çšèªéïŒ
SIEM ïŒã»ãã¥ãªãã£æ
å ±ããã³ã€ãã³ã管çïŒ-ã€ãã³ãïŒãã°ïŒããããã®çžé¢ããã³åæã«é¢ããæ
å ±ãåéããããã®ããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®è€åäœã
WikiïŒSIEMã«é¢é£ããïŒ
ãŠãŒã¹ã±ãŒã¹ã¯ãã«ãŒã«/ã¹ã¯ãªããããã³/ãŸãã¯èŠèŠåã¡ã«ããºã ã®ç¹å®ã®ã»ããã瀺ã確ç«ãããçšèªã§ãã ããšãã°ãããŒãã¹ãã£ã³ãæ€åºããã«ã¯ãIPã¢ãã¬ã¹ãå€éšã®è©äŸ¡ããŒã¿ããŒã¹ãšèª¿æŽããŸãã ãŠãŒã¹ã±ãŒã¹ã¯èªåã§äœæãããã補é å
ã®Webãµã€ãããæºåããããè«è² æ¥è
ã«æ³šæããããšãã§ããŸãã

ãã®èšäºã®ç®çã¯ããŠãŒã¹ã±ãŒã¹ã«ã¿ãã°ããã³è¿œå ãªãœãŒã¹ã«èšèŒãããŠããæ
å ±ãããã³ã³ã¡ã³ãå
ã®ã¢ã¯ãã£ããªãã€ã¢ãã°ãäœç³»åããããšã§ãã ããªãã®çµéšãå
±æããŠãã ããããããŠãç§ã¯åãåã£ãæ
å ±ã§æçš¿ãæŽæ°ããŸãã
å
容 ïŒ
1. 2016幎ã®SIEMè©äŸ¡
2. SIEMã¡ãŒã«ãŒã®Webãµã€ãã«ããã€ãã£ãããŠãŒã¹ã±ãŒã¹ã¹ãã¢
3.èªå·±èšè¿°åãŠãŒã¹ã±ãŒã¹ã®æšå¥šäºé
4.ã«ã¹ã¿ã éçºïŒã€ã³ãã°ã¬ãŒã¿ãŒã«ãŒã
5.ãµãŒãããŒãã£ãŠãŒã¹ã±ãŒã¹ã«ã¿ãã°ïŒSOC Prime UCLããã³ããŒãã©ãŒã©ã ïŒãªã¹ãã¯æŽæ°äžïŒ
6. SIEMã«é¢é£ããããã°ããã³è¿œå ã®æ
å ±ã»ãã¥ãªãã£ãªãœãŒã¹ãžã®ãªã³ã¯
1. 2016幎ã®SIEMè©äŸ¡
ãŸã SIEMãéžæããæ®µéã«ããå Žåã¯ã2ã€ã®ç¬ç«ãããœãŒã¹ããã®çŸåšã®è©äŸ¡ããããŸãã ããã«ãèšäºèªäœããœãªã¥ãŒã·ã§ã³ããšã«ç°ãªã泚æãæãçç±ãæããã«ããŸãã
åºå
žïŒGartner Magic Quadrant 2016
åºå
žïŒ 2016 InfoSec Nirvana茞å
¥ä»£æ¿ã®ã¿ã¹ã¯ãé¢é£ããå Žåããã·ã¢èªã®ã«ãŒããæã€å°ãªããšã3ã€ã®SIEMããããŸãã
PositiveTechnologiesãæäŸããè¿œå æ
å ±-MP SIEM LEããŒãžãžã®ãªã³ã¯
-www.ptsecurity.com/en-us/promo/siem-le-çŸåšã®ããã¯ã¬ãããžã®å¥ã®ãªã³ã¯
www.ptsecurity.com/upload/ptru/products/documents/mpsiem/PT-MaxPatrol-SIEM-Product-Booklet-rus.pdf-MP SIEM my.webinar.ru/record/873458ã®è©³çްãªãŠã§ãããŒãžã®ãªã³ã¯
ããã¹ãŠã®ããã·ã¢ãSIEMã®äžã§ãPT補åã¯ãããããæ
å ±ã»ãã¥ãªãã£ã«é¢ããåºç¯ãªå°éç¥èïŒãã³ãã¹ã𿻿ã·ããªãªïŒã«ãã£ãŠããã¯ã¢ãããããŠããå¯äžã®ãã®ã§ãããçŸåšã®é¡§å®¢ãœãŒã¹ãç¡æã§ã«ããŒããŠãããšèããŠããŸãã
