{"id":2839,"date":"2021-03-09T12:06:34","date_gmt":"2021-03-09T12:06:34","guid":{"rendered":"https:\/\/partnernews.sophos.com\/ja-jp\/?p=2839"},"modified":"2021-03-12T10:37:20","modified_gmt":"2021-03-12T10:37:20","slug":"how-to-protect-your-customers-from-hafnium","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/ja-jp\/2021\/03\/resources\/how-to-protect-your-customers-from-hafnium\/","title":{"rendered":"\u30cf\u30d5\u30cb\u30a6\u30e0\u304b\u3089\u304a\u5ba2\u69d8\u3092\u5b88\u308b\u65b9\u6cd5"},"content":{"rendered":"<p>2021\u5e74 3\u6708 2\u65e5\u3001Microsoft Exchange \u306b\u5f71\u97ff\u3092\u53ca\u307c\u3059\u30bc\u30ed\u30c7\u30a4\u8106\u5f31\u6027\u304c\u516c\u958b\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u3092\u3001\u56fd\u5bb6\u306e\u8105\u5a01\u6d3b\u52d5\u5bb6\u3068\u8003\u3048\u3089\u308c\u308b\u30cf\u30d5\u30cb\u30a6\u30e0\u304c\u7a4d\u6975\u7684\u306b\u60aa\u7528\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\n<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/03\/02\/microsoft-releases-out-band-security-updates-exchange-server\" target=\"_blank\" rel=\"noopener\">CISA \u306e\u901a\u77e5<\/a>\u3067\u306f\u3001\u6b21\u306e\u3088\u3046\u306b\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u300c<em>\u30de\u30a4\u30af\u30ed\u30bd\u30d5\u30c8\u306f\u3001 Microsoft Exchange Server 2013\u3001 2016\u3001 2019 \u306b\u5f71\u97ff\u3059\u308b\u8106\u5f31\u6027\u306b\u5bfe\u51e6\u3059\u308b\u305f\u3081\u306b\u3001\u5e2f\u57df\u5916\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u30ea\u30ea\u30fc\u30b9\u3057\u307e\u3057\u305f\u3002\u30ea\u30e2\u30fc\u30c8\u653b\u6483\u8005\u306f\u3001\u5f71\u97ff\u3092\u53d7\u3051\u305f\u30b7\u30b9\u30c6\u30e0\u3092\u5236\u5fa1\u3059\u308b\u305f\u3081\u306b 3\u3064\u306e\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u306e\u8106\u5f31\u6027\u3067\u3042\u308b CVE-2021-26857\u3001CVE-2021-26858 \u304a\u3088\u3073 CVE-2021-27065 \u3092\u60aa\u7528\u3057\u305f\u308a\u3001\u6a5f\u5bc6\u60c5\u5831\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u305f\u3081\u306b\u3001\u8106\u5f31\u6027 CVE-2021-26855 \u3092\u60aa\u7528\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<strong><i>\u73fe\u5728\u3001\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u3092\u3001\u7a4d\u6975\u7684\u306b\u60aa\u7528\u3059\u308b\u6d3b\u52d5\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059<\/i><\/strong>\u3002<\/em>\u300d<\/p>\n<p>\u95a2\u9023\u3059\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u3066\u3001\u653b\u6483\u8005\u304c\u30b7\u30b9\u30c6\u30e0\u5185\u306b\u5b58\u5728\u3059\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3059\u308b\u4e00\u65b9\u3001\u7d44\u7e54\u306b\u306f\u30aa\u30f3\u30d7\u30ec\u30df\u30b9\u306e Exchange Server \u306b\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3059\u308b\u3088\u3046\u306b <a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/03\/03\/cisa-issues-emergency-directive-and-alert-microsoft-exchange\" target=\"_blank\" rel=\"noopener\">CISA \u306f\u3001\u7dca\u6025\u6307\u4ee4\u3092\u767a\u884c\u3057\u307e\u3057\u305f<\/a>\u3002<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<h2><strong>\u30bd\u30d5\u30a9\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u4f55\u3092\u3059\u3079\u304d\u3067\u3059\u304b\uff1f<\/strong><\/h2>\n<p><strong>Sophos MTR \u30c1\u30fc\u30e0\u306f\u3001\u304a\u5ba2\u69d8\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3067\u611f\u67d3\u3092\u793a\u5506\u3059\u308b\u5146\u5019\u3092\u691c\u7d22\u3059\u308b\u65b9\u6cd5\u306b\u3064\u3044\u3066\u3001<\/strong><a href=\"https:\/\/news.sophos.com\/ja-jp\/2021\/03\/10\/hafnium-advice-about-the-new-nation-state-attack-jp\/\" target=\"_blank\" rel=\"noopener\"><strong>\u8a73\u7d30\u306a\u624b\u9806<\/strong><\/a><strong>\u3092\u516c\u958b\u3057\u3066\u3044\u307e\u3059\u3002<\/strong><\/p>\n<p>\u5e78\u3044\u306a\u3053\u3068\u306b\u3001Sophos MTR\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3001\u304a\u3088\u3073\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306e\u304a\u5ba2\u69d8\u306f\u3001\u65b0\u3057\u3044\u8106\u5f31\u6027\u306e\u60aa\u7528\u306b\u5bfe\u3057\u3066\u8907\u6570\u306e\u4fdd\u8b77\u3092\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u4fdd\u8b77\u306e\u591a\u304f\u306b\u3064\u3044\u3066\u66f8\u304b\u308c\u305f<a href=\"https:\/\/news.sophos.com\/ja-jp\/2021\/03\/10\/protecting-sophos-customers-from-hafnium-jp\/\" target=\"_blank\" rel=\"noopener\">\u30bd\u30d5\u30a9\u30b9\u30cb\u30e5\u30fc\u30b9\u306e\u8a18\u4e8b<\/a>\u304c\u516c\u958b\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<ul>\n<li>\u30cf\u30d5\u30cb\u30a6\u30e0\u3092\u30d6\u30ed\u30c3\u30af\u3057\u305f\u95a2\u9023 AV \u30b7\u30b0\u30cd\u30c1\u30e3\u3001\u304a\u3088\u3073\u305d\u306e\u30b7\u30b0\u30cd\u30c1\u30e3\u304c\u30c8\u30ea\u30ac\u30fc\u3055\u308c\u305f\u5834\u5408\u306e\u5bfe\u51e6\u65b9\u6cd5\u306b\u3064\u3044\u3066\u306e\u30a2\u30c9\u30d0\u30a4\u30b9<\/li>\n<li>Sophos EDR \u306e\u304a\u5ba2\u69d8\u304c\u3001\u8abf\u67fb\u306b\u5411\u3051\u3066\u6f5c\u5728\u7684\u306a Web\u30b7\u30a7\u30eb\u3092\u7279\u5b9a\u3059\u308b\u305f\u3081\u306b\u5b9f\u884c\u3059\u308b\u30af\u30a8\u30ea<\/li>\n<li>Sophos Firewall \u306e\u304a\u5ba2\u69d8\u5411\u3051\u306e IPS \u30b7\u30b0\u30cd\u30c1\u30e3<\/li>\n<\/ul>\n<p>MTR \u306e\u304a\u5ba2\u69d8\u306b\u306f\u3001\u554f\u984c\u3084\u304a\u5ba2\u69d8\u306e\u4fdd\u8b77\u3092\u7dad\u6301\u3059\u308b\u305f\u3081\u306b MTR \u304c\u4f55\u3092\u884c\u3046\u304b\u306e\u6982\u8981\u306b\u3064\u3044\u3066\u8907\u6570\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u52e7\u544a\u3092\u3059\u3067\u306b\u9001\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Sophos MTR (Managed Threat Response) \u3068 Rapid Response<\/strong><\/h2>\n<p>\u7d44\u7e54\u306f\u3001\u904e\u53bb\u6570\u65e5\u9593\u306b\u308f\u305f\u308a\u3001\u30bd\u30d5\u30a9\u30b9\u304c\u516c\u958b\u3092\u691c\u8a3c\u3067\u304d\u308b\u30b5\u30fc\u30d3\u30b9\u306b\u3064\u3044\u3066\u3001\u3088\u308a\u591a\u304f\u306e\u60c5\u5831\u3092\u6c42\u3081\u3066\u304d\u307e\u3057\u305f\u3002<strong>Sophos