ä»æ¥ã¯ãææ°ã®æ
å ±ã«åºã¥ããŠãŠãŒã¶ãŒããã³ãšã³ãã£ãã£è¡ååæ (UEBA) åžå Žã®æŠèŠã説æããŸãã
Gartner ã®èª¿æ»ã§åŸãããäž»ãªçµæã¯æ¬¡ã®ããã«èŠçŽã§ããŸãã
- ãŠãŒã¶ãŒãšãšã³ãã£ãã£ã®è¡ååæåžå Žã®æç床ã¯ããããã®ãã¯ãããžãŒãå€ãã®ããžãã¹äžã®åé¡ã解決ããããã«äžèŠæš¡ããã³å€§èŠæš¡äŒæ¥éšéã§äœ¿çšãããŠãããšããäºå®ã«ãã£ãŠç¢ºèªãããŸãã
- UEBA åææ©èœã¯ãã¯ã©ãŠã ã¢ã¯ã»ã¹ ã»ãã¥ãªã㣠ãããŒã«ãŒ (CASB)ãã¢ã€ãã³ãã£ã㣠ã¬ããã³ã¹ããã³ç®¡ç (IGA) SIEM ã·ã¹ãã ãªã©ãå¹ åºãé¢é£æ å ±ã»ãã¥ãªã㣠ãã¯ãããžã«çµã¿èŸŒãŸããŠããŸãã
- UEBA ãã³ããŒã«é¢ããèªå€§åºåãšã人工ç¥èœããšããçšèªã®èª€ã£ã䜿çšã«ããã顧客ã¯ãã€ããã ãããžã§ã¯ããå®æœããªãéããã¡ãŒã«ãŒã®ãã¯ãããžãŒãšãœãªã¥ãŒã·ã§ã³ã®æ©èœã®æ¬åœã®éããç解ããããšãå°é£ã«ãªã£ãŠããŸãã
- åºæ¬çãªè åšæ€åºã¢ãã«ã ããèæ ®ããå Žåã§ããUEBA ãœãªã¥ãŒã·ã§ã³ã®å®è£ æéãšæ¥åžžçãªäœ¿çšã¯ãã¡ãŒã«ãŒãçŽæããŠãããããå€ãã®åŽåãšæéããããå¯èœæ§ãããããšã«é¡§å®¢ã¯æ³šç®ããŠããŸãã ã«ã¹ã¿ã ãŸãã¯ãšããžã®ãŠãŒã¹ã±ãŒã¹ãè¿œå ããããšã¯éåžžã«å°é£ãªå ŽåããããããŒã¿ ãµã€ãšã³ã¹ãšåæã®å°éç¥èãå¿ èŠã§ãã
æŠç¥çãªåžå Žéçºäºæž¬:
- 2021 幎ãŸã§ã«ããŠãŒã¶ãŒããã³ãšã³ãã£ãã£è¡ååæ (UEBA) ã·ã¹ãã ã®åžå Žã¯å¥åã®é åãšããŠååšããªããªããUEBA æ©èœãåããä»ã®ãœãªã¥ãŒã·ã§ã³ã«ç§»è¡ããã§ãããã
- 2020 幎ãŸã§ã«ããã¹ãŠã® UEBA å°å ¥ã® 95% ããããåºç¯ãªã»ãã¥ãªã㣠ãã©ãããã©ãŒã ã®äžéšãšãªãã§ãããã
UEBA ãœãªã¥ãŒã·ã§ã³ã®å®çŸ©
UEBA ãœãªã¥ãŒã·ã§ã³ã¯ãçµã¿èŸŒã¿ã®åæã䜿çšããŠããŠãŒã¶ãŒããã³ãã®ä»ã®ãšã³ãã£ã㣠(ãã¹ããã¢ããªã±ãŒã·ã§ã³ããããã¯ãŒã¯ ãã©ãã£ãã¯ãããŒã¿ ã¹ãã¢ãªã©) ã®ã¢ã¯ãã£ããã£ãè©äŸ¡ããŸãã
ãããã¯ãäžå®æéã«ãããåæ§ã®ã°ã«ãŒãå
ã®ãŠãŒã¶ãŒããã³ãšã³ãã£ãã£ã®æšæºçãªãããã¡ã€ã«ããã³åäœãšæ¯èŒããç°åžžãªã¢ã¯ãã£ããã£ãè¡šããè
åšããã³æœåšçãªã€ã³ã·ãã³ããæ€åºããŸãã
ãšã³ã¿ãŒãã©ã€ãºåéã§ã®æãäžè¬çãªäœ¿çšäŸã¯ãè åšã®æ€åºãšå¯Ÿå¿ãããã³å éšé¢ä¿è ã®è åš (ã»ãšãã©ã®å Žåã䟵害ãããå éšé¢ä¿è ãå Žåã«ãã£ãŠã¯å éšæ»æè ) ã®æ€åºãšå¯Ÿå¿ã§ãã
ãŠãšãã¯ãããªæã 決æã«ãã£ãŠãš ÑÑМкÑОейãç¹å®ã®ããŒã«ã«çµã¿èŸŒãŸããŠããŸãã
- ãœãªã¥ãŒã·ã§ã³ã¯ãSIEM ãœãªã¥ãŒã·ã§ã³ãåå¥ã«è²©å£²ãããã³ããŒãå«ãããçŽç²ãªãUEBA ãã©ãããã©ãŒã ã®ã¡ãŒã«ãŒã§ãã ãŠãŒã¶ãŒãšãšã³ãã£ãã£ã®äž¡æ¹ã®è¡ååæã«ãããå¹ åºãããžãã¹äžã®åé¡ã«çŠç¹ãåœãŠãŠããŸãã
- çµã¿èŸŒã¿ â UEBA ã®æ©èœãšãã¯ãããžãŒããœãªã¥ãŒã·ã§ã³ã«çµ±åããã¡ãŒã«ãŒ/éšéã éåžžã¯ãããå ·äœçãªäžé£ã®ããžãã¹äžã®åé¡ã«çŠç¹ãåœãŠãŸãã ãã®å ŽåãUEBA ã¯ãŠãŒã¶ãŒããšã³ãã£ãã£ã®åäœãåæããããã«äœ¿çšãããŸãã
