ã¢ã©ãŒããã€ãºã®é ããã³ã¹ãïŒIDS 誀æ€ç¥ãèªåè»ã¡ãŒã«ãŒã®ãµã€ããŒã»ãã¥ãªãã£äºç®ã奪ã
èªåè»ã¡ãŒã«ãŒå瀟ã¯ããµã€ããŒæ»æã®ãªã¹ã¯ãæå°åããå®å šæ§ã確ä¿ããåçš®èŠå¶èŠä»¶ã«é©åãããããè»èŒãµã€ããŒã»ãã¥ãªãã£ã匷åããããšãäžå¯æ¬ ã§ããããšãååã«èªèããŠããŸããçŸåšãå€ãã®è»äž¡ã§ã¯ è»èŒåäŸµå ¥æ€ç¥ã»é²åŸ¡ã·ã¹ãã ïŒIDS/IDPSïŒãå°å ¥ãããŠãããè»èŒãããã¯ãŒã¯äžã®éä¿¡ããªã¢ã«ã¿ã€ã ã«ç£èŠããæ»æã®å åãšãªãããç°åžžãæ€ç¥ããŸãããããã®ç°åžžã¯éåžžãããã¯ãšã³ãã®ããªãŒãç£èŠãœãªã¥ãŒã·ã§ã³ïŒãããã Vehicle Security Operations CenterïŒVSOCïŒãžã¢ã©ãŒããšããŠéä¿¡ãããåæãšå¯Ÿå¿ãè¡ãããŸãã
IDSå®è£ ã«ãããæå€§ã®èª²é¡ã®ã²ãšã€ãããããããã¢ã©ãŒããã€ãºãã§ããå€ãã®ç¬¬1äžä»£ã®è»èŒ IDSã¯èšå€§ãªæ°ã®ã¢ã©ãŒããçæããŠããŸããå¹³åã§ãã®çŽ 80% ã誀æ€ç¥ãšããããŠããŸãããã®çµæãSOCã¢ããªã¹ããæ¬ç©ã®æ»æãèŠæ¥µããããšã極ããŠå°é£ã«ãªãã ãã§ãªããèªåè»ã¡ãŒã«ãŒã«ãšã£ãŠã¯ã»ã«ã©ãŒéä¿¡éãã¯ã©ãŠãã¹ãã¬ãŒãžã®ã³ã¹ãå¢å€§ãæãèŠå ã«ããªã£ãŠããŸãã
次äžä»£è»äž¡ãžã® IDSå°å ¥ãæ€èšããèªåè»ã¡ãŒã«ãŒã«ãšã£ãŠã誀æ€ç¥ãã³ã¹ãã«äžãã圱é¿ãæ£ããææ¡ããããšã¯æ¥µããŠéèŠã§ããè»äž¡ã©ã€ããµã€ã¯ã«å šäœã§èŠãã°ã誀æ€ç¥ã«èµ·å ãã远å ã®éçšã³ã¹ãã¯ãå€§èŠæš¡ãªããªãŒãã§ããã°æ°çŸäžãã«èŠæš¡ã«éããå¯èœæ§ããããŸãããããã£ãŠãèªåè»ã¡ãŒã«ãŒãè€æ°ã® IDS ãœãªã¥ãŒã·ã§ã³ãæ¯èŒããç·ä¿æã³ã¹ãïŒTCOïŒãè©äŸ¡ããéã«ã¯ãããããé·æçãªã³ã¹ããèæ ®ã«å ¥ããå¿ èŠããããŸãã
æ¬ããã°ã§ã¯ãåŸæ¥å IDS ãšé«ç²ŸåºŠIDS ã®éãã解説ãããšãšãã«ãèªåè»ã¡ãŒã«ãŒãé«ç²ŸåºŠ IDS ãå°å ¥ããå Žåã«åŸããã 15 幎éã®ã³ã¹ãåæžå¹æãå®éçã«ç€ºããŸãã
ãã¢ã©ãŒããã€ãºã㯠èªåè»ã¡ãŒã«ãŒã«ãšã£ãŠé倧ãªè² æ
