ããããããšã§ããããŸãåžå Žã§è§£æ±ºçãæ¢ããŸããããããèŠã€ããã®ã§ã¯ãªããèªåã§èªåã§è§£æ±ºããŸãã ãããŠãããã¯ããªããä»ã®äººã«ãããäžããã»ã©è¯ããªããŸããã ãã®ãããOpenSOCã¯ããµã€ããŒã»ãã¥ãªãã£ã®åéã§å€§éã®ããŒã¿ã管çããããã®ãªãŒãã³ãœãŒã¹ãœãªã¥ãŒã·ã§ã³ã§ãããã·ã¹ã³ç¬èªã®ããŒãºã«å¿ããŠéçºãããäžè¬ã¢ã¯ã»ã¹çšã«GitHubã«æçš¿ãããŸããã

ã¢ã¯ã»ã¹å¶åŸ¡ããã»ã¹ãã·ã¹ã³å
éšã§ã©ã®ããã«æ§ç¯ãããŠãããã«ã€ããŠã®ä»¥åã®
ã¡ã¢ã® 1ã€ãæãåºããšãå¶åŸ¡ããå¿
èŠãããããã€ã¹ã®æ°ã«æ³šæãæãããšãã§ããŸãã ãããŠããããã®ããã€ã¹ã
æ¯æ¥çæ/ééããå®å
šæ§ã«ãšã£ãŠéèŠãªããŒã¿ãèŠãŠã¿ãŸãããïŒ
- 47ãã©ãã€ãã®ãããã¯ãŒã¯ãã©ãã£ãã¯ããŒã¿
- 1.2å
ã®ãããã¯ãŒã¯ã€ãã³ã
- Cisco Umbrellaã·ã¹ãã ã®48åDNSã¯ãšãª
- Ciscoé»åã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ã®4.1çŸäžã®é»åã¡ãŒã«ã¡ãã»ãŒãž
- Cisco Webã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ããã³Ciscoã¯ã©ãŠãWebã»ãã¥ãªãã£ã«å¯Ÿãã4,500äžã®WebèŠæ±ïŒURLïŒ
- Cisco Stealthwatchåãã®150åã®NetFlowãããŒ
- Cisco NGIPSããã®150äžä»¶ã®ã¢ã©ãŒã
- Cisco AMP ThreatGridã·ã¹ãã çšã®1äžåã®ãã¡ã€ã«ã
åèšã§ãåæç®çã§æ¯æ¥4 TBã®ããŒã¿ãåéããŠä¿åããŸãã ããã¯èšå€§ãªæ
å ±ã§ãããå¹æçãªç®¡çã®ããã«ãåœç€Ÿã®ãµã€ããŒã»ãã¥ãªãã£ãµãŒãã¹ã¯åã«ç¹å¥ãªããŒã«ãå¿
èŠãšããŠããŸããã ã»ãã¥ãªãã£ã€ãã³ã管çã®ãããã¯ãçºçãããšãã«æåã«é ã«æµ®ãã¶ã®ã¯SIEMïŒã»ãã¥ãªãã£æ
å ±ã€ãã³ã管çïŒã§ãããäžçã®ä»ã®å€ãã®äŒæ¥ãšåæ§ã«ãç§ãã¡ããã®ãããªãœãªã¥ãŒã·ã§ã³ã䜿çšããããšããŸããã ããããæ®å¿µãªããšã«ãåäžã®SIEMãœãªã¥ãŒã·ã§ã³ã§åé¡ã解決ã§ããããã§ã¯ãªããããã«ã¯ããã€ãã®çç±ããããŸããã
