IDS/IPS ãšã¯ïŒ
- IDSïŒäŸµå ¥æ€ç¥ã·ã¹ãã ïŒã¯æ»æãæ€ç¥ããŠéç¥ãããéä¿¡ã¯æ¢ããªã
- IPSïŒäŸµå ¥é²æ¢ã·ã¹ãã ïŒã¯æ€ç¥ããæ»æããªã¢ã«ã¿ã€ã ã«èªå鮿ãã
- ã·ã°ããã£ããŒã¹ïŒæ¢ç¥ãã¿ãŒã³ïŒãšã¢ãããªããŒã¹ïŒéåžžããå€ããæåïŒã®2æ¹åŒããã
- 誀æ€ç¥ïŒæ£åžžéä¿¡ãæ»æãšèª€èªïŒãšèŠéãã®ãã©ã³ã¹èª¿æŽãéçšã®æ žå¿
IDSãšIPSã£ãŠååã䌌ãŠããã©äœãéãã®ïŒ
IDSã¯ãäžæ£ãªéä¿¡ãçºèŠããŠèŠåãããã ãã§éä¿¡ãæ¢ããªããIPSã¯ãçºèŠãããèªåã§é®æããããŸã§è¡ããç£èŠå¡ãšèŠåå¡ã®éãã¿ãããªã€ã¡ãŒãžã ãã
ã©ã£ã¡ã䜿ãã°ããã®ïŒ
IPSã®ã»ããèªå察å¿ã§ããŠéããã©ã誀æ€ç¥ããããšæ£åžžãªéä¿¡ãŸã§æ¢ããŠããŸããªã¹ã¯ããããéèŠãªæ¥åã·ã¹ãã ãžã®åœ±é¿ã倧ããå Žåã¯ãæåã¯IDSã§ç£èŠã»ãã¥ãŒãã³ã°ããŠãå®å®ãããIPSã«åãæ¿ãããšããæé ããšãããšãå€ããã
ãã¡ã€ã¢ãŠã©ãŒã«ãšIPSãäœãéãã®ïŒ
ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãèš±å¯ã»æåŠã®ã«ãŒã«ãã§éä¿¡ãå¶åŸ¡ãããã©ãIDSãšIPSã¯éä¿¡ã®ãå 容ã»ãã¿ãŒã³ããåæããŠæ»æãã©ããã倿ãããã ããã¡ã€ã¢ãŠã©ãŒã«ã§èš±å¯ããŠããéä¿¡ã®äžã«é ããæ»æããIDS/IPSã¯æ€ç¥ã§ããå Žåããããã
ã¢ãããªããŒã¹ã£ãŠäœïŒ
ãéåžžãšã¯éãè¡åããæ»æã®ãµã€ã³ãšããŠæ€ç¥ããæ¹æ³ã ããäŸãã°æ·±å€ã«å€§éã®ããŒã¿ãéä¿¡ãããŠãããæ®æ®µã¢ã¯ã»ã¹ããªããµãŒããžçªç¶ã¢ã¯ã»ã¹ããŠãããªã©ãããŒã¹ã©ã€ã³ããå€ããæåãæ€ç¥ãããæ°ããæ»æã«ã察å¿ã§ããåé¢ã誀æ€ç¥ãå€ããªãããã課é¡ããããã ã
ãããã¯ãŒã¯åãšãã¹ãåã£ãŠéãã®ïŒ
NIDS/NIPSïŒãããã¯ãŒã¯åïŒã¯ãããã¯ãŒã¯äžãæµãããã±ãããç£èŠãããã®ã§ãHIDS/HIPSïŒãã¹ãåïŒã¯åã ã®ãµãŒããPCã«ã€ã³ã¹ããŒã«ããŠãã®ã·ã¹ãã å ã®åäœãç£èŠãããã®ã ããHIDS/HIPSã¯ãã°ããã¡ã€ã«ã®å€æŽã»ããã»ã¹ã®åäœãªã©ãç£èŠã§ããããå éšã®äžå¯©ãªåäœãæ€ç¥ãããããNIDSãšHIDSãçµã¿åãããå€å±€é²åŸ¡ãçæ³ãªãã ãã©ããã°ãèšå€§ã«ãªããã管çã®è€éããšãã¬ãŒããªãã«ãªãããšãå€ããã ã
å®éã«äœ¿ãããŠããIDS/IPSã®ããŒã«ã£ãŠã©ããªãã®ãããã®ïŒ
ãªãŒãã³ãœãŒã¹ã§æåãªã®ãSnortãšSuricataã ããSnortã¯ã·ã°ããã£ããŒã¹ã®èèã§ãã«ãŒã«å®çŸ©ãè±å¯ã«å ¬éãããŠãããã ãSuricataã¯Snortã®ã«ãŒã«ãšäºææ§ãæã¡ã€ã€ããã«ãã¹ã¬ãã察å¿ã§é«éåŠçã§ãããã¯ã©ãŠããªãAWS GuardDutyãAWSã®è åšã€ã³ããªãžã§ã³ã¹ã𿩿¢°åŠç¿ã§äžå¯©ãªAWSæäœãæ€ç¥ããŠããã䟿å©ãªãµãŒãã¹ã ãã
ã·ã°ããã£åã£ãŠãã¿ãŒã³ç §åã£ãŠããšïŒã©ããã£ãŠæ»æãèŠåããã®ïŒ