åè¿°ã®ãšããã第1äžä»£ãŸãã¯æ±çšçãªè»èŒ IDS ã¯ãé«ãå²åã§èª€æ€ç¥ãçºçãããåŸåããããŸããããã¯éçšã³ã¹ãã®å¢å€§ãæãã ãã§ãªããã»ãã¥ãªãã£ãªã¹ã¯ã®äžæã«ãã€ãªãããŸãã
- äžèŠãªããžã£ã³ã¯ãããŒã¿ã®å€§éçºçïŒåæã«éçºãããå€ãã®ã·ã¹ãã ã¯éå°ã«ãµã€ããŒã»ãã¥ãªãã£ã¢ã©ãŒããçæããŸãããããã¯è»äž¡ãã SOC ãžéä¿¡ãããã¯ã©ãŠãã«ä¿åãããŸãããã®ããã€ãºãã¯ãèªåè»ã¡ãŒã«ãŒã«ãšã£ãŠäž»èŠãªéçšã³ã¹ãèŠå ã§ãããšãšãã«ã倧ããªéå¹çæ§ãçã¿åºãããšãææãããŠããŸãã
- éçšè² è·ãšã³ã¹ãã®å¢å€§ïŒã¢ã©ãŒãã¯ãã®çåœã«é¢ããããVSOCã®ã¢ããªã¹ãã«ãã調æ»ãå¿ èŠã§ããã¢ã©ãŒãã«å ããåœéœæ§ã®æ°ãå€ããšããªãœãŒã¹ã®æµªè²»ãéçšã³ã¹ãã®å¢å ãããã«ã¯ã»ãã¥ãªãã£ããŒã ã®ç²åŒãåŒãèµ·ãããŸããæ¥çã®çŸå Žã§ã¯ãã¢ã©ãŒããæ¬åœã«è åšãã©ãããèŠæ¥µãããŸã§ã«ãç°å¢ã«ãã£ãŠã¯æ°é±éãããããšããããŸãã
- çã®è åšãèŠéããªã¹ã¯ïŒäœå質ãªã¢ã©ãŒãã倧éã«çºçãããã®å¯Ÿå¿ã«è¿œãããç¶æ³ã§ã¯ãã»ãã¥ãªãã£ããŒã ã¯æ¬æ¥å¯ŸåŠãã¹ãå±éºãªãµã€ããŒæ»æãæ€ç¥ã»å¯Ÿå¿ããèœåã倧ããäœäžããŸããæ¬æ¥èª¿æ»ãããã¹ããªã¢ã«ãªè åšãããã€ãºã«åãããŠããŸãå¯èœæ§ãé«ãŸãããã§ãã
åŸæ¥å IDS ãš é«ç²ŸåºŠ IDS ã®éã
åŸæ¥åã®ç¬¬1äžä»£ IDS ãš é«ç²ŸåºŠ IDS ã®éããçè§£ããã°ãçµç¹ã¯åŸæ¥ã®ã¢ãããŒãã«æœãèœãšã穎ãåé¿ã§ããŸããé«ç²ŸåºŠ IDS ã®çãã¯ãåã«äŸµå ¥ãæ€ç¥ããããšã§ã¯ãªããéå°ãªã¢ã©ãŒãã§éçšãå§è¿«ããããšãªããæç¢ºã§è¡åã«ã€ãªããã€ã³ãµã€ããæäŸã§ããè³¢ãæ€ç¥ãå®çŸããããšã«ãããŸãã
åŸæ¥ã®è»èŒ IDS ãšã¯ç°ãªããé«ç²ŸåºŠ IDS ã¯è»äž¡å éšã§çºçããããã€ãºãã®å€§éšåããã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³ã«å°éããåã®æ®µéã§ãã£ã«ã¿ãªã³ã°ããŸãããã® IDS ã¯ãé¢é£æ§ã®ãªãåé·ãªããŒã¿ãçç¢ºã«æé€ããããèšèšãããŠãããã¢ã©ãŒãéãå€§å¹ ã«åæžãã€ã€ãé«ã粟床ãšé¢é£æ§ãç¶æããŸãããããã粟å¯ãªåŠçã«ãããè»èŒãããã¯ãŒã¯å ã®è²Žéãªåž¯åãèšç®ãªãœãŒã¹ãç¯çŽã§ããããããä»ã®éèŠãªæ©èœã«æŽ»çšããããšãå¯èœã«ãªããŸãã
