Habrã®äœæ°ã®çãããããã«ã¡ã¯ã ã¯ã€ã€ã¬ã¹äŸµå
¥æ€ç¥ã·ã¹ãã ã¯ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ã«ãã¬ããžã®åšå²ã«ç«ã¡ãã¬ãŒããŒãã¬ãŒããé£ç¶çã«å転ãããå¯Ÿç©ºç ²ã§ãããšèãããããããŸãã...

ãããããããå³ããçŸå®ã§ã¯ããã¹ãŠãå€å°å¹³å¡ã§ãã ãã®æçš¿ã§ã¯ã2ã€ã®WIPSïŒWireless Intrusion Prevention SystemïŒãœãªã¥ãŒã·ã§ã³ã®çµéšãå
±æããããšæããŸãã æåã®éšåã§ã¯ãWIPSã®äžè¬çãªæŠèŠãšãã®å¿
èŠæ§ã説æããMojo AirTight補åã®äž»èŠãªæ©èœã®æŠèŠãšå¿
èŠãªèšå®ã«ã€ããŠèª¬æããŸãã 第2éšã§ã¯ãã·ã¹ã³ã®åæ§ã®ãœãªã¥ãŒã·ã§ã³ãæ€èšããäºå®ã§ãã
åæ
çãªäœè«
圌ã®äººçã®ãã¹ãŠã®ãããã¯ãŒã¯ãšã³ãžãã¢ã¯ãIPS / IDSã®æŠå¿µã«åºãããããšæããŸãã çŸä»£ã®çŸå®ã§ã¯ããã¹ãŠã®èªå°å¿ã®é«ããã¡ã€ã¢ãŠã©ãŒã«ããã®æ©èœãæäŸããŠããŸãã æ©åšã®è£œé æ¥è
ã¯èžã倧声ã§èžãå©ãããç¬ç«ãããå°éç¥èã®çµæã«ãã£ãŠæž¬å®ãããŸããNGFWã¯ããŸããŸãªãã«ãŠã§ã¢ããããããã£ããããŸãã ãã®ã¯ã©ã¹ã®æ©åšãã»ããã¢ããããããã®æšå¥šäºé
ãããè¯ãèšäºãèŠã€ããããšã¯åé¡ã§ã¯ãããŸããã
æ®å¿µãªãããWIPSã§ã¯ãã¹ãŠãããã»ã©ãã©è²ã§ã¯ãããŸãããè³¢æãªè³æïŒç¹ã«ãã·ã¢èªïŒã¯ããŸããªãããããã¯äž»ã«ããŒã±ãã£ã³ã°ãã³ãã¬ããã§ãããèšå®ã®èª¬æã§ã¯ãããŸããã ãã³ããŒã®ããã¥ã¡ã³ãã¯ãã¡ãã圹ç«ã¡ãŸãããå€ãã®å Žåã質åãžã®åçã¯ããŸããŸãªãœãŒã¹ã«ãããã©ããèŠãããæšæž¬ããã«ã¯ã質åãžã®åçã®ååãç¥ãå¿
èŠããããŸãã
ãã®ã¯ã©ã¹ã®ããŸããŸãªãœãªã¥ãŒã·ã§ã³ã䜿çšããŠãããæè¡çãªã¬ã€ããäœæããäžçãšå
±æããããšã«ããŸããã
ç§ã®èšäºã¯ã以äžã§èª¬æãããœãªã¥ãŒã·ã§ã³ã®æ©èœãã«ããŒããããšãæå³ããŠãããã究極ã®çå®ã§ã¯ãããŸããã ããªãèªèº«ã®å±éºãšãªã¹ã¯ã§ãèè
ãã®çµéšã䜿çšããŠãã ããã
WIPSãšã¯äœã§ããããªãå¿
èŠãªã®ã§ããïŒ
WIPSã¯ãã»ã³ãµãŒïŒéåžžã¯Wi-Fiãé
ä¿¡ããã®ãšåãã¢ã¯ã»ã¹ãã€ã³ãã§ãïŒã䜿çšããŠåšå²ã®ç¡ç·é»æ³¢ãç£èŠããç¡ç·ä¿¡å·ãœãŒã¹ããããã®çžäºäœçšãç°åžžãªïŒç°åžžãªïŒã¢ã¯ãã£ããã£ã«é¢ããåä¿¡æ
å ±ãåæããã¢ã¯ã·ã§ã³ãé²æ¢ããã·ã¹ãã ã§ããèšå®ããã䟵å
¥é²æ¢ããªã·ãŒã«åããŠã
ããŸããŸãªWIPSã·ã¹ãã ã¯ãããŸããŸãªã¢ã«ãŽãªãºã ã䜿çšããŠããéåè
ããšãã®æŽ»åãé²ãã¡ã«ããºã ãèå¥ããŸãã ãã ããæ¹æ³ã®éãã«ãããããããåã·ã¹ãã ãæŠãããšããŠããè
åšã®ãªã¹ãã¯ã»ãŒåãã§ãïŒç§ã®å人çãªçµéšã瀺ãããã«ã宣èšãããæ©èœã¯åžžã«100ïŒ
å¹æçã§ã¯ãããŸããïŒã
- RogueAPã¯ãå®éã®å€èŠ³ïŒSSIDãšåãååãŸãã¯ãããã«ç°ãªãïŒã®ãå€èŠ³ããå®å
šãŸãã¯éšåçã«ã³ããŒããæªæã®ããã¢ã¯ã»ã¹ãã€ã³ãã§ãããMiTMæ»æãå®è£
ããããäžæ³šæãªãŠãŒã¶ãŒã®è³æ Œæ