- ããŒã¿ã®ã€ã³ããã¯ã¹äœæã®è€éãã¯ãéçºãããæ
å ±ã»ãã¥ãªãã£ããŒã«ã®ããŒã¿åœ¢åŒã®ãµããŒããå«ãæ
å ±ä¿è·ããŒã«ã«ãããã®ã§ã¯ãããŸããïŒãã®å Žåãã客æ§ã«è²©å£²ããã ãã§ãªããèªç€Ÿã§äœ¿çšããã ãã§ãªããæ
å ±ã»ãã¥ãªãã£ãšã³ãžãã¢ã«ãã£ãŠããŸããŸã«äœæãããã·ã¹ã³ããŒããã©ãªãªã«ã€ããŠã¯èšåããŠããŸããç¹å®ã®ã¿ã¹ã¯ã®ãããŒã«ãïŒ
- ã¹ã±ãŒãªã³ã°ãšããŒã¿åŠçé床ã«é¢ããæ·±å»ãªåé¡ïŒããã10 GBã®ããŒã¿ã®æ€çŽ¢ã«ã¯6å以äžããããŸããïŒ
- ã¿ã¹ã¯ã«åãããŠãœãªã¥ãŒã·ã§ã³ãã«ã¹ã¿ãã€ãºããããšã®é£ãããšããã¹ãŠã®çµã¿èŸŒã¿ã«ãŒã«ããŒãããæžãçŽãã誀æ€åºãå€ãããããšã®å¿
èŠæ§
- æ§é åããŒã¿ãšéæ§é åããŒã¿ã®æäœã®è€éãã
æ¢åã®SIEMãœãªã¥ãŒã·ã§ã³ã®ä»£æ¿ãšããŠãSplunkã®äœ¿çšãéå§ããŸãããããã«ãããäžèšã®åé¡ã®å€ãã解決ã§ããããã«ã³ã¹ããåæžã§ããŸããã ããã... Splunkã¯ããã¹ãŠã«ããããããããŸã ãã¹ãŠã®åé¡ã解決ã§ããŸããã§ããã ãããã®95ïŒ
ã®ã¿ã 圌ã¯ãã¢ã³ããŠã€ã«ã¹ãITUãIDS / IPSãã³ã³ãã³ããã£ã«ã¿ãªã³ã°ã·ã¹ãã ãªã©ããããŒã¿ãåéããŸããã ããããã€ã³ã·ãã³ã察å¿ããŒã ã«ãšã£ãŠéåžžã«éèŠãªæ
å ±ã®5ïŒ
ãè¹å€ã«æ®ãããŸããã è
åšãæ»æè
ããã®æ¹æ³ããã³æŠè¡ã«é¢ããéåžžã«éèŠãªæ
å ±ã ãã®æ
å ±ã䜿çšããŠãã»ãã¥ãªãã£ããŒã«ããSplunkã§å©çšå¯èœãªããŒã¿ãå
å®ãããããšã¯ããã»ã©ç°¡åã§ã¯ãããŸããã§ããã ãŸããããŸããŸãªåçŽãªã¹ã¯ãªãããšãŠãŒãã£ãªãã£ãäœæãããããããçãã¿ã¹ã¯ã解決ããŸããã ãã®åŸãã¢ã€ãã¢ãæãã€ãããµã€ããŒã»ãã¥ãªãã£ã®åéã§ããã°ããŒã¿ãåæããããã®å®å
šãªãã©ãããã©ãŒã ïŒThreat Intelligence PlatformïŒã«å€ããŸããã