ãã®ã¢ãããŒããäœçŸããäŸãšããŠãPlaxidityX ã® IDS 補åã¯é«åºŠãªãã¥ãŒãªã¹ãã£ãã¯ææ³ãçšããŠãéçšäžã®ãã€ãºãæå°åããããèšèšãããŠããŸããããã«ãããIDS ã¯å®éã®ç°åžžãšãïŒãŸãã«çºçããã€ãã³ãã§ãã£ãŠãïŒæ³å®å ã®éä¿¡å€åãå ±ååã«èå¥ããããšãå¯èœã§ãããã®çµæã誀æ€ç¥çãã»ãŒãŒãã«ãŸã§äœæžã§ããå€§èŠæš¡ãªããªãŒãã管çããèªåè»ã¡ãŒã«ãŒã«ãšã£ãŠæ¥µããŠéèŠãªã¡ãªãããšãªããŸãã
ãã®çµæãã»ãã¥ãªãã£ããŒã ã«ãããéçšè² è·ã¯å€§å¹ ã«è»œæžãããçã«å¯ŸåŠãã¹ãè åšãžã®éäžãå¯èœã«ãªããŸããé«ç²ŸåºŠ IDS ã¯ãããŒã¿åŠçãä¿åããã㊠SIEMïŒSecurity Information and Event ManagementïŒã»ãã¥ãªãã£æ å ±ã»ã€ãã³ã管çïŒ åæã«é¢é£ããã³ã¹ããæé©åããŸãããã®çµæãããå¹ççã§ã³ã¹ããæãããå°æ¥ã®æ¡åŒµã«ã察å¿ã§ããã»ãã¥ãªãã£äœå¶ãæ§ç¯ã§ããä»åŸç»å Žãã AIãæŽ»çšããè åšé²åŸ¡ãå®çŸããããã®ç¢ºããªåºç€ãšãªããŸãã
é«ç²ŸåºŠ IDS ãããããé·æçãªã³ã¹ãåæžå¹æã®å®éå
é«ç²ŸåºŠ IDS ãå°å ¥ããããšã§ èªåè»ã¡ãŒã«ãŒãåŸãããæœåšçãªã³ã¹ãåæžå¹æã瀺ããããããã€ãºãå€ã IDSãïŒæ¥çã§äžè¬çã§ãã誀æ€ç¥ç 80% ã® IDSïŒã«èµ·å ãã远å ã³ã¹ããå®éåããŸããã察象ãšããã³ã¹ãã¯ãããŒã¿äŒééãã¯ã©ãŠãã€ã³ãã©ããã㊠VSOC ã®éçšå¹çã«é¢ãããã®ã§ããåæã«ã¯ã50äžå°ã®è»äž¡ãããªãããªãŒããæ³å®ããåè»äž¡ã®ã©ã€ããµã€ã¯ã«ã15幎ãšèšå®ããŸããããããã®ã³ã¹ããã誀æ€ç¥ãŒãã®é«ç²ŸåºŠIDS ãšæ¯èŒããŠããŸãïŒè£è¶³ïŒPlaxidityX ã® IDS 補åã¯ã顧客ç°å¢ããã³ç¬¬äžè æ©é¢ã«ããç¬ç«è©äŸ¡ã«ãããå®éçšã§ãã®ã¬ãã«ã®ç²ŸåºŠãéæããŠããããšã確èªãããŠããŸãïŒã
ããŒã¿äŒéããã³ã¯ã©ãŠãã€ã³ãã©ã«é¢ããã³ã¹ã
