¥³¥¹¥È¤ä¿Íºà¤Ë;͵¤¬¤Ê¤¤Ãæ¾®´ë¶È¤¬Â¿ÁØËɸæ¤ò¼Â¸½¤¹¤ë¤Ë¤Ï
The Hacker News¤Ï¤³¤Î¤Û¤É¡¢¡ÖDetecting Windows-based Malware Through Better Visibility¡×¤Ë¤ª¤¤¤Æ¡¢»ñ¶âÌ̤ä¿Íºà¤Ë;͵¤Î¤Ê¤¤Ãæ¾®´ë¶È¤Ë¸þ¤±¤Æ¡¢Ä̾ï¤Ç¤Ï¿³Û¤ÎÈñÍѤ¬¤«¤«¤ë¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¤Î¿ÁØËɸæ¤òÈæ³ÓŪ¼êº¢¤Ê²Á³Ê¤Ç¼Â¸½¤¹¤ëÅý¹ç¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ÎÍøÅÀ¤òÅÁ¤¨¤¿¡£
Detecting Windows-based Malware Through Better Visibility
¡û¿ÁØËɸæ¤ÎɬÍ×À
°ìÈÌŪ¤Ë¸½¼ÂÀ¤³¦¤ÎËɱҤȥµ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¤ÎËɸæ¤È¤Ç¤Ï¡¢É¬ÍפȤµ¤ì¤ëÀï½Ñ¤¬°Û¤Ê¤ë¡£¸½¼ÂÀ¤³¦¤Ë¤ª¤±¤ëÅÁÅýŪ¤ÊÀïÆ®¤Ç¤Ï¡Ö¹¶·â3ÇܤÎˡ§¡×¤Ê¤É¤ËÂåɽ¤µ¤ì¤ë¤è¤¦¤Ë¡¢Ã±½ã¤Ê¿ôÃÍ(¿Í¿ô¤Ê¤É)¤ÎÈæ³Ó¤Ç¤¢¤ëÄøÅ٤ηë²Ì¤¬Í½Â¬¤Ç¤¤ë¤È¤µ¤ì¤ë¡£¤³¤ì¤ËÂФ·¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¤Ç¤Ï¡¢¤¿¤Ã¤¿1¤Ä¤ÎÀȼåÀ¤«¤é¤¹¤Ù¤Æ¤ò¿¯³²¤µ¤ì¤ë²ÄǽÀ¤¬¤¢¤ê¡¢¹¶·â¤È¤½¤Î·ë²Ì¤ò»öÁ°¤Ëͽ¬¤¹¤ë¤³¤È¤ÏÆñ¤·¤¤¡£
¤½¤Î¤¿¤á¡¢¶áǯ¤Î¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¤Ï²Äǽ¤Ê¸Â¤ê¤¹¤Ù¤Æ¤ÎÀȼåÀ¤ò¸¡½Ð¤·¤Æ¤Õ¤µ¤®¡¢Ëü¤¬°ìÀȼåÀ¤¬¹¶·â¼Ô¤Ëȯ¸«¤µ¤ì¤Æ¤â¤½¤Î±Æ¶Á¤ò¤Ç¤¤ë¤À¤±¾®¤µ¤¯¤¹¤ë¤³¤È¤¬½ÅÍפȤµ¤ì¤ë¡£
¤³¤ì¤ò¼Â¸½¤¹¤ë¤¿¤á¡¢¥Í¥Ã¥È¥ï¡¼¥¯¤ÎÆþ¸ý¡¢ÆâÉô¡¢½Ð¸ý¤ÎÎΰè¤ËÂФ·¤Æ½ÅÁØŪ¤ËÂкö¤ò¼Â»Ü¤¹¤ë¿ÁØËɸæ¤Î¥¢¥×¥í¡¼¥Á¤¬ÉԲķç¤È¤µ¤ì¡¢¤µ¤Þ¤¶¤Þ¤Ê¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤¬³Æ¼Ò¤«¤éÄ󶡤µ¤ì¤Æ¤¤¤ë¡£
¡û¥ê¡¼¥º¥Ê¥Ö¥ë¤Ê¥½¥ê¥å¡¼¥·¥ç¥ó¤È¤Ï
¥µ¥¤¥Ð¡¼¹¶·â¤ÎɸŪ¤ÏÂç´ë¶È¤À¤±¤Ç¤Ï¤Ê¤¤¡£Âç´ë¶È¤Ï¤½¤Î½áÂô¤Ê»ñ¶âÎϤȿͺà¤Ë¤è¤ê¶¯¸Ç¤Ê¿ÁØËɸæ¤ò¹½À®¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¤¬¡¢Ãæ¾®´ë¶È¤Ï¤½¤³¤Þ¤Ç¶¯¸Ç¤Ê¥»¥¥å¥ê¥Æ¥£¤ò¹½ÃÛ¤¹¤ë¤³¤È¤Ï¤Ç¤¤Ê¤¤¡£¤½¤Î¤¿¤á¡¢¹¶·â¼Ô¤Ï¥»¥¥å¥ê¥Æ¥£¤ÎÆÍÇˤ·¤ä¤¹¤¤Ãæ¾®´ë¶È¤òÁÀ¤¦¤³¤È¤¬¤¢¤ë¡£