ããã ããæ¢ç¥ã®æ»æãã¿ãŒã³ïŒã·ã°ããã£ïŒãããŒã¿ããŒã¹åããŠãããŠãéä¿¡å 容ãšç §åãããã ãäŸãã°SQLã€ã³ãžã§ã¯ã·ã§ã³ã®å žåçãªæååããç¹å®ã®ãã«ãŠã§ã¢ãéããã±ããã®ãã¿ãŒã³ãç»é²ããŠãããæ€ç¥ç²ŸåºŠãé«ããŠèª€æ€ç¥ãå°ãªãåé¢ãã·ã°ããã£ã«ç»é²ãããŠããªãæ°ããæ»æïŒãŒããã€ïŒã«ã¯å¯Ÿå¿ã§ããªããšãã匱ç¹ããããã ãã
ãŒããã€æ»æã£ãŠIDS/IPSã§é²ããªãã®ïŒ
ã·ã°ããã£åã§ã¯é²ãã®ãé£ãããã ããŸã å ¬éãããŠããªãè匱æ§ãçªãæ»æã¯ã·ã°ããã£ãååšããªãããããã¢ãããªåã§ããã°ãéåžžãšç°ãªãæåããšããŠæ€ç¥ã§ããããšããããã©ãå®å šã«ã¯é²ããªãã®ãçŸå®ã ããã ããIDS/IPSãéä¿¡ãããWAFãEDRãšçµã¿åãããå€å±€é²åŸ¡ãéèŠãªãã ãã
EDRã£ãŠäœïŒIDS/IPSãšã©ãéãã®ïŒ
EDRïŒEndpoint Detection and ResponseïŒã¯PCããµãŒããªã©ã®ãšã³ããã€ã³ãäžã§ã®ããã»ã¹ã»ãã¡ã€ã«æäœã»éä¿¡ãªã©ãç¶ç¶çã«èšé²ããŠãæ»æãæ€ç¥ã»å¯Ÿå¿ãããã®ã ããIDS/IPSãäž»ã«ãããã¯ãŒã¯éä¿¡ã®ç£èŠãªã®ã«å¯ŸããŠãEDRã¯ç«¯æ«å éšã®åããŸã§èŠããäŸµå ¥åŸã®æšªå±éãäžå¯©ãªããã»ã¹èµ·åãªã©ã远跡ã§ãããããè¿å¹Žã¯EDRãšSIEMãçµã¿åãããéçšãäž»æµã«ãªã£ãŠãããã ã
SIEMïŒSecurity Information and Event ManagementïŒã¯ãµãŒãã»ãããã¯ãŒã¯æ©åšã»IDS/IPSã»EDRãªã©æ§ã ãªã·ã¹ãã ã®ãã°ãäžå éçŽããŠãçžé¢åæãããã©ãããã©ãŒã ã ããIDS/IPSãåå¥ã®éä¿¡ã§ãæªãããã±ããããæ€ç¥ããã®ã«å¯ŸããŠãSIEMã¯è€æ°ã®ã·ã¹ãã ã®ãã°ã暪æçã«åæããŠãäžé£ã®æ»æã®æµãããèŠã€ããããšãã§ãããã ã
誀æ€ç¥ïŒFalse PositiveïŒãå€ããšäœãå°ãã®ïŒ
æ£åžžãªæ¥åéä¿¡ãæ»æãšèª€èªããŠé®æããŠããŸããã ããäŸãã°IPSã瀟å ã®éèŠã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ããããã¯ããŠããŸã£ãããæ¥åãæ¢ãŸã£ãŠããŸããã ããæ°ããã«ãŒã«ã远å ãããšãã¯æåã¯IDSã¢ãŒãïŒæ€ç¥ã®ã¿ïŒã§éçšããŠã誀æ€ç¥ããªãã確èªããŠããIPSã¢ãŒãã«åãæ¿ããã®ãå®å šãªæé ã ãããã¥ãŒãã³ã°ã¯å°å³ã ãã©éçšã®æ žå¿ãªãã ã
ãã¥ãŒãã³ã°ã£ãŠå ·äœçã«ã©ãããã®ïŒ
倧ãã2ã€ã®ã¢ãããŒãããããããŸããã¯ã€ããªã¹ãæ¹åŒã§ããã®IPã¢ãã¬ã¹ããã®ãã®ããŒããžã®ã¢ã¯ã»ã¹ã¯æ£åžžããšé€å€ã«ãŒã«ã远å ããæ¹æ³ãããäžã€ã¯ã·ã°ããã£ã®æåºŠèª¿æŽã§ã誀æ€ç¥ãå€ãã«ãŒã«ã®éŸå€ãäžããããç¹å®ã®æ¡ä»¶ãéãªã£ããšãã ãã¢ã©ãŒããåºãããã«å€æŽããæ¹æ³ã ããSnortãªãRuleã¬ãã«ã§ã®çްãã調æŽãã§ãããã ã
IDS/IPSã£ãŠå人ã§ã䜿ããã®ïŒäŒæ¥ã ãã®ãã®ãªã®ïŒ
å人ã§ã䜿ããããSnortãSuricataã¯ãªãŒãã³ãœãŒã¹ã§ç¡æã ããèªå® ãµãŒããå人ã®ã©ãç°å¢ã«ãå°å ¥ã§ããããã èšå®ã»ãã¥ãŒãã³ã°ã»ãã°ç®¡çã«ãããªãã®ç¥èãšæéãããããããåäººãæ¬çªã§äœ¿ããšããããã¯ã»ãã¥ãªãã£åŠç¿ã®ç°å¢ãšããŠæŽ»çšããã±ãŒã¹ãå€ãããã¯ã©ãŠãç°å¢ãªãAWS GuardDutyã®ãããªãããŒãžããµãŒãã¹ã®æ¹ãæè»œã«å§ãããããã