ãã®èšäºã¯ãã
OSSIM-çµ±åãªãŒãã³ãœãŒã¹ã»ãã¥ãªãã£ç®¡çã·ã¹ãã ã®å±é ããšããèšäºã®å°è±¡ãåããŠæžãããŸããã ç¹°ãè¿ãã¯ãããã·ã¹ãã ã®ã€ã³ã¹ããŒã«ããã»ã¹ã«ã€ããŠèª¬æããŸãã OSSIMã䜿çšããå®éã®çµéšã«é¢é£ããæç¢ºåãšæç¢ºåãè¡ãããã ãã§ãã
äœã«è³ããŸããïŒ éãŸãã¯ä»®æ³ïŒ
ã©ã®æé ã§ãããééããªãä»®æ³ãã·ã³äžã§ããèªãããšã«ãªããŸãã ç§ã®çãã¯ããééããªãéã®äžã«ãã§ãã äž¡æ¹ã®çããæ£ããã§ãã ãªãã§ïŒ
OSSIMã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšããã³ãã«ããããŠã€ã³ã¹ããŒã«ãããã€ã¡ãŒãžã®ãããã£ã¹ã¯ã«ã¯ããŒããŠã§ã¢ã«å¿
èŠãªãã©ã€ããŒãå«ãŸããŠããªãå¯èœæ§ããããããæåã®çãã¯æ£ããã§ãã ããã«ééããå Žåãããã¯ããªãã®åé¡ã«ãªããŸããããªãã¯èªåã§è§£æ±ºããå¿
èŠããããŸãã ä»®æ³ãã·ã³ã«ã€ã³ã¹ããŒã«ãããšãããã€ãã®æ±çšæ§ãæäŸãããåé¡ã¯çºçããŸããã ããã«ãæŽæ°åŸã«åé¡ãå床解決ããå¿
èŠããªããšããä¿èšŒã¯ãããŸããã ã¢ãã©ã€ã¢ã³ã¹ãšããŠè²©å£²ãããããã«å¿ããŠãµããŒããããå
¬åŒã®åçšãããŒããŠã§ã¢å®è£
ãããããŸãããããã§ã¯ãªãŒãã³ãœãŒã¹OSSIMã«æ³šç®ããããã§ãã¹ãŠã®ããŒããŠã§ã¢ã®åé¡ã¯ããªãã®åé¡ã§ãã
ãã€ããŒãã€ã¶ãŒã¯ãã¬ãŒããªã®ã§ã2çªç®ã®çãã¯æ£ããã§ãã ãŠãããŒãµã«ä»®æ³åã®æ¯æè
ã¯ãå¿
èŠãªã ããã©ã³ãããã鳎ããããã©ã ããŠã§ãŒããã©ã°ãæã¡è² ããããšãã§ããŸããããã€ããŒãã€ã¶ãŒã¯ã²ã¹ãã·ã¹ãã ã®ããã©ãŒãã³ã¹ã倧å¹
ã«äœäžãããŸãã éåžžãããã¯ç¡èŠã§ããŸãããOSSIMã¯é床ã倧奜ãã§ãã ãã®çµæã4ã³ã¢ã¢ãã ã16 GB DDR3ããã³128 GB SATA3 SSDãåãããã¢ã³ã¢ããã³ã³ãã¥ãŒã¿ãŒã«ãããHP dl380äžã®ä»®æ³ãã·ã³ã容æã«ãªããŸãã ç©çãã·ã³ãå¿
èŠãšãããããã¯ããã«å€ãã®ãªãœãŒã¹ãä»®æ³ãã·ã³ã«æäŸããå¿
èŠããããŸãã ãããŠãããã¯ãã£ãšè²»çšãããããŸãã ãã©ã€ããŒã«ã€ããŠã¯ãã€ã³ã¹ããŒã«äžã«ãå¿
èŠã«å¿ããŠãã©ã€ããŒä»ãã®USBãã©ãã·ã¥ãã©ã€ããæ¿å
¥ããããã«æ±ããããŸãã
éèŠã§ãã ã¢ã€ã¢ã³ãã·ã³ã§ã¯ãã€ã³ã¹ããŒã©ãŒã¯èµ·åå¯èœãªCDããã®ã¿èµ·åããŸãã ã€ã¡ãŒãžãUSBãã©ãã·ã¥ãã©ã€ãã«ã¢ããããŒããããšãOSSIMã¯ã€ã³ã¹ããŒã«ãããŸããããDebianãã€ã³ã¹ããŒã«ã§ããŸãã
ãšãŠãéèŠã§ãã åäœäžã®ã³ã³ãã¥ãŒã¿ãŒã«OSSIMãã2çªç®ã®ã·ã¹ãã ããšããŠã€ã³ã¹ããŒã«ããªãã§ãã ããã ã€ã³ã¹ããŒã©ãŒã¯ãèªåã裞ã®ãã·ã³ã«çœ®ãããŠãããšä¿¡ããŠãããããã£ã¹ã¯ãããŒãã£ã·ã§ã³åå²ããæ¹æ³ããšããã°ããã質åãããŸããã ãŸã第äžã«ãå°ããããšãªãã圌ã¯ããŒãã£ã·ã§ã³ããŒãã«ãäžæžããããã£ã¹ã¯ããã©ãŒãããããŸãã
OSSIMã®ã€ã³ã¹ããŒã«ã«ã¯ãã15åãããããŸããã ãã£ãšé·ãã æåŸã®æ®µéã§ã¯ãã€ã³ã¹ããŒã©ãŒãããªãŒãºãããã¹ãŠããªããªã£ããšèããããšããã§ããŸãã ã¡ãã£ãšåŸ
ã£ãŠ åœŒã¯åããŠããŸãã
éèŠåºŠã®é«ãé ã«OSSIMã®æãéèŠãªãªãœãŒã¹
ãã£ã¹ã¯ãµãã·ã¹ãã ã®é床ã SSDãæ£ãã䜿çšããŠãã ããã ããªã¥ãŒã ã¯éèŠã§ã¯ãããŸããã 100GBã§ååã§ãã ããããé床ã¯éåžžã«éèŠã§ãã ããã«ã¯2ã€ã®çç±ããããŸãã ãŸããsyslogã«éä¿¡ãããOSSIMãã©ã°ã€ã³ã«ãã£ãŠèªã¿åãããããã¹ããã°ã 次ã«ãåããã·ã³ã§å®è¡ãããããŒã¿ããŒã¹ã SSDã¯ã·ã¹ãã ã®ããã©ãŒãã³ã¹ãåçã«æ¹åããŸãã
ããã»ããµã³ã¢ã®æ°ã åã³ã¢ã®ããã©ãŒãã³ã¹ã¯ããã®æ°ã»ã©éèŠã§ã¯ãããŸããã OSSIMã¯éåžžã«ç°¡åãªæäœãå®è¡ããŸãããäžåºŠã«å€ãã®æäœãããã䞊è¡ããŠå®è¡ã§ããŸãã ãŸãããåç¥ã®ããã«ããããã¯ãŒã¯IDSïŒSuricataïŒã«ãšã£ãŠãéèŠã§ãã
RAMã®éã ããã»ã©éèŠã§ã¯ãããŸããããããŒãžãã¡ã€ã«ã«äœãããã·ã¥ããªãæ¹ãè¯ãã§ãã
ãã°å
ã®200äžã€ãã³ããšãå€èªäžèœãã€ã³ã¿ãŒãã§ã€ã¹äžã®10ãã©ãã€ãã®ãã©ãã£ãã¯ã®æ¯æ¥ã®ã¹ããªãŒã ã«åºã¥ãä»®æ³ãã·ã³ã«é©ããæ§æïŒ8ã³ã¢ã16 GBã ããããããã¯èäžåããã§ãã ãªãœãŒã¹ã¯çŒçã«é£ã¹ãããŸãã