å ±ã䟵害ãããããããã«èšèšãããŠããŸãã
- ã¢ãããã¯-LANã«æ¥ç¶ãããããã€ã¹ãWi-Fiãä»ã®ãŠãŒã¶ãŒã«é
åžãããã®çµæãLANãžã®ã¢ã¯ã»ã¹ãæäŸããåäœã¢ãŒãã
- DoS-ãµãŒãã¹æåŠæ»æã ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®çŸå®ã§ã¯ãããã¯äž»ã«ããããã¯ãŒã¯ã®å質ãäœäžãããããã«ããŠãŒã¶ãŒã®èªèšŒã解é€ããããç¡çšãªã¡ãã»ãŒãžïŒãã€ãºïŒã§ç¡ç·ãä¹±ãããããã¡ãã»ãŒãžã®ãã©ããã§ãã
- MACã¹ããŒãã£ã³ã°-ã¯ã©ã€ã¢ã³ã/ APã«ãªãããŸãããã®ã¡ãã»ãŒãžéä¿¡è
ã®ã¢ãã¬ã¹ã®åœé ã
- BruteForce-å®å
šãªåæ/èŸæžæ»æã«ããWi-Fiãã¹ã¯ãŒãéžæã
- æå·åããã³æ¿èªãããã³ã«ã®æ¢ç¥ã®è匱æ§ã«å¯Ÿããæ»æ-WEPãWPAãWPSãªã©ã®è匱æ§
ä»ã詳现ã
ã¢ãžã§ãšã¢ã¿ã€ã
æŠèŠ
Mojo Networksã®Mojo AirTightã¯ãç§ãåããŠåãçµãã ã·ã¹ãã ã§ãã ããã¯ãã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ãæäŸããWIPSãæŽçããããã®å®å
šãªãœãªã¥ãŒã·ã§ã³ã§ãã
ã·ã¹ãã ã«ã¯ãã¢ã¯ã»ã¹ãã€ã³ããšWi-Fiã³ã³ãããŒã©ãŒ+ WIPSå¶åŸ¡ã·ã¹ãã ãšããåŸæ¥ã®ã¢ãŒããã¯ãã£ããããŸãã ã¯ã©ãŠãããŒãžã§ã³ã®ã³ã³ãããŒã©ãŒãæäŸãããŠããŸããããã®ãªãã·ã§ã³ã¯ç§ãã¡ã®åœã§ã¯éèŠããããšã¯æããŸããã
ã¢ã¯ã»ã¹ãã€ã³ãã¯3ã€ã®ã¢ãŒãã§äœ¿çšã§ããŸãã
- AP-éåžžã®ã¢ã¯ã»ã¹ãã€ã³ã
- ã»ã³ãµãŒ-WIPS / WIDSã¢ãŒãã®ã¢ã¯ã»ã¹ãã€ã³ã
- Network Detector-æç·ã»ã°ã¡ã³ããã¹ãã£ã³ããã¢ã¯ã»ã¹ãã€ã³ãã
Mojo AirTightã¯ã€ã€ã¬ã¹äŸµå
¥é²æ¢ã·ã¹ãã ïŒWIPSïŒ-ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã³ã³ãããŒã©ãŒãšWIPSã®æ©èœãçµã¿åãããä»®æ³ãã·ã³ã¯ãæ¥ç¶ããããã€ã³ãã®æ°ïŒä»»æã®ã¢ãŒãïŒã«ãã£ãŠã©ã€ã»ã³ã¹ãããŸãã WIPSæ©èœã®åå¥ã®ã©ã€ã»ã³ã¹ã¯å¿
èŠãããŸããã
åäœåç
Mojo AirTight WIPSã®åäœåçã¯éåžžã«åçŽã§ããæ€åºããããã¹ãŠã®ãŠãŒã¶ãŒãšã¢ã¯ã»ã¹ãã€ã³ãã¯ãæ¿èªæžã¿ãæ§æãã¹ãå€éšãäžæãäžæ£ã®5ã€ã®ã«ããŽãªã«åé¡ãããŸãã
æ¿èªæžã¿-ä¿¡é Œãããã¢ã¯ã»ã¹ãã€ã³ããšãããã«æ¥ç¶ãããã¯ã©ã€ã¢ã³ãã
æ§æã®èª€ã-ä¿¡é ŒãããŠããããIPSããªã·ãŒã«é¢ããŠæ£ããæ§æãããŠããªãã¢ã¯ã»ã¹ãã€ã³ãã
å€éš-æ¥ç¶ãããŠããã¢ã¯ã»ã¹ãã€ã³ããšã¯ã©ã€ã¢ã³ãããããã¯ä¿¡é ŒãæªæããããŸããã äžè¬çãªWi-Fiãã€ããŒã
äžæ-ãŸã åé¡ãããŠããªãããåé¡ããã®ã«ååãªæ
å ±ããªãã¢ã¯ã»ã¹ãã€ã³ããšãããã«æ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ãã
äžæ£-æªæã®ããã¢ã¯ã»ã¹ãã€ã³ããšãããã«æ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ãã
åé¡ã¯èªåã§ãããåé¡ãæ£ãããªãå Žåãã·ã¹ãã 管çè
ã¯ä»»æã®ã«ããŽãªãæåã§å²ãåœãŠãããšãã§ããŸãïŒèª€èšå®ãé€ãïŒã
