æ
å ±ã»ãã¥ãªãã£ããŒã«ã®é«ãå¹çã確ä¿ããããã«ãã³ã³ããŒãã³ãã®æ¥ç¶ãéèŠãªåœ¹å²ãæãããŸãã å€éšã®è
åšã ãã§ãªããå
éšã®è
åšããããã¯ã§ããŸãã ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãèšèšããéãã¯ã©ã¹å
ïŒãšã³ããã€ã³ãã»ãã¥ãªãã£ãŸãã¯NGFWïŒã§æ©èœããã ãã§ãªããçžäºã«é£æºããŠè
åšãšæŠãèœåãæã€ããã«ããŠã€ã«ã¹å¯Ÿçã§ãããã¡ã€ã¢ãŠã©ãŒã«ã§ãããããããä¿è·æ段ãéèŠã§ãã
çè«ã®ããã
åœç¶ã®ããšãªãããçŸåšã®ãµã€ããŒç¯çœªè
ã¯ããèµ·æ¥å®¶ã«ãªã£ãŠããŸãã 圌ãã¯ãã«ãŠã§ã¢ãæ¡æ£ããããã«å€ãã®ãããã¯ãŒã¯æè¡ã䜿çšããŠããŸã
ãã£ãã·ã³ã°ã¡ãŒã«ã¯ããã«ãŠã§ã¢ãæ¢ç¥ã®æ»æã䜿çšããŠãããã¯ãŒã¯ã®ããããå€ãè¶
ãããããŸãã¯ããŒããã€æ»æããšããã«ç¶ãç¹æš©ã®ææ ŒããŸãã¯ãããã¯ãŒã¯å
šäœã®æšªæ¹åã®ç§»åãåŒãèµ·ãããŸãã ææããããã€ã¹ã1ã€ãããšããããšã¯ãæ»æè
ã®mercå
µç®çã§ãããã¯ãŒã¯ã䜿çšãããå¯èœæ§ãããããšãæå³ããŸãã
å Žåã«ãã£ãŠã¯ãæ
å ±ã»ãã¥ãªãã£ã³ã³ããŒãã³ãã®çžäºäœçšã確ä¿ããå¿
èŠãããå Žåãã·ã¹ãã ã®çŸåšã®ç¶æ
ã®æ
å ±ã»ãã¥ãªãã£ç£æ»ãå®æœãããšãã«ãçžäºæ¥ç¶ãããåäžã®æž¬å®ã»ããã䜿çšããŠèª¬æã§ããŸããã ã»ãšãã©ã®å Žåãç¹å®ã®ã¿ã€ãã®è
åšã«å¯Ÿæããããšã«çŠç¹ãåœãŠãå€ãã®æè¡çãœãªã¥ãŒã·ã§ã³ã¯ãä»ã®æè¡çãœãªã¥ãŒã·ã§ã³ãšã®çµ±åãæäŸããŸããã ããšãã°ããšã³ããã€ã³ãä¿è·è£œåã¯ã眲åããŒã¹ã®åäœåæã䜿çšããŠããã¡ã€ã«ãææããŠãããã©ãããå€æããŸãã æªæã®ãããã©ãã£ãã¯ãé»æ¢ããããã«ããã¡ã€ã¢ãŠã©ãŒã«ã¯Webãã£ã«ã¿ãªã³ã°ãIPSããµã³ãããã¯ã¹ãªã©ãå«ãä»ã®ãã¯ãããžãŒã䜿çšããŸãã ããã«ãããããããã»ãšãã©ã®çµç¹ã§ã¯ããããã®æ
å ±ã»ãã¥ãªãã£ã³ã³ããŒãã³ãã¯çžäºã«æ¥ç¶ãããŠããããåç¬ã§åäœããŸãã
ããŒãããŒãæè¡ã®åå
ãµã€ããŒã»ãã¥ãªãã£ã確ä¿ããããã®æ°ããã¢ãããŒãã«ã¯ãåã¬ãã«ã§ã®ä¿è·ãå«ãŸããŸããåã¬ãã«ã§äœ¿çšããããœãªã¥ãŒã·ã§ã³ã¯çžäºæ¥ç¶ãããæ
å ±ã亀æããæ©èœããããŸãã ããã«ãããSynchronized SecurityïŒSynSecïŒã·ã¹ãã ãäœæãããŸãã SynSecã¯ãåäžã·ã¹ãã ãšããŠã®æ
å ±ã»ãã¥ãªãã£ããã»ã¹ã§ãã ãã®å Žåãåæ
å ±ã»ãã¥ãªãã£ã³ã³ããŒãã³ãã¯ãªã¢ã«ã¿ã€ã ã§çžäºã«æ¥ç¶ãããŸãã ããšãã°ã