¤³¤Î¤è¤¦¤ËÃæ¾®´ë¶È¤Ë¤â¿ÁØËɸæ¤ÎƳÆþ¤¬É¬ÍפȤµ¤ì¤ë¤¬¡¢»ñ¶âÎϤä¿Íºà¤Ë¸Â¤ê¤¬¤¢¤ë¤¿¤áƳÆþ¤ÏÆñ¤·¤¤¡£¤½¤³¤ÇThe Hacker News¤Ï¤½¤ÎÂåÂذƤȤ·¤Æ¡ÖEventSentry¡×¤Î¤è¤¦¤Ê¿µ¡Ç½¤Ê´Æ»ë¥½¥ê¥å¡¼¥·¥ç¥ó¤ÎƳÆþ¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£
¤³¤Î¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤Ïñ°ì¤Î¥½¥ê¥å¡¼¥·¥ç¥ó¤Ç¤¢¤ê¤Ê¤¬¤éÆâÉô¤ËÊ£¿ô¤Î¥³¥ó¥Ý¡¼¥Í¥ó¥È¤ò´Þ¤ß¡¢¤¢¤ëÄøÅ٤οÁØËɸæ¤ò¼Â¸½¤¹¤ë¡£¼ç¤Êµ¡Ç½¤È¤·¤Æ¤Ïñ°ì¤Î´ÉÍý¥Ñ¥Í¥ë¡¢¥ê¥¢¥ë¥¿¥¤¥à¤Î¥¤¥Ù¥ó¥È¥í¥°´Æ»ë¡¢¤ï¤«¤ê¤ä¤¹¤¤¥á¡¼¥ë¥¢¥é¡¼¥È¡¢¥»¥¥å¥ê¥Æ¥£¾ðÊ󤪤è¤Ó¥¤¥Ù¥ó¥È´ÉÍý(SIEM: Security information and event management)¡¢Web¥Ù¡¼¥¹¤Î¥ì¥Ý¡¼¥È¤Ê¤É¤¬¤¢¤ë¡£
Ê£»¨²½¤òÁý¤¹¥Í¥Ã¥È¥ï¡¼¥¯¥¤¥ó¥Õ¥é¤ò¹âÅ٤ʥµ¥¤¥Ð¡¼¹¶·â¤«¤éËɸ椷¡¢¶È̳¤ò±ß³ê¤Ë¿ë¹Ô¤¹¤ë¤¿¤á¤ËÃæ¾®´ë¶È¤Ë¤â¿ÁØËɸæ¤Î¥»¥¥å¥ê¥Æ¥£Âкö¤¬µá¤á¤é¤ì¤Æ¤¤¤ë¡£¸½¼ÂŪ¤Ê²ÝÂê¤ËÀÞ¤ê¹ç¤¤¤ò¤Ä¤±¡¢³Æ¼Ò¤Î¥¤¥ó¥Õ¥é¤ËŬ¹ç¤¹¤ë¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ÎƳÆþ¸¡Æ¤¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
Detecting Windows-based Malware Through Better Visibility
°ìÈÌŪ¤Ë¸½¼ÂÀ¤³¦¤ÎËɱҤȥµ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¤ÎËɸæ¤È¤Ç¤Ï¡¢É¬ÍפȤµ¤ì¤ëÀï½Ñ¤¬°Û¤Ê¤ë¡£¸½¼ÂÀ¤³¦¤Ë¤ª¤±¤ëÅÁÅýŪ¤ÊÀïÆ®¤Ç¤Ï¡Ö¹¶·â3ÇܤÎˡ§¡×¤Ê¤É¤ËÂåɽ¤µ¤ì¤ë¤è¤¦¤Ë¡¢Ã±½ã¤Ê¿ôÃÍ(¿Í¿ô¤Ê¤É)¤ÎÈæ³Ó¤Ç¤¢¤ëÄøÅ٤ηë²Ì¤¬Í½Â¬¤Ç¤¤ë¤È¤µ¤ì¤ë¡£¤³¤ì¤ËÂФ·¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¤Ç¤Ï¡¢¤¿¤Ã¤¿1¤Ä¤ÎÀȼåÀ¤«¤é¤¹¤Ù¤Æ¤ò¿¯³²¤µ¤ì¤ë²ÄǽÀ¤¬¤¢¤ê¡¢¹¶·â¤È¤½¤Î·ë²Ì¤ò»öÁ°¤Ëͽ¬¤¹¤ë¤³¤È¤ÏÆñ¤·¤¤¡£
¤½¤Î¤¿¤á¡¢¶áǯ¤Î¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¤Ï²Äǽ¤Ê¸Â¤ê¤¹¤Ù¤Æ¤ÎÀȼåÀ¤ò¸¡½Ð¤·¤Æ¤Õ¤µ¤®¡¢Ëü¤¬°ìÀȼåÀ¤¬¹¶·â¼Ô¤Ëȯ¸«¤µ¤ì¤Æ¤â¤½¤Î±Æ¶Á¤ò¤Ç¤¤ë¤À¤±¾®¤µ¤¯¤¹¤ë¤³¤È¤¬½ÅÍפȤµ¤ì¤ë¡£
