã©ã³ã¹ãã¢ã¬ã³ãMiTMã¢ãŒãã§å®å®ããŠå°éçã«äœæ¥ã§ããŸã;
- ã»ãšãã©ãã¹ãŠã®å¥œã¿ã«å¿ãã埮åŠãªèšå®ãå€æ°ãããŸãã
補åã®çæ- 1ã€ã®ADãšã®ã¿çµ±åããŸãïŒADãžã®å
¥åãå¿
èŠã§ãïŒã
- ãèŠå¡ãã¢ãŒãã§ã¯ãã¿ã³ããªã³ãšäžç·ã«èžããããã«ãã³ãé·æéå«ç
ããå¿
èŠãããå ŽåããããŸãã
- ãã¹ã¯ãŒãã管çã§ããŸããã
- äºéèªèšŒã«ã¯ãããæ··ä¹±ããæ§æ Œãšæ§è³ªããããŸãã
ãŸãšãããš
äžèšã®ããã¹ããããããããã«ãå補åã«ã¯ç¬èªã®é·æãšçæããããŸãããã¹ãŠã¯ãå²ãåœãŠãããã¿ã¹ã¯ã®ããŒã«ã«äŸåããŸãã ã·ã¹ãã ã®ãã¹ãŠã®æ©èœã¯æ¯èŒã«åå ããŸããã§ããã
Wallixã®ããã«ãCyberââArkã·ã¹ãã ãåžå Žã«ããããèŠå¡ãã¢ãŒãã§åæ§ã®ããããããé«åºŠãªæ©èœãæã£ãŠããããšãå¥ã«æ³šæããããšæããŸãã ãã®äœæ¥ã®åºç€ã¯ããµããŒãããããããã³ã«ãšæ¥ç¶ã®æ°ãå¢ããããšãã§ããMSãªã¢ãŒãã¢ããªã±ãŒã·ã§ã³ã¡ã«ããºã ã«ãã£ãŠè¡ãããŸãã æ®å¿µãªãããèè
ã¯ãããæ¯èŒã«è¿œå ããã®ã«ååãªèœåãæã£ãŠããŸãããã圌ã¯ããã«ã€ããŠæ²é»ãä¿ã€ããšã¯ç¯çœªã§ãããšèããŠããŸãã