ãããã£ãŠãMojo管çãµãŒããŒã«çŽæ¥æ¥ç¶ãããŠããã¢ã¯ã»ã¹ãã€ã³ãã¯æ¿èªããããšèŠãªãããŸãã ã·ã¹ãã ãçµ±åãããŠããå¥ã®ã³ã³ãããŒã©ãŒã«æ¥ç¶ãããŠããã¢ã¯ã»ã¹ãã€ã³ãïŒçµ±åãªãã·ã§ã³ã«ã€ããŠã¯åŸã§èª¬æããŸãïŒã Mojoã«æ¥ç¶ãããŠããªããããã®èšå®ãIPSã»ãã¥ãªãã£ããªã·ãŒã«æºæ ããŠãããã€ã³ãã
æ§æã®èª€ã-èšå®ãWIPSããªã·ãŒã«æºæ ããŠããªããã€ã³ãïŒããšãã°ããã€ã³ãã¯WPAã䜿çšããWIPSããªã·ãŒã¯WPA2-Personalã®ã¿ãå¿
èŠãšããŸãïŒã ãããã¯ãMojo管çãµãŒããŒãŸãã¯ã·ã¹ãã ãçµ±åãããŠããå¥ã®Wi-Fiã³ã³ãããŒã©ãŒã«æ¥ç¶ã§ããŸãã
Mojoã«ãã£ãŠç£èŠãããŠãããèš±å¯ãããŠããªãæç·ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããã¢ã¯ã»ã¹ãã€ã³ãã¯ãæªæã®ããïŒæªæã®ããïŒïŒäŒæ¥ã®ã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒã®ãµãŒãã¹ãåããŠããªããããã¯ãŒã¯ã«èª°ããè¿œå ã®ã¢ã¯ã»ã¹ãã€ã³ããã¹ã¿ãã¯ããå ŽåïŒãšèŠãªãããŸãã ãŸããäŒæ¥ã®SSIDãéä¿¡ãããã€ã³ãïŒäžèšã®åºæºã«åŸã£ãŠèš±å¯ãããŠããªãïŒããã³ãã©ãã¯ãªã¹ãã«ç»é²ãããŠããSSIDããæªæã®ããããã°ã©ã ã®ãªã¹ãã«å«ãŸããŸãã
ããŠãä»ã®ãã¹ãŠã®ãã€ã³ãã¯å€éšãšããŠåé¡ãããŸãã
åé¡çµæã«åºã¥ããŠãWIPSããªã·ãŒã§èª¬æãããŠããã¢ã¯ã·ã§ã³ããã€ã³ããšãŠãŒã¶ãŒã«é©çšãããŸãã ãã®ããªã·ãŒã¯ãèš±å¯ããããªããžã§ã¯ãã®åŠšããããªãçžäºäœçšãæå³ããŸãããä»ã®ã«ããŽãªã¯å¶éã§ããŸãã Rogueããã³Misconfiguredãªããžã§ã¯ããšã®å¯Ÿè©±ãçŠæ¢ããããšããå§ãããŸãããExternalã°ã«ãŒãã®ãªããžã§ã¯ãã«ã¯å¶éãé©çšããªãã§ãã ããã
ã·ã¹ãã ã¯éåžžã«ã説åŸåããããããšãèŠããŠããå¿
èŠããããŸãã ãã€ã³ããŸãã¯ãŠãŒã¶ãŒããã€ãŠäžæ£ãšåé¡ãããå Žåã管çè
ããããããæ£åœåããããŸã§ããããã¯ãã®ãŸãŸã§ãã ãã®ããã次ã®ç¶æ³ãçºçããå¯èœæ§ããããŸããããžãã¹ã»ã³ã¿ãŒã®é£äººã誀ã£ãŠã¢ã¯ã»ã¹ãã€ã³ããã¹ã€ããã³ã°ã«ãŒã ã®ééã£ãã¹ã€ããã«åºå®ããã ãã°ããããŠã圌ãã¯ééãã«æ°ã¥ãã誀ããä¿®æ£ããŸããããMojoã¯ãã§ã«ãã®ç¹ãèŠã€ããŠåé¡ããŠããŸããã ãããŠåœŒã¯ãããšãã°ããŠãŒã¶ãŒãæ¥ç¶ããããšããè©Šã¿ãæå¶ããããã«ãæ¿æ²»ã«ãã£ãŠå®çŸ©ãããã¢ã¯ã·ã§ã³ãé©çšãå§ããŸããã ãã®åŸãMojoã¯ãé£æ¥ããWi-Fiã«å±ããåããã©ã¡ãŒã¿ãŒïŒåãSSIDãåããã€ã³ãã¢ãã«ãªã©ïŒã§æ®ãã®å¯èŠãã€ã³ããååé¡ããåãéåœã«çŽé¢ããŸãã ããã«ãã®ãããªè¡ã®ç¢ºå·ããããŸãã
åæèšå®
ã·ã¹ãã ã®ã€ã³ã¹ããŒã«ãšæ§æã«ã€ããŠèª¬æããŸãã
ã€ã¡ãŒãžãä»®æ³åç°å¢ã«å±éãããšã次ã®ã³ã³ãœãŒã«ãã¥ãŒã衚瀺ãããŸãã

