ããã¯é説çã§ã¯ãããŸãããããã«ãŠã§ã¢ãšã®æŠãã«é¢ããã¢ããã€ã¹ãšããŠãææ°ã®ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã䜿çšããŠå®æçã«æŽæ°ããããšããå§ãããŸãã WannaCryãšPetya / Nyetyaã®ææ°ã®ã¹ããŒãªãŒã¯ããã«ãŠã§ã¢ãšæŠãããã«å¿
èŠãªã®ã¯ã¢ã³ããŠã€ã«ã¹ã ãã ãšãŸã ä¿¡ããŠãã人ã
ãšã¯ç°ãªãäžçã§èµ·ãã£ãããã§ãã åªããã¢ã³ããŠã€ã«ã¹ã ãã¥ãŒãªã¹ãã£ãã¯ãªã¡ã«ããºã ã§ãã 黿ºãå
¥ã£ãŠããŠãåæã«PCã®é床ãäœäžããªãå Žåã§ãã ãããã®ã¡ã«ããºã ãæ©èœããåãªãããŒã±ãã£ã³ã°ã®èªæã§ã¯ãããŸããã ç°¡åãªçµè«ãç«ãŠãæãæ¥ãŸãã-çŸä»£ã®ãã«ãŠã§ã¢ãšã®æŠãã«ã¯ãå
šäœçãªæŠç¥ãšãããŸããŸãªäŸµå
¥ããã³æææ¹æ³ã«ããæªæã®ããã³ãŒãã®äœ¿çšãæ€åºããã³é²æ¢ããããã®ããŸããŸãªãã¯ãããžãŒã®ãã©ã³ã¹ã®åããã¢ããªã±ãŒã·ã§ã³ãå¿
èŠã§ãã ãããŠããããµãããã¬ãŒãºã«éå®ãããªãããã«ããã«ãŠã§ã¢ãšæŠãããã®å
šäœçãªæŠç¥ã«å«ãŸããã¹ããã®ãå®åŒåããŠã¿ãŸãããã
VPOéçºç£æ¥
ããããåã
ã®æè¡çã¬ã³ã¬ããé²è·å£ãæ§ç¯ãå§ããåã«ãçŸä»£ã®ãã«ãŠã§ã¢ãã©ã®ãããªãã®ãæãåºããŠã¿ãŸãããã ããã¯éåžžã«éèŠã§ããã¡ãŒã«ãŒãæªç¥ã®ãŠã€ã«ã¹ã100ïŒ
æ€åºãããšããããŒã±ãã£ã³ã°ã¹ããŒãã¡ã³ããäœæããããšãèš±å¯ããå¿
èŠã¯ãããŸããããçŸä»£ã®ãã«ãŠã§ã¢ãã§ããããšãšããã§ãªããã®ãèªèããããã«å¿ããŠããã«å¯ŸåŠããæ¹æ³ãçè§£ããããã§ãã
ã¯ããåžå Žã§æšæºçã§åºã䜿çšãããŠãããŠã€ã«ã¹å¯Ÿçãœããã«ãã£ãŠååã«æ€åºãããå€ããŠã€ã«ã¹ããããŸãã ããããæªãããã°ã©ã ã®ç·æ°ã®çŽ80ïŒ
ããããŸãã å€ãã®å ŽåãäŒæ¥ã®YouTubeãã£ã³ãã«ã®ããŸããŸãªãããªã§èŠãããšãã§ããŸãããŸããããã·ã¥ã¯ããŸããŸãªãã¬ãŒã³ããŒã·ã§ã³ãè³æã«ããç»å ŽããŸãã æ¬¡ã«ãVirusTotalã«ãã®ãããªããã·ã¥ãå
¥åããããšã§ã補åããã®ãããªæ¹æ³ã§ãã®ææããã£ããããããšã確èªã§ããŸãã ãããšã䟡å€ããªãïŒ
ãããŠãæªæã®ããã³ãŒãã®äœæè
