⇃ᮏ㧗➼ᑓ㛛Ꮫᰯඵ௦࢟ࣕࣥࣃࢫ࠾ࡅࡿ
ධ᳨▱ࢩࢫࢸ࣒ࡢᵓ⠏㐠⏝
ᑠᓥ ಇ㍜
1,*⸨ᮏ ὒ୍
1ᒾᮏ ⯙
2Construction and Operation of Intrusion Detection System
at National Institute of Technology, Kumamoto College, Yatsushiro Campus
Shunsuke Oshima1,*, Yoichi Fujimoto1, Mai Iwamoto2
In order to detect cyber security threat at NIT Kumamoto, Yatsushiro Campus, we construct and operate an Intrusion Detection System (IDS) in our computer network since December, 2017. IDS has based on a predetermined signature and it can detect intrusions, attacks and other signs by monitoring packet-flow through the computer network. In this paper, we report introduction, construction and operation of this system.
࣮࣮࢟࣡ࢻ㸸ධ᳨▱ࠊࢿࢵࢺ࣮࣡ࢡࣥࣇࣛࠊࢧࣂ࣮ࢭ࢟ࣗࣜࢸࠊSnortࠊSecurity Onion
.H\ZRUGV㸸Intrusion Detection, Network Infrastructure, Cyber Security, Snort, Security Onion
㸯㸬ࡲ࠼ࡀࡁ
⇃ᮏ㧗➼ᑓ㛛Ꮫᰯඵ௦࢟ࣕࣥࣃࢫ࡛ࡣࠊᏛෆࢿࢵࢺ࣮࣡ ࢡ࠾ࡅࡿࢧࣂ࣮ࢭ࢟ࣗࣜࢸࡢ⬣ጾࢆ᳨ฟࡍࡿࡓࡵࠊ 2017 ᖺ ᗘ ࡼ ࡾ ධ ᳨ ▱ ࢩ ࢫ ࢸ ࣒ 㸦 Intrusion Detection Systemࠊ௨ᚋ IDS ␎㸧ࡢ㸯✀࡛࠶ࡿ Snort(1)ࢆᑟධࡋ࡚࠸ ࡿࠋࡲࡓࠊ2018 ᖺᗘࡼࡾ Snort ࢆᇶᖿࡋ࡚ࠊࢭ࢟ࣗࣜࢸ ࣋ࣥࢺࡢྍどࡸࣟࢢࡢ㞟᳨࣭⣴ᶵ⬟࡞ከࡃࡢࢿ ࢵࢺ࣮࣡ࢡࢭ࢟ࣗࣜࢸ㛵ಀࢶ࣮ࣝࢆ㞟⣙ࡋࡓLinux ࢹ ࢫࢺࣜࣅ࣮ࣗࢩ࡛ࣙࣥ࠶ࡿ Security Onion(2)ࢆᑟධࡋᐇ⦼ ࢆᣲࡆ࡚࠸ࡿࠋᮏ✏࡛ࡣࠊ⇃ᮏ㧗ᑓෆࡢࢿࢵࢺ࣮࣡ࢡ࠾ ࡅࡿࡇࢀࡽධ᳨▱ࢩࢫࢸ࣒ࡢලయⓗ࡞ᑟධᵓ⠏ࡘ࠸ ࡚⤂ࡍࡿࡶࠊᐇ㝿IDS ࢆ㐠⏝ࡋࡓࡇ࡛ᚓࡽࢀ ࡓ▱ぢࡘ࠸࡚ࡶేࡏ࡚グ㍕ࡋ࡚࠾ࡃࠋ
㸰㸬,'6
,'6 ࡢศ㢮
IDS ࡣࠊࢿࢵࢺ࣮࣡ࢡࢆὶࢀࡿࣃࢣࢵࢺࡸ࣍ࢫࢺࡢࣟࢢ ࡞ࢆ┘どࡋࠊ࠶ࡽࡌࡵỴࡵࡽࢀࡓ࠶ࡿࣃࢱ࣮࣐ࣥࢵ ࢳࡍࡿ≉ᚩࢆ᳨ฟࡍࡿࡇ࡛ṇධࢆ᳨▱ࡍࡿࢩࢫࢸ࣒ ࡛࠶ࡿࠋ᭷ྡ࡞IDS ࡋ࡚ࡣ Snort ࡸ Suricata(3)ࡀᣲࡆࡽࢀ ࡿࠋ IDS ࡣࠊ᳨▱ࡍࡿሙᡤࡼࡗ࡚ࡁࡃ 2 ࡘศ㢮ࡍࡿࡇ ࡀ࡛ࡁࡿࠋ୍ࡘࡣࠊ࣍ࢫࢺࢥࣥࣆ࣮ࣗࢱ࡞ᖖ㥔ࡋࠊࣜ ࢯ࣮ࢫࡸࣟࢢࢆ┘どࡍࡿ࣍ࢫࢺ࣮࣋ࢫᆺࠊࡶ࠺୍ࡘࡣࠊࢿ ࢵࢺ࣮࣡ࢡࢆὶࢀࡿࣃࢣࢵࢺࢆ┘どࡋࠊ␗ᖖࢆ᳨▱ࡍࡿࢿ ࢵࢺ࣮࣡ࢡᆺ࡛࠶ࡿࠋ ᅇᑟධࡍࡿ IDS ࡣࢿࢵࢺ࣮࣡ࢡᆺࢆ㑅ᢥࡍࡿࠋࢿࢵ ࢺ࣮࣡ࢡᆺࡍࡿ⌮⏤ࡣࠊ1) OS ࢱࣉࡀ Windows, Linux, MacOS, Android ࡢሙྜࡣ࣐࢙ࣝ࢘ᑐ⟇ᑓ⏝ࡢࢯࣇࢺ࢙࢘ ࡀᏑᅾࡍࡿࡀࠊࣉࣜࣥࢱࠊࢫ࢟ࣕࢼࠊ࣐ࢥࣥࡸྛ✀IoT ᶵჾ࡛ࡣᑓ⏝ࡢ࣐࢙ࣝ࢘ᑐ⟇ࢯࣇࢺ࢙࢘ࡀ࡞ࡃࠊࡇࢀ ࡽᶵჾࡢᑐ⟇ࡀᛴົ࡛࠶ࡿࡇࠊ2) BYOD (Bring Your Own Device) ࡼࡿࢹࣂࢫࡢᣢࡕ㎸ࡳࡸಶேᡤ᭷ࡢ USB ࣓ࣔࣜࡢ᥋⥆ࡼࡾࠊ࣐࢙ࣝ࢘ᑐ⟇ࡀ༑ศ࡛ࡣ࡞࠸ᶵჾ ࡽṇ࡞ࢥ࣮ࢻࡀධࡋ࡚ࡃࡿྍ⬟ᛶࡀ࠶ࡿࡇࠊࡀᣲ ࡆࡽࢀࡿࠋ ࢿࢵࢺ࣮࣡ࢡᆺIDS ࡛࠶ࢀࡤࠊOS ࡸࢹࣂࢫ౫Ꮡࡏࡎࠊ ࢹࣂࢫࡀṇࢡࢭࢫࢆཷࡅࡓࡾࠊࢹࣂࢫࡽࡢࢿ ࢵࢺ࣮࣡ࢡᶵჾᑐࡍࡿ␗ᖖ࡞ືࡁࡀ࠶ࡗࡓሙྜࠊ᪩ᮇ ᳨▱࡛ࡁࡿྍ⬟ᛶࡀ㧗࠸ࠋ 6QRUW ࡢᴫせ Snort ࡣ࣮࢜ࣉࣥࢯ࣮ࢫࡢࢿࢵࢺ࣮࣡ࢡᆺ IDS ࡛࠶ࡿࠋ 1998 ᖺ㛤Ⓨࡉࢀ Sourcefire ♫ࡽ࣮࢜ࣉࣥࢯ࣮ࢫࡋ࡚ 㓄ᕸࡉࢀ࡚࠸ࡓࡀࠊ2013 ᖺ Cisco Systems ♫ࡀ㈙ࠊࡑ ࡢᚋࡶ࣮࢜ࣉࣥࢯ࣮ࢫࡋ࡚Snort 3 ࡀ㓄ᕸࡉࢀ࡚࠸ࡿࠋ 1 ᣐⅬࣉࣟࢪ࢙ࢡࢺ⣔㸦ሗࢭ࢟ࣗࣜࢸࢭࣥࢱ࣮㸧 ࠛ866-8501 ⇃ᮏ┴ඵ௦ᕷᖹᒣ᪂⏫ 2627 Center for Information Security,2627 Hirayama-Shinmachi, Yatsushiro-shi, Kumamoto, Japan 866-8501
2 ᢏ⾡࣭ᩍ⫱ᨭࢭࣥࢱ࣮
ࠛ866-8501 ⇃ᮏ┴ඵ௦ᕷᖹᒣ᪂⏫ 2627 Center for Technical and Educational Support,
2627 Hirayama-Shinmachi, Yatsushiro-shi, Kumamoto, Japan 866-8501
* Corresponding author:
E-mail address: oshima kumamoto-nct.ac.jp (S. Oshima).