Gartner ã¯ãåé¡è§£æ±ºããŒã«ãåæãããŒã¿ ãœãŒã¹ãå«ã XNUMX ã€ã®è»žã«æ²¿ã£ãŠ UEBA ãæããŠããŸã (å³ãåç §)ã
ãçŽç²ãªãUEBA ãã©ãããã©ãŒã ãšçµã¿èŸŒã¿ UEBA ã®æ¯èŒ
Gartner ã¯ããçŽç²ãªãUEBA ãã©ãããã©ãŒã ãšã¯æ¬¡ã®ãããªãœãªã¥ãŒã·ã§ã³ã§ãããšèããŠããŸãã
- æœè±¡çãªãç°åžžãªãŠãŒã¶ãŒæŽ»åã®ç£èŠãã ãã§ãªããç¹æš©ãŠãŒã¶ãŒã®ç£èŠãçµç¹å€ãžã®ããŒã¿åºåãªã©ãããã€ãã®å ·äœçãªåé¡ã解決ããŸãã
- å¿ ç¶çã«åºæ¬çãªåæã¢ãããŒãã«åºã¥ãè€éãªåæã®äœ¿çšãå«ãŸããŸãã
- ã€ã³ãã©ã¹ãã©ã¯ãã£ã«åå¥ã®ãšãŒãžã§ã³ããå°å ¥ããå¿ èŠããªããçµã¿èŸŒã¿ã®ããŒã¿ ãœãŒã¹ ã¡ã«ããºã ãšãã°ç®¡çããŒã«ãããŒã¿ ã¬ã€ã¯ãSIEM ã·ã¹ãã ã®äž¡æ¹ããã®ããŒã¿åéãªãã·ã§ã³ãããã€ãæäŸããŸãã
- ã«å«ãŸããã®ã§ã¯ãªããã¹ã¿ã³ãã¢ãã³ ãœãªã¥ãŒã·ã§ã³ãšããŠè³Œå
¥ããŠå±éã§ããŸãã
ä»ã®è£œåã®æ§æã
以äžã®è¡šã¯ XNUMX ã€ã®ã¢ãããŒããæ¯èŒããŠããŸãã
è¡š 1. ãçŽç²ãªãUEBA ãœãªã¥ãŒã·ã§ã³ãšçµã¿èŸŒã¿ãœãªã¥ãŒã·ã§ã³
ã«ããŽãª | ãçŽç²ãªãUEBA ãã©ãããã©ãŒã | UEBAãå èµãããã®ä»ã®ãœãªã¥ãŒã·ã§ã³ |
解決ãã¹ãåé¡ | ãŠãŒã¶ãŒã®è¡åãšãšã³ãã£ãã£ã®åæã | ããŒã¿ãäžè¶³ããŠãããšãUEBA ããŠãŒã¶ãŒãŸãã¯ãšã³ãã£ãã£ã®ã¿ã®è¡åãåæããããšãå¶éãããå¯èœæ§ããããŸãã |
解決ãã¹ãåé¡ | å¹ åºãåé¡ã®è§£æ±ºã«åœ¹ç«ã¡ãŸã | éãããã¿ã¹ã¯ã«ç¹åãã |
åæè« | ããŸããŸãªåæææ³ã䜿çšããç°åžžæ€åº - äž»ã«çµ±èšã¢ãã«ãšæ©æ¢°åŠç¿ãããã³ã«ãŒã«ãšã·ã°ããã£ã䜿çšããŸãã ãŠãŒã¶ãŒãšãšã³ãã£ãã£ã®ã¢ã¯ãã£ããã£ãäœæãããã®ã¢ã¯ãã£ããã£ãšãã®ååã®ãããã¡ã€ã«ãšæ¯èŒããããã®åææ©èœãçµã¿èŸŒãŸããŠããŸãã | çŽç²ãª UEBA ãšäŒŒãŠããŸãããåæããŠãŒã¶ãŒããã³/ãŸãã¯ãšã³ãã£ãã£ã®ã¿ã«éå®ã§ããŸãã |
åæè« | ã«ãŒã«ã ãã«å¶éãããªãé«åºŠãªåææ©èœã ããšãã°ããšã³ãã£ãã£ãåçã«ã°ã«ãŒãåããã¯ã©ã¹ã¿ãªã³ã° ã¢ã«ãŽãªãºã ã§ãã | ãçŽç²ãªãUEBA ã«äŒŒãŠããŸãããäžéšã®çµã¿èŸŒã¿è åšã¢ãã«ã®ãšã³ãã£ã㣠ã°ã«ãŒãåã¯æåã§ã®ã¿å€æŽã§ããŸãã |
åæè« | ç°åžžãªã¢ã¯ãã£ããã£ãç¹å®ããããã®ããŠãŒã¶ãŒããã³ä»ã®ãšã³ãã£ãã£ã®ã¢ã¯ãã£ããã£ãšè¡åã®çžé¢é¢ä¿ (ãã€ãžã¢ã³ ãããã¯ãŒã¯ãªã©ã䜿çš)ãããã³åã ã®ãªã¹ã¯è¡åã®éçŽã | çŽç²ãª UEBA ãšäŒŒãŠããŸãããåæããŠãŒã¶ãŒããã³/ãŸãã¯ãšã³ãã£ãã£ã®ã¿ã«éå®ã§ããŸãã |
ããŒã¿ãœãŒã¹ | çµã¿èŸŒã¿ã¡ã«ããºã ãŸãã¯æ¢åã®ããŒã¿ ã¹ã㢠(SIEM ãããŒã¿ ã¬ã€ã¯ãªã©) ãä»ããŠãããŒã¿ ãœãŒã¹ãããŠãŒã¶ãŒããã³ãšã³ãã£ãã£ã«é¢ããã€ãã³ããçŽæ¥åä¿¡ããŸãã | ããŒã¿ãååŸããã¡ã«ããºã ã¯éåžžãçŽæ¥çãªãã®ã®ã¿ã§ããããŠãŒã¶ãŒããã³/ãŸãã¯ä»ã®ãšã³ãã£ãã£ã«ã®ã¿åœ±é¿ããŸãã ãã°ç®¡çããŒã«/SIEM/ããŒã¿ã¬ã€ã¯ã¯äœ¿çšããªãã§ãã ããã |