ã§ããäœæè
ã®èгç¹ããèŠãŠã¿ãŸãããã 圌ããŸãã¯çŸä»£ã®ãã¹ãŠã®ãéå°æãã®èåŸã«ããè³æ Œã®ããããã°ã©ããŒããã³ã¢ãŒããã¯ãã®ã°ã«ãŒãå
šäœããåæããŒã¿ãšããŠæ¬¡ã®åçãæã£ãŠããŸãã
- 圌ãã¯ãã«ãŠã§ã¢ãæ
å ±ä¿è·ã®ããŸããŸãªææ®µã§æ€çŽ¢ãããããšãç¥ã£ãŠããŸã
- ãµã³ãããã¯ã¹ã䜿çšããŠæªç¥ã®æªæã®ããã³ãŒããåæã§ããããšãç¥ã£ãŠããŸã
- 被害è
ã®äŒæ¥ã®99ïŒ
ãåºç¯å²ã«è³Œå
¥ããä¿è·ãœãããŠã§ã¢ã䜿çšããŠããããšãç¥ã£ãŠããŸãã
ã»ãã¥ãªãã£ã¬ãŒããç¥ã£ãŠããããã3ã€ã®æçœãªãã€ã³ããããäœããã®çç±ã§ãæªã®åŽã«ç«ã¡ãåŸæ¥ã®ä¿è·ã·ã¹ãã ããã¹ãŠåé¿ããããšãããããã«ãŒã®ããã«ãèããªãããã«ãã©ã®ãããªçµè«ãå°ãåºãããšãã§ããŸããïŒ ç§ã¯ããã«æ¬¡ã®çµè«ãå°ããŸãã
- æªæã®ããã³ãŒãã¯äžæã§ããå¿
èŠããããç¹°ãè¿ããªãã§ãã ãã
- æªæã®ããã³ãŒãã¯è€æ°ã®é
åžãã¯ãã«ã䜿çšããå¿
èŠããããŸã
- æªæã®ããã³ãŒãã¯ã¢ãžã¥ãŒã«åããå¿
èŠããããŸã
- æªæã®ããã³ãŒãã¯ããã®æ€åºãšåæã®æ¹æ³ããã€ãã¹ããå¿
èŠããããŸãã
ãã®ããããã«ãŠã§ã¢äœææ¥çãçºå±ããäºç®ãååã«ããããœãããŠã§ã¢éçºã®ãã¹ããã©ã¯ãã£ã¹ãã³ããŒããŠããŸãïŒããããŠã€ã«ã¹éçºè
ã«ãã¢ãžã£ã€ã«ããããŸãïŒã ããããæãéèŠãªããšãšããŠããã«ãŠã§ã¢éçºè
ã¯ãäœæç©ã®ææçãšæ€åºçãäœãããããšã«é«ãé¢å¿ãæã£ãŠããŸãã ããã¯ã2016幎åé ã®éåžžã«å€ã1ã€ã®äŸã§ããã¢ã³ããŠã€ã«ã¹ã¯ãæãåçŽãªæªæã®ããããã°ã©ã ã§ãããæ€åºã§ããªãããšã瀺ããŠããŸãã
ãã«ãŠã§ã¢ããä¿è·ããããã®å
žåçãªã¢ãããŒãã¯ãæãªããã®æ¹æ³ã§ãŠã€ã«ã¹ãšåŒã°ããããšãå€ããåé¡ã®è»œèããæããããããããŠã€ã«ã¹å¯Ÿçãšãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¢ã䜿çšããããšã§ãã ãã ããäžã§èŠãããã«ãææ°ã®æªæã®ããã³ãŒãã¯ã¯ããã«è€éã§ãã ããã€ãã®ææçµè·¯ããããŸã-é»åã¡ãŒã«ãWebãWi-Fiããã©ãã·ã¥ãã©ã€ãããœãããŠã§ã¢ã¢ããããŒããè«è² æ¥è