ãã®è£œåã®ã©ã€ã»ã³ã¹ã¯MACã¢ãã¬ã¹ã«é¢é£ä»ããããŠããããšã«æ³šæããŠãã ããã ä»®æ³ãã·ã³ãä»®æ³åç°å¢ãä»ããŠç§»è¡ãããšãä»®æ³ãã·ã³ã®MACã¢ãã¬ã¹ãå€æŽãããå¯èœæ§ããããããæåã§å²ãåœãŠãããšããå§ãããŸãã ã¢ãã¬ã¹ãå€æŽããããšãã©ã€ã»ã³ã¹ã¯ãé£ã³ç«ã¡ããŸããæ°ããMACã®ã©ã€ã»ã³ã¹ãåçºè¡ãããããã³ããŒã«äŸé Œããããå€ãMACãè¿ããŠåèµ·åããå¿
èŠããããŸãã
ããã©ã«ãã®ãŠãŒã¶ãŒå/ãã¹ã¯ãŒãconfig / configãå
¥åããåæåãŠã£ã¶ãŒããå®è¡ããŸãã åæåäžã«ã次ãæäŸãããŸãã

åæåæåäžã«ãåäœããŠããNTPããã³DNSãµãŒããŒãæå®ããããšãéèŠã§ãã ãããè¡ããªããšãWebã€ã³ã¿ãŒãã§ã€ã¹ãèµ·åããããã以äžã®ã·ã¹ãã æ§æãäžå¯èœã«ãªãå¯èœæ§ããããŸã;ãããã®ãã©ã¡ãŒã¿ãŒãã³ã³ãœãŒã«ããåæ§æããåèµ·åããå¿
èŠããããŸãã DNSãµãã£ãã¯ã¹ãæå®ããå¿
èŠããããŸãã ãã®ãã©ã¡ãŒã¿ãŒã¯ãã¢ã¯ã»ã¹ãã€ã³ãã«ãããµãŒããŒã®èªåæ€åºã®ã¡ã«ããºã ãæ£ããæ©èœãããããã«å¿
èŠã§ãã MojoãµãŒããŒãDNSãµãŒããŒãããã³åã¢ã¯ã»ã¹ãã€ã³ãã§äžèŽããå¿
èŠããããŸãã
次ã«ãWebã€ã³ã¿ãŒãã§ã€ã¹ã«åŸã£ãŠãã©ã€ã»ã³ã¹ãã¡ã€ã«ããå
¥åãããŸãã ã©ã€ã»ã³ã¹ãã¡ã€ã«ãååŸããã«ã¯ïŒãã¡ãã賌å
¥åŸïŒã補é å
ã«é£çµ¡ããŠããµãŒããŒã®MACã¢ãã¬ã¹ãæäŸããå¿
èŠããããŸãã ã·ã¹ãã ã«ã¯è©Šçšæéãšç¶äºæéã¯ãããŸããã

ãã®åŸãèšå®ã®æºåãã§ããã·ã¹ãã ããããŸãããæãéèŠãªãã®ãã€ãŸãã¢ã¯ã»ã¹ãã€ã³ãããããŸããã ã¢ã¯ã»ã¹ãã€ã³ãã«ã¯åå¥ã®ãã¥ã¢ã³ã¹ããããŸããäžåºŠã«ã¢ã¯ã»ã¹ãã€ã³ãã¯3ã€ã®ã¢ãŒãïŒAPãã»ã³ãµãŒããããã¯ãŒã¯ãã£ãã¯ã¿ãŒïŒã®ãããã1ã€ã«ãããªããŸããã
äž»ãªãã£ããã¯ãåæã«æ
å ±ãéä¿¡ãã空æ°ãã¹ãã£ã³ããããšã§ãããã€ã³ãã¯äŸµå
¥ãé²ãããšãã§ããŸããã ãããã£ãŠãWIPSãæ©èœããã«ã¯ããã®ã¿ã¹ã¯ã®ã¿ãå®è¡ããåã
ã®ãã€ã³ãã®é
眮ãèšç»ããå¿
èŠããããŸãã
ã¢ã¯ã»ã¹ãã€ã³ããMojoãµãŒããŒã«èªåçã«æ¥ç¶ããã«ã¯ãWIPSãDHCPãä»ããŠIPã¢ãã¬ã¹ãDNSãµãŒããŒã¢ãã¬ã¹ãããã³DNSãµãã£ãã¯ã¹ãååŸããå¿
èŠããããŸãã ãŸãããwifi-security-serverããšããååã®ãšã³ããªãDNSãµãŒããŒã«ååšããMojoãµãŒããŒãæããŠããå¿
èŠããããŸãã ååãšããŠãåãã€ã³ãã¯æåã§èª¿æŽã§ããŸãããããã¯ç§ãã¡ã®æ¹æ³ã§ã¯ãããŸããã
ãã¡ã€ã¢ãŠã©ãŒã«ãä»ããŠäœæ¥ããå Žåã以äžã§èª¬æããçžäºäœçšãæå¹ã«ãªã£ãŠããããšã確èªããå¿
èŠããããŸãã
枯 | 䜿çšãã |
---|
TCP / 21 | FTP-ãã¡ã€ã«è»¢éãã¢ããããŒãã«äœ¿çšã§ããŸã |
TCP / 22 | Ssh |
TCP / 25 | SMTPãšã®çµ±å-ã¢ã©ãŒãã®éä¿¡ã«äœ¿çš |
TCP / 80 | WIPSãµãŒããŒãžã®ã¢ã¯ã»ã¹ãã€ã³ãã«ããOSã¢ããããŒãã®ããŠã³ããŒã |
TCP / 443 | 管çGUI |
TCP / 1035 | ã¯ã©ã¹ã¿ãŒã§å®è¡ãããŠããWIPSãµãŒããŒéã®çžäºéçšæ§ |
TCP / 3851 | AirTight Mobileãšã®çžäºäœçš-Mojo Networksã®ãšã³ããã€ã³ãã¯ã©ã€ã¢ã³ã |