ඵ௦࢟ࣕࣥࣃࢫ࠾ࡅࡿධ᳨▱ࢩࢫࢸ࣒ࡢᵓ⠏㸦ᑠᓥಇ㍜㸧 Snort ࡣࣃࢣࢵࢺࢆᖖ┘どࡋࠊSnort ࣮ࣝࣝࡤࢀࡿࠊ ࠶ࡽࡌࡵᐃ⩏ࡋࡓࣃࢱ࣮࣐ࣥࢵࢳࡍࡿ㐪ࣃࢣࢵࢺࢆ ᳨ฟࡋࡓሙྜࠊ㆙࿌࡞ࡢࢡࢩࣙࣥࢆᐇ⾜ࡍࡿࠋᅗ 1 Snort ࣮ࣝࣝࡢ⡆༢࡞ࢆ♧ࡍࠋࡇࡢ࣮ࣝࣝࡣ࣮ࣘࢨࡀ ಶูグ㏙ࡋࠊ⤌⧊⊂⮬ࡢ࣮ࣝࣝࢭࢵࢺࢆసᡂࡍࡿࡇࡀ ࡛ࡁࡿࡀࠊ࣮ࣝࣝࢭࢵࢺࡀධ᳨▱ࡢᛶ⬟┤⤖ࡍࡿࡓࡵࠊ ㏻ᖖࡣ↓ᩱࡢCommunity ࣮ࣝࣝࢭࢵࢺࢆ⏝࠸ࡿ Personal ࡸBusiness ࠸ࡗࡓ Cisco Systems ♫ࡀᥦ౪ࡍࡿ᭷ᩱࡢࣉࣛ ࣥࢆ㑅ᢥࡋࠊ⤌⧊ࡈࡢ࢝ࢫࢱ࣐ࢬࢆຍ࠼ࡿࠋ
Snort ࣮ࣝࣝࢆ᭱᪂ಖࡘࡓࡵࡢ⤌ࡳࡋ࡚ࠊPulled Pork ࡤࢀࡿࢵࣉࢹ࣮ࢱࠊ࠾ࡼࡧ Snort ࣮ࣝࣝࢆࢲ࢘ ࣮ࣥࣟࢻࡍࡿ㝿ࡢㄆドࢥ࣮ࢻ࡛࠶ࡿ Oinkcode ࡀᚲせ࡞ ࡿࠋ࠸ࡎࢀࡶᑓ⏝ࢧࢺࡽྲྀᚓࡍࡿࡇࡀ࡛ࡁࡿࠋࢧ ࢺࡽྲྀᚓࡋࡓOinkcode ࡣ Pulled Pork ࡢタᐃࣇࣝ ᇙࡵ㎸ࡴࠊᚋ㏙ࡍࡿSecurity Onion ࡢࣥࢫࢺ࣮ࣝ ᣦᐃࡍࡿࠋ
6HFXULW\2QLRQ ࡢᴫせ
Security Onion ࡣ Ubuntu Linux ࢆᇶᮏ OS ࡋࠊࡑࡢୖ ධ᳨▱ࡸࣃࢣࢵࢺゎᯒࠊࣟࢢࡢ✚࣭ྍど࡞ከࡃࡢ ࢭ࢟ࣗࣜࢸࢶ࣮ࣝࢆ୍ࡘࡢࣃࢵࢣ࣮ࢪࡋࡓ Linux ࢹ ࢫࢺࣜࣅ࣮ࣗࢩ࡛ࣙࣥ࠶ࡿࠋ᭱᪂ࣂ࣮ࢪࣙࣥࡣUbuntu 16.04 LTS ࢆ࣮࣋ࢫࡍࡿ Security Onion 16.04.6.1 (2019/8/1 ⌧ᅾ) ࡛࠶ࡾࠊᮏᐙࡢUbuntu ྠᵝࠊ2021 ᖺ 4 ᭶ࡲ࡛ࢧ࣏࣮ࢺࡉࢀ ࡿࠋOS ࡢ ISO ࣓࣮ࢪࡀ㓄ᕸࡉࢀ࡚࠾ࡾ࣓ࢽ࣮ࣗᚑࡗ࡚ ࣥࢫࢺ࣮ࣝࡍࡿࡇࡀ࡛ࡁࡿࠊLinux ࢆࣥࢫࢺ࣮ࣝ ࡋࡓᚋࠊSecurity Onion ࡢࣃࢵࢣ࣮ࢪࢆᒎ㛤ࡋ࡚ᵓ⠏ࡍࡿࡇ ࡶ࡛ࡁࡿࠋࡓࡔࡋࠊࣃࢵࢣ࣮ࢪᒎ㛤࡛ṇᘧࢧ࣏࣮ࢺࡉ ࢀࡿOS ࡣ Ubuntu16.04 ࡢࡳ࡛࠶ࡿࠋ
Security Onion ࡣࠊࣥࢫࢺ࣮ࣝ Snort ࡲࡓࡣ Suricata ࡢࡕࡽ୍᪉ࢆ IDS ࡋ࡚㑅ᢥࡍࡿࡇࡀ࡛ࡁࡿࠋIDS ௨እ௨ୗࡢࡼ࠺࡞ࢶ࣮ࣝࡀᶆ‽࡛ࣥࢫࢺ࣮ࣝࡉࢀࡿࠋ Erasticsearch(4) ᩥ᳨⣴࢚ࣥࢪࣥ Logstash ࣟࢢ࣋ࣥࢺࡢ┘どಖ⟶ Kibana ࣈࣛ࢘ࢨ࣮࣋ࢫࡢࣟࢢྍどࢶ࣮ࣝ Sguil/ Squert(5) ࢹ࣮ࢱศᯒࢶ࣮ࣝ Bro(6) ࡿ⯙࠸ᣦྥࣇ࢛ࣞࣥࢪࢵࢡࢶ࣮ࣝ Wireshark(7) ࣃࢣࢵࢺᣦྥࣇ࢛ࣞࣥࢪࢵࢡࢶ࣮ࣝ netsniff-ng(8) ௵ពࣃࢣࢵࢺ⏕ᡂࢶ࣮ࣝ ࡇࢀࡽࡢࢶ࣮ࣝࡣ༢⊂࡛㉳ືࡋ࡚⏝ࡍࡿሙྜࡶ࠶ࡿ ࡀࠊSguil ࡸ Squert ࡞ࡢࢹ࣮ࢱศᯒࢶ࣮ࣝࢆධࡾཱྀࡋ࡚ࠊ ┦㐃ᦠࡋ⿵ࡍࡿࡇ࡛ᵝࠎ࡞ࢧࣂ࣮ࢭ࢟ࣗࣜࢸ ࡢ⬣ጾࢆࢩ࣮࣒ࣞࢫゎᯒ࡛ࡁࡿࡼ࠺タィࡉࢀ࡚࠸ࡿࠋ
㸱㸬6QRUW ࡢᑟධᵓ⠏