ãã¡ãããã¹ã€ããã®ã¹ãã³ããŒããããããã¯ãŒã¯ã®ãã¹ãŠã®ãŽã£ã©ã³ããããŒã¢ãã£ããã®åæã®ããã«åéããããã©ãã£ãã¯ãã¹ããŒããå€èªäžèœãªã€ã³ã¿ãŒãã§ã€ã¹ã¯10Gbsã§ããå¿
èŠããããŸãã ãã以å€ã®å Žåã¯ãåã«ãã§ãŒã¯ããŸãã
Windowsãã·ã³ããOSSIMãµãŒããŒã管çããå Žåã¯ããããšWinSCPãå¿
èŠã§ãã ãŸãããŸãã¯ããªãã圌ãæããŠãããªãé ãã UbuntuãæèŒãããã·ã³ãããã©ã€ãããæ¹ã䟿å©ã§ãã å°ãªããšããã¹ã¯ãªããã§CRLFãšããŠè¡æ«ã誀ã£ãŠæžãããã©ãããæ¯å確èªããå¿
èŠã¯ãããŸããã
ã€ã³ã¹ããŒã«åŸããªã¢ãŒããã·ã³ããSSHçµç±ã§ãµãŒããŒã«æ¥ç¶ããããšã¯ã§ããŸããã Debian 8ã§ã¯ãsshdèšå®ã®ããã©ã«ããªãã·ã§ã³ã¯ãPermitRootLogin without-passwordãã§ããã `/ etc / ssh / ssh_config`ã§` PermitRootLogin yes`ã«å€æŽããå¿
èŠããããŸãã
ã¿ã€ã ãŸãŒã³
ãã1ã€ã®éèŠãªããšã¯ããã©ã°ã€ã³ã®ã¿ã€ã ãŸãŒã³ã®æ£ããæ§æã§ãã å®éããã¹ãŠã®ãã°ãœãŒã¹ãåãã¿ã€ã ãŸãŒã³ã«ããå Žåã§ããå¿
ãããåãçŸå°æéã䜿çšããŠããããã§ã¯ãããŸããã ããšãã°ãSystem Center Configuration Managerã¯ãUTCã§ããŒã¿ããŒã¹ã«æéãä¿åããã®ã劥åœã§ãããšèããŠããŸãã ãŸããããŒã¿ããŒã¹ããæ°ããã€ãã³ããèªã¿åããã©ã°ã€ã³ãæã£ãŠããå ŽåïŒãããŠãç§ã¯ãããæã£ãŠããŸãïŒããããã¯çŸå°æéã§èšé²ãããªãããšãèæ
®ããå¿
èŠããããŸãã
ãã©ã°ã€ã³ã®ã¿ã€ã ãŸãŒã³ã¯2ã€ã®å Žæã§èšå®ãããŸãïŒæåã«ããã¹ãŠã®ãã©ã°ã€ã³ã®ããã©ã«ãã®ã¿ã€ã ãŸãŒã³ã `/ etc / ossim / agent / config.cfg`ã«èšå®ãããæ¬¡ã«ãåã
ã®ãã©ã°ã€ã³ã®èšå®ãã¡ã€ã«ã§åå®çŸ©ã§ããŸãã ã¿ã€ã ãŸãŒã³ã®å®çŸ©ãšã¯ããã©ã°ã€ã³ãžã§ãã¬ãŒã¿ãŒã«ãããŒã¿ããã®ãããªã¿ã€ã ãŸãŒã³ããæ¥ãŠãããšæ³å®ããæéãæã
ã®æéã«å€æãããããšãæå³ããŸãã ãã®å Žåããoursãã¯ãµãŒããŒã®çŸå°æéã§ãã å®éãæéã¯ããŒã¿ããŒã¹ã«UTCã§æžã蟌ãŸããŸããããããŒã«ã«ã·ã¹ãã ãã®ãªãã»ãããæžã蟌ãŸããå¥ã®ãã£ãŒã«ãããããŸãã
ç°ãªãã¿ã€ã ãŸãŒã³ã«åãã¿ã€ãã®2ã€ã®ãœãŒã¹ãããå Žåãè峿·±ãããšãå§ãŸããŸãã ããšãã°ãããŸããŸãªãã©ã³ãããcisco-asaã«ãŒã¿ãã°ãååŸããŸãã ãã®å Žåãç°ãªããã©ã¡ãŒã¿ãŒ `tzone =`ãæå®ããèšå®ãã¡ã€ã«ã§ãç°ãªããã©ã°ã€ã³ã§ããããåŠçããå¿
èŠããããŸãã ãã®ãã©ã¡ãŒã¿ãŒã¯ `[default]`ã»ã¯ã·ã§ã³ã§èšå®ãããŸãã ããªããããã¥ã¡ã³ãã§ãããèŠã€ããããªãã®ã§ãç§ã¯ããã«ã€ããŠæžããŠããŸããç§ã¯çç±ãç¥ããŸããã POSIX圢åŒïŒãtzone = Europe / Moscowãã
Windowsãã°ãåéããæè¯ã®æ¹æ³ã¯äœã§ããïŒ
ç§ã®çãïŒããã€ãã£ããããŒã«AlienVault HIDSãå¥åOSSECã ãã¡ãããããã«ã€ããŠç°¡åã«èª¬æããŸãã
çè«çã«ã¯ãå€ãã®ãšãŒãžã§ã³ãã®ããããã䜿çšããŠãWindowsã€ãã³ããã°ãsyslogã«éä¿¡ããããWMIã䜿çšãããã§ããŸãã OSSIMã«ã¯WMIã¯ã©ã€ã¢ã³ãããããWindowsãã°ãèªã¿åãããã®æšæºãã©ã°ã€ã³ããããŸãã SNAREãšãŒãžã§ã³ãçšã®æšæºãã©ã°ã€ã³ããããŸããããã·ã¢ã®Windowsãæ±ã£ãŠããå Žåãããã¯åœ¹ã«ç«ã¡ãŸããã åé¡ã¯ãSNAREããã·ã¢ã®Windowsããcp1251ãšã³ã³ãŒãã£ã³ã°ã§ããŒã¿ãéä¿¡ããSNAREã®æšæºããŒãµãŒãcp1252ã®äžã«èšè¿°ãããŠããããšã§ãã ã¬ã®ã¥ã©ãŒã·ãŒãºã³ãç·šéããå¿
èŠããããŸãã
ããããæãè峿·±ãããšã¯ããå€èšèªãã·ã¹ãã ãããã°ãåéãããšãã«å§ãŸããŸãã ããšãã°ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ãã·ã¢èªã®WindowsãããããµãŒããŒã«è±èªããããŸãã ãããŠä»ããããåæããæ¹æ³ã¯ïŒ ããã¯å®éããã¹ãŠã®SIEMã«å
±éã®åé¡ã§ãã 圌ãã¯ãããããŸããŸãªæ¹æ³ã§è§£æ±ºããŸãã ããšãã°ãArcSightã¯Windowsãã°ã®åéã«ããªãæŽç·Žãããã·ã¹ãã ã䜿çšããŠãããããã·ã¹ãã ã®ããŒã«ã©ã€ãºã«é¢ä¿ãªããè±èªã®ã¿ã§ãã°ãåéã§ããŸãã OSSECã¯éåžžã«åçŽãªææ³ã䜿çšããŸãã Windowsã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ãããšãè±èªã®Windowsãã°ã®æååã¡ãã»ãŒãžã®ããŒãã«ãå«ãcsvãã¡ã€ã«ããã®äœæ¥ãã£ã¬ã¯ããªã«æžã蟌ãŸããŸãã ãããã£ãŠãåæã«å¿