MaxPatrol SIEMã«æ»ããPositive Technologies Knowledge BaseïŒPTKBïŒã«åºã¥ãPositive Research Knowledge Centerãå°éç¥èã®è£œåã«ç§»è¡ããã¡ã«ããºã ãå®è£
ãããŸããã ããã¯ã䟵å
¥ãã¹ããã»ãã¥ãªãã£ç£æ»ã®çµéšãå«ããç ç©¶ã»ã³ã¿ãŒã®15幎ã®çµéšã«åºã¥ããŠåœ¢æããããé«ã¬ãã«ã§åžžã«æŽæ°ãããããŒã¿ã»ããã§ãã
è©äŸ¡ã«ã¯å«ãŸããŠããŸããããèšåãã䟡å€ããããŸãïŒ
âOSSIMïŒãªãŒãã³ãœãŒã¹ã»ãã¥ãªãã£æ
å ±ç®¡çïŒ
habr1 ã
habr2â
OpenSOC ã
Apache Metronã§çºç
2. SIEMã¡ãŒã«ãŒã®Webãµã€ãã«ããã€ãã£ãããŠãŒã¹ã±ãŒã¹ã¹ãã¢
å
¬éæ¥æç¹ã®æ
å ±ïŒ2016幎11ææ«ïŒã çŸåšãUse Case'ovã®å
¬éçšã«ç¬èªã®ãµã€ããç·šæããŠããã¡ãŒã«ãŒã¯4瀟ã®ã¿ã§ãã ãŸããã»ãšãã©ã®ã¡ãŒã«ãŒã¯ãæ
å ±ã亀æããæ°ããªåé¡ã®è§£æ±ºçãèŠã€ããããã®å
éšãã©ãŒã©ã ãæã£ãŠããŸãã
HPE ArcSightããŒã±ãããã¬ã€ã¹ææã§ç¡æã§ãã 远å ã®ãã£ã«ã¿ãªã³ã°ãé©çšããªãå Žåããµã€ãã«ã¯åèš170ã®ãŠãŒã¹ã±ãŒã¹ããããŸãã
IBM Security App Exchangeç¡æã§ããŠã³ããŒãããŠãã ããã IBMãšããŒãããŒã®äž¡æ¹ãéçºããåèš73ã®ãŠãŒã¹ã±ãŒã¹ãå©çšã§ããŸãã
ãã°ãªãºã ãããŸã§ã®ãšããã19ä»¶ã®ãŠãŒã¹ã±ãŒã¹ã®ã¿ã§ãã ãããã圌ãã®ããŒã±ãã£ã³ã°ã®èª¬æã
ã¹ãã©ã³ã¯ã»ãã¥ãªãã£ãäžæ£ãã³ã³ãã©ã€ã¢ã³ã¹ã®ãµãã»ã¯ã·ã§ã³ã«ã¯ã487ã®ã¢ããªã±ãŒã·ã§ã³ãå«ãŸããŠããŸãã ãã ããã¢ããªã±ãŒã·ã§ã³ã®ã¿ãé€å€ãïŒã¢ããªã³ãéèŠã§ã¯ãããŸãããïŒã補åããŒãžã§ã³6.0以éãæå®ãããšãåèšæ°ã¯236 Use Case'ovã«æžå°ããŸãã
3.èªå·±èšè¿°åãŠãŒã¹ã±ãŒã¹ã®æšå¥šäºé
ãŠãŒã¹ã±ãŒã¹ã®éçºæ¹æ³ã¯ã
ããã° ïŒAnton ChuvakinïŒãš
èšäºã§è©³ãã説æãããŠã
ãŸã ã
ã€ãŸããæ¬æ Œçãªãããããžã§ã¯ããšããŠã¿ã¹ã¯ã«ã¢ãããŒãããå¿
èŠããããŸãã
- 解決ããåé¡ãšãã®åå ãæç¢ºã«å€æããŸãïŒããã¯ãããžãã¹èŠä»¶ãããŒã¿ä¿è·ã®ããã®æ¥çæšæºãèŠå¶ãéµå®ããå¿
èŠæ§ãªã©ïŒã
- ãããžã§ã¯ãã®å¢çïŒã€ãŸããä¿è·ãããITã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç¹å®ã®ã»ã¯ã·ã§ã³ïŒãå®çŸ©ããŸãã