6QRUW ᑟධࡢ᳨ウ㡯 ⇃ᮏ㧗ᑓඵ௦࢟ࣕࣥࣃࢫ࡛ࡣࠊ2017 ᖺᗘᏛෆእࡢ㏻ಙ ࡢ␗ᖖࢆ᳨▱ࡍࡿ┠ⓗ࡛ࠊProxy ࢧ࣮ࣂࢆ㏻㐣ࡍࡿࣃࢣࢵࢺ ࡢ┘どࢆࡍࡿSnort ࢆᑟධࡋࡓࠋᑟධ㝿ࡋ࡚ࡣࠊSnort ࡢ Business ࣉࣛࣥࡢ㈝⏝ࢆ 2017 ᖺᗘࡢண⟬࡛☜ಖࡋ࡚࠸ࡿࠋ Snort ࡣࢿࢵࢺ࣮࣡ࢡᆺ IDS ࡛࠶ࡾࠊࢭࣥࢧࣀ࣮ࢻࢆ」ᩘಶ ᡤタ⨨ࡍࡿࡇࡶ࡛ࡁࡿࡀࠊ┘どᑐ㇟ࡢᩘࡀከ࠸ࣛࣥ ࢽࣥࢢࢥࢫࢺࡶ㧗㢠࡞ࡿࡢ࡛ࠊᅇࡣ⇃ᮏ㧗ᑓඵ௦࢟ࣕ ࣥࣃࢫࡢProxy ࢧ࣮ࣂ 1 ྎࡢࡳタ⨨ࡋࡓࠋ ḟᚲせ࡞ࡿࡢࡣSnort ࢆ✌ാࡍࡿࢧ࣮ࣂ࡛࠶ࡿࠋඛࡢ Proxy ࢧ࣮ࣂࡣ HTTP Proxy ௨እࠊᏛෆ㸦LAN㸧Ꮫእ 㸦WAN㸧ࢆ᥋⥆ࡍࡿࢤ࣮ࢺ࢙࢘ࡋ࡚ືసࡋ࡚࠾ࡾࠊᏛ ෆእࡢࣃࢣࢵࢺࡀ㏻㐣ࡍࡿࠋ2017 ᖺᗘࡣࢧ࣮ࣂ㈝⏝ࡀ ฟ࡛ࡁ࡞ࡗࡓࡓࡵࠊSnort ࢆูࢧ࣮ࣂ࡛ࡣ࡞ࡃ Proxy ࢧ࣮ ࣂୖᦚ㍕ࡍࡿࡇࡋࡓࠋయࡢᵓᡂࢆᅗ 2 ♧ࡍࠋࡇ ࡢᅗࡽࡶࢃࡿࡼ࠺ࠊSnort ഃࡢタᐃࡣ┘どᑐ㇟ࡢࢿࢵ ࢺ࣮࣡ࢡࣥࢱࣇ࢙࣮ࢫࢆᣦᐃࡍࡿ᪉ᘧ࡛࠶ࡾࠊProxy ࢧ࣮ ࣂෆ࡛ᵓ⠏ࡍࡿࡇ࡛Proxy ࡸ Default Gateway ࡢタᐃኚ᭦ ࡣᚲせ࡞࠸ࠋDefault Gateway ࡢタᐃኚ᭦ࡀᚲせ࡞࠸࠸࠺ ࡇࡣࠊࡓ࠼ࡤSnort ࡢ⏝⋡ࡀୖ᪼ࡋࠊࢧ࣮ࣂࡀ㧗㈇Ⲵ ࡞ࡗࡓࡇ࡛≀⌮ⓗ࡞ࣃࢣࢵࢺ㐜ᘏࡸࢻࣟࢵࣉࡀⓎ⏕ࡋ ࡓሙྜ࡛ࡶࠊSnort ࣉࣟࢭࢫࢆ⥭ᛴṆࡍࢀࡤࡍࡄඖᡠࡿ ࠸࠺ࡁ࡞࣓ࣜࢵࢺࡀ࠶ࡿࠋ ࢧ࣮ࣂࢫ࣌ࢵࢡࡢỴᐃProxy ࢧ࣮ࣂࡣࠊIntel Xeon 4Core 3.0GHz ࡢ Linux ࢆ࣍ࢫ ࢺOS ࡍࡿࠊ2CPU 12000BogoMipsࠊ Mem4GB ࡢ KVM ௬ ࣐ ࢩ ࣥ ࡋ ࡚ ᵓ ⠏ ࡋ ࡚ ࠸ ࡿ ࠋ ᪥ ୰ ࡢ ㏻ ಙ 㔞 ࡣ ࠾ ࡼ ࡑ 100Gbps ࡛࠶ࡾࠊProxy ࡢࡳࡢ≧ែ࡛ CPU ㈇Ⲵࡣᩘࣃ࣮ࢭࣥ ࢺ࡛࠶ࡿࠋࡇࡢProxy ࢧ࣮ࣂෆ Snort ࢆᑟධࡍࡿ CPU ㈇Ⲵࡀ㧗ࡃ࡞ࡿࡇࡀணࡉࢀࡿࡀࠊProxy ࢧ࣮ࣂࡣ௬࣐ ࢩ࡛ࣥ࠶ࡾࠊ㧗㈇Ⲵࡢ㝿ࡣ௬࣐ࢩࣥࡢࢫ࣌ࢵࢡࢆୖࡆ ࡿࡇࢆ᳨ウࡍࢀࡤࡼ࠸ࠋ ⤖ᯝࠊSnort ࢆ✌ാࡋࡓ㝿ࡢ CPU ㈇Ⲵࡣ 10㹼30%⛬ᗘ࡞ ࡾࠊእ㒊ࡢ᥋⥆ᛶᙳ㡪ࢆཬࡰࡍࢺࣛࣈࣝࡣ☜ㄆ࡛ࡁ࡞ ࡗࡓࠋࡑࡢࡓࡵࠊᅇࡣ௬࣐ࢩࣥࡢࢫ࣌ࢵࢡࢆࡑࡢࡲ ࡲኚ᭦ࡍࡿࡇ࡞ࡃᮏ✌ാ⛣⾜ࡍࡿࡇࡀ࡛ࡁࡓࠋ FireWall ϱνʖϋρφ
಼ָLANProxyγʖώ Gateway Snort ࢻ ಃգܗ HTTP Proxy ᅗ 6QRUW ࡢタ⨨ሙᡤయࡢᵓᡂ ᭩ᘧ㸸DFWLRQSURWRVUF,3VUF3RUW!GVW,3GVW3RUW NH\ZRUGDUJ>NH\ZRUGDUJ@ 㸸DOHUWWFSDQ\DQ\! IODJV6PVJ66+&RQQHFWLRQDWWHPSW ᅗ 6QRUW ࣮ࣝࣝࡢ᭩ᘧ
␗ᖖ᳨▱ࡢ ✌ാࡋࡓSnort ࡀ᳨▱ࡋࡓ␗ᖖࡢࢆᅗ 3 ♧ࡍࠋࢭ࢟ࣗ ࣜࢸୖࡢ⌮⏤ࡼࡾࠊIP ࢻࣞࢫࡣ୍㒊ຍᕤࡋ࡚࠶ࡿࠋ Snort ࡢ␗ᖖ᳨▱ࡣࠊࡇࡢᅗࡢࡼ࠺㐪ࣃࢣࢵࢺ 1 ಶࡘ ࡁ 1 ⾜ࡢࣟࢢࠊ࠾ࡼࡧࣃࢣࢵࢺࢲࣥࣉࢆฟຊࡍࡿࠋࡇࡇ࡛ ≉➹ࡍࡁࡣࠊpcap ᙧᘧࡋ࡚ฟຊࡉࢀࡓࣃࢣࢵࢺࢲࣥࣉ ࡣ㐪ࡋࡓࣃࢣࢵࢺࡢࡳ࡛࠶ࡿ࠸࠺ࡇࡔࠋ⟶⌮⪅ࡀ␗ ᖖࢆ▱ࡿࡣࠊࡲࡎSnort ࡢࣟࢢࢆ┠どࡼࡾ᳨ᰝࡋࠊࡋ ࠸ᛮࢃࢀࡿࣃࢣࢵࢺࢲࣥࣉࢆWireshark ࡞ࡢࣃࢣࢵࢺゎ ᯒࢶ᳨࣮࡛ࣝᰝࡍࡿᚲせࡀ࠶ࡿࠋ㏻ᖖࠊ୍ࡘࡢ㏻ಙࢭࢵࢩ ࣙࣥࡣ」ᩘࡢࣃࢣࢵࢺࡽᵓᡂࡉࢀ࡚࠾ࡾࠊಖᏑࡉࢀࡓ 1 ࣃࢣࢵࢺࡢࡳࡽ␗ᖖྰࢆุ᩿ࡍࡿࡇࡣ㞴ࡋ࠸ࡀࠊ Snort ࡢࡳ࡛ࡣ㐪ࣃࢣࢵࢺࡢ࿘ᅖࡢࣃࢣࢵࢺࡲ࡛ྵࡵࡓㄪ ᰝࢆࡍࡿࡇࡣ࡛ࡁ࡞࠸ࠋ ࡲࡓࠊᮏᰯ࡛Snort ࢆ✌ാࡋ࡚ࢃࡗࡓࡇࡣࠊ㐪ࣃࢣ ࢵࢺࡢࣟࢢࡢಶᩘࡀពእከ࠸࠸࠺ࡇ࡛࠶ࡿࠋᅗ 3 ࡢ ࡛ࡣ⣙ 1 ศ࠾ࡁࣟࢢࡀฟຊࡉࢀ࡚࠾ࡾࠊ㐪ࣃࢣࢵࢺ ࡣࡇࡢࡼ࠺㢖⦾Ⓨ⏕ࡋ࡚࠸ࡿࠋࡑࡢࡓࡵࠊෆᐜࢆࡍ ࡚ㄪᰝࡍࡿࡇࡣ㛫ⓗ↓⌮ࡀ࠶ࡿุ᩿ࡋࠊ࣓࣮ࣝ ࡼࡾࣟࢢࢆ⮬ື㏻▱ࡍࡿ⤌ࡳࢆᵓ⠏ࡋࡓࠋࡲࡓࠊSnort ࡀ Prioriry 3 ௨ୖࢆࡋࡓࣟࢢࡸࣃࢣࢵࢺࢲࣥࣉ⤠ࡗ࡚ヲ ⣽ㄪᰝࡍࡿ࡞ᐇാࣞ࣋ࣝࡢᕤኵࢆࡋࡓࠋ
㸲㸬6HFXULW\2QLRQ ࡢᑟධᵓ⠏
6HFXULW\2QLRQ ᑟධࡢ᳨ウ㡯 ๓❶࡛㏙ࡓ㏻ࡾࠊSnort ࠾࠸࡚㐪ࣃࢣࢵࢺࡢࣟࢢ pcap ᙧᘧࡢࣃࢣࢵࢺࢲࣥࣉ 1 ಶ 1 ಶࢆᡭసᴗ࡛ゎᯒࡍࡿࡢ ࡣ㝈⏺ࡀ࠶ࡿࠋࡑࡇ࡛ࠊ2018 ᖺᗘࢿࢵࢺ࣮࣡ࢡࡢ┘ど⏝ PC ࢆᑟධࡍࡿࡓࡵࡢண⟬ᥐ⨨ࢆ⾜࠸ࠊ2019 ᖺ 3 ᭶ Snort ࢆIDS ࡋࡓ Security Onion ࢆ✌ാࡋࡓࠋ࡞࠾ࠊSnort ࡣ 2017 ᖺᗘࡢ Business ࣉࣛࣥࢆ⥅⥆ࡍࡿࡇࡋࠊOinkcode ࡣ Security Onion ࡑࡢࡲࡲᘬࡁ⥅ࡄࡇࡋࡓࠋ ࢧ࣮ࣂࢫ࣌ࢵࢡ ᅇᑟධࡋࡓᑓ⏝PC ࡢ࣐ࢩࣥࢫ࣌ࢵࢡࢆ⾲ 1 ♧ࡍࠋ ᑟධࡋࡓ PC ࡣᑗ᮶ⓗ࡞ᣑᙇࢆ⪃៖ࡋ࡚࣑ࢻࣝࢱ࣮࣡ᆺࡢ ࢹࢫࢡࢺࢵࣉPC ࡋࡓࠋHDD ᐜ㔞ࡣᑟධண⟬ࡢවࡡྜ ࠸࡛᭱ᑠ㝈ࡢ2TB ࡋࡓࡀࠊᐜ㔞ࡀࡁࡅࢀࡤࡑࢀࡔࡅࣟ ࢢࡸࣃࢣࢵࢺࢲࣥࣉࡢ㛗ᮇಖᏑࡀྍ⬟࡞ࡿࠋ⇃ᮏ㧗ᑓඵ ௦࢟ࣕࣥࣃࢫࡢࢿࢵࢺ࣮࣡ࢡࡢ⏝≧ἣࢆㄪᰝࡋࡓࡇ ࢁࠊ2TB ࡢᐜ㔞ࡣࠊኟఇࡳ࡞ࡢ㛗ᮇఇᬤ୰࡛ 1 㐌㛫⛬ᗘࠊ ᖹ᪥࡛࠶ࢀࡤ0.5㹼1 ᪥࡛࠸ࡁࡿࡇࡀศࡗࡓࠋࡑࡢࡓ ࡵࠊ10 ᪥ࡢࣃࢣࢵࢺࢲࣥࣉࢆಖ⟶ࡍࡿሙྜࡣ༢⣧ィ⟬࡛ 20 㹼40TB ࡢᐜ㔞ࡀᚲせ࡞ࡿࠋࡇࡢࡇࡽࠊࣟࢢ⏝ HDD ࡢቑタഛ࠼࡚SATA ࣏࣮ࢺࡸ㟁※ᐜ㔞ࠊࢣ࣮ࢫࡢ✵ࡁࢫࣟ ࢵࢺࡣ࡛ࡁࡿ㝈ࡾవ⿱ࢆࡶࡗ࡚☜ಖࡋ࡚࠾࠸ࡓ࠺ࡀⰋ ࠸ࠋ ࡲࡓࠊᅇࡣCPU ࡢࢥᩘࢆ㸴ࡋࡓࠋࢥᩘࢆከࡃࡋ ࡓ⌮⏤ࡣࠊSecurity Onion ࡛ࡣࠊSnort ࡸ Bro ࠸ࡗࡓฎ⌮ࡀ 㔜࠸ࣉࣟࢭࢫࡢࠊ௬࣐ࢩࣥࢆ」ᩘືసࡉࡏ࡞ࡅࢀ ࡤ࡞ࡽ࡞࠸ࡽ࡛࠶ࡿࠋᅇࠊ6 ࢥࢆ☜ಖ࡛ࡁࡓࡓࡵࠊSnort ࡢࣉࣟࢭࢫࢆSecurity Onion ෆ㒊࡛ 2 ࡘ㉳ືࡋࡓࠋࡇࢀࡼ ࡾࣃࢣࢵࢺゎᯒࢆ 2 ࡘࡢࢥ࡛ศᩓฎ⌮࡛ࡁࠊࣃࢣࢵࢺゎ ᯒࡢྲྀࡾࡇࡰࡋせᅉࢆῶࡽࡍࡇࡀ࡛ࡁࡿࠋࡲࡓࠊSecurity Onion ࡛ࡣࡑࢀ௨እ Docker(9) ࡤࢀࡿࢥࣥࢸࢼᆺ௬ ⎔ቃࡀᚲせ࡛࠶ࡿࠋ㏻ᖖࡢLinux ࢹࢫࢺࣜࣅ࣮ࣗࢩࣙࣥ ࡛ࡣ୍㒊ࡢࣇ࣮࣒࢙࢘ࢆࣂ࣮ࢪࣙࣥࢵࣉࡋࡓࡇ࡛ ືసⰋࡀⓎ⏕ࡍࡿࡇࡀࡓࡧࡓࡧ࠶ࡿࡀࠊDocker ࡛ࡣࢥ ࣥࢸࢼࡤࢀࡿ୍ᥞ࠸ࡢࣇ࣮࣒࢙࢘ࣜࢯ࣮ࢫࡀᥦ౪ ࡉࢀࡿࡓࡵࠊ࠸ࢃࡺࡿࣇ࣮࣒࢙࢘ࣂ࣮ࢪࣙࣥࡼࡿ┦ ᛶ ၥ 㢟 ࡀ Ⓨ ⏕ ࡋ ࡞ ࠸ ࠋ ࡇ ࡢ Docker ࡢ ≉ ᚩ ࢆ ⏝ ࡋ ࡚ ElasticStack(4) ࡢࡰࡍ࡚ࡢࢧ࣮ࣅࢫࡀᥦ౪ࡉࢀࡿࠋᡭඖ ࡢ⎔ቃ࡛ࡣࠊSecurity Onion ࡀ㉳ືࡍࡿ containerd-shim ࡀ 5 ࡘࠊdocker-proxy ࡀ 9 