TCP / 3852 | Cloud Integration PointïŒCIPïŒã䜿çšããŠVPNãéã |
TCP / 4433 | 蚌ææž/ã¹ããŒãã«ãŒãã§ã¯ã©ã€ã¢ã³ããèªèšŒãããšãã«äœ¿çšãããŸã |
TCP / 5432 | PostgreSQL WIPSãµãŒããŒã¯ã©ã¹ã¿ãŒããŒã¿ããŒã¹éã®çžäºäœçš |
Tcp / 2002 | ãã±ãããã£ããã£ã«äœ¿çšãããããŒãã ãã®ããŒãã§ã¯ãã¢ã¯ã»ã¹ãã€ã³ãã¯ãµãŒããŒããã®ã³ãã³ãããã©ãã£ãã¯åéã»ãã·ã§ã³ãéå§ããã®ãåŸ
ã¡ãŸãã |
Udp / 23 | NTP-æå»ã®åæïŒãã€ã³ããšãµãŒããŒã®äž¡æ¹ã®çžäºäœçšïŒ |
UDP / 161 | SNMPïŒã¡ãã»ãŒãžåä¿¡ïŒ-ãµãŒãããŒãã£ã®ã³ã³ãããŒã©ãŒïŒäŸïŒCisco WLCïŒãšã®çµ±åã«å¿
èŠ |
UDP / 162 | SNMP-ïŒã¡ãã»ãŒãžã®éä¿¡ïŒ-ãµãŒãããŒãã£ã®ã³ã³ãããŒã©ãŒïŒããšãã°ãCisco WLCïŒãšã®çµ±åã«å¿
èŠ |
UDP / 389 | LDAP-ãŠãŒã¶ãŒèªèšŒã®ããã®LDAPçµ±å |
UDP / 694 | WIPSã¯ã©ã¹ã¿ãŒãµãŒããŒéã®ããŒãããŒã |
UDP / 514 | Syslog-å€éšSIEMãšã®çµ±å |
UDP / 1194 | ã¯ã©ã¹ã¿ãŒå
ã®ãµãŒããŒéã§VPNãéã |
UDP / 1812 | Radius-RADIUSãµãŒããŒãä»ãããŠãŒã¶ãŒèªèšŒ |
UDP / 3851 | Exchange SpectraTalkã¢ã¯ã»ã¹ãã€ã³ã |
ããã©ã«ãã§ã¯ããã€ã³ãã¯ãAPãã¢ãŒãã§ã·ã¹ãã ã«æ¥ç¶ãããŸãã ãã®åŸãç®çã®ã¢ãŒãã«åãæ¿ããããšãã§ããŸãã æ¥ç¶ãããŠãããã¹ãŠã®APãå¿
èŠãªã¢ãŒãã«èªåçã«åãæ¿ããããã€ã¹ãããã¡ã€ã«ãèšå®ããããšãã§ããŸãã
ãããããã€ãã®ããã«ã泚æç¹ã1ã€ãããŸãããã€ã³ããé·æéã³ã³ãããŒã©ãŒãèŠã€ããããªãå Žåã倱æããç¡æ°åãªå€¢ã«é¥ãããã¡ã€ã¢ãŠã©ãŒã«/ã«ãŒãã£ã³ã°/ DNSãäºåèšå®ããåŸã®ãªããŒãã®ã¿ããã®åé¡ã解決ããŸãã
ãããã¯ãŒã¯æ€åºã¢ãŒãã®ãã€ã³ãã¯ãSSH /ã³ã³ãœãŒã«æ¥ç¶ãä»ããŠæåã§æ§æããå¿
èŠããããŸãã ãã®ã¢ãŒãã®æå³ã¯ããã©ã³ã¯äžã®ãã€ã³ããLANã®ãã¹ãŠã®VLANã«æ¥ç¶ãããã®äžã®äžæ£ã¢ã¯ã»ã¹ãã€ã³ãã®æç·æ¥ç¶ã®å
åãæ¢ãããšã§ãã èŠã€ãã£ãå ŽåãMACã¢ãã¬ã¹ã®ã¹ããŒãã£ã³ã°ãéå§ããããããæ¹æ³ã§ç掻ã劚害ããŸãã ããã€ã¹ã®ãã®åäœã¯ãã¹ã€ããã«äžå¿«æãåŒãèµ·ããå¯èœæ§ããããããã¹ã€ãããèšå®ããããšããå§ãããŸãã ãããã¯ãŒã¯æ€åºåšèªäœã®èšå®ã¯éåžžã«ç°¡åã§ãïŒåäœã¢ãŒãã®å€æŽããã©ã³ã¯ã®èšå®ïŒVLANãªã¹ãã®æå®ïŒãåVLANã®ãããã¯ãŒã¯èšå®ã®èšå®ïŒIPã¢ãã¬ã¹ãšãããã¯ãŒã¯ãã¹ã¯ã®èšå®ïŒãMojoãµãŒããŒãããã¯ããVLANããã³äœæã
å®éã«ã¯ãã·ã¹ãã ã®åæã»ããã¢ããã¯ã管çãµãŒããŒãšã¢ã¯ã»ã¹ãã€ã³ãããäºããèŠããšãã«å®äºããŸããã Mojoã䜿çšããŠWi-Fiãã»ããã¢ããããããšã¯èããŸããããã®ããã»ã¹ã¯ãä»ã®ãã³ããŒã®æ©åšã«ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãã»ããã¢ããããããšãšå€ãããŸããã 次ã«ãWIPSãç¹ã«WIPSã«å¿
èŠãªãµãŒãã¹ã®èšå®ã«ã€ããŠèª¬æããŸãã
ãã±ãŒã·ã§ã³èšå®
次ã«ããããã¯ãŒã¯ã®ããããããæ§æããå¿
èŠããããŸãã ãããè¡ãã«ã¯ããããããžããæ§æããå¿
èŠããããŸããç¹å¥ãªãšã³ãã£ãã£-ã建ç©ããšãåºããäœæããŸãïŒãããã®å Žåããããªã«æåã䜿çšããŸãã-ã·ã¹ãã ã¯ããããµããŒãããŸããïŒ ãããã¢ãããšã«-ããã¢ãã©ã³ãã¢ããããŒããããã¹ãŠã®ã»ã³ãµãŒãšæ£åœãªã¢ã¯ã»ã¹ãã€ã³ãã®äœçœ®ãããŒã¯ããŸãã
ããããžèŠçŽ ã¯ã[å Žæ] >> [å Žæã®è¿œå ]ã¡ãã¥ãŒã§äœæãããŸãã å°å³ã®èªã¿èŸŒã¿-å Žæ>>建ç©X>ããã¢Y>ã¬ã€ã¢ãŠãã®è¿œå ã ããããããŒããããšããéšå±ã®é·ããšå¹
ãæå®ãã枬å®åäœãéžæããå¿
èŠããããŸãã æ®å¿µãªãããå°å³ã¯åãªãç»åïŒjpg圢åŒïŒã§ããããã®äžã«ãªããžã§ã¯ãïŒå£ãªã©ïŒã瀺ãæ©èœã¯ãããŸããã
ãã©ã³ãžã®ã»ã³ãµãŒ/ã¢ã¯ã»ã¹ãã€ã³ãã®è¿œå ã¯ãã¡ãã¥ãŒã§å®è¡ããŸãïŒå Žæ>>建ç©X>ããã¢Y>ããã€ã¹ãªã¹ãã®è¡šç€ºã 衚瀺ãããããã€ã¹ã®ãªã¹ããããã»ã³ãµãŒ/ãã€ã³ãããããäžã®å Žæã«ããã©ãã°ãããå¿
èŠããããŸãã
ã«ãŒãã¯ãã§ããã ãæ£ç¢ºã§ãã»ã³ãµãŒãšã¢ã¯ã»ã¹ãã€ã³ãã®é
眮ãæ£ç¢ºã§ããå¿
èŠããããŸãã ããã¯ãäœçœ®æ±ºãã¡ã«ããºã ãæ£ããæ©èœããããã«å¿
èŠã§ãïŒè©³çŽ°ã¯ä»¥äžïŒã
IPSã»ããã¢ãã
IPSãæ§æããã«ã¯ã3ã€ã®æé ãé çªã«å®è¡ããå¿
èŠããããŸãã
- èš±å¯ãããSSIDã®ããªã·ãŒãæ§æããŸãã ãã®æ®µéã§ãæ£åœãªSSIDããšã«ãããã¡ã€ã«ãäœæããSSIDåããã®ãã©ã¡ãŒã¿ãŒïŒæå·åãèªèšŒæ¹æ³ãªã©ïŒã瀺ããŸãã èšå®ã¯ãã¡ãã¥ãŒã®[èšå®]> [WIPS]> [æ¿èªãããWLANããªã·ãŒ] <å Žæã®åå>ã§å®è¡ãããŸãã ãã¹ãŠã®SSIDãããã¡ã€ã«ãäœæããããç¹å®ã®å Žæã«ååšã§ããSSIDã«å¿ããŠãå Žæããšã«ãããã¡ã€ã«ãã¢ã¯ãã£ãã«ããå¿
èŠããããŸãã åå Žæã®ããªã·ãŒèšå®ã¯ãããããã¯ãªãã¯ããŠããªã·ãŒãç·šéããã³ã«ã¹ã¿ãã€ãºã§ããããã«ããããªã³ã¯ãã¯ãªãã¯ããåŸã«è¡ãããŸãã ããã©ã«ãã§ã¯ãããªã·ãŒã¯ã«ãŒãã®å Žæããç¶æ¿ãããŸãã
- IPSããªã·ãŒãæ§æããŸãã





ããã§ã¯ãã¹ãŠãéåžžã«ç°¡åã§ã-èå³ã®ããæ©èœã®æšªã«ãããã§ãã¯ããã¯ã¹ããªã³ã«ããŠãããã ãã§ãã - IPSãæå¹ã«ããŸãã é»æºãå
¥ããåã«ãã·ã¹ãã ã¯WIDSã®ããã«åäœããŸãããã¹ãŠãèªèããŸãããå¹²æžã¯ããŸããã

èšå®ãããããªã·ãŒã«åŸã£ãŠã1ã€ã®ãã§ãã¯ããŒã¯ãé²æ¢ã®éå§ããç§ãã¡ãåé¢ããŸãã
ç§ã¯ãæ»æè
ãžã®å¯Ÿæãã©ã®ããã«è¡ããããã詳现ã«èª¬æããå¿
èŠã¯ãªããšèããŠããŸãã ããã¯ãã³ããŒã®ããã¥ã¡ã³ãã§èªããã次ã®ããã«èšãããšãã§ããŸãã
ããã« ã
æ¢åã®Wi-Fiãšã®çµ±å
ãã®ã·ã¹ãã ã®å©ç¹ã®1ã€ã¯ããµãŒãããŒãã£ã®Wi-Fiã³ã³ãããŒã©ãŒãšçµ±åã§ããããšã§ãã ãããã£ãŠãæ©èœãåºããããšãã§ããŸã-Wi-Fiã¯1ã€ã®ããã€ã¹ãé