- ãã®åŸãå¯èœæ§ã®ãããã€ãã³ãã®ãœãŒã¹ããç¹å®ããŸãããã®åŠçã«ãããå®çšçãªãŠãŒã¹ã±ãŒã¹ãå®è£
ã§ããŸãã ããã€ã¹ããã®ãã°ãã€ãã³ããã°ãæ§æèšå®ãªã©ããããŸãã
- ãœãŒã¹ãå¿
èŠãªãã¹ãŠã®ããŒã¿ãæ£ããæäŸããŠããããšã確èªããŸããããããªããšãæ£ããéçºããããŠãŒã¹ã±ãŒã¹ã广çã«æ©èœããŸããïŒæ©èœããŸããã
- æåŸã«ããŠãŒã¹ã±ãŒã¹ã®éçºãéå§ããŸãã
- ããžãã¯ãšãããå€ã調æŽããŠãã€ã³ã¹ããŒã«ãšãã¹ããè¡ããŸãã
- ãŠãŒã¹ã±ãŒã¹ãæ¢ã«ãã¹ããããæ¬çªç°å¢ã«ã€ã³ã¹ããŒã«ãããŠããå Žåããã®æäœã«å¯Ÿããåå¿ãæ£ããæ§æããããšãéèŠã§ãïŒããŒã¿ãããã·ã¥ââããŒãã«åã«åºåããããSMS /é»åã¡ãŒã«éç¥ãå¿
èŠãšããããã¹ã¬ãŒãããã€ã¹ã®æ§æã®å€æŽãèªåçã«éå§ããã ãã§ååã§ãïŒããšãã°ãIBMã¯ããã宣èšããŸãïŒ SIEMã¯IPS /ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã倿Žã§ããŸãïŒã
- ããããããã¹ãŠããŸãããïŒ ãã ããããã«é¢ããäœæ¥ã¯å®äºããŠããŸãã-éçºãããã補åã®ã¡ã³ããã³ã¹ãå¿
èŠã§ãïŒåŠçã®ããã«ããŒã¿ãåä¿¡ãããã©ããã宿çã«ç¢ºèªãããã®åœ¢åŒã倿ŽãããŠããªãå Žåã¯ãITã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€åããããããžãšããžãã¹ã®ããŒãºã«åãããŠãŠãŒã¹ã±ãŒã¹èªäœã倿ŽããŸãã
4.ã«ã¹ã¿ã éçºïŒã€ã³ãã°ã¬ãŒã¿ãŒã«ãŒã
ããªãèªèº«ã®åŒ·ã¿/æé/èœåãååã§ãªãå Žåã¯ãå°éå®¶ã«é Œãããšãã§ããŸã-99ïŒ
ã®ã±ãŒã¹ã§ã¯ãåç¬ã§ããŸãã¯SIEMãã³ããŒããã®ãããã§ãã·ã§ãã«ãµãŒãã¹ã«é¢äžããŠããŠãŒã¹ã±ãŒã¹ã®ã«ã¹ã¿ã éçºãšãµããŒããè¡ãã€ã³ãã°ã¬ãŒã¿ãŒäŒæ¥ã«ãªããŸãã
人æ°ã®ããSIEMã®ãããŒãããŒãã±ãŒã¿ãŒãã»ã¯ã·ã§ã³ãžã®ãªã³ã¯ïŒ
â
findapartner.hpe.comâ
www-356.ibm.com/partnerworld/wps/bplocator/search.jspâ
logrhythm.com/partners/resellers-and-mssps/find-a-partner ïŒããŒãããŒã®ãªã¹ãã¯å
¬éãããŠããŸãããããŒãããŒããŒã¿ãéä¿¡ããããã«ããªã¯ãšã¹ããã©ãŒã ã«èšå
¥ããããšããå§ãããŸãïŒã
â
www.rsa.com/en-us/partners/findâ
www.splunk.com/en_us/partners/find-a-partner.htmlãããã®ãªã³ã¯ã§å©çšå¯èœãªããŒãããŒã«é¢ããæ
å ±ã«åºã¥ããŠããŠã¯ã©ã€ããäŸã«äœ¿çšããŠäžè¬çãªè¡šãäœæããŸããïŒããã³ç§ãã¡ã«å