èŠãªã¡ãã»ãŒãžã®ãå¿
é éšåãã¯ãã·ã¹ãã ã®ããŒã«ã©ã€ãºã«é¢ä¿ãªããåžžã«1ã€ã®èšèªã§éä¿¡ãããŸãã ãããããããŒã¿ãã¯ãå
ã®èšèªã§ãæ¥ãŸãã ãšãŠã䟿å©ã§ãã
ããã«ãOSSECãšãŒãžã§ã³ãã®æšæºãã©ã°ã€ã³ã¯éåžžã«ããæžãããŠããŸãã 圌ã¯ã€ãã³ããã¿ã€ãããšã«æ
éã«è§£æããŸãã ãã°ãåéããããã«å¥ã®æ¹æ³ã䜿çšããå Žåãæ£ã§ã€ãã³ããæé
ããã®ã«å€ãã®æ±ããããªããã°ãªããŸããã æåŸã«ãOSSECã¯åãªãããã°è»¢éãã§ã¯ãªããå®éã«ã¯ãã¹ãIDSã§ãããæªããã®ã§ããããŸããã ãã¬ã³ããã€ã¯ãã¯ããã®ãšã³ãžã³ããé«åºŠãªããŠã€ã«ã¹å¯Ÿçã«äœ¿çšããããšã«æ±ºããŸããã ã¯ããOSSECã¯ã³ã³ãããŒã«ã·ã§ãããšããŠä¿¡é Œã§ããŸãã éèŠãªã·ã¹ãã ã«ãšãŒãžã§ã³ããå®å
šã«ã€ã³ã¹ããŒã«ã§ããŸãã
ãã®ä»ã ãŠãµã®ã¯è²Žéãªæ¯ç®ã§ããã ãã§ãªãã3ã4ããã°ã©ã ã®é£èã§ããããŸãã OSSECã¯ãã°ã³ã¬ã¯ã¿ãŒã§ã¯ãªããããèªäœãSIEMã§ãã OSSIMã§ã¯ãWindowsãã°ã¯ãŸã£ããéä¿¡ãããŸããããç¬èªã®alert.logã¯ãšãŒãžã§ã³ãããåä¿¡ããã€ãã³ãã®äºååŠçã«åºã¥ããŠåœ¢æãããŸãã ããã«ã¯ãããšãã°ãå¶åŸ¡ããããã¡ã€ã«ã®å€æŽã€ãã³ãããŸãã¯ãè€æ°ã®ãšã©ãŒãããã¬ãžã¹ããªå
ã®ããŒã®ãã§ãã¯ãµã ã®è€æ°ã®å€æŽããªã©ã®éçŽã€ãã³ãããããŸãã åãªãã³ã¬ã¯ã¿ãŒããã䟿å©ã§ãã OSSECã¯ã€ã³ã¿ãŒãããäžã§éåžžã«åºãæ®åããŠãããWebãµãŒããŒãä¿è·ããããã«é »ç¹ã«äœ¿çšãããŠãããããã³ãã¥ããã£ã¯å€§ããæŽ»çºã§ãã
ãã¡ãããWindowsã®ãã°ãåéããä»ã®æ¹æ³ã詊ãããšãã§ããŸãã ããã¯é¢çœãã§ãã
OSSECãšãŒãžã§ã³ãæ§æã«ã€ããŠã®äœã
Windowsãã·ã³ã§ã¯ããšãŒãžã§ã³ãã¯ããã©ã«ãã®æ§æãã¡ã€ã«ãšãšãã«ã€ã³ã¹ããŒã«ãããŸãã ãã®ãã¡ã€ã«ã¯æ¬¡ã®å Žæã«ãããŸãïŒ `/ usr / share / ossec-generator / installer / ossec.conf`ã OSSECã¯ããµãŒããŒããã®æ§æã®ããŠã³ããŒãããµããŒãããŠããŸãã ãã¡ã€ã« `/ var / ossec / etc / shared / agent.conf`ããã®ç®çã«äœ¿çšãããŸãã ããã©ã«ãã§ã¯ååšããŸããã ãã®ãã¡ã€ã«ã¯ãOSSIMã³ã³ãœãŒã«ã®Webã€ã³ã¿ãŒãã§ãŒã¹ããäœæã§ããŸãïŒç°å¢-æ€åº-ãšãŒãžã§ã³ã-agent.confïŒã ãŸãã¯ãããã¹ããšãã£ã¿ã§äœæããŸãã
ããŒã«ã«ãšãŒãžã§ã³ãèšå®ãã¡ã€ã«ãšããŒãžãããXML圢åŒã®èšå®ãã£ã¬ã¯ãã£ããå«ããå¿
èŠããããŸãã ããŸããŸãªãšãŒãžã§ã³ãã®ãã£ã¬ã¯ãã£ããããã¯ãããŒã¯ããŠãé©åãªãšãŒãžã§ã³ãã«ã®ã¿é©çšã§ããŸãã OSã¿ã€ãããšãŒãžã§ã³ãåããããã¡ã€ã«åã«ããããŒãã³ã°ãèš±å¯ãããŸãïŒããŒã«ã«ãšãŒãžã§ã³ãæ§æã§ã¯ããã®å Žåããããã¡ã€ã«ã®ååã瀺ãå¿
èŠããããŸãïŒã
<agent_config name="agent001|agent002|agent018">
</agent_config>
<agent_config os="Linux|FreeBSD">
</agent_config>
<agent_config os="Windows">
</agent_config>
<agent_config profile="web-server">
</agent_config>
ãã®ããã«ããŠããšãŒãžã§ã³ãã®æ§æãäžå
çãã€åå¥ã«å€æŽã§ããŸãã ãããŒãžããšããçšèªã«ã¯æç¢ºåãå¿
èŠã§ãã æ§æãã¡ã€ã«ã®ããŒã«ã«ã»ã¯ã·ã§ã³ããªãŒããŒã©ã€ãããããšã©ããªããŸããïŒ çè«ã§ã¯ãããŒã«ã«ãã¡ã€ã«ãæåã«èªã¿èŸŒãŸããæ¬¡ã«ãµãŒããŒãã¡ã€ã«ãèªã¿èŸŒãŸããæåŸã«èªã¿èŸŒãŸããã«ãŒã«ãæåŸã«èªã¿èŸŒãŸãã以åã®ãã¡ã€ã«ã¯ãã¹ãŠäžæžããããŸãã å®éã«ã¯ããã®ãããªæ§æãã©ã¡ãŒã¿ãŒã®äº€å·®ã詊ããããšã¯ãããŸããã åã«å¿
èŠã¯ãããŸããã§ããã å¿
èŠã«å¿ããŠãæãããã«æ©èœããããšãé¡ã£ãŠããŸãã
ããäžã€ã®éèŠãªãã€ã³ãã ããŒã«ã«ãšãŒãžã§ã³ãæ§æã®ãã³ãã¬ãŒãã¯ããµãŒããŒãžã®æ¥ç¶æ¹æ³ã瀺ããŠããŸãã
<server-ip>172.17.2.10</server-ip>
<notify_time>120</notify_time>