ããŒã¿ãœãŒã¹ | ãœãªã¥ãŒã·ã§ã³ã¯ãäž»ãªããŒã¿ ãœãŒã¹ãšããŠãããã¯ãŒã¯ ãã©ãã£ãã¯ã®ã¿ã«äŸåããå¿ èŠã¯ãªãããŸãããã¬ã¡ããªãåéããããã«ç¬èªã®ãšãŒãžã§ã³ãã®ã¿ã«äŸåããã¹ãã§ããããŸããã | ãã®ãœãªã¥ãŒã·ã§ã³ã¯ããããã¯ãŒã¯ ãã©ãã£ã㯠(NTA - ãããã¯ãŒã¯ ãã©ãã£ãã¯åæãªã©) ã®ã¿ã«çŠç¹ãåœãŠãããšãããšã³ã ããã€ã¹äžã®ãšãŒãžã§ã³ãã䜿çšããããšãã§ããŸã (åŸæ¥å¡ç£èŠãŠãŒãã£ãªãã£ãªã©)ã |
ããŒã¿ãœãŒã¹ | ãŠãŒã¶ãŒ/ãšã³ãã£ã㣠ããŒã¿ãã³ã³ããã¹ãã§æºããã ãªã¢ã«ã¿ã€ã ã§ã®æ§é åã€ãã³ãã®åéãšãIT ãã£ã¬ã¯ã㪠(ããšãã°ãActive Directory (AD) ããã®ä»ã®æ©æ¢°å¯èªæ å ±ãªãœãŒã¹ (ããšãã°ãHR ããŒã¿ããŒã¹)) ããã®æ§é å/éæ§é åã®ãŸãšãŸã£ãããŒã¿ã®åéããµããŒãããŸãã | çŽç²ãª UEBA ã«äŒŒãŠããŸãããã³ã³ããã¹ã ããŒã¿ã®ç¯å²ã¯ã±ãŒã¹ããšã«ç°ãªãå ŽåããããŸãã AD ãš LDAP ã¯ãçµã¿èŸŒã¿ UEBA ãœãªã¥ãŒã·ã§ã³ã§äœ¿çšãããæãäžè¬çãªã³ã³ããã¹ã ããŒã¿ ã¹ãã¢ã§ãã |
å¯çšæ§ | ãªã¹ããããŠããæ©èœãã¹ã¿ã³ãã¢ãã³è£œåãšããŠæäŸããŸãã | çµã¿èŸŒã¿ã® UEBA æ©èœãè³Œå ¥ããã«ã¯ããããçµã¿èŸŒãŸããŠããå€éšãœãªã¥ãŒã·ã§ã³ãè³Œå ¥ããå¿ èŠããããŸãã |
åºå ž: Gartner (2019 幎 XNUMX æ) |
ãããã£ãŠãç¹å®ã®åé¡ã解決ããããã«ãçµã¿èŸŒã¿ UEBA ã¯åºæ¬ç㪠UEBA åæ (ããšãã°ãåçŽãªæåž«ãªãæ©æ¢°åŠç¿) ã䜿çšã§ããŸãããåæã«å¿ èŠãªããŒã¿ã«æ£ç¢ºã«ã¢ã¯ã»ã¹ã§ãããããå šäœãšããŠãçŽç²ãªãåæãããå¹æçã«ãªãå¯èœæ§ããããŸãã UEBA ãœãªã¥ãŒã·ã§ã³ã åæã«ããçŽç²ãªãUEBA ãã©ãããã©ãŒã ã¯ãäºæ³ã©ãããçµã¿èŸŒã¿ã® UEBA ããŒã«ãšæ¯èŒããŠãããè€éãªåæãäž»èŠãªããŠããŠãšããŠæäŸããŸãã ãããã®çµæãè¡š 2 ã«ãŸãšããŸãã
è¡š 2. ãçŽç²ãªãUEBA ãšçµã¿èŸŒã¿ UEBA ã®éãã®çµæ
ã«ããŽãª | ãçŽç²ãªãUEBA ãã©ãããã©ãŒã | UEBAãå èµãããã®ä»ã®ãœãªã¥ãŒã·ã§ã³ |
åæè« | ããŸããŸãªããžãã¹äžã®åé¡ã解決ããããã®é©çšæ§ã¯ãããè€éãªåæããã³æ©æ¢°åŠç¿ã¢ãã«ã«éç¹ã眮ãããããæ±çšç㪠UEBA æ©èœã®ã»ãããæå³ããŸãã | ããå°èŠæš¡ãªããžãã¹äžã®åé¡ã«çŠç¹ãåœãŠããšããããšã¯ãããåçŽãªããžãã¯ãåããã¢ããªã±ãŒã·ã§ã³åºæã®ã¢ãã«ã«çŠç¹ãåœãŠããé«åºŠã«ç¹æ®åãããæ©èœãæå³ããŸãã |
åæè« | ã¢ããªã±ãŒã·ã§ã³ã·ããªãªããšã«åæã¢ãã«ã®ã«ã¹ã¿ãã€ãºãå¿ èŠã§ãã | åæã¢ãã«ã¯ãUEBA ãçµã¿èŸŒãŸããããŒã«çšã«äºåæ§æãããŠããŸãã äžè¬ã«ãUEBA ãçµã¿èŸŒãŸããããŒã«ã¯ãç¹å®ã®ããžãã¹äžã®åé¡ã解決ããéã«ãããè¿ éãªçµæããããããŸãã |
ããŒã¿ãœãŒã¹ | äŒæ¥ã€ã³ãã©ã®ããããå ŽæããããŒã¿ ãœãŒã¹ã«ã¢ã¯ã»ã¹ããŸãã | ããŒã¿ ãœãŒã¹ãå°ãªããéåžžã¯ãããã®ãšãŒãžã§ã³ãã®å¯çšæ§ããŸã㯠UEBA æ©èœãåããããŒã«èªäœã«ãã£ãŠå¶éãããŸãã |