±éã®SIEMïŒã ã芧ã®ãšãããäžéšã®ã€ã³ãã°ã¬ãŒã¿ãŒã¯ãäžå€«äžå©Šå¶ãã§ã¯ãããŸããã
SIEM
ã€ã³ãã°ã¬ãŒã¿ãŒ
| QRadar
| ã¢ãŒã¯ã©ã€ã
| ã¹ãã©ã³ã¯
|
ã¢ã¯ãã£ãç£æ»æ©é¢
| - | - | å販æ¥è
|
Bettaã»ãã¥ãªãã£
| - | - | å販æ¥è
|
BMSã³ã³ãµã«ãã£ã³ã°
| ããžãã¹ããŒãã㌠| ãŽãŒã«ãããŒãã㌠| - |
CBSã°ã«ãŒã
| ããžãã¹ããŒãã㌠| - | - |
Center of Systrem Integration | - | ããžãã¹ããŒãã㌠| - |
COMPAREXãŠã¯ã©ã€ã
| ããžãã¹ããŒãã㌠| - | - |
ã³ã ã»ãã¯
| - | - | å販æ¥è
|
CS Integra
| - | ããžãã¹ããŒãã㌠| - |
IBPM
| ããžãã¹ããŒãã㌠| - | - |
ICSystems
| - | ããžãã¹ããŒãã㌠| - |
èª å®ãªããžã§ã³
| ããžãã¹ããŒãã㌠| - | - |
ISSP
| - | ã·ã«ããŒããŒãããŒã ãšã³ãžãã¢èªå® | - |
IT for BusinessïŒSupportioïŒ
| - | ããžãã¹ããŒãã㌠| - |
ITã€ã³ãã°ã¬ãŒã¿ãŒïŒIncomïŒ
| ããžãã¹ããŒãã㌠| - | - |
ã©ã³ããã¯
| - | ãã©ããããŒãã㌠| - |
SI BIS
| ããžãã¹ããŒãã㌠| - | - |
SIã»ã³ã¿ãŒ
| - | ããžãã¹ããŒãã㌠| - |
ã¹ãããã¶ããããã£ã«
| - | ããžãã¹ããŒãã㌠| - |
ã¹ãã
| ããžãã¹ããŒãã㌠| - | - |
SVIT IT
| ããžãã¹ããŒãã㌠| ãŽãŒã«ãããŒãããŒã ãšã³ãžãã¢èªå® | - |
ã·ã¹ãã çµ±åãµãŒãã¹
| ããžãã¹ããŒãã㌠| - | - |
æ
å ±ã¯100ïŒ
é¢é£ããŠããŸããã ããŒãããŒã®ã¹ããŒã¿ã¹ã¯éåžžã«äžæŽ»æ§ã§ç¶æ³ã«å¿ããŠæŽæ°ãããŸãïŒèª°ããäºåã«äžãããã誰ãããã§ã«éèŠãªçµæãéæããŠããŸãããã¹ããŒã¿ã¹ã¯ããã6ãæåŸã«æŽæ°ããã誰ãããã§ã«å声ãšãšãã«ãšã³ãžãã¢ã倱ããŸãããããŸã å®å
šãªã¬ã¬ãªã¢ãæã£ãŠããŸããªã¹ããããŠããŸãã ããã«ãå€§èŠæš¡ãã³ããŒïŒHPEãIBMïŒã®å Žåãã©ã®ããŒãããŒãéåžžã«å€ãã®è£œåã®ã©ãã«ç¹åããŠããããçè§£ããããšã¯éåžžã«å°é£ã§ãã ãããã£ãŠãããã«ïŒå¿åã§ïŒSIEMã®ãã£ã¹ããªãã¥ãŒã¿ãŒã«é»è©±ããŠãã©ã®ããŒãããŒãæšèŠããããå°ããããšããå§ãããŸãã
å
¬åŒã®ããŒãããŒã¹ããŒã¿ã¹ã®æ¬ åŠã¯ãååãšããŠã補åã®è²©å£²ã®æåã劚ããŸãã-åçã®ã¿ãæžå°ããŸãã 補åã®äžå®æã®äœæ¥äžã«ã¹ããŒã¿ã¹ãååŸããããšã¯éåççã§ããå ŽåããããŸãïŒããšãã°ããšã³ãžãã¢ã®åŒ·å¶çãªé«äŸ¡ãªèªèšŒãç¹å®ã®å¹Žéã¬ãã«ã®è²©å£²ãå¿
èŠãªå Žåãªã©ïŒã