ࡘ⮬ືⓗ㉳ືࡋ࡚࠸ࡿࠋᵓ⠏ᚋࠊSecurity Onion ࡢ CPU ⏝⋡ࢆㄪᰝࡋࡓࠋලయ ⓗࡣࠊࢩ࢙࡚ࣝࣟࢢࣥᚋࠊtop ࢥ࣐ࣥࢻᐇ⾜୰'1'ࢆ ᢲୗࡍࡿࢥࡈࡢࣜࣝࢱ࣒࡞⏝⋡ࡀ⾲♧ࡉࢀ ࡿࠋᅗ4 ⤖ᯝࢆ♧ࡍࠋ%Cpu ࡢᚋ⥆ࡃ us ࡀ࣮ࣘࢨࣉࣟ ࢭࢫࠊsy ࡀࢩࢫࢸ࣒ࣉࣟࢭࢫࠊid ࡀࢻࣝ㛫࡛࠶ࡾࠊ ࡑࢀࡒࢀࡢྜ(%)ࡀ⾲♧ࡉࢀ࡚࠸ࡿࠋᅗࡽࡶࢃࡿ࠾ ࡾࠊ6 ࢥࡑࢀࡒࢀࡀᆒ➼㈇Ⲵศᩓࡉࢀ࡚࠾ࡾࠊᖹᆒࡋ࡚ 20.0%ࡢ CPU ࢥ⏝⋡࡛࠶ࡿࡇࡀࢃࡗࡓࠋCPU ⏝ ⋡వ⿱ࡀ࠶ࡿࡼ࠺ᛮ࠼ࡿࡀࠊ✺Ⓨⓗ࡞㧗㈇Ⲵᑐᛂࡍ ࡿࡓࡵࡣࡇࡢ⛬ᗘ࡛␃ࡵ࡚࠾࠸ࡓ᪉ࡀⰋ࠸ࠋࡲࡓᅗ 4 ࡢ ୗ㒊CPU ⏝⋡ࡢ㧗࠸㡰ࣉࣟࢭࢫࡀ⾲♧ࡉࢀ࡚࠸ࡿࠋ ᅗࡽࡶࢃࡿࡼ࠺ࠊjava, Bro, Snort ࡀ CPU 㛫ࢆᾘ㈝ ࡍࡿୖࣉࣟࢭࢫ࡛࠶ࡗࡓࠋ࡞࠾ࠊࡇࡢ࠺ࡕjava ࡀ Docker ࡛⏝ࡋ࡚࠸ࡿࣉࣟࢭࢫ࡛࠶ࡿࠋࡇࡢࡇࡽࠊࢿࢵࢺ࣡ ࣮ࢡࡢᇶᖿ㒊ศタ⨨ࡍࡿSecurity Onion ࡣࢥᩘࢆ࡛ࡁࡿ ࡔࡅከࡃ☜ಖࡋ࡚࠾࠸ࡓ᪉ࡀⰋ࠸⪃࠼ࡿࠋ
12/18-11:27:57.684574 [**] [129:12:1] Consecutive TCP small segments exceeding threshold [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 10.*.*.*:41714 -> *.217.*.110:443 12/18-11:28:01.117007 [**] [129:5:1] Bad segment, adjusted size <= 0 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 10.*.*.*:51521 -> *.52.*.18:80
12/18-11:28:02.986880 [**] [129:15:1] Reset outside window [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 10.*.*.*:50098 -> *.58.*.227:443
12/18-11:28:03.332611 [**] [129:14:1] TCP Timestamp is missing [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 10.*.*.*:52261 -> *.13.*.3:443 ᅗ 6QRUW ࡼࡿ␗ᖖ᳨▱ࡢ ⾲ 6HFXULW\2QLRQᑓ⏝ 3& ࡢ࣐ࢩࣥࢫ࣌ࢵࢡ &38 ,QWHO5&RUH70L&38#*+]&RUH 0(0 *% +'' 7%㸦ྍ⬟࡞ࡽ 㹼7%㸧 1HWZRUN ,QWHUIDFH %DVH7;㸰 6$7$ ࣏࣮ࢺ㸦࡛ࡁࡿࡔࡅከ࠸᪉ࡀⰋ࠸㸧 ࢣ࣮ࢫ ࣑ࢻࣝࢱ࣮࣡ᆺ LQFK ࣋ ࢫࣟࢵࢺ 㟁※ :㸦࡛ࡁࡿࡔࡅࡁ࠸᪉ࡀⰋ࠸㸧