ãã€ãºã®å€ã第1äžä»£ IDS ã¯ã誀æ€ç¥ãåé·ããŒã¿ãéå°ãªãã°åºåã«ãã£ãŠå€§éã® âãžã£ã³ã¯â ããŒã¿ãçæããŠããŸãããšããããŸãããããã®äžèŠãªããŒã¿ïŒèª€ã¢ã©ãŒãããã°ãã³ã³ããã¹ãæ å ±ãªã©ïŒã¯ãã¹ãŠãè»äž¡ã«æèŒããã SIM ãéããŠã»ã«ã©ãŒåç·ã§ VSOC ã«éä¿¡ããããããè»äž¡åŽã®ããŒã¿éä¿¡ã³ã¹ããæŒãäžããèŠå ãšãªããŸãã
ããã«ãIDS ã®èª€æ€ç¥ã«ãã£ãŠçæãããéå°ã§äŸ¡å€ã®äœãããŒã¿ãä¿åããããšã¯ãã¯ã©ãŠãã¹ãã¬ãŒãžããã³åŠçã³ã¹ãã«çŽæ¥åœ±é¿ããŸããçŸåšã®äž»èŠãªã¯ã©ãŠããããã€ãã¯ãé·æçãªã¹ãã¬ãŒãžå©çšéã«å ããé¢é£ããã¯ã©ãŠãåŠçïŒåæãåã蟌ã¿ã倿ãªã©ïŒã«ã課éããŠããŸãããã®ãããIDS ãçæãããžã£ã³ã¯ããŒã¿ãå€ãã»ã©ãèªåè»ã¡ãŒã«ãŒãè² æ ããã¯ã©ãŠãé¢é£ã³ã¹ãã¯é«ããªããŸãã
詊ç®äŸïŒäžè¬çãªããŒã¿éä¿¡è²»çšãããã³ã¯ã©ãŠãã®ã¹ãã¬ãŒãžã»åŠçå䟡ã«åºã¥ããšããã€ãºã®å€ã IDS ã¯ãè»äž¡ã©ã€ããµã€ã¯ã«å šäœã§ 1 å°ãããçŽ 2.50ïœ4.50 ãã«ã®è¿œå ããŒã¿é¢é£ã³ã¹ãã®çºçãæšå®ãããŸããæ¬æ¥ã¯åé¿å¯èœãªã³ã¹ãã§ãããããªãŒãèŠæš¡ã倧ãããªãã»ã©ç·é¡ã¯å€§ããå¢å ããŠãããŸãã
VSOC éçšå¹çã®æé©å
ãã€ãºã®å€ã IDS ãããããæå€§ã®éçšã³ã¹ãã¯ã誀æ€ç¥ã¢ã©ãŒã ã®èª¿æ»ã«æµªè²»ããã人çãªãœãŒã¹ã§ããããšãã°ãSOC ããŒã ã 20 åã®ã¢ããªã¹ãã§æ§æãããŠãããšãããšã1 æ¥ã«åŠçã§ããã¢ã©ãŒãæ°ã«ã¯æç¢ºãªäžéããããŸããããªãŒãèŠæš¡ãæ¡å€§ããIDS ã®èª€æ€ç¥ãå«ãã¢ã©ãŒãéãå¢ãç¶ããã°ãèªåè»ã¡ãŒã«ãŒã¯ããŒã ã®å¢å¡ïŒãã ããäºç®å¶çŽãã¹ãã«äžè¶³ã«ããåžžã«å¯èœãšã¯éããŸããïŒãè¡ããããããã¯ãå®éã®è åšãèŠéããªã¹ã¯ãé«ãŸãããšããçŸå®ã«çŽé¢ããŸãã
詊ç®äŸïŒé«ç²ŸåºŠ IDS ã¯èª€æ€ç¥ãå€§å¹ ã«åæžãïŒã·ã¹ãã ã«ãã£ãŠã¯ 90%以äžã®åæžãå¯èœïŒãVSOC ã¢ããªã¹ãã®äœæ¥æéã® 25ã50% ãåæžããããšãã§ããŸãã50 äžå°èŠæš¡ã®ããªãŒããæ¯ããäžèŠæš¡ VSOC ããŒã ã§ã¯ãããããçç£æ§åäžãçã®è åšãžéäžããããšã§ã幎é 10 äžã25 äžãã«ä»¥äžã®éçšäŸ¡å€ãçãŸããå¯èœæ§ããããŸãïŒããŒã èŠæš¡ã人件費ã«ãã£ãŠå€åããŸãïŒãããªãŒãèŠæš¡ã倧ãããªãã»ã©ãã¢ããªã¹ã 1 人ãããã®å¹çæ¹åã®éèŠæ§ã¯ããã«é«ãŸããŸãã