ããŒã¿ãœãŒã¹ | åãã°ã«å«ãŸããæ å ±ã¯ããŒã¿ ãœãŒã¹ã«ãã£ãŠå¶éãããå Žåããããéäžå UEBA ããŒã«ã«å¿ èŠãªããŒã¿ããã¹ãŠå«ãŸããŠããªãå ŽåããããŸãã | ãšãŒãžã§ã³ãã«ãã£ãŠåéãããUEBA ã«éä¿¡ãããçããŒã¿ã®éãšè©³çŽ°ã¯ãå ·äœçã«æ§æã§ããŸãã |
ã¢ãŒããã¯ã㣠| ããã¯ãçµç¹åãã®å®å šãª UEBA 補åã§ãã SIEM ã·ã¹ãã ãŸãã¯ããŒã¿ ã¬ã€ã¯ã®æ©èœã䜿çšãããšãçµ±åãããç°¡åã«ãªããŸãã | UEBA ãçµã¿èŸŒãŸããŠãããœãªã¥ãŒã·ã§ã³ããšã«ãåå¥ã® UEBA æ©èœã®ã»ãããå¿ èŠã§ãã çµã¿èŸŒã¿ UEBA ãœãªã¥ãŒã·ã§ã³ã§ã¯ãå€ãã®å ŽåããšãŒãžã§ã³ãã®ã€ã³ã¹ããŒã«ãšããŒã¿ã®ç®¡çãå¿ èŠã§ãã |
ÐÐœÑегÑаÑÐžÑ | ããããã®ã±ãŒã¹ã§ãUEBA ãœãªã¥ãŒã·ã§ã³ãšä»ã®ããŒã«ãæåã§çµ±åããŸãã çµç¹ã¯ãã¢ããã°ã®äžã§æé«ã®ãã®ãã¢ãããŒãã«åºã¥ããŠãã¯ãããžãŒ ã¹ã¿ãã¯ãæ§ç¯ã§ããŸãã | UEBA æ©èœã®äž»èŠãªãã³ãã«ã¯ãã¡ãŒã«ãŒã«ãã£ãŠããŒã«èªäœã«ãã§ã«çµã¿èŸŒãŸããŠããŸãã UEBA ã¢ãžã¥ãŒã«ã¯å èµãããŠããåãå€ãã§ããªããããã客æ§ãç¬èªã®ãã®ã«äº€æããããšã¯ã§ããŸããã |
åºå ž: Gartner (2019 幎 XNUMX æ) |
æ©èœãšããŠã®UEBA
UEBA ã¯ãè¿œå ã®åæããæ©æµãåããããšãã§ãããšã³ãããŒãšã³ãã®ãµã€ããŒã»ãã¥ãªã㣠ãœãªã¥ãŒã·ã§ã³ã®æ©èœã«ãªãã€ã€ãããŸãã UEBA ã¯ãããã®ãœãªã¥ãŒã·ã§ã³ã®åºç€ãšãªãããŠãŒã¶ãŒããšã³ãã£ãã£ã®è¡åãã¿ãŒã³ã«åºã¥ããé«åºŠãªåæã®åŒ·åãªã¬ã€ã€ãŒãæäŸããŸãã
çŸåšåžå Žã§ã¯ãçµã¿èŸŒã¿ã® UEBA æ©èœã¯ãæè¡ç¯å²ããšã«ã°ã«ãŒãåããã次ã®ãœãªã¥ãŒã·ã§ã³ã«å®è£ ãããŠããŸãã
- ããŒã¿ã«éç¹ââã眮ããç£æ»ãšä¿è·ã¯ãæ§é åããŒã¿ ã¹ãã¬ãŒãžããã³éæ§é åããŒã¿ ã¹ãã¬ãŒãž (å¥å DCAP) ã®ã»ãã¥ãªãã£ã®åäžã«éç¹ã眮ããŠãããã³ããŒã§ãã
Gartner ã¯ããã®ã«ããŽãªã®ãã³ããŒã«ã€ããŠããšããã次ã®ããã«ææããŠããŸãã
Varonis ãµã€ããŒã»ãã¥ãªã㣠ãã©ãããã©ãŒã ã¯ãããŸããŸãªã€ã³ãã©ã¡ãŒã·ã§ã³ ã¹ãã¢ã«ãããéæ§é åããŒã¿ã®ã¢ã¯ã»ã¹èš±å¯ãã¢ã¯ã»ã¹ãããã³äœ¿çšç¶æ³ã®å€åãç£èŠããããã®ãŠãŒã¶ãŒè¡ååæãæäŸããŸãã - CASB ã·ã¹ãã ãé©å¿åã¢ã¯ã»ã¹å¶åŸ¡ã·ã¹ãã ã䜿çšããŠãäžèŠãªããã€ã¹ããŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ ããŒãžã§ã³ã®ã¯ã©ãŠã ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ããããã¯ããããšã§ãã¯ã©ãŠã ããŒã¹ã® SaaS ã¢ããªã±ãŒã·ã§ã³ã®ããŸããŸãªè
åšã«å¯Ÿããä¿è·ãæäŸããŸãã
åžå ŽããªãŒããããã¹ãŠã® CASB ãœãªã¥ãŒã·ã§ã³ã«ã¯ UEBA æ©èœãå«ãŸããŠããŸãã
- DLP ãœãªã¥ãŒã·ã§ã³ â éèŠãªããŒã¿ã®çµç¹å€ãžã®è»¢éãŸãã¯ãã®æªçšã®æ€åºã«éç¹ã眮ããŸãã
