ãã®æçš¿ã¯ãAWS ãš Fortinet ã®ä»¥äžã®æ
åœè
ãå
±åã§å·çããŸããïŒ Ferry Mulyadi, Principal Partner Solution Architect, AWS Derek Ewell, Principal Partner Solution Architect, AWS Julian Petersohn, Global SAP Engineer, Fortinet Fabian Lee, Solution Architect, AWS Introduction CyberCrime ã®ç·šéé·ã¹ãã£ãŒãã»ã¢ãŒã¬ã³ã«ãããšãã ãµã€ããŒç¯çœªã¯2025幎ãŸã§ã«å¹Žé10.5å
ãã«ã®ã³ã¹ããäžçã«ãããã ã-ããã¯ç±³åœãäžåœã«æ¬¡ãã§äžç第3äœã®çµæžèŠæš¡ã«çžåœããŸããSAP ã·ã¹ãã ã«ã¯ããã·ã§ã³ã¯ãªãã£ã«ã«ãªããŒã¿ãæ ŒçŽãããŠããããã®ããŒã¿ã¯æ©å¯æ§ãé«ãããšãå€ããããæªè³ªã®ããæ»æè
ã«ãšã£ãŠæ Œå¥œã®æšçãšãªã£ãŠããŸããS/4HANA ãžã®ã¢ããã€ãŒãŒã·ã§ã³ãé²ããŠãã SAP ã®ã客æ§ã«ãšã£ãŠãã»ãã¥ãªãã£ãªã¹ã¯ã®ç¶æ³ã¯ãSAP FioriãWeb ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ãã¢ãã€ã«ããã€ã¹ãã·ã¹ãã ã€ã³ã¿ãŒãã§ã€ã¹ãSAP ã¢ããªã±ãŒã·ã§ã³ã«æ¥ç¶ãããã¯ã©ãŠããµãŒãã¹ãªã©ãæ°ããªé åã«ç§»è¡ãã€ã€ãããŸãããã®ãããSAP ã®ã客æ§ã¯æçµçã«ãããžãã¹ã¯ãªãã£ã«ã«ãªãšã³ã¿ãŒãã©ã€ãºã·ã¹ãã ã«å¯ŸããŠãã»ãã¥ãªãã£ã¢ããããŒã以å€ã®è¿œå ã®ã»ãã¥ãªãã£ç®¡çã宿œããå¿
èŠã«è¿«ãããŸããSAP ã®ã客æ§ãæ¯æŽããããã«ãæã
㯠AWS Network Firewall ãã©ã®ããã« SAP on AWS ãããã€ã¡ã³ãã«å¯Ÿããã»ãã¥ãªãã£ãåäžãããããšãã§ãããã«ã€ããŠããã°ãã·ãªãŒãºã§è€æ°æžããŸããã æåã®ããã° ã§ã¯ãéåä¿¡ã€ã³ã¿ãŒãã§ãŒã¹ãSAP ãµããŒãããªã¢ãŒããŠãŒã¶ãŒãã¢ãã€ã«ã¢ã¯ã»ã¹ãSAP BTP çµ±åãªã©ã® SAP ã®ãŠãŒã¹ã±ãŒã¹ã«åºã¥ããŠãSAP ã®ã客æ§ã«ãããã€å¯èœãªæ§ã
ãªã¢ãŒããã¯ãã£ãã¿ãŒã³ã«ã€ããŠèª¬æããŸããããã®ã¢ãŒããã¯ãã£ãã¿ãŒã³ã¯ã AWS Security Reference Architecture (SRA) ãš AWS Network Firewall ã䜿ã£ã Inspection Deployment Models ã«åºã¥ããŠãããæªæã®ããæ»æè