ã®ã©ãããããã管ççšã®å人ã®ã¢ãã€ã«ããã€ã¹ãªã©ãããã«ãäœæããããã«ãŠã§ã¢ã¯ãæ¢ç¥ã®å€ãè匱æ§ãšæªç¥ã®ç©Žã®äž¡æ¹ã䜿çšã§ããŸãïŒ0 -æ¥ïŒã åæã«ã誰ãããã§ã«äœ¿çšããŠãããŠã€ã«ã¹ã®æçã¯ãæªæã®ããã³ãŒãã®åºç€ãšããŠäœ¿çšããããšãããŒãããäœæããã³ãŒãïŒããŸããŸãªã¬ãã«ã§ä¿è·ããŒã«ããã€ãã¹ããããã®ããŸããŸãªæè¡ã®äœ¿çšãå«ãïŒãšããŠäœ¿çšããããšãã§ããŸãã

ITUã®æªãã¢ã³ããŠã€ã«ã¹ãšã¯äœã§ããïŒ
2ã€ãŸãã¯3ã€ã®ç°ãªããŠã€ã«ã¹å¯Ÿçã䜿çšããããšããããŸãïŒããšãã°ããã·ã¢éè¡ã®èŠå¶ææžã§æšå¥šãŸãã¯èŠæ±ãããŠããããïŒããããã¯ããŸã圹ã«ç«ã¡ãŸããã ç°ãªããŠã€ã«ã¹å¯Ÿçãšã³ãžã³ã䜿çšããŠããå ŽåïŒãŸãã¯ããã§ãªãå ŽåããããŸã:-)ã§ããäœå¹Žãåã«å€±æããæ¹æ³ã«åºã¥ããŠããŸã-æ»æã·ã°ããã£ãšã®æ¯èŒãã€ãŸãæ¢ç¥ã®ãã®ã®æ€åºã 仿¥ã®å€ãã®æ
å ±ã»ãã¥ãªãã£ãã¬ãŒã€ãŒã®çµ±èšã«ãããšããããŸã§ç¥ãããŠããªãã£ããã«ãŠã§ã¢ã¯ãã»ãšãã©ã®ã客æ§ã«ãšã£ãŠå§åçã«ãŠããŒã¯ã§ãã ããã¯ãã»ãšãã©ã®ãŠã€ã«ã¹å¯Ÿç補åãã衚瀺ãããªããã®ãç¥ããªããã®ã«å¯ŸåŠã§ããªãããšãæå³ããŸãã
æè¿ãååãã
Cisco Threat Gridãµã³ãããã¯ã¹ã§ç¢ºèªããããã«äŸé Œãããã¡ã€ã«ãéãããŠããŸããã 圌ã¯ãã®ãã¡ã€ã«ã«é¢ããŠçå¿µãæ±ããŠããã圌ã®ã¢ã³ããŠã€ã«ã¹ã¯ãã¡ã€ã«ã«äžåå¿çããŸããã§ããã åæã®éå§ããæ°ååŸãCisco Threat Gridã¯å€å®-ZBotããã€ã®æšéЬãçºè¡ããŸããã ããããããã¯ããªãããç¥ãããå€ããã«ãŠã§ã¢ã§ãã ãŠã€ã«ã¹å¯Ÿçãããããã£ããããªãã£ãã®ã¯ãªãã§ããïŒ ããŒã¯ãŒãã¯ãå€ããã§ãã ã¢ã³ããŠã€ã«ã¹ãã³ããŒã¯ãåããŒãœãã«ã³ã³ãã¥ãŒã¿ãŒã«ã泚ãããã眲åããŒã¿ããŒã¹ã®ãµã€ãºãå°ããããããã«ãå€ã眲åãç¡å¹ã«ããããšã«ããŸããã ãããŠãããã¯çè§£ããããšãã§ããŸãã 眲åã®æ°ã¯çµ¶ããå¢å ããŠãããæ¢ã«æ°åããæ°åååäœã§æž¬å®ãããŠããŸãããã®ãããªæ
å ±ããã¹ãŠä¿åããã®ã«ååãªããŒããã£ã¹ã¯ã¯ãããŸããã ç§ãã¡ã¯éžæãããªããã°ãªãããããã¯æ²æšãªçµæã«ã€ãªããå¯èœæ§ããããŸãã