OpenSOCãšåŒã°ãããã®ã·ã¹ãã ã¯ãç¬èªã®ããŒãºã®ããã«äœæããããããã·ã¹ã³è£œåã®äœæã«é¢äžããéçºè
ãåŒãä»ããããšã¯ã§ããŸããã§ãããç¬èªã®æ
å ±ã»ãã¥ãªãã£ãµãŒãã¹ã䜿çšããã ãã§æžã¿ãŸããã ãããã£ãŠããã¹ãŠããŒãããäœæããã®ã§ã¯ãªãããªãŒãã³ãœãŒã¹ãœãªã¥ãŒã·ã§ã³ã䜿çšããããšã¯è«ççã§ããããã®äžã§äž»ãªåœ¹å²ãæããããŸããã
- FlumeïŒhttps://flume.apache.orgïŒã¯ãããŸããŸãªåœ¢åŒïŒSyslogãSNMPãNetflowãJMSãHTTPããã¡ã€ã«ãPCAPãªã©ïŒã®ããŸããŸãªãœãŒã¹ãã倧éã®ããŒã¿ãåéããã³éçŽããããã®åæ£ããŒã«ã§ãã OpenSOCã§ã¯ãFlumeã¯ããŸããŸãªã»ãã¥ãªãã£ããŒã«ãã¢ããªã±ãŒã·ã§ã³ãããã³æ©åšãããã¬ã¡ããªãŒãåéããŸãã
- KafkaïŒhttp://kafka.apache.orgïŒã¯ãåæ£åã®é«æ§èœã¡ãã»ãŒãžãããŒã«ãŒïŒãã¹ïŒã§ãã
- StormïŒ[http://storm.apache.org]ïŒã¯ãKafkaãå«ããèšç®ãå®è¡ããããã®ããŒã¿ãåãåãåæ£ãªã¢ã«ã¿ã€ã ããŒã¿ãã³ãã©ã§ãã çµã¿èŸŒã¿ã®ãã³ãã©ãŒã䜿çšãããšãã»ãã¥ãªãã£ã€ãã³ãã«é¢ããããŸããŸãªã¿ã¹ã¯ïŒãã£ã«ã¿ãªã³ã°ãæ£èŠåã解æãè
åšã«é¢ããæ
å ±ã®åŒ·åïŒãå®è¡ã§ããŸãã åŸè
ã®å Žåãæ£èŠåãããããŒã¿ã¯ãæ
å ±ã»ãã¥ãªãã£ã®ã³ã³ããã¹ãïŒå°çäœçœ®æ
å ±ãIPè©äŸ¡ãWhoisããã®æ
å ±ãªã©ïŒã«ãã£ãŠæ¡åŒµãããŸãã OpenSOCã®å
¬éããŒãžã§ã³ã«ã¯ãããã©ã«ãã§ãœãŒã¹ããŒã¿ã匷åãã4ã€ã®ããã»ããµã®ã¿ãå«ãŸããŠããŸãã

- HadoopïŒ[hadoop.apache.org]ïŒ-åæ£ããã°ã©ã ã®å®è¡ãéçºããããã®ãæ€çŽ¢ãã³ã³ããã¹ãã¡ã«ããºã ãªã©ã®ãŠãŒãã£ãªãã£ãšã©ã€ãã©ãªã®ã»ããã ããã°ããŒã¿æè¡ã®åºç€ãç¯ããŸãã OpenSOC Hadoopã¯ã©ã¹ã¿ãŒã¯ãã¹ãŠã®ããŒã¿ãä¿åããŸã
- Elasticsearchã¯ã倧éã®ããŒã¿ã®ãªã¢ã«ã¿ã€ã æ€çŽ¢ããã³ã€ã³ããã¯ã¹äœæã·ã¹ãã ã§ãã
- HBaseã¯éãªã¬ãŒã·ã§ãã«åæ£ããŒã¿ããŒã¹ã§ãã OpenSOCã¯ãé·æãããã¯ãŒã¯ãã±ããã¹ãã¬ãŒãžïŒPCAPïŒãæäŸããŸãã
- Hiveã¯ãHBaseãå«ãHadoopã«åºã¥ãããŒã¿ããŒã¹ç®¡çã·ã¹ãã ã§ãã OpenSOCã¯ãã»ãã¥ãªãã£ã€ãã³ãã®é·æä¿åãæäŸããŸãã
- MySQLã¯ãªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ç®¡çã·ã¹ãã ã§ãã OpenSOCã¯ãHiveã¡ã¿ããŒã¿ãšãå°çäœçœ®æ
å ±ãªã©ã®ä»ã®ããŒã¿ãä¿åããŸãã
- Kibanaã¯èŠèŠåã·ã¹ãã ã§ãã