<time-reconnect>240</time-reconnect>
ããªããããã§èŠãããšãã§ããããã«IPã¢ãã¬ã¹ã èè
ããã®ãããªãã³ãã¬ãŒãã奜ãã çç±ã¯ããããŸããã FQDNãæå®ãããšããã®ã»ã¯ã·ã§ã³ã¯ç°ãªãããã«èŠããã¯ãã§ãã
<server-hostname>fqdn</server-hostname>
...
ãã ããããã¯è¡ãããŠããŸããã ããã¯ããµãŒããŒã®IPã¢ãã¬ã¹ã倿Žãããšããã¹ãŠã®ãšãŒãžã§ã³ããèœã¡ãããšãæå³ããŸãã è¯ãèãã§ã¯ãããŸããã ãã¡ãããSIEMã¯IPã¢ãã¬ã¹ã倿Žããããããªããã€ã¹ã§ã¯ãããŸããããã©ããããããäžå¿«ã§ãã ãã¡ããããã³ãã¬ãŒãã®ãã®ã»ã¯ã·ã§ã³ã倿Žã§ããŸãããã»ãšãã©ã®å Žåãæ¬¡ã®æŽæ°ã§ãã³ãã¬ãŒããåçæãããŸãã ãããåžžã«ç£èŠããå¿
èŠããããŸãã ã¢ãã¬ã¹ã倿Žããç¿æ
£ããªãã®ã§ããã®åé¡ã¯ç§ãæ©ãŸããŸããã
ãã¹ããšãŒãžã§ã³ãã®ã€ã³ã¹ããŒã«ã«é¢ããèæ
®äºé
Windowsã§ã¯ãèªåå±éãã¿ã³ã䜿çšããŠOSSIM Webã³ã³ãœãŒã«ãããšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããã®ãæã䟿å©ã§ãã ãã ããã¿ãŒã²ãããã¹ãïŒãŸãã¯ãã¡ã€ã³ïŒã®ããŒã«ã«ç®¡çè
ã®è³æ Œæ
å ±ãå¿
èŠã«ãªããŸãã ã°ã«ãŒãããªã·ãŒããã®ã€ã³ã¹ããŒã«ãŸãã¯SCCMã®äœ¿çšã¯éåžžã«å°é£ã§ãã å®éã«ã¯ãåã€ã³ã¹ããŒã«ãã¡ã€ã«ã¯ããµãŒããŒãšã®éä¿¡ãæå·åããããã®äžæã®ããŒãå«ããããç¹å®ã®ãã¹ãã«å¯ŸããŠåå¥ã§ãã PCI DSSã¬ãã«ã§ã®ãã®ãããªç§å¯ã æ²ãã¿ã
Linuxã®å ŽåããšãŒãžã§ã³ãã¬ã¹ãå¯èœã§ãããSSHãä»ãããã¹ãæ¥ç¶ã®ã»ããã¢ãããå¿
èŠã§ãã ç§ã®æèŠã§ã¯ãããã¯æªãèãã§ãã ç§ã¯ãšãŒãžã§ã³ãã眮ãããšã奜ã¿ãŸãã ãã®å Žåããçãããã¿ãŒã²ãããã·ã³ã«ãšãŒãžã§ã³ããã³ã³ãã€ã«ããŠå®å
šã«æåã§ã€ã³ã¹ããŒã«ããŸãã ããŒãžã§ã³2.8.2ãå
¬åŒã«ãµããŒãããŸããããããŒãžã§ã³2.8.3ãåé¡ãªãæ©èœããŸãã å®éã«ã¯ãããšãã°Debianãªã©ãããŸããŸãªã·ã¹ãã çšã®ããã±ãŒãžããããŸãã 詳现ã¯
ãã¡ããã芧ãã ããã
ããã¥ã¡ã³ããæ¢ãå Žæãšèªãã¹ããã®
Webã³ã³ãœãŒã«ã¡ãã¥ãŒã®ãµããŒããã¿ã³ãã¯ãªãã¯ããŠããªã³ã¯ãååŸããŸãã èªãå¿
èŠããããŸãïŒ
USM 5.xãã©ã°ã€ã³ç®¡çã¬ã€ãçžé¢ãã£ã¬ã¯ãã£ããŸãã¯çžäºçžé¢ã«ãŒã«ã®ã«ã¹ã¿ãã€ãºAlienVaultã§ã®äŸµå
¥æ€ç¥ããªã·ãŒç®¡çã®åºç€OTXã§USMããã³OSSIM 5.1ã䜿çšãã-AlienVaultè³ç£ãã°ã«ãŒãããããã¯ãŒã¯ã·ã¹ãã ãšã©ãŒãèŠåãææ¡SIEMãå¿
èŠãªçç±
誰ããçè§£ããŠããããã«èŠããŸãããããžãã¹ã«é¢ããŠã¯ãã»ãšãã©ã®å Žåã人ã
ã¯SIEMã®ç®çãæ£ããçè§£ããŠããªãããšãããããŸãã ãŸã第äžã«ãããã¯ææžçã§ã¯ãããŸããã ãã»ãã¥ãªãã£ç®¡çã·ã¹ãã ãã§ããªãã®ã§ããã®èšäºã®ã¿ã€ãã«ã倱瀌ããŸãããæåã«å§ããããã§ã¯ãããŸããã å®éãããã¯ã»ãã¥ãªãã£äŸµå®³ã®æåãæ€åºããææ®µã§ãã ä¿è·ãæ§ç¯ããããã®æšæºçãªã¹ããŒã ã¯ãèµ·ããããæ»æïŒå®éã®è
åšïŒãšãããã®å®è¡æ¹æ³ã®èå¥ããå§ãŸããŸãã æ¬¡ã«ãèãããããæ»æãã¯ãã«ãã«çœ®ãããæè¡çããã³çµç¹çãªé²åŸ¡ææ®µãèæ¡ãããå®è£
ãããŸãã ãããŠãããããã¹ãŠã®åŸããã³ã³ãããŒã«ããèšå®ãããŸãããã®ç®çã¯ããã¹ãŠã®ä¿è·ææ®µãæ©èœããªãããšã確èªããããšã§ãã ãŸããSIEMã¯ãã®ã¯ã©ã¹ã«å±ããŸãã
ããã¯ããªããçè§£ããå¿
èŠããããã®ã§ãã SIEMã¯ããã§ã«çºçããéåãæ€åºããããæè¡çããã³çµç¹çãªä¿è·ææ®µãåé¿ããããã«èšèšãããŠããŸãã ããã¯ããããªç£èŠã·ã¹ãã ã®ãããªãã®ã§ãã ãŸãããããã®éåãæ€åºããå
åãSIEMããããã®å
åãèå¥ããæ¹æ³ãå¿
èŠãªæ
å ±ãååŸããå Žæã決å®ããå¿
èŠããããŸãã SIEMã«è¡šç€ºãããªããããããŸãŒã³ãã¯ãããŸããã ç¶æ³ã¯æãäºæ³å€ã®å ŽåããããŸãã

OSSIMã¯ãåæã®ããã«çããããã±ãããpcap圢åŒã§ä¿åããŸãã ããã«ãããŸãïŒ

ããã¯äœã ã£ãïŒ
ããããããã¯ãã®ãããªãã®ã§ããã ãããªãã£ã¹ã§ã¯ãITå°éå®¶ãTomcatã¢ããªã±ãŒã·ã§ã³ãµãŒããŒç°å¢ã§å転ããŠããããçš®ã®ãã®ããã¹ãããŸããã ãã¡ãããåºäŒã£ãæåã®ãµãŒããŒã«ãã®ãã®ãã€ã³ã¹ããŒã«ããã³ã³ãœãŒã«ã®å