ã¯ããWannaCryã®è©±ãèŠããŠããã§ããããå€ãã®ã¢ã³ããŠã€ã«ã¹ãã³ããŒãããæªç¥ã®ãŠã€ã«ã¹ã®100ïŒ
æ€åºããã¹ãã§åå©ãèªã£ãŠãæµè¡ã®çºçåŸã®ç¿æ¥ïŒãã¹ãŠã®éææ¥ã®å€ã§ã¯ãªãïŒã«æšå¥šãéä¿¡ãå§ãããšããã®ææãå
æããããã«äœãããå¿
èŠããããã èŠããŠãïŒ å¥åŠãªç¶æ³ãåŸãããŸãã WannaCryã䜿çšããè匱æ§ã«é¢ããæ
å ±ã¯1ãæéç¥ãããŠããŸãããæªæã®ããã³ãŒãã§ã¯ãŸã 䜿çšãããŠããªãããããŠã€ã«ã¹å¯ŸçããŒã¿ããŒã¹ã«çœ²åã¯ãããŸããã ãããã£ãŠãæªæã®ããã³ãŒããšæŠãåŸæ¥ã®ææ®µã®ã»ãšãã©ã¯äºåŸçã«åäœããæ¢ç¥ã®ãã®ãšæ ŒéããŠããŸãã å€§èŠæš¡ãªæµè¡ã«é¢ããŠã¯ããã®ã¢ãããŒãã¯æ©èœããŸããããã»ãšãã©ããŠããŒã¯ãªãã«ãŠã§ã¢ã®ç¶æ³ã§ã¯å€±æãå§ããŸããã
ããããŸããããITUã¯CïŒCãµãŒããŒãžã®æ¥ç¶ãåæããã®ã«åœ¹ç«ã¡ãŸãããïŒ çè«çã«ã¯ãã¯ãã å®éã«ã¯ã2ã€ã®å°é£ã«çŽé¢ããŸãã ãŸããã·ã¹ã³ã®çµ±èšã«ãããšãæªæã®ããããã°ã©ã ã®çŽ92ïŒ
ãDNSãããã³ã«ã䜿çšããŠããŸããããã¯ãéåžžã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãã£ã«ã¿ãªã³ã°ã§ããªããã®ã§ãïŒããã§ã¯ã
Cisco Firepower NGFWãªã©ã®DNSã€ã³ã¹ãã¯ã·ã§ã³ã䌎ãNGFWãå¿
èŠã§ãïŒã 次ã«ãCïŒCããŒããšã®çžäºäœçšããããã¯ããã«ã¯ããããã®ããŒãã®ã¢ãã¬ã¹ãç¥ãå¿
èŠããããŸãããããã®ããŒãã¯çµ¶ããå€åãããããITUãã«ãŒã«ãè¿
éã«æŽæ°ããå¿
èŠããããŸãããããã¯å®éã«ã¯è¡ãããŸããã
ãŸããã»ãã¥ãªãã£Webããã³é»åã¡ãŒã«ã²ãŒããŠã§ã€ã远å ããå Žåã¯ã©ããªããŸããïŒ
ãã«ãŠã§ã¢ããã®äŒæ¥ã®ä¿è·ã匷åããã«ã¯ãäœãããå¿
èŠããããŸããïŒ ãŠãŒã¶ãŒã«ããããŒã«ã«ç®¡çè
ã®æš©éã®äœ¿çšã«é¢ããããããããã¯ã¢ãããããã³å¶éã®å®æçãªã€ã³ã¹ããŒã«ã«å ããŠãèããããææçµè·¯ãæãåºããŠã¿ãŸãããã çµ±èšã«ãããšããã¹ãŠã®ææã®å€§éšåã¯ãWebãšé»åã¡ãŒã«ãšãã2ã€ã®äž»èŠãªãã£ãã«ãä»ããŠå®è¡ãããŸãã ããã¯ãæªæã®ããæ·»ä»ãã¡ã€ã«ã®ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããä¿è·ãœãªã¥ãŒã·ã§ã³ããããã®ãã£ãã«ãä¿è·ããå¿