MTR Advanced<\/strong> \u306f\u3001\u30cf\u30d5\u30cb\u30a6\u30e0\u306e\u3088\u3046\u306a\u9ad8\u5ea6\u306a\u653b\u6483\u306b\u5bfe\u3057\u3066\u4fdd\u8b77\u3057\u7d9a\u3051\u308b\u7406\u60f3\u7684\u306a\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3067\u3059\u3002<\/p>\n<p>\u65e2\u5b58\u306e MTR \u306e\u304a\u5ba2\u69d8\u306f\u3001MTR \u304c\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306b\u3042\u308b\u95a2\u9023\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u8fc5\u901f\u306b\u691c\u7d22\u3057\u3066\u3044\u305f\u306e\u3092\u77e5\u3063\u3066\u3044\u308b\u306e\u3067\u3001\u5b89\u5fc3\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>MTR \u4ee5\u5916\u306e\u304a\u5ba2\u69d8\u306b\u3001\u3082\u3057\u95a2\u9023\u3057\u305f\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u7d4c\u9a13\u3057\u3066\u3044\u308b\u5146\u5019\u304c\u898b\u3089\u308c\u308b\u5834\u5408\u306f\u3001\u3059\u3050\u306b <a href=\"https:\/\/www.sophos.com\/ja-jp\/products\/managed-threat-response\/rapid-response.aspx\" target=\"_blank\" rel=\"noopener\">Sophos Rapid Response \u30c1\u30fc\u30e0<\/a>\u306b\u9023\u7d61\u3059\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>2021\u5e74 3\u6708 2\u65e5\u3001Microsoft Exchange \u306b\u5f71\u97ff\u3092\u53ca\u307c\u3059\u30bc\u30ed\u30c7\u30a4\u8106\u5f31\u6027\u304c\u516c\u958b\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u3092\u3001\u56fd\u5bb6\u306e\u8105\u5a01\u6d3b\u52d5\u5bb6\u3068\u8003\u3048\u3089\u308c\u308b\u30cf\u30d5\u30cb\u30a6\u30e0\u304c\u7a4d\u6975\u7684\u306b\u60aa\u7528\u3057\u3066\u3044\u307e\u3059\u3002 CISA \u306e\u901a\u77e5\u3067\u306f\u3001\u6b21\u306e\u3088\u3046\u306b\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002 \u300c\u30de\u30a4\u30af\u30ed\u30bd\u30d5\u30c8\u306f\u3001 Microsoft Exchange Server 2013\u3001 2016\u3001 2019 \u306b\u5f71\u97ff\u3059\u308b\u8106\u5f31\u6027\u306b\u5bfe\u51e6\u3059\u308b\u305f\u3081\u306b\u3001\u5e2f\u57df\u5916\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u30ea\u30ea\u30fc\u30b9\u3057\u307e\u3057\u305f\u3002\u30ea\u30e2\u30fc\u30c8\u653b\u6483\u8005\u306f\u3001\u5f71\u97ff\u3092\u53d7\u3051\u305f\u30b7\u30b9\u30c6\u30e0\u3092\u5236\u5fa1\u3059\u308b\u305f\u3081\u306b 3\u3064\u306e\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u306e\u8106\u5f31\u6027\u3067\u3042\u308b CVE-2021-26857\u3001CVE-2021-26858 \u304a\u3088\u3073 CVE-2021-27065 \u3092\u60aa\u7528\u3057\u305f\u308a\u3001\u6a5f\u5bc6\u60c5\u5831\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u305f\u3081\u306b\u3001\u8106\u5f31\u6027 CVE-2021-26855 \u3092\u60aa\u7528\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u73fe\u5728\u3001\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u3092\u3001\u7a4d\u6975\u7684\u306b\u60aa\u7528\u3059\u308b\u6d3b\u52d5\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u300d \u95a2\u9023\u3059\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u3066\u3001\u653b\u6483\u8005\u304c\u30b7\u30b9\u30c6\u30e0\u5185\u306b\u5b58\u5728\u3059\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3059\u308b\u4e00\u65b9\u3001\u7d44\u7e54\u306b\u306f\u30aa\u30f3\u30d7\u30ec\u30df\u30b9\u306e Exchange Server \u306b\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3059\u308b\u3088\u3046\u306b CISA \u306f\u3001\u7dca\u6025\u6307\u4ee4\u3092\u767a\u884c\u3057\u307e\u3057\u305f\u3002 \u00a0 \u30bd\u30d5\u30a9\u30b9\u306e\u304a\u5ba2\u69d8\u306f\u4f55\u3092\u3059\u3079\u304d\u3067\u3059\u304b\uff1f Sophos MTR \u30c1\u30fc\u30e0\u306f\u3001\u304a\u5ba2\u69d8\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3067\u611f\u67d3\u3092\u793a\u5506\u3059\u308b\u5146\u5019\u3092\u691c\u7d22\u3059\u308b\u65b9\u6cd5\u306b\u3064\u3044\u3066\u3001\u8a73\u7d30\u306a\u624b\u9806\u3092\u516c\u958b\u3057\u3066\u3044\u307e\u3059\u3002 \u5e78\u3044\u306a\u3053\u3068\u306b\u3001Sophos MTR\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3001\u304a\u3088\u3073\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306e\u304a\u5ba2\u69d8\u306f\u3001\u65b0\u3057\u3044\u8106\u5f31\u6027\u306e\u60aa\u7528\u306b\u5bfe\u3057\u3066\u8907\u6570\u306e\u4fdd\u8b77\u3092\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u3002 \u3053\u308c\u3089\u306e\u4fdd\u8b77\u306e\u591a\u304f\u306b\u3064\u3044\u3066\u66f8\u304b\u308c\u305f\u30bd\u30d5\u30a9\u30b9\u30cb\u30e5\u30fc\u30b9\u306e\u8a18\u4e8b\u304c\u516c\u958b\u3055\u308c\u307e\u3057\u305f\u3002 \u30cf\u30d5\u30cb\u30a6\u30e0\u3092\u30d6\u30ed\u30c3\u30af\u3057\u305f\u95a2\u9023 AV \u30b7\u30b0\u30cd\u30c1\u30e3\u3001\u304a\u3088\u3073\u305d\u306e\u30b7\u30b0\u30cd\u30c1\u30e3\u304c\u30c8\u30ea\u30ac\u30fc\u3055\u308c\u305f\u5834\u5408\u306e\u5bfe\u51e6\u65b9\u6cd5\u306b\u3064\u3044\u3066\u306e\u30a2\u30c9\u30d0\u30a4\u30b9 Sophos [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":300000351,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3],"tags":[28,77,21],"coauthors":[43],"class_list":["post-2839","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-resources","tag-managed-threat-response","tag-rapid-response","tag-threats-malware"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2019\/11\/featured-image-cybersecurity.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/posts\/2839","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/comments?post=2839"}],"version-history":[{"count":2,"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/posts\/2839\/revisions"}],"predecessor-version":[{"id":2841,"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/posts\/2839\/revisions\/2841"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/media?parent=2839"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/categories?post=2839"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/tags?post=2839"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/ja-jp\/wp-json\/wp\/v2\/coauthors?post=2839"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}