¥ãå£ã«ç©ºã®ãã¹ã¯ãŒããæ®ããŸããã ãã¹ãããŠå¿ããŠããŸã£ãã æåã®ãµãŒããŒã¯ã¿ãŒããã«ãµãŒãã¹ãµãŒããŒã§ããããšã倿ããŸããã ãããŠããåãã®ãšãããtomcatã¯ã·ã¹ãã ã¢ã«ãŠã³ãã§åäœããŸããã éªæªãªããã«ãŒãã£ãã·ã³ã°ãåŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒã«ããã€ã®æšéŠ¬ãæ»ã蟌ãŸãããããã¯ãŒã¯äžã§æçšãªãã®ã調ã¹ãŸããã ãã®å¿ããããWebãµãŒããŒãèŠã€ããŠåãã§ããã ã³ã³ãœãŒã«ã³ãã³ãããµããŒãããããã«ã©ã€ãã©ãªã泚ããŸããã ãã®ã©ã€ãã©ãªããã¹ããããã®ç¬éãåçã«ç€ºãããŠããŸãã net userã³ãã³ããå®è¡ãããsuricataãhttp-responceã®åºåã®å
容ãèŠãŠããŒã€ã³ã°ãåºããŸããã 圌ããã©ããªçš®é¡ã®ãŽããæŽçããŠããéãéªæªãªããã«ãŒã¯ãã§ã«ããã«ããããã«æŒã蟌ã¿ããŠãŒã¶ãŒãã¹ã¯ãŒããåéãå§ããŸããã幞ããªããšã«ããããã¯ãã¹ãŠã¿ãŒããã«ãµãŒããŒã«è¡ããŸãã
ç¶æ³ã¯éåžžã«éèŠã§ãã 人ã
ã¯åžžã«ééããç¯ããŸãã ITå°éå®¶ã ãã§ãªããããã«ãŒãã
ãŸãã¯ãããã«ç°¡åãªè©±ããããŸãã ããã¯ãå®å
šã«æ°ããã¢ã©ãŒã ããŒãžã§ãã

ããã¯ãããããOTXãã«ã¹ã§ãã è©³çŽ°ã¯æ¬¡ã®ãšããã§ãã

ããã¯äœã ã£ãïŒ
ãããŠãããã¯åŸæ¥å¡ã®1人ã®ãã©ãŠã¶ã§ãããbankir.ruã®ãã©ãŒã©ã ã¹ã¬ããã®1ã€ãèŠãŠãURL owqkq.ne1t3v8.topã«æ¥ãã§è¡ããŸãããããã¯Angler Exploit Toolkitã䜿çšããé§è»ããŒãžã®1ã€ã§ãã ãŸãè峿·±ã話ã
ãããããŸãŒã³ããåé¿ããã«ã¯ããŸããããã¯ãŒã¯äžã®ãã¹ãŠã®ãã¹ãã«HIDSãšãŒãžã§ã³ãïŒOSSECïŒãé
眮ããå¿
èŠããããŸãã æ¬¡ã«ãå
éšãããã¯ãŒã¯äžã®ãã¹ãŠã®ãã©ãã£ãã¯ã®ãå€èªäžèœããªOSSIMã€ã³ã¿ãŒãã§ã€ã¹ãžã®éä¿¡ãæ§æããŠãNIDSïŒSuricataïŒã«ãã£ãŠåŠçãããããã«ããŸãã å°ãªããšããã¹ãŠã®DMZããŒãã®OpenVASã¹ãã£ããŒã§å®æçãªè匱æ§ã¹ãã£ã³ãæ§æããŠå®è¡ããããšãäžå¯æ¬ ã§ãã ããã¯éèŠã§ãã 芳å¯ã«ãããšãéåžžã«å°ããªäŒç€Ÿã§ããæ¯æ¥20ã50ã®æµã¹ãã£ããŒãééããŠããŸãã ããªãã圌ããããåã«è匱æ§ãçºèŠãããªãã°ãããã¯ããè¯ãã§ãããã ç§ã¯èªåŒµã§ã¯ãªãããã 軜èŠããŠããŸãã 以äžã¯ãæ¥å ±ã®å®éã®ã¹ããããã§ãã
2016:02:18 - 2016:02:19
IP
2016-02-18 09:22:46 180.97.106.37 Nanjing Malicious Host
2016-02-18 09:38:37 216.218.206.123 Fremont Malicious Host
2016-02-18 09:52:57 85.25.214.226 Germany Scanning Host
2016-02-18 10:08:11 146.185.250.105 Saint Petersburg Malicious Host
2016-02-18 10:22:54 178.62.14.193 London Malicious Host
2016-02-18 10:23:24 94.102.49.79 Netherlands Malicious Host
2016-02-18 10:47:52 195.88.209.6 Moscow Malicious Host
2016-02-18 10:53:29 222.186.34.177 Nanjing Malicious Host
2016-02-18 11:07:48 71.6.135.131 San Diego Malicious Host
2016-02-18 11:58:17 193.105.134.220 Sweden Malicious Host
2016-02-18 11:58:51 62.210.206.219 France Malicious Host
2016-02-18 12:28:13 193.109.69.150 Russia Malicious Host
2016-02-18 12:43:40 216.218.206.96 Fremont Malicious Host
2016-02-18 13:08:50 209.126.124.67 St Louis Malicious Host
2016-02-18 13:53:19 178.33.17.241 France Malicious Host
2016-02-18 14:23:52 198.20.70.114 Chicago Malicious Host
2016-02-18 14:32:49 104.219.238.10 Rye Malicious Host Scanning Host
2016-02-18 14:38:38 198.23.112.119 Dallas Scanning Host
2016-02-18 15:02:58 198.20.69.98 Chicago Malicious Host
2016-02-18 15:03:29 64.125.239.136 United States Malicious Host
2016-02-18 15:28:35 162.248.74.2 Clarks Summit Malicious Host