ã SAP ã·ã¹ãã ã®ããã©ãŒãã³ã¹ãå¯çšæ§ã«åœ±é¿ãäžããã®ãé²ããSAP ã·ã¹ãã ããã®ããŒã¿çé£ãé²ããŸããCustomer Obsessionã貫ãç§ãã¡ã¯ãAWS Network Firewall ã®ãããã€é床ãåäžãããããã«ã©ã®ãããªæ¯æŽãã§ããããåžžã«ã客æ§ãããŒãããŒæ§ã®å£°ã«è³ãåŸããŠããŸããç§ãã¡ã Network Firewall ãéçºãããšããã¿ã¹ã¯ã® 1 ã€ã¯ SAP ãããã¯ãŒã¯ãã©ãã£ãã¯ããã现ããå¶åŸ¡ãããã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ãå®çŸ©ããããšã§ãããŒãããå§ããå Žåããã®äœæ¥ã¯å€§å€ã§ãã AWS ãããŒãžãã«ãŒã« ã¯ãAWS ãäœæã»ç®¡çããããã«äœ¿ããã«ãŒã«ã§ãããAWS ã®ã客æ§ãç¡æã§å©çšã§ããããããããã®ãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã®å®è£
ãããã«å§ããããšãã§ããŸãããŸããã«ã¹ã¿ã ã«ãŒã«ãšããŒãããŒãããŒãžãã«ãŒã«ã«ã€ããŠã説æããŸãã®ã§ãçµç¹ã®ã»ãã¥ãªãã£ããŒãºã«åãããŠããå°éçãªã«ãŒã«ãå°å
¥ããããšãã§ããŸãããã®ããã°ã§ã¯ãFortinet ãæåŸ
ããAmazon Network Firewall çšã®ãããŒãžã IDS ãš IPS ã«ãŒã«ã«ã€ããŠå
±æããŸãã Network Firewall ã® AWS ãããŒãžãã«ãŒã« AWS Network Firewall ã¯ãæè»ãªãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ãšã³ãžã³ãæäŸãããã现ããªãããã¯ãŒã¯ä¿è·ãå®çŸããŸããNetwork Firewall ã® AWS ãããŒãžãã«ãŒã«ã¯ããããããå®çŸ©ãããããã«äœ¿ãããã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã§ããæ°ããè匱æ§ãè
åšãåºçŸãããšãAWS ã¯èªåçã«ãããŒãžãã«ãŒã«ã°ã«ãŒããæŽæ°ããŸãã AWS ãããŒãžãã«ãŒã«ã°ã«ãŒãã¯ãã¢ããªã±ãŒã·ã§ã³ã«ã»ãã¥ãªãã£ã®å¥ã®ã¬ã€ã€ãŒã远å ããããšã§ãäžè¬çãªè
åšãããšã³ã¿ãŒãã©ã€ãºã¯ãŒã¯ããŒããä¿è·ããããã«èšèšãããŠããŸãããã ããAWS ãããŒãžãã«ãŒã«ã°ã«ãŒãã¯ãã客æ§ã®ã»ãã¥ãªãã£è²¬ä»»ã代æ¿ãããã®ã§ã¯ãããŸãããAWS ã®ãªãœãŒã¹ãé©åã«ä¿è·ãããŠããããšã確èªããã«ã¯ã 責任å
±æã¢ãã« ãåç
§ããŠãã ããã çŸåšãAWS ã®ãããŒãžãã«ãŒã«ã°ã«ãŒãã«ã¯ä»¥äžã®ãã®ããããŸãïŒ Domain List Rule Groups : HTTP ãŸã㯠HTTPS ã®ãã¡ã€ã³åã«åºã¥ããŠãã©ãã£ãã¯ãèå¥ãããããã¯ããŸãã Threat Signature Rule Groups : Threat signature ã®ããã€ãã®ã«ããŽãªã«åºã¥ããŠãã©ãã£ãã¯ãèå¥ãããããã¯ããŸãã ãããŒãžã ãã¡ã€ã³ãªã¹ã ã«ãŒã«ã°ã«ãŒã (Egress Filtering) ãã¡ã€ã³ãªã¹ãã«ãŒã«ã¯ãã¬ãã¥ããŒã·ã§ã³ãäœãããŸãã¯ãã«ãŠã§ã¢ããããããããšã®é¢é£ãç¥ãããŠããããŸãã¯çãããŠãããã¡ã€ã³ãžã® HTTP