ඵ௦࢟ࣕࣥࣃࢫ࠾ࡅࡿධ᳨▱ࢩࢫࢸ࣒ࡢᵓ⠏㸦ᑠᓥಇ㍜㸧 యᵓᡂ ᅇタ⨨ࡋࡓSecurity Onion ࡢタ⨨ሙᡤ࠾ࡼࡧయᵓᡂࢆ ᅗ5 ♧ࡍࠋSecurity Onion ⏝ࡢࢧ࣮ࣂࡣࠊ㸰ࡘࡢࢿࢵࢺ ࣮࣡ࢡࣥࢱࣇ࢙࣮ࢫࢆ⏝ពࡋࡓࠋ୍᪉ࡣᏛෆࢿࢵࢺ࣮࣡ ࢡ᥋⥆ࡍࡿࡓࡵࠊࡶ࠺୍᪉ࡣ⭾࡞㏻ಙࢆ┘どࡍࡿࡓࡵ ࡢࡶࡢ࡛࠶ࡾࠊᚋ⪅ࡣࣉ࣑ࣟࢫ࢟ࣕࢫ࣮ࣔࢻ࡛ືసࡉࡏࡿ ࡇࡋࡓࠋࣃࢣࢵࢺ┘どᑓ⏝ࡢ࣏࣮ࢺࢆ⏝ពࡋࡓࡇ࡛ࠊ ㏻ᖖࡢࢧ࣮ࣂࡢ㛫ࡢ㏻ಙࣃࢣࢵࢺࡀศ㞳࡛ࡁࠊ┘どࣃࢣ ࢵࢺࡢḞᦆࢆῶࡽࡍࡇࡀྍ⬟࡞ࡿࠋ ␗ᖖ᳨▱ࡢ ࡇࡇ࡛ࡣࠊSecurity Onion ᳨࡛▱ࡋࡓලయⓗ࡞㐪ࣃࢣࢵ ࢺࡸྍどࡉࢀࡓࣟࢢࡢࢆ♧ࡋ࡚࠾ࡃࠋᅗ 6 ࡣࠊSquert ࡤࢀࡿࢹ࣮ࢱࡢศᯒ⏝ࡍࡿࢶ࣮ࣝࡢࢫࢡ࣮ࣜࣥࢩ ࣙࢵࢺ࡛࠶ࡿࠋSnort ࡀ㐪ࣃࢣࢵࢺࡋุ࡚ᐃࡋࡓሗࢆ ᇶࠊᶓ㍈㛫ࠊ⦪㍈Ⓨ⏕௳ᩘࢆ♧ࡋࡓࢢࣛࣇࡀᥥ⏬ ࡉࢀࠊ㐪ࣃࢣࢵࢺࡢ㛫ኚࢆ☜ㄆࡍࡿࡇࡀ࡛ࡁࡿࠋ ࡲࡓࠊᅗࡢୗ㒊ࡣࠊほ ࡉࢀࡓ㐪ࣃࢣࢵࢺࡀ✀㢮ࡈ ศ㢮ࡉࢀ⾲♧ࡉࢀ࡚࠸ࡿࠋࡇࢀࡼࡾࠊ㐪ࣃࢣࢵࢺࡢ ⥲ᩘࡸഴྥࡀ୍┠࡛ࢃࡿࠋ ᅗ7 ࡣ Kibana ࡤࢀࡿࣃࢣࢵࢺྍどࢶ࣮ࣝࡢࢫࢡ ࣮ࣜࣥࢩࣙࢵࢺࢆ♧ࡋࡓࠋᅗࡣࠊᖹ᪥୍᪥ࡢDNS ࢡ࢚ࣜ ࡘ࠸࡚ࠊᶓ㍈ࢆ㛫ࠊ⦪㍈ࢆᅇᩘࡋ࡚ࢢࣛࣇ⾲♧ࡋ࡚࠸ ࡿᵝᏊ࡛࠶ࡿࠋᑵᴗ㛫࡛࠶ࡿ༗๓8 ༙ࡈࢁࡽୖ᪼ࡋࠊ 17 ࢆ㐣ࡂࡿᚎࠎୗ㝆ࡋ࡚࠸ࡃࠋ␗ᖖࡀⓎ⏕ࡋࡓࡁ ࡣDNS ࢡ࢚ࣜኚࢆ᮶ࡓࡍࡇࡀከࡃࠊࡇࡢࡼ࠺᪥㡭 ࡽᖹᖖࡢDNS ࢡ࢚ࣜࡢᵝᏊࢆほ ࡋ࡚࠾ࡃࡼ࠸ࠋ ᅗ 6TXHUW ࡼࡿ᳨ฟ⤖ᯝࡢศ㢮㛫ศᕸ 3UR[\γʖώ *: )LUH:DOO ϱνʖϋρφ ಼ָ/$1 6QRUW ϕϫϝηΫϡηϠʖχ 6: 6HFXULW\ 2QLRQ ϛʖφ ϝϧʖϨϱή ᅗ 6HFXULW\2QLRQ ࡢタ⨨ሙᡤయࡢᵓᡂ ᅗ ྛࢥ࠾ࡼࡧࣉࣟࢭࢫࡈࡢ &38 ⏝⋡
ᅗ8 ࡣ Security Onion ࡢࡶ࠺୍ࡘࡢ௦⾲ⓗ࡞ศᯒࢶ࣮ ࡛ࣝ࠶ࡿSquil ࡢࢫࢡ࣮ࣜࣥࢩࣙࢵࢺࢆ♧ࡋ࡚࠾࠸ࡓࠋࢭ࢟ ࣗࣜࢸୖࡢ⌮⏤ࡼࡾᅗࡢ୍㒊ࡣຍᕤࡋ࡚࠶ࡿࠋ ࡇࡢࢶ࣮ࣝࡣࠊSnort ࡼࡾほ ࡉࢀࡓ㐪ࣃࢣࢵࢺࢆ 㛫㡰ࡸIP ࢻࣞࢫ㡰࡞┠ⓗᛂࡌ࡚▐୪ኚ࠼ࡿࡇ ࡀ࡛ࡁࡿࠋࡲࡓࠊఝࡓࡼ࠺࡞㐪ࣃࢣࢵࢺࡣ 1 ⾜ࡲ ࡵࡽࢀಶᩘࡀ⾲♧ࡉࢀࡿࡓࡵࠊయⓗ࡞ぢ㏻ࡋࡀ㠀ᖖⰋ ࠸ࠋ㐪ࣃࢣࢵࢺࢆྑࢡࣜࢵࢡࡍࡿࡇ࡛ࠊIP ࢻࣞࢫࢆ VirusTotal(10)ࡸwhois ࡛ㄪᰝࡋࡓࡾࠊ௦⾲ⓗ࡞ࣃࢣࢵࢺゎᯒ ࢶ࣮࡛ࣝ࠶ࡿWireshark ࢆ㉳ືࡋࠊࢩ࣮࣒ࣞࢫヲ⣽ゎᯒ ࡍࡿࡇࡀྍ⬟࡛࠶ࡿࠋ ࡇࡢSguil ࢆ 5 ᭶㛫⏝ࡋࡓ⤖ᯝࠊ⇃ᮏ㧗ᑓඵ௦࢟ࣕࣥ ࣃࢫ࡛ࡣᖹᆒࡋ୍࡚᪥ᩘ௳㹼10 ௳⛬ᗘࡢ㐪ࣃࢣࢵࢺࡀ ᳨ฟࡉࢀࡿࡇࡀࢃࡗࡓࠋࡇࡢ㐪ࣃࢣࢵࢺࡢከࡃࡣᏛ ⏕VLAN ࡽࡢ᥋⥆࡛࠶ࡿࠋᗈ࿌ࢧࢺࡸࣈࣛࢵࢡࣜࢫࢺ IP ࢻࣞࢫࡢ㏻ಙࠊࢭ࢟ࣗࣜࢸ⬤ᙅᛶࢆࡘ࠸ࡓ PDF ࣇ ࣝࢲ࣮࢘ࣥࣟࢻ࡞ከᒱཬࢇ࡛࠸ࡿࡀࠊヲ⣽࡞ㄪᰝ ࡢ⤖ᯝࠊ࣐࢙ࣝ࢘ᑐ⟇ࢯࣇࢺࡢࣃࢱ࣮ࣥࣇࣝࡸࣉ ࣜࢣ࣮ࢩࣙࣥࡢࢵࣉࢹ࣮ࢺࣃࢵࢳࡀᥦ౪ࡉࢀࡿ࡞ࠊᑐ ⟇ࡀࡉࢀ࡚࠸ࡿࡶࡢࡀ༙ࢆ༨ࡵ࡚࠸ࡿࡇࡀࢃࡗ ࡓࠋ ࡲࡓࠊࡇࢀࡲ࡛ࠊᏛ⏕ࡀᏛෆᣢࡕ㎸ࢇࡔ➃ᮎࡀࢻ ࢙࢘ឤᰁࡋ࡚࠸ࡓࡾࠊࣈࣛࢵࢡࣜࢫࢺࡋ࡚Ⓩ㘓ࡉࢀ ࡚࠸ࡿIP ࢻࣞࢫ㏻ಙࡋࡓࡾࡋ࡚࠸ࡓࢣ࣮ࢫࡀ 5 ௳࠶ࡗ ࡓࠋ࠸ࡎࢀࡶᏛෆࡢ࣐࢙ࣝ࢘ᣑᩓࡸሗ₃ὤ࡞ࡢ ࣥࢩࢹࣥࢺࡣ⮳ࡗ࡚࠸࡞࠸ࠋⓎぢᚋࡢᑐᛂࡋ࡚ࠊ㐪 ࣃࢣࢵࢺࡢIP ࢻࣞࢫሗᏛෆ Wi-Fi ࡢ⏝グ㘓ࠊIP ࢻࣞࢫᡶ࠸ฟࡋሗࢆ✺ࡁྜࢃࡏࡿࡇ࡛Ꮫ⏕ࢆ≉ᐃࡍࡿ ࡇࡀ࡛ࡁࡓࡓࡵࠊᮏேὀពႏ㉳ࡋ࣐࢙ࣝ࢘ᑐ⟇ࡸ HDD ࣇࣝࢫ࢟ࣕࣥࢆồࡵࡓࠋࡲࡓࠊ୍㒊ࡢᏛ⏕ࡣ 1 㛫 ⛬ᗘࡢ㠃ㄯࢆᐇࡋ࡚ヲ⣽ࡢ☜ㄆ࡞ࢆ⾜ࡗࡓࠋ ✌ാ≧ἣࡢㄪᰝ Security Onion ࡢ✌ാ≧ἣࢆㄪᰝࡋࡓ⤖ᯝࢆᅗ 9 ♧ࡍࠋ Security Onion ࡣ 5 ศ࠾ࡁࣟࢢࢆฟຊࡋ࡚࠾ࡾࠊࢢࣛࣇࡢ ⦪㍈ࡣࡍ࡚ 5 ศ㛫࠶ࡓࡾࡢᖹᆒ್ࡋ࡚♧ࡋ࡚࠶ࡿࠋᅗ 9(a)ࡢ㏻㐣ࣃࢣࢵࢺᩘࡣࠊ5-20[kPackets/sec]࡛࠶ࡾࠊከࡃࡢ ࣃࢣࢵࢺࢆฎ⌮ࡋ࡚࠸ࡿᵝᏊࡀࢃࡿࠋࡲࡓࠊᅗ9(b) ࡢ CPU ⏝⋡ࡢㄪᰝ࡛ࡣ20-40%⛬ᗘࢆ♧ࡋ࡚࠾ࡾࠊ࠸ࡎࢀࡢ㛫 ᖏ࠾࠸࡚ࡶCPU100%࡞ࡽ࡞࠸ࡇࡀࢃࡗࡓࠋ ୍᪉ࠊᅗ9(c) ࡢ㐪ࣃࢣࢵࢺࡢ࣮ࣛࢺᩘࡘ࠸࡚ࡣὀ ពࡀᚲせ࡛࠶ࡿࠋࢢࣛࣇࡢ್᭱0.93 [௳/sec]ࡣ 5 ศ㛫࠶ࡓ ࡾࡢᖹᆒ್ࡋ࡚ࡢ⾲グ࡛࠶ࡾࠊࡘࡲࡾ 5 ศ㛫Ⓨ⏕ࡋࡓ 㐪ࣃࢣࢵࢺࡢ࣮ࣛࢺᩘࢆ300 ⛊࡛ࡗࡓ 1 ⛊࠶ࡓࡾࡢ ௳ᩘࡋ࡚⾲♧ࡋ࡚࠸ࡿࠋࡑࡢࡓࡵࠊࢢࣛࣇ್ 300 ࢆ ࡌࡓࡶࡢࡀᐇ㝿ࡢ 5 ศ㛫ᙜࡓࡾࡢ࣮ࣛࢺ௳ᩘ࡞ࡾࠊ᭱ ࡛5 ศ㛫࠶ࡓࡾ࠾ࡼࡑ 280 ௳ࡢ࣮ࣛࢺࡀሗ࿌ࡉࢀ࡚࠸ ࡿࡇࡀࢃࡿࠋࡕ࡞ࡳࡇࡢ࣮ࣛࢺ᭱௳ᩘࡣࢺࢵࣉ ࣞ࣋ࣝࢻ࣓ࣥ㸦TLD㸧ࡢ DNS ᳨⣴㛵ࡍࡿࡶࡢ࡛࠶ࡗࡓࠋ ࡑࢀ௨እࡶከࡃࡢ㐪ࣃࢣࢵࢺࡢ࣮ࣛࢺࡀᣲࡀࡗ࡚࠸ ࡿࠋ ᅗ10 ࡛ࡣࠊ2019 ᖺ 8 ᭶ 8 ᪥㸦ᮌ㸧୍᪥ᙜࡓࡾࡢฎ⌮ࣃࢣ ࢵࢺᩘࢆ♧ࡋ࡚࠸ࡿࠋࡇࡢ᪥ࡣᮏᰯ࡛ࡣ㏻ᖖᤵᴗ㸦ヨ㦂㏉ ༷➼㸧ࡀᐇࡉࢀ࡚࠸ࡿࠋᅗࡽࠊᑵᴗ㛤ጞᛴ⃭ୖ᪼ࡋࠊ ᑵᴗ⤊ᚋᚎࠎῶᑡࡍࡿ࠸࠺୍᪥ࡢฎ⌮ࣃࢣࢵࢺࡢ ࠾࠾ࡼࡑࡢኚࡀㄞࡳྲྀࢀࡿࠋ
㸳㸬ࡲࡵ
ᅇࠊSnort Security Onion ࢆᑟධࡋࡓࠋᑟධࡢࢥࢫ ࢺࡣࡑࢀ㧗ࡃࡣ࡞࠸ࡶࡢࡢࠊᑟධᚋࡢࢥࢫࢺࡀ㠀ᖖ 㧗ࡃࠊ1 ௳ࡢ㐪ࣃࢣࢵࢺࢆㄪᰝࡍࡿࡔࡅ࡛ከࡃࡢ㛫ࢆᚲ せࡍࡿࡇࡀࢃࡗࡓࠋ㐪ࣃࢣࢵࢺࡢㄪᰝࢆ㐍ࡵ࡚࠸ ࡃ୰࡛ࠊ㐪ࣃࢣࢵࢺࡢከࡃࡀㄗ᳨▱࡛༨ࡵࡽࢀ࡚࠸ࡿࡇ ࡀศࡗ࡚ࡁࡓࠋᑟධᙜึࡣ㐪ࣃࢣࢵࢺࡢࡍ࡚ࡘ ࠸࡚㏣㊧ㄪᰝࢆࡋ࡚࠸ࡓࡀࠊ㠀ᖖከࡃࡢ㛫ࢆᾉ㈝ࡋ࡚ ࡋࡲ࠺ࡇࡽࠊ㐣ཤㄪᰝࡋࡓࡶࡢࡼࡃఝࡓ㐪ࣃࢣ ࢵࢺࡘ࠸࡚ࡣㄪᰝࡋ࡞࠸࡞ࡢᕤኵࡶᚲせ࡛࠶ࡾࠊ࠶ࡿ ⛬ᗘࡢ⤒㦂ࡀᚲせ࡛࠶ࡿࠋࡲࡓࠊᑗ᮶ⓗࡣㄗ᳨▱ࢆῶࡽ ࡍࡼ࠺ Snort ࣮ࣝࣝࡢయⓗ࡞ぢ┤ࡋࡶᚲせ࡞ࢁ࠺ࠋ ᅗ 6JXLO ࡼࡿ᳨ฟ⤖ᯝࡢศ㢮ྍど ᅗ .LEDQD ࡼࡿ '16 ࣃࢣࢵࢺࡢศ㢮㛫ኚ
ඵ௦࢟ࣕࣥࣃࢫ࠾ࡅࡿධ᳨▱ࢩࢫࢸ࣒ࡢᵓ⠏㸦ᑠᓥಇ㍜㸧 ୍᪉ࠊㄗ᳨▱ࡢ୰ࡣࠊSSL ࡞ᬯྕࡉࢀࡓ㏻ಙࡶྵ ࡲࢀ࡚࠾ࡾࠊᬯྕࡉࢀࡓࣛࣥࢲ࣒࡞ࣃࢣࢵࢺࡀ㐪ࣃࢣ ࢵࢺࡢࣃࢱ࣮ࣥഅ↛୍⮴ࡋࡓࡼ࠺࡞ࡶࡢࡶぢཷࡅࡽࢀ ࡓࠋ1 ᪥࠶ࡓࡾ 2TB ࡢ㏻ಙࡀⓎ⏕ࡍࡿ Proxy ࢧ࣮ࣂࡢ⎔ቃୗ ࡛ࡣࡇࡢࡼ࠺࡞അ↛ࡀᩘከࡃⓎ⏕ࡍࡿࡀࠊࡇࡢㄗ᳨▱ࢆῶ ࡽࡍᢤᮏⓗ࡞ゎỴ⟇ࡣ࡞࠸ࠋ ᚋࡢ᳨ウ㡯ࡋ࡚ࠊᬯྕࣃࢣࢵࢺࡢ㏣㊧ࡀ࠶ࡿࠋ ⌧ᅾࠊ⇃ᮏ㧗ᑓඵ௦࢟ࣕࣥࣃࢫࡢProxy ࢧ࣮ࣂ࡛ࡣ SSL ࡞ ࡢᬯྕ㏻ಙࡀࣃࢣࢵࢺయࡢ 5 ࢆ༨ࡵ࡚࠸ࡿࠋ⌧ᅾ ᑟධࡋ࡚࠸ࡿSecurity Onion ࡣࠊᬯྕ㏻ಙࡢ୰࡛ࡲ࡛ㄪᰝ ࡍࡿᡭẁࡀ࡞࠸ࡓࡵࠊ༢⣧ィ⟬࡛㐪ࣃࢣࢵࢺࡢ༙ᩘࡀぢ 㐣ࡈࡉࢀ࡚࠸ࡿࡇ࡞ࡿࠋᚋࠊᬯྕ㏻ಙࡢྜࡣࡲ ࡍࡲࡍከࡃ࡞ࡿࡇࡀணࡉࢀ࡚࠾ࡾࠊSSL ࣥࢫ࣌ࢡࢩ ࣙࣥ࡞ᬯྕࣃࢣࢵࢺࢆᖹᩥࣃࢣࢵࢺࡍࡿ᪂ࡓ࡞⤌ࡳ ࡀᚲせ࡞ࡿࠋࡇࡢᐇ⌧ࡣᢏ⾡ⓗ࡞ㄢ㢟ࡶࡉࡿࡇ࡞ࡀ ࡽࠊ⌮ⓗ࡞ၥ㢟ࡶ࠶ࡿࠋࡓ࠼ࡤࠊࣟࢢࣥࡀᚲせ࡞ࢧ ࢺ ࡢ ࢝ ࢘ ࣥ ࢺ ࡸ ࣃ ࢫ ࣡ ࣮ ࢻ ࡞ ࢆ ྵ ࡵ ࡍ ࡚ ࡀ Security Onion ୖ࡛ᖹᩥᡠࡉࢀ࡚ࡋࡲ࠺ࡓࡵࠊࣃࢫ࣮࣡ࢻ ࢆ┐⫈ࡋ࡚࠸ࡿࡇఱࡽኚࢃࡽ࡞࠸ࠋᐇ⌧ࡣᏛෆࡢࢥ ࣥࢭࣥࢧࢫࢆᚓࡿᚲせࡀ࠶ࡿࡀ㠀ᖖᅔ㞴࡛࠶ࡿ⪃࠼ ࡿࠋ ᭱ᚋࠊSecurity Onion ࡣከᶵ⬟࡛࠶ࡾࠊ࠸ࡇ࡞ࡍࡣ ᭦࡞ࡿ័ࢀ⤒㦂ࡀᚲせ࡛࠶ࡿࡇࢆ③ឤࡋ࡚࠸ࡿࠋࢭ࢟ ࣗࣜࢸ㛵㐃ࡍࡿᩍ⫋ဨ࡛ຮᙉ࡞ࢆ㛤ദࡍࡿ࡞ࡋ ࡚࠸ࡁࡓ࠸ࠋ 㸦௧ඖᖺ9 ᭶ 25 ᪥ཷ㸧 㸦௧ඖᖺ12 ᭶ 5 ᪥ཷ⌮㸧 ཧ⪃ᩥ⊩
(1) Cisco : Snort - Network Intrusion Detection & Prevention System㸪https://snort.org/, 2019/9/21
(2) Security Onion Solutions : Security Onion, https:// securityonion.net/, 2019/9/21
(3) OISF : Suricata, Open Source IDS / IPS / NSM engine, https://suricata-ids.org/, 2019/9/21
(4) Elastic : ࣮࢜ࣉࣥࢯ࣮ࢫࡢ Elastic Stack㸦Elasticsearchࠊ KibanaࠊBeatsࠊLogstash㸧࡛ࣜࣝࢱ࣒࡞᳨⣴ศ ᯒ, https://www.elastic.co/jp/, 2019/9/21
(5) Squert Proejct : The squert project, http://www. squertproject.org/, 2019/9/21
(6) Bro Project : The Zeek Network Security Monitor, https: //www.zeek.org/, 2019/9/ 21
(7) Wireshark Foundations : Wireshark - Go Deep, https:// www.wireshark.org/, 2019/9/21
(8) The netsniff-ng Proejct : netsniff-ng toolkit, http://netsniff -ng.org/, 2019/9/21
(9) Docker Inc. : Enterprise Container Platform | Docker, https://www.docker.com/, 2019 /9/21
(10) VirusTotal Community : VirusTotal, https://www. virustotal.com/, 2019/9/21 ᅗ ୍᪥࠶ࡓࡾࡢฎ⌮ࣃࢣࢵࢺᩘࡢ᥎⛣ (a) 5 ᭶㛫ࡢฎ⌮ࣃࢣࢵࢺᩘ㸦5 ศ㛫࠶ࡓࡾࡢᖹᆒ㸧 (b) 5 ᭶㛫ࡢ CPU ⏝⋡㸦5 ศ㛫࠶ࡓࡾࡢᖹᆒ㸧 (c) 5 ᭶㛫ࡢ㐪ࣃࢣࢵࢺ࣮ࣛࢺᩘ㸦5 ศ㛫࠶ࡓࡾࡢᖹᆒ㸧 ᅗ 6HFXULW\2QLRQ ࡢ✌ാ≧ἣㄪᰝ