DLP ã®é²æ©ã¯äž»ã«ã³ã³ãã³ãã®ç解ã«åºã¥ããŠããããŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ãå Žæãæéãã€ãã³ãã®é床ããã®ä»ã®å€éšèŠå ãªã©ã®ã³ã³ããã¹ãã®ç解ã«ã¯ããŸãéç¹ã眮ãããŠããŸããã DLP 補åãå¹æçã§ããããã«ã¯ãã³ã³ãã³ããšã³ã³ããã¹ãã®äž¡æ¹ãèªèããå¿ èŠããããŸãã ãã®ãããå€ãã®ã¡ãŒã«ãŒã UEBA æ©èœãèªç€Ÿã®ãœãªã¥ãŒã·ã§ã³ã«çµ±åãå§ããŠããŸãã
- åŸæ¥å¡ã®ç£èŠ éåžžãïŒå¿
èŠã«å¿ããŠïŒæ³çæç¶ãã«é©ããããŒã¿åœ¢åŒã§ãåŸæ¥å¡ã®è¡åãèšé²ããã³åçããæ©èœã§ãã
ãŠãŒã¶ãŒãç¶ç¶çã«ç£èŠãããšãæåã«ãããã£ã«ã¿ãªã³ã°ã人éã«ããåæãå¿ èŠãšãªãèšå€§ãªéã®ããŒã¿ãçæãããããšããããããŸãã ãããã£ãŠãUEBA ã¯ç£èŠã·ã¹ãã å ã§äœ¿çšããããããã®ãœãªã¥ãŒã·ã§ã³ã®ããã©ãŒãã³ã¹ãåäžãããé«ãªã¹ã¯ã®ã€ã³ã·ãã³ãã®ã¿ãæ€åºããŸãã
- ãšã³ããã€ã³ãã»ãã¥ãªã㣠â ãšã³ããã€ã³ãæ€åºããã³å¿ç (EDR) ãœãªã¥ãŒã·ã§ã³ãšãšã³ããã€ã³ãä¿è·ãã©ãããã©ãŒã (EPP) ã¯ã匷åãªèšæž¬ãšãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãã¬ã¡ããªãæäŸããŸãã
ãšã³ãããã€ã¹ããã®ãããªãŠãŒã¶ãŒé¢é£ã®ãã¬ã¡ããªãåæããŠãçµã¿èŸŒã¿ã® UEBA æ©èœãæäŸã§ããŸãã
- ãªã³ã©ã€ã³è©æ¬º â ãªã³ã©ã€ã³è©æ¬ºæ€åºãœãªã¥ãŒã·ã§ã³ã¯ããªãããŸãããã«ãŠã§ã¢ããŸãã¯å®å
šã§ãªãæ¥ç¶/ãã©ãŠã¶ ãã©ãã£ãã¯ã®ååã®æªçšã«ãã顧客ã®ã¢ã«ãŠã³ãã®äŸµå®³ã瀺ãéžè±ããã¢ã¯ãã£ããã£ãæ€åºããŸãã
ã»ãšãã©ã®äžæ£è¡çºãœãªã¥ãŒã·ã§ã³ã¯ãUEBA ã®æ¬è³ªã§ãããã©ã³ã¶ã¯ã·ã§ã³åæãšããã€ã¹æž¬å®ã䜿çšããŠãããããé«åºŠãªã·ã¹ãã 㯠ID ããŒã¿ããŒã¹å ã®é¢ä¿ãç §åããããšã§ããããè£å®ããŸãã
- IAMãšã¢ã¯ã»ã¹å¶åŸ¡ â Gartner ã¯ãã¢ã¯ã»ã¹å¶åŸ¡ã·ã¹ãã ãã³ããŒãçŽç²ãªãã³ããŒãšçµ±åããäžéšã® UEBA æ©èœãèªç€Ÿã®è£œåã«çµã¿èŸŒãé²ååŸåã«ãããšææããŠããŸãã
- IAM ããã³ ID ã¬ããã³ã¹ããã³ç®¡ç (IGA) ã·ã¹ãã UEBA ã䜿çšããŠãç°åžžæ€åºãé¡äŒŒãšã³ãã£ãã£ã®åçã°ã«ãŒãååæããã°ã€ã³åæãã¢ã¯ã»ã¹ ããªã·ãŒåæãªã©ã®è¡åããã³ã¢ã€ãã³ãã£ãã£åæã·ããªãªãã«ããŒããŸãã
- IAM ãšç¹æš©ã¢ã¯ã»ã¹ç®¡ç (PAM) â 管çã¢ã«ãŠã³ãã®äœ¿çšãç£èŠãã圹å²ã®ãããPAM ãœãªã¥ãŒã·ã§ã³ã«ã¯ã管çã¢ã«ãŠã³ããã©ã®ããã«ããªãããã€ãã©ãã§äœ¿çšããããã瀺ããã¬ã¡ããªãåãã£ãŠããŸãã ãã®ããŒã¿ã¯ã管çè ã®ç°åžžãªåäœãæªæã®ååšã«ã€ããŠãUEBA ã®çµã¿èŸŒã¿æ©èœã䜿çšããŠåæã§ããŸãã
- ã¡ãŒã«ãŒ NTA (ãããã¯ãŒã¯ãã©ãã£ãã¯åæ) â æ©æ¢°åŠç¿ãé«åºŠãªåæãã«ãŒã«ããŒã¹ã®æ€åºãçµã¿åãããŠäœ¿çšââããäŒæ¥ãããã¯ãŒã¯äžã®äžå¯©ãªã¢ã¯ãã£ããã£ãç¹å®ããŸãã
NTA ããŒã«ã¯ããœãŒã¹ ãã©ãã£ãã¯ããã㌠ã¬ã³ãŒã (NetFlow ãªã©) ãç¶ç¶çã«åæããäž»ã«ãšã³ãã£ãã£ã®åäœåæã«çŠç¹ãåœãŠãŠãéåžžã®ãããã¯ãŒã¯åäœãåæ ããã¢ãã«ãæ§ç¯ããŸãã