ãŸã㯠HTTPS ãã©ãã£ãã¯ããããã¯ããŸãããããã®ã«ãŒã«ã°ã«ãŒããã A2. ã€ã³ã¿ãŒããããšã°ã¬ã¹ã¢ã¯ã»ã¹ã®ã¢ãŒããã¯ãã£èšèšãã¿ãŒã³ ãïŒãã®ããã°ã·ãªãŒãºã®ããŒã1ïŒã䜿çšããŠãããã®ã«ãŒã«ã°ã«ãŒããå±éãããšãSAP ç°å¢ããçºä¿¡ãããçããããšã°ã¬ã¹ ãã©ãã£ãã¯ããããã¯ã§ããŸãã ã«ãŒã«å 説æ AbusedLegitBotNetCommandAndControlDomainsActionOrderRules äžè¬çã«ã¯åæ³çã ããå±éºã§ããããããããã¹ãããŠããå¯èœæ§ããããã¡ã€ã³ã®ã¯ã©ã¹ãžã®ãªã¯ãšã¹ãããããã¯ã§ããã«ãŒã« MalwareDomainsActionOrder ãã«ãŠã§ã¢ããã¹ãããŠããããšãç¥ãããŠãããã¡ã€ã³ãžã®ãªã¯ãšã¹ãããããã¯ã§ããã«ãŒã« AbusedLegitMalwareDomainsActionOrder äžè¬çã«ã¯åæ³ã ããå±éºã§ãã«ãŠã§ã¢ããã¹ãããŠããå¯èœæ§ããããã¡ã€ã³ã®ã¯ã©ã¹ãžã®ãªã¯ãšã¹ãããããã¯ã§ããã«ãŒã« BotNetCommandAndControlDomainsActionOrder ããããããããã¹ãããŠããããšãç¥ãããŠãããã¡ã€ã³ãžã®ãªã¯ãšã¹ãããããã¯ã§ããã«ãŒã« AWS Network Firewall ã¯ãHTTPS ã® TLS ããŽã·ãšãŒã·ã§ã³äžã« Server Name Indication (SNI) ãšã¯ã¹ãã³ã·ã§ã³ã«ãã£ãŠãHTTP ãã©ãã£ãã¯ã®ãã¹ããããã«ãã£ãŠãªã¯ãšã¹ãã®ãã¡ã€ã³åãæ±ºå®ããŸããDNS 解決ã¬ãã«ã§ãã¡ã€ã³ããã£ã«ã¿ãªã³ã°ããã«ã¯ãAmazon Route 53 Resolver DNS Firewall ã Amazon Network Firewall ã«ãŒã«ãšçµã¿åãããŠæŽ»çšããããšã§ãããã«ä¿è·ããããšãã§ããŸããïŒ Amazon Route 53 Resolver DNS Firewall ã§ Amazon VPC ã® DNS 解決ãä¿è· SAP ã«é©çšå¯èœãªè
åšã·ã°ããã£ã®ã«ãŒã«ã°ã«ãŒã AWS Network Firewall ã管çããè
åšã·ã°ããã£ã®ã«ãŒã«ã°ã«ãŒãã¯ãæ§ã
ãªã¿ã€ãã®ãã«ãŠã§ã¢ããšã¯ã¹ããã€ãããµãŒãã¹æåŠããããããããWeb æ»æãã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°ãã¹ãã£ã³ããŒã«ãã¡ãŒã«ãã¡ãã»ãŒãžã³ã°æ»æããä¿è·ããããã«ãããã€ãã®ã«ããŽãªã®è
åšã·ã°ããã£ããµããŒãããŠããŸãããŸãã䟵å
¥æ€ç¥ãå
¬æ£äœ¿çšããªã·ãŒã®é©çšãæ°ããªè