2016-02-18 15:43:36 222.174.5.28 Jinan Malicious Host
2016-02-18 15:57:42 66.240.236.119 San Diego Malicious Host
2016-02-18 16:13:09 74.82.47.45 Fremont Malicious Host
2016-02-18 16:13:44 64.125.239.92 United States Malicious Host
2016-02-18 17:07:57 142.54.162.74 Kansas City Malicious Host
2016-02-18 17:22:41 64.125.239.107 United States Malicious Host
2016-02-18 17:58:54 23.239.66.99 United States Malicious Host
2016-02-18 18:07:50 61.216.2.14 Taiwan Malicious Host
2016-02-18 18:08:03 198.20.69.74 Chicago Malicious Host
2016-02-18 18:08:18 141.212.122.84 Ann Arbor Malicious Host
2016-02-18 18:08:18 141.212.122.81 Ann Arbor Malicious Host
2016-02-18 19:52:53 185.94.111.1 Russia Malicious Host
2016-02-18 19:58:27 162.244.35.24 United States Malicious Host
2016-02-18 20:23:00 162.244.35.22 United States Malicious Host
2016-02-18 20:23:37 89.248.160.192 Netherlands Malicious Host
2016-02-18 20:43:55 222.174.5.17 Jinan Malicious Host
2016-02-18 21:23:55 185.130.5.201 Republic of Lithuania Malicious Host
2016-02-18 21:47:39 92.60.184.34 Ukraine Scanning Host
2016-02-18 22:33:48 209.126.102.181 St Louis Malicious Host
2016-02-18 22:57:37 71.6.167.142 San Diego Malicious Host
2016-02-18 23:13:37 212.83.148.78 France Malicious Host
2016-02-19 00:07:54 185.130.5.240 Republic of Lithuania Scanning Host
2016-02-19 00:48:22 64.125.239.224 United States Malicious Host
2016-02-19 01:13:11 66.240.192.138 San Diego Malicious Host Scanning Host
2016-02-19 02:33:05 198.204.234.74 Kansas City Scanning Host Malicious Host
2016-02-19 02:57:03 104.243.223.8 Tampa Malicious Host
2016-02-19 02:58:02 198.20.99.130 Netherlands Malicious Host
2016-02-19 03:27:43 162.244.35.25 United States Malicious Host
2016-02-19 03:28:13 89.163.251.200 Germany Malicious Host
2016-02-19 04:28:25 71.6.165.200 San Diego Malicious Host
2016-02-19 04:52:08 93.174.93.181 Netherlands Malicious Host
2016-02-19 04:58:24 184.105.247.238 Fremont Malicious Host
2016-02-19 05:23:07 192.162.101.79 Russia Malicious Host
2016-02-19 05:23:20 64.125.239.112 United States Malicious Host
2016-02-19 06:12:43 188.138.1.218 Germany Malicious Host Scanning Host
2016-02-19 06:12:44 74.82.47.55 Fremont Malicious Host
2016-02-19 06:43:55 209.239.123.106 St Louis Malicious Host
2016-02-19 07:13:45 185.56.28.67 Netherlands Malicious Host
2016-02-19 08:13:09 184.105.247.228 Fremont Malicious Host
2016-02-19 08:28:51 184.105.139.72 Fremont Malicious Host
ãããŠãããã¯ã³ãã¥ããã£ã«ç¥ãããŠããæªåœ¹ã«é¢é£ããéšåã®ã¿ã§ãããã¬ããŒãã«ã¯æªç¥ã®æªåœ¹ã®ãªã¹ããå«ãå¥ã®éšåããããŸãã ãã¡ããããããã®ã»ãšãã©ã¯ããŸãããã·ã¥ããŸããã äŸïŒãã®ããã«ïŒããã¯åãã¬ããŒãããã®åãæãã§ãïŒïŒ
Netflow 180.97.106.37 : Nanjing : Malicious Host