èŠãããããšãæå³ããŸãã ã·ã¹ã³ã§ã¯ãããã
Eã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ããã³
Webã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ã§ãã

ããããçµç¹å
ã«äŸµå
¥ããæªæã®ããã³ãŒãã®2ã€ã®äž»èŠãªãã£ãã«ãéè€ããŠããæ¢ç¥ã®ãŠã€ã«ã¹ã®ã¿ããã£ãããããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã®åé¡ã¯åãé€ãããŸããã ããžã¿ã«æçŽïŒçœ²åïŒã®æç¡ã«é¢ä¿ãªãããã¡ã€ã«ãåæã§ãããã¯ãããžãŒã¯ãããŸããïŒ ã¯ãããµã³ãããã¯ã¹ãšåŒã°ããã¬ãžã¹ããªãžã®ã¢ã¯ã»ã¹ããã¡ã€ã«ã®ã³ããŒãCïŒCãµãŒããŒãšã®å¯Ÿè©±ãèš±å¯ããããã©ãã£ãã¯ã®ã«ãã»ã«åãªã©ãäžæ£ãªã¢ã¯ã·ã§ã³ãå®è¡ããç®çã§ããã¡ã€ã«ã®éçããã³åçåæãå®è¡ã§ããŸãã åãCisco Threat Gridãµã³ãããã¯ã¹ã¯ã700ãè¶
ããããŸããŸãªãã©ã¡ãŒã¿ãŒãšãã¡ã€ã«ã®åäœèŠå ãåæããŠããã¡ã€ã«ã®æå®³æ§ã倿ã§ããŸãã çµã¿èŸŒã¿ã®ãŠââã€ã«ã¹å¯Ÿçãšã³ãžã³ãåããããŒã«ãä¿è·ããã®ã¯ãµã³ãããã¯ã¹ã§ãããæªç¥ã®ãŠã€ã«ã¹ã¯æ€åºã§ããŸããã ãµã³ãããã¯ã¹ãšã®çµ±åã¯ããã®ãããªæ©äŒãæäŸããŸãã ã·ã¹ã³ã®ã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ã®å Žåããã¹ãŠã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯ãè
åšã°ãªãããµã³ãããã¯ã¹ã«é¢é£ä»ããããŠããŸã-Ciscoé»åã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ãWebã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ãCisco Firepower NGFW / NGIPSãFirePOWERãµãŒãã¹ãåããCisco ASAããšã³ããã€ã³ãåãCisco AMPãCisco Umbrellaãªã©
ã¢ãã€ã«ãŠãŒã¶ãŒãä¿è·ããæ¹æ³