- SIEM â å€ãã® SIEM ãã³ããŒã¯çŸåšãé«åºŠãªããŒã¿åææ©èœã SIEM ã«ããŸãã¯å¥åã® UEBA ã¢ãžã¥ãŒã«ãšããŠçµã¿èŸŒãã§ããŸãã ãã®èšäºã§èª¬æããããã«ã2018 幎ãéããŠããã㊠2019 幎ã®ãããŸã§ã®ãšãããSIEM ãš UEBA ã®æ©èœã®éã®å¢çã¯ç¶ç¶çã«ææ§ã«ãªã£ãŠããŸããã
ãææ°ã® SIEM ã®ãã¯ãããžãŒã«é¢ããæŽå¯ã ã SIEM ã·ã¹ãã ã¯ãåæãšã®é£æºãåäžããããè€éãªã¢ããªã±ãŒã·ã§ã³ ã·ããªãªãæäŸã§ããããã«ãªããŸããã
UEBA ã¢ããªã±ãŒã·ã§ã³ ã·ããªãª
UEBA ãœãªã¥ãŒã·ã§ã³ã¯å¹ åºãåé¡ã解決ã§ããŸãã ãã ããã¬ãŒãããŒã®ã¯ã©ã€ã¢ã³ãã¯ãäž»ãªäœ¿çšäŸã«ã¯ããŠãŒã¶ãŒã®è¡åãšä»ã®ãšã³ãã£ãã£ã®éã®é »ç¹ãªçžé¢é¢ä¿ã衚瀺ããã³åæããããšã«ãã£ãŠéæããããããŸããŸãªã«ããŽãªã®è åšã®æ€åºãå«ãŸããããšã«åæããŠããŸãã
- äžæ£ãªã¢ã¯ã»ã¹ãšããŒã¿ã®ç§»åã
- ç¹æš©ãŠãŒã¶ãŒã®äžå¯©ãªè¡åãåŸæ¥å¡ã®æªæã®ãã掻åãŸãã¯äžæ£ãªæŽ»åã
- éæšæºçãªã¢ã¯ã»ã¹ãšã¯ã©ãŠã ãªãœãŒã¹ã®äœ¿çšã
- ãã
ãŸããè©æ¬ºãåŸæ¥å¡ã®ç£èŠãªã©ããµã€ããŒã»ãã¥ãªãã£ä»¥å€ã®éå žåçãªãŠãŒã¹ã±ãŒã¹ãæ°å€ãããããããã«å¯Ÿã㊠UEBA ãæ£åœåãããå¯èœæ§ããããŸãã ãã ããå€ãã®å ŽåãIT ããã³æ å ±ã»ãã¥ãªãã£ä»¥å€ã®ããŒã¿ ãœãŒã¹ããŸãã¯ãã®åéãæ·±ãç解ããç¹å®ã®åæã¢ãã«ãå¿ èŠã«ãªããŸãã UEBA ã¡ãŒã«ãŒãšãã®é¡§å®¢ã®äž¡æ¹ãåæãã XNUMX ã€ã®äž»èŠãªã·ããªãªãšã¢ããªã±ãŒã·ã§ã³ã以äžã«èª¬æããŸãã
ãæªæã®ããã€ã³ãµã€ããŒã
ãã®ã·ããªãªãã«ããŒãã UEBA ãœãªã¥ãŒã·ã§ã³ ãããã€ããŒã¯ãåŸæ¥å¡ãšä¿¡é Œã§ããè«è² æ¥è ã®ç°åžžãªããæªããããŸãã¯æªæã®ããè¡çºã®ã¿ãç£èŠããŸãã ãã®å°éåéã®ãã³ããŒã¯ããµãŒãã¹ ã¢ã«ãŠã³ãããã®ä»ã®äººé以å€ã®ãšã³ãã£ãã£ã®åäœãç£èŠãŸãã¯åæããŸããã ãã®ããšãäž»ãªçç±ã§ãããã«ãŒãæ¢åã®ã¢ã«ãŠã³ããä¹ã£åãé«åºŠãªè åšã®æ€åºã«éç¹ã眮ããŠããŸããã 代ããã«ãæ害ãªæŽ»åã«é¢äžããŠããåŸæ¥å¡ãç¹å®ããããšãç®çãšããŠããŸãã
åºæ¬çã«ããæªæã®ããã€ã³ãµã€ããŒãã®æŠå¿µã¯ãéçšäž»ã«æ害ãäžããæ¹æ³ã暡玢ãããæªæã®ããä¿¡é Œã§ãããŠãŒã¶ãŒããçããŠããŸãã æªæã®ããæå³ã¯æž¬å®ãé£ããããããã®ã«ããŽãªã®åªãããã³ããŒã¯ãç£æ»ãã°ã§ã¯ç°¡åã«å ¥æã§ããªãç¶æ³ã«å¿ããåäœããŒã¿ãåæããŸãã
ãã®åéã®ãœãªã¥ãŒã·ã§ã³ ãããã€ããŒã¯ãé»åã¡ãŒã«ã®ã³ã³ãã³ããçç£æ§ã¬ããŒãããœãŒã·ã£ã« ã¡ãã£ã¢æ å ±ãªã©ã®éæ§é åããŒã¿ãæé©ã«è¿œå ããã³åæããŠãè¡åã®ã³ã³ããã¹ããæäŸããŸãã
䟵害ãããå éšé¢ä¿è ããã³äŸµå ¥è ã®è åš
課é¡ã¯ãæ»æè
ãçµç¹ã«ã¢ã¯ã»ã¹ã㊠IT ã€ã³ãã©ã¹ãã©ã¯ãã£å
ã移åãå§ãããšãã«ããæªããåäœãè¿
éã«æ€åºããŠåæããããšã§ãã
ã¢ãµãŒãã£ãè
åš (APT) ã¯ãæªç¥ã®è
åšããŸã ååã«ç解ãããŠããªãè