SIEM ããã³ããã¯ãšã³ãåŠçã³ã¹ãã®åæž
å€ãã® èªåè»ã¡ãŒã«ãŒãå©çšããSIEMãã©ãããã©ãŒã ïŒäŸïŒMicrosoft SentinelïŒãããã®ä»ã®ã¯ã©ãŠãããŒã¹ã®ããã¯ãšã³ãåæã·ã¹ãã ã¯ãåã蟌ãããŒã¿éãåŠçããã€ãã³ãæ°ã«å¿ããŠèª²éãããä»çµã¿ãæ¡çšããŠããŸãã
詊ç®äŸïŒé«ç²ŸåºŠ IDS ãçæãã粟床ã®é«ããäºåã«çµã蟌ãŸããã¢ã©ãŒãããŒã¿ã SIEM ã«å ¥åããããšã§ãSIEM ã«ãããããŒã¿åã蟌ã¿ã»ä¿åã»åŠçã«é¢é£ããã³ã¹ãã 20ã40% åæžã§ãããšèŠèŸŒãŸããŸãã50 äžå°èŠæš¡ã®ããªãŒãã§ã¯ãããããåæžå¹æã¯ èªåè»ã¡ãŒã«ãŒã«ãšã£ãŠå€§ããªè²¡åçã¡ãªãããšãªãã ãã§ãªããäžå€®éçŽåã»ãã¥ãªãã£åæã®æ§èœãšæå¹æ§åäžã«ãå¯äžããŸãã
ã©ã€ãã¿ã€ã å šäœã§èŠãç·åçãªåæžå¹æ
äžèšã§åæããåã³ã¹ãèŠçŽ ã«åºã¥ãã50 äžå°èŠæš¡ã®ããªãŒãã«ãããŠè»äž¡å¯¿åœãäžè¬ç㪠15 幎ãšä»®å®ãããšãIDS ã®èª€æ€ç¥ã«ãã£ãŠ èªåè»ã¡ãŒã«ãŒã远å ã§è² æ ããã³ã¹ãã¯çŽ 150 äžã230 äžãã«ã«éãããšæšå®ãããŸãã
è»èŒã»ãã¥ãªãã£ã®æªæ¥ïŒAI ãæŽ»çšããé«ç²ŸåºŠ IDS
èªåè»ãµã€ããŒã»ãã¥ãªãã£ã®é åã¯æ¥éã«é²åããŠãããè åšæ€ç¥ãšå¯Ÿå¿ã«ãã㊠AI ãä»åŸãŸããŸãéèŠãªåœ¹å²ãæãããšèããããŠããŸããå°æ¥ã® IDS ãœãªã¥ãŒã·ã§ã³ã¯ãAI ãæŽ»çšããŠè€éãªæ»æãã¿ãŒã³ãç¹å®ããæ°ãã«åºçŸããè åšãäºæž¬ããããã«ã¯å¯Ÿå¿ã®èªååãå®çŸããŠããã§ãããã
ãšã¯ãããAI ãæŽ»çšããã»ãã¥ãªãã£ã·ã¹ãã ã®æå¹æ§ã¯ããã®å ¥åããŒã¿ã®è³ªãšä¿¡é Œæ§ã«å€§ããå·Šå³ãããŸããäžèŠãªããŒã¿ãæé€ããæèã«åºã¥ããŠé«ç²ŸåºŠãªæ å ±ãæäŸã§ãã IDS ã¯ãå°æ¥çã« AI äž»å°ã®é«åºŠãªã»ãã¥ãªãã£æ©èœãå°å ¥ã»æŽ»çšããäžã§ãæ¬ ãããªãåææ¡ä»¶ãšãªããŸãã