Sophos Centralãœãªã¥ãŒã·ã§ã³ã¯ãã®ååã«åŸã£ãŠå®è£
ãããŸãã
ã»ãã¥ãªãã£ããŒãããŒããã¯ãããžãŒã¯ãã»ãã¥ãªãã£ã³ã³ããŒãã³ãéã®éä¿¡ãæäŸããã·ã¹ãã ãšãã®ç£èŠã®å
±åæ©èœãä¿èšŒããŸãã 以äžã®ã¯ã©ã¹ã
Sophos Centralã«çµ±åãããŠããŸãã
Sophos Centralãããªãåºç¯å²ã®æ
å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ããµããŒãããŠããããšã¯å®¹æã«ç解ã§ããŸãã Sophos Centralã®SynSecã³ã³ã»ããã¯ãæ€åºãåæãå¿çãšãã3ã€ã®éèŠãªååã«åºã¥ããŠããŸãã ãããã®è©³çŽ°ãªèª¬æã«ã€ããŠã¯ãããããã«ã€ããŠèª¬æããŸãããã
SynSecã®æŠå¿µ
æ€åº ïŒæªç¥ã®è
åšã®èå¥ïŒ
Sophos Centralãå®è¡ãããœãã©ã¹è£œåã¯èªåçã«æ
å ±ãå
±æãã以äžãå«ããªã¹ã¯ãšæªç¥ã®è
åšãèå¥ããŸãã
- ãªã¹ã¯ã®é«ãã¢ããªã±ãŒã·ã§ã³ãšæªæã®ãããã©ãã£ãã¯ãèå¥ããæ©èœãåãããããã¯ãŒã¯ãã©ãã£ãã¯åæã
- ãããã¯ãŒã¯äžã§ã®ã¢ã¯ã·ã§ã³ã®çžé¢åæã«ããããªã¹ã¯ã®é«ãã°ã«ãŒããæã€ãŠãŒã¶ãŒã®æ€åºã
åæ ïŒå³æãã€çŽæçïŒ
ãªã¢ã«ã¿ã€ã ã®ã€ã³ã·ãã³ãåæã«ãããã·ã¹ãã ã®çŸåšã®ç¶æ³ãå³åº§ã«ææ¡ã§ããŸãã
- ãã¹ãŠã®ãã¡ã€ã«ãã¬ãžã¹ããªããŒãURLãªã©ãå«ããã€ã³ã·ãã³ãã«ã€ãªãã£ãã€ãã³ãã®å®å
šãªãã§ãŒã³ã衚瀺ããŸãã
RESPONSE ïŒèªåã€ã³ã·ãã³ã察å¿ïŒ
ã»ãã¥ãªãã£ããªã·ãŒãèšå®ãããšãæ°ç§ã§ææãã€ã³ã·ãã³ãã«èªåçã«å¯Ÿå¿ã§ããŸãã ããã¯ä»¥äžã«ãã£ãŠæäŸãããŸãïŒ
- ææããããã€ã¹ãå³åº§ã«éé¢ãããªã¢ã«ã¿ã€ã ã§æ»æãåæ¢ããŸãïŒåããããã¯ãŒã¯/ãããŒããã£ã¹ããã¡ã€ã³å
ã§ãïŒã
- ããªã·ãŒãæºãããªãããã€ã¹ã®äŒæ¥ãããã¯ãŒã¯ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶éããã
- çºä¿¡ã¹ãã ãæ€åºããããšããªã¢ãŒãã§ããã€ã¹ã®ã¹ãã£ã³ãéå§ããŸãã
Sophos Centralãæ©èœããåºæ¬çãªã»ãã¥ãªãã£ååãæ€èšŒããŸããã 次ã«ãSynSecãã¯ãããžãŒãå®éã«ã©ã®ããã«æ©èœãããã®èª¬æã«ç§»ããŸãããã
çè«ããå®è·µãž