5.ãµãŒãããŒãã£ã®ãã£ã¬ã¯ããªã®ãŠãŒã¹ã±ãŒã¹ 'ov
çŸæç¹ã§ã¯ãããŒãºã«åãããŠãŠãŒã¹ã±ãŒã¹ãããŠã³ããŒãã§ãã代æ¿ãªãœãŒã¹ãããã€ããããŸãã
LinkedInã»ãã¥ãªãã£ã°ã«ãŒãååãšããŠãããã¯åã®æ®µèœãšäŒŒãŠããŸãã ããããå¹³åããŠãã³ã³ãã³ãã¯ããè¯ãèšèšããããšãã§ããŸã-çµå±ã®ãšãããåºçç©ã¯å¯èœãªéçšè
ã®èŠéã§äººäºãªãœãŒã¹äžã«ããããããã¡ã€ã«ïŒå¥åå±¥æŽæžïŒãžã®æç¢ºãªãªã³ã¯ãæã£ãŠããŸãã
ãSIEMãŠãŒã¹ã±ãŒã¹ã
www.linkedin.com/groups/6704216 åçšãµã€ããŠãŒã¹ã±ãŒã¹ã©ã€ãã©ãªãã³ããŒSOC PrimeçŸåšã3ã€ã®SIEMããµããŒããããŠããŸãïŒHPE ArcSightãIBM QRadarãSplunkã ã©ã€ãã©ãªèªäœã«ã¯ããSOC PrimeããéçºããUse Case'yããããä»ã®ãŠãŒã¶ãŒãããã«æçš¿ããŠããŸãã äºæ³å€ãã-ãã¹ãŠã®ã³ã³ãã³ãã¯è±èªãšãã·ã¢èªã§è€è£œãããŸãïŒ ïŒãããã¡ã€ã«èšå®ã®ã¹ã€ããïŒã
ucl.socprime.com åèšïŒ22ã¢ããªã±ãŒã·ã§ã³ã ãµã€ãããã®æ
å ±ã«ãããšããµã€ãã®ç«ã¡äžãã¯2016幎8æ31æ¥ã§ãã£ãããããããªãæé·ãæåŸ
ãããŠããŸãã å¥ã®22ã®ãŠãŒã¹ã±ãŒã¹ãéçºäžã§ãïŒRïŒDã¹ããŒã¿ã¹ã®äžïŒã
ãŠãŒã¹ã±ãŒã¹ã¯ããéã§æ¯æãããèªåã®åªåã§çšŒãããšãã§ãããã€ã³ãã§è³Œå
¥ããŸãïŒè³Œå
¥ããã¢ããªã±ãŒã·ã§ã³ã®ã¬ãã¥ãŒããŠãŒã¹ã±ãŒã¹ã®æçš¿ããã£ãŒãããã¯ãã©ãŒã ããã®ã¢ã€ãã¢ã®ææ¡ïŒã

æåã®ã¹ã¯ãªãŒã³ã·ã§ããã®ç¶ãã§ããããªã¹ãã衚瀺ããããã®ä»£æ¿ã¹ããŒã ããããŸãïŒ

åŸã§å€æããããã«ãããã«ããã«ç»é²ããããšã¯ã§ããŸãã-圌ãã¯å
¬éãããGmailã®ã¡ãŒã«ã¢ãã¬ã¹ãç¡èŠããäŒæ¥ã®ã¢ãã¬ã¹ã®ã¿ã«ç»é²ããããšã匷å¶ããŸããã ãæ»æè
ãç¡æã®é»åã¡ãŒã«ãä»ããŠç°¡åã«ç»é²ããä¿è·ã¢ã«ãŽãªãºã ãåŠç¿ã§ããå Žåããã®ãããªä¿è·ãåé¿ããæ¹æ³ãããã«åŠç¿ã§ããŸããã
SIEMé¢é£ã®ããã°ãšè¿œå æ
å ±ã»ãã¥ãªãã£ãªãœãŒã¹ èè
ã«ã€ã㊠ïŒ
ç§ã®çµéšã¯ãã»ãã¥ãªãã£ã€ã³ãã°ã¬ãŒã¿ãŒã§4幎ããã£ã¹ããªãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£éšéã§2幎ããããŠITããžãã¹ã¢ããªã¹ãã®ç«å Žã§FMCG顧客ã®åŽã§3幎ã§ãã ç¿æ
£ãããç§ã¯ãŸã ã»ãã¥ãªãã£ãã¥ãŒã¹ããã©ããŒãããŠãŒã¹ã±ãŒã¹ã䜿çšããã¿ã¹ã¯ã§ãå人ãå©ããŸãã-ããããã£ããã«ãèšäºãæºåããããšã«ããŸããã