åšãšåæ§ãæ€åºãéåžžã«é£ãããæ£èŠã®ãŠãŒã¶ãŒ ã¢ã¯ãã£ããã£ããµãŒãã¹ ã¢ã«ãŠã³ãã®èåŸã«é ããŠããããšããããããŸãã ãã®ãããªè
åšã«ã¯éåžžãè€éãªéçšã¢ãã«ããããŸã (ããšãã°ãèšäºã
ãã ãããããã®äŸµå ¥çãªè åšã®å€ãã¯éæšæºçãªåäœãåŒãèµ·ãããå€ãã®å Žåãç¡é²åãªãŠãŒã¶ãŒããšã³ãã£ã㣠(å¥åã䟵害ãããå éšé¢ä¿è ) ãé¢äžããŸãã UEBA æè¡ã¯ããã®ãããªè åšã®æ€åºãä¿¡å·å¯Ÿéé³æ¯ã®æ¹åãéç¥éã®çµ±åãšåæžãæ®ãã®ã¢ã©ãŒãã®åªå é äœä»ããå¹æçãªã€ã³ã·ãã³ã察å¿ãšèª¿æ»ã®ä¿é²ãªã©ãããã€ãã®èå³æ·±ãæ©äŒãæäŸããŸãã
ãã®åé¡é åã察象ãšãã UEBA ãã³ããŒã¯ãå€ãã®å Žåãçµç¹ã® SIEM ã·ã¹ãã ãšåæ¹åã®çµ±åãè¡ã£ãŠããŸãã
ããŒã¿ã®åŒãåºã
ãã®å Žåã®ã¿ã¹ã¯ã¯ãããŒã¿ãçµç¹å€ã«è»¢éãããŠãããšããäºå®ãæ€åºããããšã§ãã
ãã®èª²é¡ã«çŠç¹ãåœãŠããã³ããŒã¯éåžžãç°åžžæ€åºãšé«åºŠãªåæãåãã DLP ãŸã㯠DAG æ©èœã掻çšããããã«ãã£ãŠ S/N æ¯ãæ¹åããéç¥éãçµ±åããæ®ãã®ããªã¬ãŒã«åªå
é äœãä»ããŸãã è¿œå ã®ã³ã³ããã¹ããšããŠããã³ããŒã¯éåžžããããã¯ãŒã¯ ãã©ãã£ã㯠(Web ãããã·ãªã©) ãšãšã³ããã€ã³ã ããŒã¿ã«å€§ããäŸåããŸãããããã®ããŒã¿ ãœãŒã¹ã®åæã¯ããŒã¿æŒæŽ©ã®èª¿æ»ã«åœ¹ç«ã€ããã§ãã
ããŒã¿æŒæŽ©ã®æ€åºã¯ãçµç¹ãè ããå éšé¢ä¿è ãå€éšã®ããã«ãŒãææããããã«äœ¿çšãããŸãã
ç¹æš©ã¢ã¯ã»ã¹ã®èå¥ãšç®¡ç
ãã®å°éåéã«ãããç¬ç«ç³» UEBA ãœãªã¥ãŒã·ã§ã³ã®ã¡ãŒã«ãŒã¯ãéå°ãªç¹æš©ãç°åžžãªã¢ã¯ã»ã¹ãç¹å®ããããã«ããã§ã«åœ¢æãããæš©å©ã·ã¹ãã ãèæ¯ã«ãŠãŒã¶ãŒã®è¡åã芳å¯ããã³åæããŸãã ããã¯ãç¹æš©ã¢ã«ãŠã³ãããµãŒãã¹ ã¢ã«ãŠã³ããå«ãããã¹ãŠã®çš®é¡ã®ãŠãŒã¶ãŒãšã¢ã«ãŠã³ãã«é©çšãããŸãã çµç¹ã¯ãäŒæ¢ã¢ã«ãŠã³ããå¿ èŠä»¥äžã«é«ããŠãŒã¶ãŒæš©éãåé€ããããã« UEBA ã䜿çšããŸãã
ã€ã³ã·ãã³ãã®åªå é äœä»ã
ãã®ã¿ã¹ã¯ã®ç®æšã¯ããã¯ãããžãŒ ã¹ã¿ãã¯å ã®ãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠçæãããéç¥ã«åªå é äœãä»ããŠãã©ã®ã€ã³ã·ãã³ããŸãã¯æœåšçãªã€ã³ã·ãã³ãã«æåã«å¯ŸåŠããå¿ èŠãããããç解ããããšã§ãã UEBA ã®æ¹æ³è«ãšããŒã«ã¯ãç¹å®ã®çµç¹ã«ãšã£ãŠç¹ã«ç°åžžãªããŸãã¯ç¹ã«å±éºãªã€ã³ã·ãã³ããç¹å®ããã®ã«åœ¹ç«ã¡ãŸãã ãã®å ŽåãUEBA ã¡ã«ããºã ã¯ãåºæ¬ã¬ãã«ã®ã¢ã¯ãã£ããã£ããã³è åšã¢ãã«ã䜿çšããã ãã§ãªããäŒç€Ÿã®çµç¹æ§é ã«é¢ããæ å ± (ããšãã°ãéèŠãªãªãœãŒã¹ãåŸæ¥å¡ã®åœ¹å²ãšã¢ã¯ã»ã¹ ã¬ãã«) ãããŒã¿ã«é£œåãããŸãã
UEBA ãœãªã¥ãŒã·ã§ã³ã®å®è£ ã®åé¡
UEBA ãœãªã¥ãŒã·ã§ã³ã®åžå Žã®æ©ã¿ã¯ãäŸ¡æ Œãé«ããå®è£ ãã¡ã³ããã³ã¹ã䜿çšãè€éã§ããããšã§ãã äŒæ¥ã¯ããŸããŸãªç€Ÿå ããŒã¿ã«ã®æ°ã«èŠåŽããŠããäžæ¹ã§ãå¥ã®ã³ã³ãœãŒã«ãå ¥æããŠããŸãã æ°ããããŒã«ãžã®æéãšãªãœãŒã¹ã®æè³ã®èŠæš¡ã¯ãåœé¢ã®ã¿ã¹ã¯ãšããããã解決ããããã«å¿ èŠãªåæã®çš®é¡ã«ãã£ãŠç°ãªããã»ãšãã©ã®å Žåãå€é¡ã®æè³ãå¿ èŠã«ãªããŸãã