ã¯ããã«ãSynSecãããŒãããŒããã¯ãããžãŒã䜿çšããŠããã€ã¹ã®çžäºäœçšã確ç«ããæ¹æ³ã説æããŸãããã æåã®ã¹ãããã¯ãSophos XGãSophos Centralã«ç»é²ããããšã§ãã ãã®æ®µéã§ã圌ã¯ãèªå·±èå¥ã®èšŒææžãHeartbeatãã¯ãããžãŒã䜿çšããŠãšã³ãããã€ã¹ãéä¿¡ããIPã¢ãã¬ã¹ãšããŒããããã³Sophos Centralã§ç®¡çãããŠãããšã³ãããã€ã¹IDã®ãªã¹ããšãã®ã¯ã©ã€ã¢ã³ã蚌ææžãåãåããŸãã
Sophos XGã®ç»é²ãè¡ãããçŽåŸã«ãSophos Centralã¯ããŒãããŒãéä¿¡ãéå§ããããã«ãšã³ãããã€ã¹ã«æ
å ±ãéä¿¡ããŸãã
- Sophos XG蚌ææžã®çºè¡ã«äœ¿çšããã蚌ææ©é¢ã®ãªã¹ã
- Sophos XGã«ç»é²ãããŠããããã€ã¹IDã®ãªã¹ãã
- éä¿¡çšã®ããŒãããŒãIPã¢ãã¬ã¹ãšããŒãã
ãã®æ
å ±ã¯ã次ã®æ¹æ³ã§ã³ã³ãã¥ãŒã¿ãŒã«ä¿åãããŸããïŒ
ProgramDataïŒ
\ Sophos \ Hearbeat \ Config \ Heartbeat.xmlãå®æçã«æŽæ°ãããŸãã
ããŒãããŒããã¯ãããžãŒã¯ãããžãã¯IPã¢ãã¬ã¹52.5.76.173:8347ã«ãšã³ããã€ã³ãã¡ãã»ãŒãžãéä¿¡ããããšã§éä¿¡ããŸãã åæã«ããããã³ããŒãçºè¡šããããã«ããã±ããã¯15ç§ã®åšæã§éä¿¡ãããããšãæããã«ãªããŸããã Heartbeatã¡ãã»ãŒãžã¯XG Firewallã«ãã£ãŠçŽæ¥åŠçãããããšã«æ³šæããŠãã ãããXGFirewallã¯ãã±ãããååãããšã³ããã€ã³ãã®ã¹ããŒã¿ã¹ãç£èŠããŸãã ãã¹ãã§ãã±ããããã£ããã£ãããšããã©ãã£ãã¯ãããŒã¯å€éšIPã¢ãã¬ã¹ãšã®éä¿¡ã«äŒŒãŠããŸãããå®éã«ã¯ãšã³ããã€ã³ãã¯XGãã¡ã€ã¢ãŠã©ãŒã«ãšçŽæ¥éä¿¡ããŸãã
æªæã®ããã¢ããªã±ãŒã·ã§ã³ãäœããã®æ¹æ³ã§ã³ã³ãã¥ãŒã¿ãŒã«äŸµå
¥ããããã«ããŸãã Sophos Endpointã¯ãã®æ»æãæ€åºãããããã®ã·ã¹ãã ããã®ããŒãããŒãã®åä¿¡ãåæ¢ããŸãã ææããããã€ã¹ã¯ãã·ã¹ãã ææã«é¢ããæ
å ±ãèªåçã«éä¿¡ããã¢ã¯ã·ã§ã³ã®èªåãã§ãŒã³ãåŒãèµ·ãããŸãã XG Firewallã¯å³åº§ã«ã³ã³ãã¥ãŒã¿ãŒãéé¢ããæ»æã®æ¡æ£ãšCïŒCãµãŒããŒãšã®çžäºäœçšãé²ããŸãã
Sophos Endpointã¯ãã«ãŠã§ã¢ãèªåçã«åé€ããŸãã åé€åŸããšã³ãããã€ã¹ã¯Sophos CentralãšåæãããXG Firewallã¯ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãå埩ããŸãã æ ¹æ¬åå åæïŒRCAãŸãã¯EDR-ãšã³ããã€ã³ãæ€åºããã³å¿çïŒã¯ãäœãèµ·ãã£ããã®è©³çŽ°ãªã¢ã€ãã¢ãæäŸããŸãã
ã¢ãã€ã«ããã€ã¹ãšã¿ãã¬ããã䜿çšããŠäŒæ¥ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ãããšä»®å®ãããšããã®å Žåã«SynSecãæäŸããããšã¯å¯èœã§ããïŒ
