攻撃の真実: 進化する攻撃に打ち勝つ

:
2015
Traps
2 | ©2014, Palo Alto Networks. Confidential and Proprietary.
9
IoT
IT
/
3 | ©2014, Palo Alto Networks. Confidential and Proprietary.
$$$
:
! 
! 
! 
(
)
=
7 | ©2014, Palo Alto Networks. Confidential and Proprietary.
|
SLIDESOURCE
>
! 
>
! 
! 
|
RSS
(
|
CIO
12,000 )
IPS
Web
Google
1
2
2012-0158/2010-3333
:
! 
:
! 
:
! 
! 
! 
Web
USB
/
:
:
CEO
http://...
Web
(PoisonIvy)
OS
! 
! 
! 
!  Web
19 | ©2014, Palo Alto Networks. Confidential and Proprietary.
(CyberGate)
(NetWire)
21 | ©2014, Palo Alto Networks. Confidential and Proprietary.
:
• 
• 
• 
• 
Android
[…] $4,000
• 
• 
• 
[…] $15,000
23 | ©2014, Palo Alto Networks. Confidential and Proprietary.
:
AV
URL DNS
! 
! 
! 
! 
! 
! 
25 | ©2014, Palo Alto Networks. Confidential and Proprietary.
26 | ©2014, Palo Alto Networks. Confidential and Proprietary.
:
Traps (
)
–
! 
–
! 
–
! 
–
! 
–
! 
lto Networks. Confidential and Proprietary.
DEP
1.
PDF
2. PDF
Reader
Acrobat
OS
3.
4.
! 
! 
! 
...
1.
PDF
2. PDF
Reader
Acrobat
3.
4.
1.
DEP
1.
PDF
2. PDF
Reader
Acrobat
3.
4.
1.
2.
EPM 1
: Carbanak
2013
12
CVE-2012-0158
CVE-2013-3906
CVE-2014-1761
Carbanak
+
+
+
100
10
Carbanak
Traps
CVE-2012-1058
Memory
Limit Heap
Spray Check
CVE-2013-3906
Memory Limit
Heap Spray
Check and
Shellcode
Preallocation
CVE-2014-1761
DEP
UASLR
1
DEP
ROP
ROP
UASLR
ROP/OS
ROP
Mitigation OS
ROP
Mitigation
DLL
Security
OS
ROP Mitigation/
DLL Security
DLL
Security
DLL
Security
:
LightsOut
2014
2
CVE-2012-1723
CVE-2013-1347
CVE-2013-1690
CVE-2013-2465
http://...
http://...
39essex[.]com
Java IE
Adobe Reader
LightsOut
Traps
Java
Java
Java
CVE-2012-1723
CVE-2013-1465
CVE-2014-1761
CVE-2014-1761
CVE-2013-1347
CVE-2013-1347
Java
DEP
Java
UASLR
Shellcode
Preallocation
ROP
DEP
ROP
Mitigation
UASLR
DLL
Security
OS
ROP/OS
DLL
Security
ROP Mitigation/
DLL Security
- GameOverZeus
Zeus Temp
Zeus
explorer.exe
explorer.exe
Zeus
%USERPROFILE%\AppData\Local\Temp
.exe
: GameOverZeus
1
%USERPROFILE%\AppData\Local\Temp
Local\Temp
2
.exe
explorer.exe
:
Traps
10
1
2
3
1
2
WildFire
3
WildFire
WildFire
OS
JIT
Traps
Traps
LAN
/
/
VM
! 
! 
! 
! 
38 | ©2014, Palo Alto Networks. Confidential and Proprietary.
1
39 | ©2014, Palo Alto Networks. Confidential and Proprietary.
40 | ©2014, Palo Alto Networks. Confidential and Proprietary.
2
3
4