å€ãã®ã¡ãŒã«ãŒã®äž»åŒµã«åããŠãUEBA ã¯ãèšå®ãããåŸã¯å¿ãããããŒã«ã§ã¯ãªããäœæ¥ãç¶ããŠå®è¡ã§ããŸãã
ããšãã°ãGartner ã®ã¯ã©ã€ã¢ã³ãã¯ãUEBA ã€ãã·ã¢ããããŒãããç«ã¡äžããŠããã®ãœãªã¥ãŒã·ã§ã³ãå®è£
ãããåé¡ã®è§£æ±ºã®æåã®çµæãåŸããŸã§ã« 3 ïœ 6 ãæããããšææããŠããŸãã çµç¹å
ã®å
éšé¢ä¿è
ã«ããè
åšã®ç¹å®ãªã©ãããè€éãªã¿ã¹ã¯ã®å Žåãæé㯠18 ãæã«å¢å ããŸãã
UEBA ã®å®è£ ã®é£ãããšããŒã«ã®å°æ¥ã®æå¹æ§ã«åœ±é¿ãäžããèŠå :
- çµç¹ã¢ãŒããã¯ãã£ããããã¯ãŒã¯ ããããžãããŒã¿ç®¡çããªã·ãŒã®è€éã
- é©åãªè©³çŽ°ã¬ãã«ã§ã®é©åãªããŒã¿ã®å¯çšæ§
- ãã³ããŒã®åæã¢ã«ãŽãªãºã ã®è€éããããšãã°ãçµ±èšã¢ãã«ãæ©æ¢°åŠç¿ã®äœ¿çšãšåçŽãªãã¿ãŒã³ãã«ãŒã«ã®äœ¿çšã
- å«ãŸããäºåæ§æãããåæã®éãã€ãŸããåã¿ã¹ã¯ã§ã©ã®ãããªããŒã¿ãåéããå¿ èŠãããããåæãå®è¡ããããã«ã©ã®å€æ°ãšå±æ§ãæãéèŠã§ãããã«ã€ããŠã®ã¡ãŒã«ãŒã®ç解ã§ãã
- ã¡ãŒã«ãŒã«ãšã£ãŠãå¿
èŠãªããŒã¿ãšèªåçã«çµ±åããããšãããã«ç°¡åã§ãããã
ããšãã°ã次ã®ããã«
- UEBA ãœãªã¥ãŒã·ã§ã³ãããŒã¿ã®äž»ãªãœãŒã¹ãšã㊠SIEM ã·ã¹ãã ã䜿çšããŠããå ŽåãSIEM ã¯å¿ èŠãªããŒã¿ ãœãŒã¹ããæ å ±ãåéããŸãã?
- å¿ èŠãªã€ãã³ã ãã°ãšçµç¹ã³ã³ããã¹ã ããŒã¿ã UEBA ãœãªã¥ãŒã·ã§ã³ã«ã«ãŒãã£ã³ã°ã§ããŸãã?
- SIEM ã·ã¹ãã ã UEBA ãœãªã¥ãŒã·ã§ã³ã«å¿ èŠãªããŒã¿ ãœãŒã¹ããŸã åéããã³å¶åŸ¡ããŠããªãå Žåãã©ãããã°ããŒã¿ ãœãŒã¹ãããã«è»¢éã§ããã§ãããã?
- çµç¹ã«ãšã£ãŠã¢ããªã±ãŒã·ã§ã³ ã·ããªãªãã©ã®çšåºŠéèŠããããã«å¿ èŠãªããŒã¿ ãœãŒã¹ã®æ°ã¯ã©ãããããããã®ã¿ã¹ã¯ã¯ã¡ãŒã«ãŒã®å°éåéãšã©ã®çšåºŠéè€ããŠãããã
- ã©ã®çšåºŠã®çµç¹ã®æç床ãšé¢äžãå¿ èŠã â ããšãã°ãã«ãŒã«ãã¢ãã«ã®äœæãéçºãæ¹è¯ã è©äŸ¡ã®ããã«å€æ°ã«éã¿ãå²ãåœãŠãã ãŸãã¯ãªã¹ã¯è©äŸ¡ã®ãããå€ã調æŽããŸãã
- çµç¹ã®çŸåšã®èŠæš¡ãšå°æ¥ã®èŠä»¶ãšæ¯èŒããŠããã³ããŒã®ãœãªã¥ãŒã·ã§ã³ãšãã®ã¢ãŒããã¯ãã£ã¯ã©ã®çšåºŠã¹ã±ãŒã©ããªãã£ããããã
- åºæ¬çãªã¢ãã«ããããã¡ã€ã«ãã㌠ã°ã«ãŒããæ§ç¯ããŸãã å€ãã®å Žåã補é æ¥è ã¯ãæ£åžžãªãæŠå¿µãå®çŸ©ã§ããããã«ãªããŸã§ã«ãåæã®å®æœã«å°ãªããšã 30 æ¥ (å Žåã«ãã£ãŠã¯æ倧 90 æ¥) ãèŠããŸãã å±¥æŽããŒã¿ãäžåºŠããŒããããšãã¢ãã«ã®ãã¬ãŒãã³ã°ãé«éåã§ããŸãã èå³æ·±ãã±ãŒã¹ã®äžã«ã¯ãéåžžã«å°éã®åæããŒã¿ã§æ©æ¢°åŠç¿ã䜿çšããããããã«ãŒã«ã䜿çšããããšã§ããéãç¹å®ã§ãããã®ããããŸãã
- åçãªã°ã«ãŒãåãšã¢ã«ãŠã³ã ãããã¡ã€ãªã³ã° (ãµãŒãã¹/å人) ãæ§ç¯ããããã«å¿ èŠãªåŽåã®ã¬ãã«ã¯ããœãªã¥ãŒã·ã§ã³ã«ãã£ãŠå€§ããç°ãªãå ŽåããããŸãã
åºæïŒ habr.com