åžãïŒãããŠ1人ãããã管çããŸãïŒããããç£èŠããŸã-å¥ã®ïŒãããã£ãŠãããã¯å¥ã®äººã®è²¬ä»»ç¯å²ãããããŸããïŒã

Cisco WLCãAruba Mobility Controllerãããã³HP MSM Controllerãšã®çµ±åããµããŒããããŠããŸãã 察話ã¯SNMPãä»ããŠè¡ãããŸãã ããã§äœãèšå®ããå¿
èŠã¯ãããŸãããã³ã³ãããŒã©ããIPã¢ãã¬ã¹ãæå®ããSNMPã®ããŒãžã§ã³ãéžæããã³ãã¥ããã£ã®ååãè³æ Œæ
å ±ïŒSNMPv3ã®å ŽåïŒãæå®ããã³ã³ãããŒã©ããååŸãããã©ã¡ãŒã¿ãéžæããå¿
èŠããããŸãã WIPSã®å ŽåãååãšããŠãAPãšã¯ã©ã€ã¢ã³ãã«é¢ããæ
å ±ã ãã§ååã§ãããçžäºäœçšãæ§æããã³ã³ãããŒã©ãŒã«ãã£ãŠãµãŒãã¹ãããåã¢ã¯ã»ã¹ãã€ã³ãã衚瀺ããããã€ã³ãã«é¢ããæ
å ±ãéžæããããšãã§ããŸãã ããã¯ã次ã®ç¶æ³ã§åœ¹ç«ã€å ŽåããããŸããçµ±åããã³ã³ãããŒã©ãŒãè€æ°ã®å»ºç©ã«åæã«ãµãŒãã¹ãæäŸãããšããŸãã Aã®å»ºç©ã«ã¯ãç¬èªã®Mojoã»ã³ãµãŒããããŸããã»ã³ãµãŒèªäœããã¹ãŠãèªèããAPã®æ¯æŽã¯å¿
èŠãããŸããã ãããããBããæ§ç¯ããéã«ã¯ã»ã³ãµãŒããªããã³ã³ãããŒã©ãŒããã©ãžãªæŸéã®åå è
ã«é¢ããæ
å ±ãååŸã§ããŸãã ãã¡ãããã·ã¹ãã ã¯ã³ã³ãããŒã©ãŒã«ãã£ãŠå¶åŸ¡ããããã€ã³ãããæå¶ãããããã«åäœãããããšã¯ã§ããŸãããããã®ããã«ããŠèŠããã®ãåé¡ããããšã¯ããªãå¯èœã§ãã ãããŠããã®æ¹æ³ã§ãã«Bã®äžæ£ãã€ã³ããåé¡ãããšãã·ã¹ãã ã¯ã¢ã©ãŒã ãçæãã管çè
ã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§ããã確èªããŠå¯Ÿçãè¬ããããšãã§ããŸãã ãã¡ãããèªåçã§ã¯ãããŸããããå°ãªããšãäœããã®åœ¢ã§ã
äžè¬ã«ãçµ±åã®ã»ããã¢ããããã¹ãŠã§ãã å床æ確ã«ããŸãããµãŒãããŒãã£ã®Wi-Fiã³ã³ãããŒã©ãŒããåãåã£ããã€ã³ããæ¿èªããã«ã¯ãäžã§æžããããã«IPSãæ§æããå¿
èŠããããŸãã ãããè¡ãããªãå Žåããããã¯èª€ã£ãŠæ§æãããŸãã
確ãã«ããã®ã¡ã«ããºã ã¯åžžã«æ£ããæ©èœãããšã¯éããŸããã ããšãã°ãäœããã®çç±ã§WLCããåä¿¡ãããã¹ãŠã®Cisco 1600ãã€ã³ããèš±å¯ããããã€ã³ãã«èªåçã«è¿œå ããããäžè¬ã«ïŒSSIDã®æ°ã«ãã£ãŠïŒããã€ãã®å¥åã®ãã€ã³ããšããŠè¡šç€ºããããšãããã°ã«å¯ŸåŠããå¿
èŠããããŸããã WIPSã®åé¡ãåé¿ããããã«ãããããæåã§åé¡ããå¿
èŠããããŸããã
ãªããžã§ã¯ãã®é
眮
ãã®ã·ã¹ãã ã®æãèå³æ·±ãæ©èœã®1ã€ã¯ãWi-Fiãããã¯ãŒã¯ãªããžã§ã¯ãã®é
眮ã§ãã çè«çã«ã¯ããã®ã¡ã«ããºã ã®èšå®ã¯äžèŠã§ããããã®ãŸãŸäœ¿çšã§ããŸãã å®éã«ã¯ã以äžã®äŸã®ããã«ãã¹ãŠãçŸããããããã«ãã«ãŒãã®éåžžã«æ
éãªã»ããã¢ãããšã»ã³ãµãŒã®ãã£ãªãã¬ãŒã·ã§ã³ãå¿
èŠã§ãã ãã£ãªãã¬ãŒã·ã§ã³ã¯ããªããžã§ã¯ãã®äžè§æž¬éã®ã°ã©ãã®ã·ã¹ãã ã«ããæ§ç¯ã§ããããªããžã§ã¯ããŸã§ã®è·é¢ã決å®ããŸãã ã·ã¹ãã ã¯å®éã®ã°ã©ãã£ãã¯ãšäºæ³ãããã°ã©ãã£ãã¯ã衚瀺ããŸãããçæ³çã«ã¯äžèŽããå¿