OpenSOCã¯ãã·ã¹ã³ã®çµ±åã»ãã¥ãªãã£ããŒã¿åæãã©ãããã©ãŒã ã«ãªããŸããã
- ç°åžžããã®ä»ã®æçœã§æé»çãªISéåãæ€åºããããã«ãããŸããŸãªè§åºŠããããŒã¿ãåéãä¿åãåŠçãåæããŸã
- ããŸããŸãªäºæž¬ã¢ãã«ããã³çžé¢ã¢ãã«ã䜿çšããŠãåéãããããŒã¿ã®é ããçžäºäŸåé¢ä¿ãæ€çŽ¢ã§ããŸãã
- åæãããããŒã¿ã®ã³ã³ããã¹ãããªã¢ã«ã¿ã€ã ã§èæ
®ããŸã
- é©åãªç°å¢ã§ã»ãã¥ãªãã£ã€ãã³ããèŠèŠåããå©å®³é¢ä¿è
åãã®ã¬ããŒããçæããŸãã
æè¡çãªèŠ³ç¹ããã¯ã45åã®Cisco UCSãµãŒããŒïŒ1440ããã»ããµã12 TBã®ã¡ã¢ãªïŒã®ã¯ã©ã¹ã¿ãŒãåè¿°ã®ãã¯ãããžãŒHadoopãHiveãHBaseãElasticsearchãªã©ã«åºã¥ããŠããŸãã Cisco OpenSOCã¹ãã¬ãŒãžã®å®¹éã¯1.2 PBã§ãã 1ã€ã®ããŒãã«ã«ã¯ã1.3å
ãè¶
ããè¡ãå«ãŸããŸãã

2013幎ã«Cisco OpenSOCã®äœæãéå§ãã2013幎9æã«æåã®ãããã¿ã€ããç»å ŽããŸããã éäžã2013幎12æã«
Hortonworksãåå ãããããžã§ã¯ãã®éçºã«åŒŸã¿ãã€ããOpenSOCã«ãªãã¯ãã®é«æ§èœã§åæ£åã®ãã©ãããã©ãŒã ã«ãªãŒãã³ãœãŒã¹ã³ã³ããŒãã³ãã䜿çšããããã®å€ãã®èå³æ·±ãã¢ã€ãã¢ããããããŸããã 2014幎3æã«OpenSOCã®éçºãå®äºãã2014幎9æã«å
¬éã
ãŠGitHubã«æçš¿ããŸããã

åºæ¬æ§æã¯ãããŒã¿ã®åéãä¿åãåæã®æ©èœããµããŒãããè
åšã被害è
ãæ»æè
ã«é¢ããæ
å ±ã匷åããŸãã OpenSOCã®å
¬éããŒãžã§ã³ã§ããŸããŸãªã€ãã³ããçžé¢ãããæ©èœãæ¬è³ªçã«å®è¡ããã¢ããã¿ãŒã®æ°ã¯å°ãªãã§ãã ã»ãšãã©ã®SIEMãšåæ§ãããã«äœ¿çšã§ããçžé¢ã«ãŒã«ã¯ããŸãããŸãæ©èœããªããããOpenSOCã§ã¯ãã·ã¹ãã ã®åã³ã³ã·ã¥ãŒããŒã«å¯ŸããŠç¬ç«ããŠèšè¿°ããå¿
èŠããããŸãã ããšãã°ãNTTã°ã«ãŒãã®äŒæ¥ã¯ãããªã¬ãŒãšçžé¢ã«ãŒã«ãäœæããããã®ããŒã«ãšããŠ
EsperãªãŒãã³ãœãŒã¹ãšã³ãžã³ã䜿çšããŠããŸãã