2016-02-18 09:22:46.585 0.000 ICMP 91.111.111.9:0 180.97.106.37:3.0 1 56 1
2016-02-18 09:22:46.586 0.000 TCP 180.97.106.37:46024 91.111.111.9:3128 1 40 1
2016-02-18 20:32:23.247 0.000 TCP 180.97.106.37:37254 91.111.111.101:22 1 40 1
2016-02-18 20:43:38.783 0.000 TCP 180.97.106.37:45840 91.111.111.25:22 1 40 1
2016-02-18 20:43:38.783 0.000 ICMP 91.111.111.25:0 180.97.106.37:3.0 3 204 1
2016-02-18 22:07:25.502 0.000 TCP 180.97.106.37:54895 91.111.111.36:22 2 80 1
2016-02-18 22:41:06.739 0.000 TCP 91.111.111.13:22 180.97.106.37:48365 1 40 1
2016-02-18 23:16:01.974 0.996 TCP 180.97.106.37:13302 91.111.111.32:80 10 539 1
2016-02-18 23:16:01.975 0.679 TCP 91.111.111.32:80 180.97.106.37:13302 7 3048 1
2016-02-18 23:20:07.473 0.000 TCP 180.97.106.37:43667 91.111.111.9:22 2 80 1
2016-02-18 23:20:07.473 0.000 ICMP 91.111.111.9:0 180.97.106.37:3.0 1 56 1
2016-02-19 05:50:52.757 12.217 TCP 91.111.111.44:80 180.97.106.37:53461 5 260 1
ããããéåžžã«éªéãªæ§æ ŒããããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ãã°ãå¿
èŠã«ãªããŸãã ããã¯ãã©ã®ãªãã£ã¹ã§ãæå°å€ã§ãã ãããŠãå
éšã®ãã®ããããŸããDBMSããã³åã
ã®ããžãã¹ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãã°ãWebãµãŒããŒãã°ãªã©ã§ãã ãªã© å¿
èŠãªãã®ããã¹ãŠåéã§ããŸãã ãã°ãè§£æããããã®æšæºãã©ã°ã€ã³ããªãå Žåã¯ãç¬èªã®ãã©ã°ã€ã³ãäœæããã®ã¯éåžžã«ç°¡åã§ãã çå®ã¯ç°¡åã§ãã æåã®ãã©ã°ã€ã³ãéçºããã®ã«æ°æ¥ãããããŸããã ãããŠã2çªç®ã®éçºã«ã¯æ°æéããããŸãã
ããšãã°ãçµç¹ã®ã»ãã¥ãªãã£å¯Ÿçã®éåãç£èŠããå Žåããªãã£ã¹ã§ã¯ãæ
å ±ã»ãã¥ãªãã£ãµãŒãã¹ã®æ¿èªãªãã«éçšç°å¢ã®æ§æã倿Žããããšã¯çŠæ¢ãããŠããŸãã OSSECã¯ãæ§æã®å€æŽã«ã€ããŠå£sã鳎ãããåæããããã©ããã確èªã§ããŸãã æãè峿·±ãéšåã¯ã誰ããã®å€æŽãè¡ã£ãŠããªãããšã倿ãããšãã«å§ãŸããŸãã
ã©ã®å¶åŸ¡ã«ãŒã«ãé©çšãã¹ããã«ã€ããŠæ£ç¢ºã«ã¢ããã€ã¹ããã€ããã¯ãããŸããã åæã«ã¯ç¬èªã®äŒçµ±ããããŸãã ã質åãããå Žåã¯ããåãåãããã ããã
éèŠã§ãã AlienVault OSSIMã¯ãå€å
žçãªæå³ã§ã®SIEMã ãã§ã¯ãããŸããã ããã¯ããã¹ãIDSããããã¯ãŒã¯IDSãã¯ã€ã€ã¬ã¹IDSãVolnurability ScanerãNetFlow Collectorãå«ãæ¬æ£å
šäœã§ãã ã€ãŸããäŒæ¥ã®ãããã¯ãŒã¯ã®ãããªç£èŠãæŽçããããã®å®å
šãªå€å
žçãªãã³ã³ãããŒã«ãã®ã»ããã§ãã
ãã©ãã«ãšå°æ
äœãããããããšæãããå Žåã¯ããã°ã確èªããŠãã ããã ã©ãïŒ
OSSECãã°ãšãšã©ãŒïŒ
`/var/ossec/logs/ossec.log`-ããã«OSSECãšã©ãŒã衚瀺ãããŸãã æãäžè¬çãªééãã¯ããšãŒãžã§ã³ããšã®éä¿¡ã倱ãããããšã§ããããã¯ããããã¯ãŒã¯äžã§èŽåœçãªéä¿¡é害ãçºçããå ŽåããŸãã¯ãšãŒãžã§ã³ããåã€ã³ã¹ããŒã«ããåŸã«çºçããŸãã ãŸãã§ããããšãŒãžã§ã³ãã®æ°ãå€ãå Žåãããã»ã©çããããšã§ã¯ãããŸããã ãšãŒãžã§ã³ããã¢ã¯ãã£ãã§ãªãããšãã³ã³ãœãŒã«ã§ç¢ºèªããã³ã³ãã¥ãŒã¿ãŒã®é»æºãå
¥ã£ãŠããããšãããã£ãŠããå Žåã¯ãããã«ããŸãã ãã°ã§ã¯ããšã©ãŒã¯ãERRORïŒDuplicated counter for 'agent-name'ãã®ããã«ãªããŸãã åçŽã«æé€ãããŸãã Webã³ã³ãœãŒã«ïŒç°å¢-æ€åº-ãšãŒãžã§ã³ãïŒãŸãã¯ãã¡ã€ã« `/ var / ossec / etc / client.keys`ã§ããã®ååã®ãšãŒãžã§ã³ããæ¢ãããã®çªå·ïŒå·Šç«¯ã®åã®çªå·ïŒã確èªããŸãã æ¬¡ã«ã `/ var / ossec / queue / rids`ãã£ã¬ã¯ããªã«ç§»åãããã®äžã®ãã¡ã€ã«-ãšãŒãžã§ã³ãçªå·ãåé€ããŸãã SSHããµãŒããŒã³ã³ãœãŒã«ã«ç§»åããã³ãã³ãã©ã€ã³ãçµäºããŠã `/ etc / init.d / ossec restart`ãå®è¡ããŸãã ãã¹ãŠã®ãã®ã æ£çŽãªãšãããOSSECã§ä»ã®ãšã©ãŒãèŠãããšã¯ãããŸããã