ãããã¯ãŒã¯å¢çãä¿è·ãããšä»®å®ããŸãããã¢ãã€ã«ãŠãŒã¶ãŒã¯ã©ãããŸããïŒ ãããã®åšèŸºã§ã¯ãITUãIPSãã³ã³ãã³ãã²ãŒããŠã§ã€ããµã³ãããã¯ã¹ããé²åŸ¡å£ãæ§ç¯ããããšã¯ã§ããŸããã MDMãœãªã¥ãŒã·ã§ã³ã¯ç®çãç°ãªããããæªæã®ããã³ãŒããžã®å¯ŸåŠã«ã¯ããŸã圹ç«ã¡ãŸããã ã¢ãã€ã«ãŠã€ã«ã¹å¯ŸçïŒ åœŒã¯ä»¥åã«èª¬æããã®ãšåãåé¡ãæ±ããŠããŸãã ãŸãããã¹ãŠã®ã¢ãã€ã«ãã©ãããã©ãŒã ã«ãã«ãŠã§ã¢å¯ŸçããŒã«ãæèŒãããŠããããã§ã¯ãããŸããïŒããšãã°ãiPhoneçšïŒã ã©ããã£ãŠæŠãã®ïŒ ç¹°ãè¿ããŸãããæ»æè
ã®åŽã«ç«ã¡ãæ»æè
ãã©ã®ããã«äœæç©ãäœæãããã確èªããå¿
èŠããããŸãã ååãšããŠããããã¯èªåŸçã«åäœããŸãããã管çãµãŒããŒãšã®éä¿¡ãæå³ããã¯ã©ã€ã¢ã³ããµãŒããŒã¢ãŒããã¯ãã£ã䜿çšããŸããããã«ã¯ãã»ãšãã©ã®å ŽåDNSãããã³ã«ã䜿çšãããŸãã æ€æ»ã§ããã°ãã¢ãã€ã«ãã©ãããã©ãŒã ã®æªæã®ããã³ãŒãã«é¢ããåé¡ã®ã»ãšãã©ã解決ã§ããŸãã ãã®å ŽåãGoogleãŸãã¯Yandexã®DNSãµãŒããŒã¢ãã¬ã¹ãç¹æ®ãªãµãŒãã¹ïŒ
Cisco Umbrellaãªã© ïŒã®ã¢ãã¬ã¹ã«çœ®ãæããã ãã§ãDNSãµãŒãã¹ã«å ããŠãCïŒCãµãŒããŒãšã®çžäºäœçšãããå®å
šã«ä¿è·ãããŸãã å®éãCisco Umbrellaã§ã¯ããã£ãã·ã³ã°ãªãœãŒã¹ããã«ãŠã§ã¢ã®æ¡æ£ã«äœ¿çšãããDGAãã¡ã€ã³ãã¯ããŒã³ãµã€ãã®è¿œè·¡ãã¹ã€ãããã¡ã€ã³ã®åŒ·å¶çµäºãªã©ã鮿ããããšãã§ããŸãã

NTAãšEDRãèŠãŠã¿ãŸããã
WannaCryã®è©±ã«æ»ããŸãããã éææ¥ã®å€æ¹ãå€§äŒæ¥ã®CEOãèªå®
ã®ã³ã³ãã¥ãŒã¿ãŒã§WannaCryãæŸããŸããã ããããããšãªããåææ¥ã®æãåœŒã¯ææããã©ããããããè·å Žã«æã¡èŸŒã¿ããããäŒæ¥ãããã¯ãŒã¯ã«æ¥ç¶ããåæã«ITå°éå®¶ã«ãæ°åãæ¶ãå»ã£ããã 圌ããä»äºãããŠããéãWannaCryã¯ãå¢çä¿è·ãããªãåªããŠããã«ãããããããå
éšãããã¯ãŒã¯å
šäœã«åºããå§ããŸããã ããããæªç¥ã®ãŠã€ã«ã¹ãWi-Fiã®ãããã³ã°ãè«è² æ¥è