èŠããããŸãã ããããå£ãå¹²æžãçæããä»ã®ãªããžã§ã¯ãã®ååšãèãããšãæ£ç¢ºãªäœçœ®æ±ºãã®ããã®è¯ãçµæã¯ã°ã©ãã®70ïŒ
ã§ãã ããã¯ãã¹ãŠãéšå±ã®ãã€ã³ãã®æé©ãªäœçœ®ãšãããã®æ£ããèšå®ã«åž°çããŸãïŒãã¡ãããããã§ã®ãã¥ã¢ã³ã¹ã¯æµ·ã§ãïŒã ä»ã®æ©èœããããŸã-ãŸããã·ã¹ãã ã¯äžå®ã®ééã§ãµãŒãããŒãã£ã®Wi-Fiã³ã³ãããŒã©ãŒã«ãã£ãŠå¶åŸ¡ãããã¢ã¯ã»ã¹ãã€ã³ãããæ
å ±ãåä¿¡ãããã®æ
å ±ã䜿çšããŠç§»åãªããžã§ã¯ããé
眮ããå Žåãã»ã³ãµãŒããã®çŸåšã®ããŒã¿ã5åéã®ã¢ã¯ã»ã¹ãã€ã³ãããã®ããŒã¿ãšæ¯èŒãããšãåŠæ¹ã¯ããããã«ãäžæ£ç¢ºã§ãã 第äºã«ãã«ãŒã ããããäœæãããšããä¿¡å·äŒéãæãªããªããžã§ã¯ããæå®ããããšã¯ã§ããŸããã ããšãã°ãåºã«ããé»æ°ããã«ã¯ãç»åã倧ããæªããå¯èœæ§ããããŸãã
ã©ã®ããã«æ©èœããŸããïŒ
ããšãã°ãæªæã®ãã䟵å
¥è
ããããã¯ãŒã¯ã«çŸããã®ã§ãèŠã€ããå¿
èŠããããŸãã
[Monitoring]> [Security]ã¿ãã«ç§»åããé¢å¿ã®ããã¯ã©ã€ã¢ã³ããèŠã€ããŠãã¹ã¯ãªãŒã³ã·ã§ããã§é»äžžã§å²ãŸãã[Locate]ãªãã·ã§ã³ãéžæããŸãïŒãã®äŸã§ã¯ããã©ãã¯ãªã¹ãã«ãã€ããŒã¢ã¯ã»ã¹ãã€ã³ããè¿œå ãããšããã¹ãŠã®ã¯ã©ã€ã¢ã³ããèªåçã«ãæªãã«ãªããŸããïŒã

ãããã®ç°¡åãªæäœã®åŸããããäžã«å°ããªéãæ£æ¹åœ¢ã衚瀺ãããŸãïŒãã¹ãŠãæ£ããæ§æããã調æŽãããŠããå ŽåïŒã

ã¹ã¯ãªãŒã³ã·ã§ããã¯ãã·ã¹ãã ãå®æ§çã«èŒæ£ããããšãã®äœçœ®æ±ºãã®äŸã瀺ããŠããŸãã
ããšãã
äžè¬ã«ã解決çã¯ããèªäœã§ããŸã衚瀺ãããç§ã¯ãã以äžã®ç¹å¥ãªåé¡ã«ééããŸããã§ããïŒæ¬æã§èª¬æãããŠãããã®ãé€ãïŒã ãã ããããŒã¿è»¢éçšã«å¥ã®ãã€ã³ããé
眮ããWIPSçšã«å¥ã®ãã€ã³ããé
眮ããå¿
èŠæ§ã¯ãç§ã«ãšã£ãŠã¯ããå¥åŠã«æããŸãã 競åãããœãªã¥ãŒã·ã§ã³ã®ã»ãšãã©ã¯ããã®æ©èœã1ã€ã®ãã€ã³ãã§çµã¿åãããããšãã§ããŸãïŒã«ãã¬ããžã®ååŸã¯æªåããŸãããããã§ãçµã¿åããããŸãïŒã ã¯ãããŸããäŸã®ããã«ããžã·ã§ãã³ã°ãæ©èœããããã«ã¯ããã€ã¢ã°ã©ã ãéåžžã«æ£ç¢ºã«äœæããã»ã³ãµãŒã®é
眮ãèšç»ããã¿ã³ããªã³ãšãã³ã¹ããå¿
èŠããããŸãã ãã ãããã¹ã䟵å
¥è
ãæç·ãããã¯ãŒã¯ã«æ¥ç¶ãããåé·ãã€ã³ããæ€åºããã¯ã©ã€ã¢ã³ããäžè¬ã«ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã«æ¥ç¶ããã®ãé²ãããã®ãã¹ãŠã®ãã¹ãã¯æåããŸããïŒäž»ãªããšã¯ããã¹ã§ã®ããããã³ã°ãè©Šãããšã§ã¯ãããŸãã-æ°åã害ããŸããïŒã DoSã®åäœçšã¯ããŸãæ©èœããŸãããæèŠçãªãã®ã¯åšæ³¢æ°åŠšå®³ã«å¯ŸåŠããæ€åºã¯éãããç¯å²ã§ã®ã¿æ€çŽ¢ã«åœ¹ç«ã¡ãŸãã 倱æãå§ããŸãã ãŸããæ¥ç¶ãã©ããã匷å¶åæãªã©ã®æšæºæ»æã«å¯Ÿæããå Žå ãããã¯ãŒã¯åž¯åå¹
ã®äœäžã¯äŸç¶ãšããŠé¡èã§ãã ãã ãããœãŒã¹ãèŠã€ããã®ã¯ç°¡åã§ãã
ã·ã¹ã³åãã§ããç¶ç¶ããã
Artem BobrikovãJet Infosystemsã®æ
å ±ã»ãã¥ãªãã£èšèšãšã³ãžãã¢