`/ var / ossec / logs / alerts / alerts.log`ã¯ãOSSECããšãŒãžã§ã³ãããåãã ã€ãã³ããåéãããã°ã§ããããã¯ãOSSIMãOSSECã®ãã©ã°ã€ã³ã§ã€ãã³ããèªã¿åããåŠçããå Žæã§ãã ããã§ãäœãããã«è¡ããã©ã®ããã«èŠããããèŠãããšãã§ããŸãã
åŸæ¥ã® `/ var / log`ã«ããæ®ãã®ãã°ã¯ã` / var / log / alienvault / agent / agent.log`ãšåãå Žæã«ããã `agent_error.log`ã«ãããŸãã ç¬èªã®ãã©ã°ã€ã³ããããã°ãããšãã«äŸ¿å©ã§ãã äœæ¥ã·ã¹ãã ã§ã¯ããagent.logãã®ãµã€ãºã¯ã®ã¬ãã€ãåäœã§ããããšã«æ³šæããŠãã ããã
OSSIMã®åäœã«é倧ãªãšã©ãŒãèŠãããšã¯ãããŸããã ã·ã¹ãã ã®æ¬¡ã®æŽæ°åŸã宿çãªããã¯ã¢ãããæ©èœããªããªããŸããã ãã¡ã€ã«ã®1ã€ã«æš©éã誀ã£ãŠå²ãåœãŠãããšã倿ããŸããã ããã¯ç¿æ¥ãæåéãä¿®æ£ãããŸããã ãã®ãããªåé¡ã«é¢ããæ
å ±ã¯ãã³ãã¥ããã£ãã©ãŒã©ã ã§éå¬ãããŸãã ããäžåºŠãæ¬¡ã®æŽæ°åŸãæ¬¡ã®æŽæ°ãæ©èœããªããªããŸããã ä»åã¯ã4æéåã«æçš¿ãããæŽæ°ã«ãã°ãå«ãŸããŠããããã®æ¹æ³ã§ä¿®æ£ããå¿
èŠããããšããéç¥ãæ¥ãŸããããä¿®æ£ãããæŽæ°ã¯ãã®ãããªææã«æçš¿ãããŸããã ã¡ãªã¿ã«ãæšæºçãªææ®µïŒWebãŸãã¯sshã³ã³ãœãŒã«ããïŒã«ããæŽæ°ãã¯ã©ãã·ã¥ããŠæ©èœããªãå Žåã¯ãã³ãã³ãã§æŽæ°ãå®è¡ã§ããŸãã
apt-get update
apt-get upgrade
ãµãŒããŒã³ã³ãœãŒã«ããã
ãããããããç§ãèšãããã£ãããšã®ãã¹ãŠã§ãã ãããŠæãéèŠãªããšã§ãã ããã¯ãªãŒãã³ãœãŒã¹ã§ãã ããªããæããã®ã¯äœã§ããPythonã¯ããªããšäžç·ã§ãã ãããŠãããªãã圌ãšäžç·ã«ããããªãå Žåã¯ãåçšç-PythonãèŠãŠãã ããã ãããŠããã§æåŸã®è³ªåã«è¡ããŸãã
ãªãŒãã³ãœãŒã¹ããšã³ã¿ãŒãã©ã€ãºãïŒ
ç§ã®çãã¯ãäŒç€Ÿã®ããŒãºã«åãããŠSIEMãå¿
èŠãªå Žåã¯ããšã³ã¿ãŒãã©ã€ãºã§ãã ãã¡ãããäŒæ¥ãç¬èªã®SIEMã®éçºãç®æããŠããªãå ŽåããªãŒãã³ãœãŒã¹ããŒãžã§ã³ããšã³ã¿ãŒãã©ã€ãºã¬ãã«ã«ããããã®ååãªäººçããã³æè¡çãªãœãŒã¹ã¯ãããŸããã ãããããããããªãã®ããžãã¹ã§ã¯ãªãå Žåãããªãèªèº«ã®äžè©±ãããŠãã ããã æ®å¿µãªããããšã³ã¿ãŒãã©ã€ãºSIEMã¯éåžžã«é«äŸ¡ã§ãã ããããéåžžã«é«äŸ¡ãªã®ã¯ãç°åžžãªçžé¢ãµãŒããŒãšã³ãžã³ãããããã§ã¯ãªããã€ãã³ãçžé¢ã«ãŒã«ã©ã€ãã©ãªã®äœæãè€éãªæ»æã®ãã·ã°ããã£ãã®åæãšãããã®æ€åºæ¹æ³ãããã³ãããã®ã¡ãœããã®ãããã°ã«å€å€§ãªæè³ãããããã§ãã ããã¯ãèªåã§ã¯ã§ããªãä»äºã§ãã ããã§ã¯åçšè£œåã®å©ç¹ã«ã€ããŠã¯èª¬æããŸããããããã®å©ç¹ã¯æããã§ãããè°è«ãã䟡å€ã¯ãããŸããã
ã§ã¯ããªããã®ãªãŒãã³ãœãŒã¹ã«æéãç¡é§ã«ããŠããã®ã§ããããïŒ ãŸã第äžã«ãç§ã¯åœŒã奜ãã§ãã ãã®ãããªãã¹ãŠã®ãªãŒãã³ãœãŒã¹ãããžã§ã¯ãã®äžã§ãããã¯æåããŠããŸãã 第äºã«ãAlienVaultã®Webãµã€ãã¯ãã誰ã§ãã»ãã¥ãªãã£ã«ã¢ã¯ã»ã¹ã§ããããã«ãããããšèšã£ãŠããŸãã ããèãã ã ãµããŒãããŸãã ããŸãã«ãå€ãã®äŒæ¥ã¯ããã®ã¯ã©ã¹ã®åçšè£œåã賌å
¥ããäœè£ããããŸããã sysadminã®ããªãŒã©ã³ãµãŒã倧å¢ããããšã¯ç¥ã£ãŠããŸããå°ããªäŒç€Ÿã«ãµãŒãã¹ãæäŸããŠãããšããŸãããã 圌ãããã®ããã«èŠããããšã¯çã«ããªã£ãŠããŸãã åé ã§ããã³ã³ãã¥ãŒã¿ãŒã«ã€ããŠèšåããã®ã¯ãäœã®æå³ããããŸããã Little SIEMã¯éåžžã«çŸå®çãªãã®ã§ãã
ãšã³ã¿ãŒãã©ã€ãº-ãšã³ã¿ãŒãã©ã€ãºãããã³ã³ãã¥ããã£-ã³ãã¥ããã£ã åå°-蟲æ°ãå·¥å Ž-åŽåè
ããé-éè¡å¡ã ããã¹ãŠã®äººã«å¹žçŠãããããŠãã¹ãŠã®äººã«ååãïŒA.ãšB. Strugatskyããå芳è
ã®ãã¯ããã¯ãïŒã
䜿çšããããœãŒã¹ïŒ
https://www.alienvault.com/documentationhttps://alienvault.ru/open-threat-exchange/http://ossec.imtqy.com/docs/http://suricata-ids.org/docs/