ã®ã©ããããããªã©ãæèŒãããã©ãã·ã¥ãã©ã€ãã¯ãŸã ååšããŸãã ãã®ç¶æ³ã§äœããã¹ããïŒ å¯äžã®çãã¯ãNTAããã³EDRãã¯ãããžãŒã䜿çšããŠå
éšã€ã³ãã©ã¹ãã©ã¯ãã£ãç£èŠããããšã§ãã ãããã¯ããããã¯ãŒã¯ãã©ãã£ãã¯åæãšãšã³ããã€ã³ãã®æ€åºãšå¿çãšãã2ã€ã®ã¯ã©ã¹ã®ã»ãã¥ãªãã£æ©èœãæå³ããç¥èªã§ãã
ãããã¯ãŒã¯ãã©ãã£ãã¯ã®åæïŒããšãã°ã
Cisco Stealthwatchã䜿çšïŒã«ããã端æ«ããã€ã¹ã«ä¿è·ããŒã«ããªããŠããå€ããªã£ãã¢ã³ããŠã€ã«ã¹ããã£ãŠããæªæã®ããã³ãŒãã®å
åãèå¥ããããšãã§ããŸãã ããã«ã
ETAãã¯ãããžãŒã«ãããæå·åããããã©ãã£ãã¯ã§ãæªæã®ããã¢ã¯ãã£ããã£ã®å
åãæ€åºããããšãå¯èœã§ãã æ¬¡ã«ããã¹ãŠã®100ïŒ
è
åšã鲿¢ãããšããååã«åºã¥ããŠæ§ç¯ãããŠããªãEDRã¯ã©ã¹ã®ãœãªã¥ãŒã·ã§ã³ïŒããšãã°ã
Cisco AMP for Endpoint ïŒãšãŠã€ã«ã¹å¯Ÿçã亀æããŸãããã®äºå®ãæ€åºããããã«åå¿ããŸãã
å¢çäžã®ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãå
éšãããã¯ãŒã¯ã«ç¬èªã®é¡äŒŒç¹ããããŸã-ããã¯ã
äœããã®æ¹æ³ã§å
éšãããã¯ãŒã¯ã«äŸµå
¥ããå Žåã«ãå
éšãããã¯ãŒã¯ã®ã»ã°ã¡ã³ããŒã·ã§ã³ãšæªæã®ããã³ãŒãã®æ¡æ£ã®ããŒã«ãªãŒãŒã·ã§ã³ãæäŸãããããã¯ãŒã¯ã¢ã¯ã»ã¹å¶åŸ¡ã·ã¹ãã ïŒããšãã°ã
Cisco ISE ïŒã§ãã çæ³çã«ã¯ãæªæã®ããã³ãŒããæ¡æ£ãããæåã®è©Šã¿ãæ€åºãããããã¯ãŒã¯ãã©ãã£ãã¯åæãœãªã¥ãŒã·ã§ã³ã¯ãã¹ã€ããããŒããç¡å¹ã«ããããã«ãŒã¿ãŒã®ACLã倿ŽããŠæ€ç«ãµããããã«å
¥ãããšã«ããããããã¯ãŒã¯ã¢ã¯ã»ã¹å¶åŸ¡ã·ã¹ãã ã«ã³ãã³ããéä¿¡ããææããã³ã³ãã¥ãŒã¿ãŒããããã¯ã§ããŸãã
ãã¡ãããäžèšã®ãã¹ãŠã®æè¡ã¯åå¥ã«ãŸãã¯ãªãã©ã€ã³ã§æ©èœããã®ã§ã¯ãªããã¢ã©ãŒã ãã»ãã¥ãªãã£ããªã·ãŒãã³ãã³ããããã³äŸµå®³ã®ææšã亀æããŠäºãã«å¯æ¥ã«é£æºããå¿
èŠããããŸãã ãšããã§ãã€ã³ãžã±ãŒã¿ãŒïŒIoCïŒã«ã€ããŠã ãŸããå€éšãœãŒã¹ãã宿çã«ååŸããå¿
èŠãããïŒ
Cisco Talosã¯ãã®ãããªãœãŒã¹ã®åœ¹å²ã§ãïŒãçµ¶ããå€åããè
åšã«é¢ããç¥èããã¹ãŠã®ä¿è·ããŒã«ïŒå¢çãã¯ã©ãŠããå人ããŸãã¯å
éšïŒãåããŠããå¿
èŠããããŸãã

éãããœãããŠã§ã¢ç°å¢ã«æ»ããå€çããéé¢ãã
äžèšã®æŠç¥ã¯ãæªæã®ããã³ãŒãã®98ïŒ
ã«å¯Ÿããä¿è·ã«æé©ã§ãã 倧åãªçŸã«è¿ã¥ãããšã§ããã®äŸ¡å€ãé«ããããšãã§ããŸããïŒ å®éã«ã¯å¯èœã§ããããã®å Žåããããã¯ãŒã¯ã®éçšç¹æ§ã倧å¹
ã«äœäžããããŠãŒã¶ãŒã®äœ¿ãããããäœäžãããå¿
èŠãããããšãçè§£ããå¿
èŠããããŸãã ããã¯ããã©ãã¯ãªã¹ããã©ãã€ã ãæåŠãããæ¢ç¥ã®ãã®ã®ã¿ãèš±å¯ãããããšããã«ãŒã«ãžã®ç§»è¡ã«ãã£ãŠå®çŸãããŸãã èš±å¯ãããã¢ããªã±ãŒã·ã§ã³ãIPã¢ãã¬ã¹ããŠãŒã¶ãŒãªã© ç§ãã¡ãçè§£ããŠããããã«ããã®ã¢ãããŒãã«ã¯å®ç掻ã«ãããŠå€§ããªå¶éããããŸãããæªæã®ããã³ãŒãã®åäœãèããå¶éããå¯èœæ§ããããŸãã å颿è¡ãä»®æ³åããªã¢ãŒããã©ãŠã¶ãŒãTPMãOSæŽåæ§å¶åŸ¡ããªã¢ãŒãæ€èšŒãé»åã¡ãŒã«çœ²åã«ããã远å ã®ä¿è·ã¬ãã«ãå®çŸãããŸãã

ãŸãšããšããŠ
æªæã®ããã³ãŒãããä¿è·ããããã®ããã€ãã®æŠç¥ã説æããŸãã-æå°ããæå€§ãŸã§ã ããã¯ãå
éšãããã¯ãŒã¯ãšã¢ãã€ã«ãŠãŒã¶ãŒã®ææãå®å
šã«é²ãããšãã§ãããšããããšã§ããïŒ ããã 100ïŒ
ã®ä¿è·ãä¿èšŒã§ãã人ã¯ããŸããã ãããããã®ã¡ã¢ã®ã¿ã¹ã¯ã¯ç°ãªã£ãŠããŸãã-ãŠã€ã«ã¹å¯Ÿçã ãã§ææ°ã®ãã«ãŠã§ã¢ããä¿åã§ãããšãã芳ç¹ã¯ãŸã é·ãéãè
æãããŠãããçµ±åã¢ãããŒãã®ã¿ãåé¡ã解決ã§ãããŠãŒã¹ã±ãŒã¹ãã䜿çšããå¿
èŠãããããšã瀺ãããç§ãã¡ããã§ã«
æžããããš ã
è¿œå æ
å ±ïŒ
Ciscoãããã¯ãŒã¯äžã®Cisco Stealthwatchã¢ããªã±ãŒã·ã§ã³ã®
説ææå·åããããã©ãã£ãã¯ã®æªæã®ããã³ãŒããæ€åºããæè¡ã®
説æãããã¯ãŒã¯äžã®ã¯ãªãããã€ããŒãæ€åºããã¢ãããŒãã®
説æãŠãŒã¹ã±ãŒã¹ã«åºã¥ããã»ãã¥ãªãã£ã·ã¹ãã ã®
æ§ç¯æå·åããã°ã©ã ãšæŠããã
ã®æŠç¥ã®
説æWannaCryãšæŠããã
ã®æŠç¥ã®
説æCiscoãããã¯ãŒã¯ã§ã®Cisco ISE
ã®äœ¿çšã®
説æ