ãã®ã·ããªãªã§ã¯ãSophos Centralã¯
Sophos Mobileãš
Sophos Wirelessã®ãµããŒããæäŸããŸãã ãŠãŒã¶ãŒãSophos Mobileã§ä¿è·ãããã¢ãã€ã«ããã€ã¹ã®ã»ãã¥ãªãã£ããªã·ãŒã«éåããããšãããšããŸãã Sophos Mobileã¯ãã»ãã¥ãªãã£ããªã·ãŒéåãæ€åºããã·ã¹ãã ã®æ®ãã®éšåã«ã¢ã©ãŒããéä¿¡ããŠãã€ã³ã·ãã³ãã«å¯ŸããŠäºåã«æ§æãããå¿çãããªã¬ãŒããŸãã Sophos Mobileãããããã¯ãŒã¯æ¥ç¶ãçŠæ¢ãããããªã·ãŒã§èšå®ãããŠããå ŽåãSophos Wirelessã¯ãã®ããã€ã¹ã®ãããã¯ãŒã¯ã¢ã¯ã»ã¹ãå¶éããŸãã Sophos Wirelessã¿ãã®Sophos CentralããŒã«ããŒã«ã¯ãããã€ã¹ãææããŠãããšããéç¥ã衚瀺ãããŸãã ãŠãŒã¶ãŒããããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããšããŠããéãã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãå¶éãããŠããããšãç¥ãããã¹ãã©ãã·ã¥ç»é¢ãç»é¢ã«è¡šç€ºãããŸãã
ãšã³ããã€ã³ãã«ã¯ãããã€ãã®ããŒãããŒãã¹ããŒã¿ã¹ã¹ããŒã¿ã¹ããããŸãïŒèµ€ãé»ãç·ã
èµ€ã®ã¹ããŒã¿ã¹ã¯ã次ã®å Žåã«çºçããŸãã
- æ€åºãããã¢ã¯ãã£ããªãã«ãŠã§ã¢
- ãã«ãŠã§ã¢ãèµ·åããããšããŸããã
- æªæã®ãããããã¯ãŒã¯ãã©ãã£ãã¯ãæ€åºãããŸãã
- ãã«ãŠã§ã¢ã¯åé€ãããŠããŸããã
é»è²ã®ã¹ããŒã¿ã¹ã¯ãéã¢ã¯ãã£ããªãã«ãŠã§ã¢ããšã³ããã€ã³ãã§æ€åºãããããšããŸãã¯PUPïŒæœåšçã«äžèŠãªããã°ã©ã ïŒãæ€åºãããããšãæå³ããŸãã ç·è²ã®ã¹ããŒã¿ã¹ã¯ãäžèšã®åé¡ãæ€åºãããŠããªãããšã瀺ããŸãã
ä¿è·ãããããã€ã¹ãšSophos Centralã®çžäºäœçšã®å€å
žçãªã·ããªãªã®ããã€ããæ€èšããåŸããœãªã¥ãŒã·ã§ã³ã®ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ãŒã¹ã«ã€ããŠèª¬æããåºæ¬èšå®ãšãµããŒããããæ©èœãæ€èšããŸãã
GUI
ã³ã³ãããŒã«ããã«ã«ææ°ã®éç¥ã衚瀺ãããŸãã ãŸãããã€ã¢ã°ã©ã ã®åœ¢åŒã§ãããŸããŸãªä¿è·ã³ã³ããŒãã³ãã®èŠçŽç¹æ§ã衚瀺ãããŸãã ãã®å ŽåãããŒãœãã«ã³ã³ãã¥ãŒã¿ãŒã®ä¿è·ã«é¢ããèŠçŽããŒã¿ã衚瀺ãããŸãã ãã®ããã«ã«ã¯ãäžé©åãªã³ã³ãã³ããå«ãå±éºãªãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹è©Šè¡ã«é¢ããæŠèŠæ
å ±ãšãé»åã¡ãŒã«åæã®çµ±èšã衚瀺ãããŸãã
Sophos Centralã¯ãé倧床ã«å¿ããã¢ã©ãŒãã®è¡šç€ºããµããŒãããŠããããããŠãŒã¶ãŒã¯éèŠãªã»ãã¥ãªãã£ã¢ã©ãŒããã¹ãããã§ããŸããã Sophos Centralã¯ãä¿è·ã·ã¹ãã ã®ã¹ããŒã¿ã¹ã«é¢ããç°¡æœãªæŠèŠæ
å ±ã«å ããŠãã€ãã³ããã°ãSIEMã·ã¹ãã ãšã®çµ±åããµããŒãããŠããŸãã å€ãã®äŒæ¥ã®Sophos Centralã¯ãå
éšSOCãšã顧客ãžã®ãµãŒãã¹æäŸïŒMSSPïŒã®äž¡æ¹ã®ãã©ãããã©ãŒã ã§ãã
éèŠãªæ©èœã®1ã€ã¯ããšã³ããã€ã³ãã¯ã©ã€ã¢ã³ãã®æŽæ°ãã£ãã·ã¥ã®ãµããŒãã§ãã ããã«ãããå€éšãã©ãã£ãã¯ã®åž¯åå¹
ãç¯çŽãããŸãããã®å ŽåãæŽæ°ã¯ãšã³ããã€ã³ãã¯ã©ã€ã¢ã³ãã®1ã€ã«1åããŠã³ããŒãããããã®åŸãä»ã®ãšã³ãããã€ã¹ãããããæŽæ°ãããŠã³ããŒãããããã§ãã 説æããæ©èœã«å ããŠãéžæãããšã³ããã€ã³ãã¯ãã»ãã¥ãªãã£ããªã·ãŒã¡ãã»ãŒãžãšæ
å ±ã¬ããŒãããœãã©ã¹ã¯ã©ãŠãã«äžç¶ã§ããŸãã ãã®æ©èœã¯ãã€ã³ã¿ãŒãããã«çŽæ¥ã¢ã¯ã»ã¹ã§ããªããä¿è·ãå¿
èŠãªãšã³ãããã€ã¹ãããå Žåã«åœ¹ç«ã¡ãŸãã Sophos Centralã«ã¯ãã³ã³ãã¥ãŒã¿ãŒä¿è·èšå®ã®å€æŽãŸãã¯ãšã³ããã€ã³ããšãŒãžã§ã³ãã®åé€ãçŠæ¢ãããªãã·ã§ã³ïŒæ¹ããé²æ¢ïŒããããŸãã
ãšã³ããã€ã³ãä¿è·ã®ã³ã³ããŒãã³ãã®1ã€ã¯ã次äžä»£ã®ãŠã€ã«ã¹å¯ŸçïŒNGAVïŒã§ãã
Intercept Xã§ãã ãã£ãŒããã·ã³ã©ãŒãã³ã°ãã¯ãããžãŒã䜿çšããŠããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã¯ãã·ã°ããã£ã䜿çšããã«ã以åã¯æªç¥ã§ãã£ãè
åšãæ€åºã§ããŸãã æ€åºç²ŸåºŠã¯ã·ã°ããã£ã®åçç©ã«å¹æµããŸãããããããšã¯ç°ãªããããã¢ã¯ãã£ããªä¿è·ãæäŸãããŒããã€æ»æãé²ããŸãã Intercept Xã¯ãä»ã®ãã³ããŒã®ã·ã°ããã£ã¢ã³ããŠã€ã«ã¹ãšäžŠè¡ããŠåäœã§ããŸãã
ãã®èšäºã§ã¯ãSophos Centralã«å®è£
ãããŠããSynSecã®æŠå¿µãšããã®ãœãªã¥ãŒã·ã§ã³ã®æ©èœã®äžéšã«ã€ããŠç°¡åã«èª¬æããŸããã 以äžã®èšäºã§ãSophos Centralã«çµ±åãããåä¿è·ã³ã³ããŒãã³ãã®æ©èœã«ã€ããŠèª¬æããŸãã ãœãªã¥ãŒã·ã§ã³ã®ãã¢çã¯
ãã¡ãããå
¥æã§ã
ãŸã ã
ãœãªã¥ãŒã·ã§ã³ã«èå³ãããå Žåã¯ããœãã©ã¹ã®è²©å£²ä»£çåºã§ãã
Factor Groupã«ãåãåãããã ããã
sophos@fgts.ruã«èªç±åœ¢åŒã§æžã蟌ãã ãã§åå
ã§ã ã