瀟å
ã§OpenSOCãæåããåŸãã¢ãŠããœãŒã·ã³ã°ãµãŒãã¹ã®åºç€ãšããŠéçºããããšã決å®ãããŸããã
Cisco Active Threat Analytics ïŒATAïŒã¯ãåºæ¬çã«åæ£ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã»ã³ã¿ãŒïŒSOCïŒã§ãããã客æ§ã®æ
å ±ã»ãã¥ãªãã£ãç£èŠããã³ç®¡çããæ©èœãæ
ã£ãŠããŸãã äŒæ¥å
ããã³Cisco ATAã®ãã¬ãŒã ã¯ãŒã¯å
ã§OpenSOCãéçºããŠãããšãApache 2.0ã©ã€ã»ã³ã¹ã§ã¯å¿
èŠãªãã®ããã¹ãŠå®è£
ã§ãããšã¯éããªããšããäºå®ã«çŽé¢ããŠããŸãã ã¯ãããªãŒãã³ãœãŒã¹ã³ã³ããŒãã³ãã®ã¿ã§ããçºçãããã¹ãŠã®åé¡ã解決ããããã«å¶éããããšã¯ã§ããŸããã

OpenSOCã®éçºã2ã€ã®é åã«åå²ããããšã決å®ãããŸããã æåã®ãµãŒãã¹ã¯ãISãµãŒãã¹ãšATAãµãŒãã¹ã®ããŒãºã®ããã«ã·ã¹ã³ã«æ®ããŸããã ãããã2çªç®ã®æ¹åã¯éåžžã«èå³æ·±ããã®ã§ããã OpenSOCã¯Apacheã€ã³ãã¥ããŒã¿ãŒã«å
¥ãããªãŒãã³ãœãŒã¹ã³ãã¥ããã£ã«ãã£ãŠéçºãããæ¬æ Œçãªãããžã§ã¯ãã«ãªããŸããã OpenSOCãååãå€æŽãã
Apache Metronã«ãªããŸããã 2016幎4æãApache Metron 0.1ã®æåã®ããŒãžã§ã³ããªãªãŒã¹ãããŸããã åæã«ãã€ããªãã®ãŒã¯å€æŽãããŠããããOpenSOCãŠãŒã¶ãŒã¯Apache Metronã«ç°¡åã«åãæ¿ããããšãã§ããŸãã

Cisco OpenSOCã¯ãå¥ã®æ¹åã§éçºãããŸããã ããã«åºã¥ããŠãMapRã¯
Security Log Analyticsãœãªã¥ãŒã·ã§ã³ãäœæããŸããããã®ãœãªã¥ãŒã·ã§ã³ã¯ãäžèšã®NTTäŒæ¥ãZions Bankãããã³ãã®ä»ã®é¡§å®¢ã䜿çšããŠããŸãã ããããApache Metronã®å Žåã®ããã«ãOpenSOCã®ã€ããªãã®ãŒã¯å€ãããŸããããµã€ããŒã»ãã¥ãªãã£ã®ããã°ããŒã¿åæãšãæ§é åãããããŒã¿ã ãã§ãªããéæ§é åããŒã¿ã§ãæ©èœããŸãã ããã«ãããäŒæ¥ã®è
åšç£èŠæ©èœã倧å¹
ã«æ¡åŒµããããå€ãã®æ
å ±æºã䜿çšããŠã以åãããã¯ããã«å€ãã®æ
å ±ããèŠããããšãã§ããŸãã ããšãã°ãéå»æ°å¹Žã«ããã£ãŠã·ã¹ã³ã§ã¯ã誰ããç¥ã£ãŠããéçãªã«ãŒã«ãšã·ã°ããã£ãããè¡ååæãç°åžžãè
åšã€ã³ããªãžã§ã³ã¹ãžã®ç§»è¡ããããŸããã ããããã¹ãŠã¯ãCisco OpenSOCãªãã§ã¯äžå¯èœã§ããã