¤³¤ì¤ò¼Â¸½¤¹¤ë¤¿¤á¡¢¥Í¥Ã¥È¥ï¡¼¥¯¤ÎÆþ¸ý¡¢ÆâÉô¡¢½Ð¸ý¤ÎÎΰè¤ËÂФ·¤Æ½ÅÁØŪ¤ËÂкö¤ò¼Â»Ü¤¹¤ë¿ÁØËɸæ¤Î¥¢¥×¥í¡¼¥Á¤¬ÉԲķç¤È¤µ¤ì¡¢¤µ¤Þ¤¶¤Þ¤Ê¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤¬³Æ¼Ò¤«¤éÄ󶡤µ¤ì¤Æ¤¤¤ë¡£
¡û¥ê¡¼¥º¥Ê¥Ö¥ë¤Ê¥½¥ê¥å¡¼¥·¥ç¥ó¤È¤Ï
¥µ¥¤¥Ð¡¼¹¶·â¤ÎɸŪ¤ÏÂç´ë¶È¤À¤±¤Ç¤Ï¤Ê¤¤¡£Âç´ë¶È¤Ï¤½¤Î½áÂô¤Ê»ñ¶âÎϤȿͺà¤Ë¤è¤ê¶¯¸Ç¤Ê¿ÁØËɸæ¤ò¹½À®¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¤¬¡¢Ãæ¾®´ë¶È¤Ï¤½¤³¤Þ¤Ç¶¯¸Ç¤Ê¥»¥¥å¥ê¥Æ¥£¤ò¹½ÃÛ¤¹¤ë¤³¤È¤Ï¤Ç¤¤Ê¤¤¡£¤½¤Î¤¿¤á¡¢¹¶·â¼Ô¤Ï¥»¥¥å¥ê¥Æ¥£¤ÎÆÍÇˤ·¤ä¤¹¤¤Ãæ¾®´ë¶È¤òÁÀ¤¦¤³¤È¤¬¤¢¤ë¡£
¤³¤Î¤è¤¦¤ËÃæ¾®´ë¶È¤Ë¤â¿ÁØËɸæ¤ÎƳÆþ¤¬É¬ÍפȤµ¤ì¤ë¤¬¡¢»ñ¶âÎϤä¿Íºà¤Ë¸Â¤ê¤¬¤¢¤ë¤¿¤áƳÆþ¤ÏÆñ¤·¤¤¡£¤½¤³¤ÇThe Hacker News¤Ï¤½¤ÎÂåÂذƤȤ·¤Æ¡ÖEventSentry¡×¤Î¤è¤¦¤Ê¿µ¡Ç½¤Ê´Æ»ë¥½¥ê¥å¡¼¥·¥ç¥ó¤ÎƳÆþ¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£
¤³¤Î¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤Ïñ°ì¤Î¥½¥ê¥å¡¼¥·¥ç¥ó¤Ç¤¢¤ê¤Ê¤¬¤éÆâÉô¤ËÊ£¿ô¤Î¥³¥ó¥Ý¡¼¥Í¥ó¥È¤ò´Þ¤ß¡¢¤¢¤ëÄøÅ٤οÁØËɸæ¤ò¼Â¸½¤¹¤ë¡£¼ç¤Êµ¡Ç½¤È¤·¤Æ¤Ïñ°ì¤Î´ÉÍý¥Ñ¥Í¥ë¡¢¥ê¥¢¥ë¥¿¥¤¥à¤Î¥¤¥Ù¥ó¥È¥í¥°´Æ»ë¡¢¤ï¤«¤ê¤ä¤¹¤¤¥á¡¼¥ë¥¢¥é¡¼¥È¡¢¥»¥¥å¥ê¥Æ¥£¾ðÊ󤪤è¤Ó¥¤¥Ù¥ó¥È´ÉÍý(SIEM: Security information and event management)¡¢Web¥Ù¡¼¥¹¤Î¥ì¥Ý¡¼¥È¤Ê¤É¤¬¤¢¤ë¡£
Ê£»¨²½¤òÁý¤¹¥Í¥Ã¥È¥ï¡¼¥¯¥¤¥ó¥Õ¥é¤ò¹âÅ٤ʥµ¥¤¥Ð¡¼¹¶·â¤«¤éËɸ椷¡¢¶È̳¤ò±ß³ê¤Ë¿ë¹Ô¤¹¤ë¤¿¤á¤ËÃæ¾®´ë¶È¤Ë¤â¿ÁØËɸæ¤Î¥»¥¥å¥ê¥Æ¥£Âкö¤¬µá¤á¤é¤ì¤Æ¤¤¤ë¡£¸½¼ÂŪ¤Ê²ÝÂê¤ËÀÞ¤ê¹ç¤¤¤ò¤Ä¤±¡¢³Æ¼Ò¤Î¥¤¥ó¥Õ¥é¤ËŬ¹ç¤¹¤ë¥»¥¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ÎƳÆþ¸¡Æ¤¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£