é«ç²ŸåºŠ IDS ã¯ãã€ã³ããªãžã§ã³ããªè åšæ€ç¥ã·ã¹ãã ã®åŠç¿ããã³éçšã«ãããŠæ¥µããŠéèŠãªåœ¹å²ãæãããŸãã誀æ€ç¥ãæå°éã«æããã¯ãªãŒã³ã§ä¿¡é Œæ§ã®é«ãããŒã¿åºç€ããªããã°ãAI ã¢ã«ãŽãªãºã ã¯ååã«åŠç¿ã§ãããå Žåã«ãã£ãŠã¯æ¢åã®ããã€ãºããå¢å¹ ããŠããŸãããã®äŸ¡å€ãæãªãæãããããŸãã
PlaxidityX ã§ã¯ããã®ååããã§ã« IDS 補åãžé©çšããŠããŸããããšãã°ãçŸåšã®ã«ãŒã«ã»ããã»ã³ã³ãã£ã®ã¥ã¬ãŒã¿ãŒã«ã¯ AI ãæŽ»çšããŠãããè»äž¡éä¿¡ããŒã¿ããŒã¹ïŒDBC ã ARXML ãã¡ã€ã«ãªã©ïŒãã»ãã¥ãªãã£èšå®éã®å¹²æžãæé€ããããã©ãŒãã³ã¹æé©åãèªåã§è¡ããŸãããã® AI ããŒã¹ã®æ©èœã«ãããèªåè»ã¡ãŒã«ãŒã¯ããã 2 é±éçšåºŠã§ IDS ãå°å ¥ããæé©åãããã«ãŒã«ã»ãããçæããããšãå¯èœã«ãªããŸãã
ãŸãšã
çŸä»£ã®é«ç²ŸåºŠ IDS ã¯ã¢ã©ãŒããã€ãºãæå°åããèªåè»ã¡ãŒã«ãŒããã匷åºã§å¹ççããã€ã³ã¹ãå¹çã®é«ãè»èŒãµã€ããŒã»ãã¥ãªãã£éçšãæ§ç¯ããããã®åºç€ãæäŸããŸãã
- âã¢ã©ãŒãç²ãâ ã®åé¿ïŒã»ãã¥ãªãã£ããŒã ãä¿¡é ŒããŠéçšã§ããä»çµã¿ãå°å
¥
- è
åšæ€ç¥åã®åŒ·åïŒèª€æ€ç¥ãžã®å¯Ÿå¿ã§ã¯ãªããçã«å±éºãªè
åšã«ãªãœãŒã¹ãéäž
- éçšã³ã¹ãã®æé©åïŒå€§éã§äœå質ãªã¢ã©ãŒãåŠçã«äŒŽãã³ã¹ããåæžããå¹Žéæ°åäžãã«èŠæš¡ã®ç¯çŽïŒèŠæš¡ã«ããããŸãïŒ
- å°æ¥ãèŠæ®ããã»ãã¥ãªãã£äœå¶ïŒé²åãç¶ãããµã€ããŒã»ãã¥ãªãã£ååã«é©åããAI äž»å°ã®é«åºŠãªé²åŸ¡ãå®çŸããããã®åå°ãæ§ç¯
IDS ã®èª€æ€ç¥ã¯ãè»äž¡ã©ã€ããµã€ã¯ã«å šäœã«ããã èªåè»ã¡ãŒã«ãŒã®éçšã³ã¹ããžå€§ããªåœ±é¿ãäžããŸããããã¯ãè»äž¡ããªãŒãåãã® IDS ãœãªã¥ãŒã·ã§ã³ãè©äŸ¡ããéã«æ±ºããŠèŠéãããŠã¯ãªããªãéèŠãªèŠçŽ ã§ããå ç¢ã§é«ç²ŸåºŠãª IDS ã«æè³ããããšã¯ãçŸåšã®ããªãŒãéçšã«ãããç·ä¿æã³ã¹ãïŒTCOïŒãåæžããã ãã§ãªããå°æ¥çãªAIãæŽ»çšããè åšé²åŸ¡ãžåããæŠç¥çãªã¹ãããã«ããªããŸãã
åœç€Ÿã® CAN ããã³ Ethernet è»èŒãããã¯ãŒã¯åãé«ç²ŸåºŠ IDS ãœãªã¥ãŒã·ã§ã³ã®è©³çްã«ã€ããŠã¯ããã²ãªã³ã¯ããã芧ãã ããã
å·çïŒ2025幎11æ17æ¥