åšã«å¯Ÿããé²åŸ¡ã®ããã®ã·ã°ããã£ããããŸããçŸåšãNetwork Firewall 㯠Suricata äºæã®ã¹ããŒããã« ãããŒãžãã«ãŒã«ã°ã«ãŒãã®ã¿ããµããŒãããŠããŸãã äžè¡šã®ã«ãŒã«ã¯ãSAP ã®æè¡ã¹ã¿ãã¯ã«æå®³ãªæ¢ç¥ã®ã·ã°ããã£ãæã€æªæã®ãããªã¯ãšã¹ãããããã¯ããŸãã以äžã®ãããªã«ãŒã«ã¯ SAP ã®ãŠãŒã¹ã±ãŒã¹ãšã¯é¢ä¿ãªãããé€å€ããŠããŸãïŒ ãã«ãŠã§ã¢ã³ã€ã³ãã€ãã³ã°ãVOIPãã²ãŒã ãäžé©åãP2Pãå®è£
ã³ã¹ããæé©åããããã«ã該åœãããããã®ã«ãŒã«ãäºåã«éžæããããšãã§ããŸãã ã«ããŽãª ã«ãŒã«å Botnet ThreatSignaturesBotnet â ã¢ã¯ãã£ããªããããããããã®ä»ã®ã³ãã³ãïŒã³ã³ãããŒã«ïŒC2ïŒãã¹ãã®æ¢ç¥ããã³ç¢ºèªãããè€æ°ã®ãœãŒã¹ããèªåçæãããã·ã°ãã㣠Botnet Web ThreatSignaturesBotnetWeb â HTTP ãããããããæ€åºããã·ã°ãã㣠Compromised ThreatSignaturesIOC â æ»æã¬ã¹ãã³ã¹ â LMHost ãã¡ã€ã«ã®ããŠã³ããŒããç¹å®ã®ãŠã§ããããŒã®ååšãMetasploit Meterpreter kill ã³ãã³ãã®æ€åºãªã©ã䟵å
¥ã瀺ãã¬ã¹ãã³ã¹ãèå¥ããããã®ã·ã°ãã㣠ãšã¯ã¹ããã€ãããã â ãšã¯ã¹ããã€ããããããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãé
ä¿¡ã«é¢é£ããæŽ»åãæ€ç¥ããããã®ã·ã°ãã㣠DoS ThreatSignaturesDoS â ãµãŒãã¹æåŠïŒDoSïŒã®è©Šã¿ãæ€åºããã·ã°ãã㣠Emerging Threats ThreatSignaturesEmergingEvents â çŸåšã®ã€ãã³ã â æŽ»çºã§çæéã®ãã£ã³ããŒã³ããäžæçãªãã®ãšäºæ³ãããæ³šç®åºŠã®é«ãé
ç®ã«å¯Ÿå¿ããŠéçºãããã«ãŒã«ãæã€çœ²å DoS ThreatSignaturesDoS â ãµãŒãã¹æåŠïŒDoSïŒã®è©Šã¿ãæ€åºããã·ã°ãã㣠Exploits ThreatSignaturesExploits â ãšã¯ã¹ããã€ã â ç¹å®ã®ãµãŒãã¹ã»ã«ããŽãªã§ã«ããŒãããŠããªãçŽæ¥çãªãšã¯ã¹ããã€ãããä¿è·ããã·ã°ããã£ãActiveXãFTPãICMPãNetBIOSããªã¢ãŒãã»ããã·ãŒãžã£ã»ã³ãŒã«ïŒRPCïŒãShellCodeïŒãªã¢ãŒãã»ã·ã§ã«ã³ãŒãæ€åºïŒãSNMPïŒSimple Network Management ProtocolïŒãTelnetãTFTPïŒTrivial File Transport ProtocolïŒãSQLïŒStructured Query LanguageïŒ Malware ThreatSignaturesMalware â ãã«ãŠã§ã¢ãæ€åºããã·ã°ããã£ïŒTCPãUDPãSMTPãICMPãSMBãIPïŒããã³ WORMããã«ãŠã§ã¢ â æªæã®ãããœãããŠã§ã¢ãæ€åºããŸãããã®ã«ããŽãªã®ã«ãŒã«ã¯ããããã¯ãŒã¯äžã§æ€åºãããæªæã®ãããœãããŠã§ã¢ã«é¢é£ããã¢ã¯ãã£ããã£ãæ€åºããŸããã¯ãŒã â è匱æ§ãæªçšããŠã€ã³ã¿ãŒãããå
šäœãŸãã¯ãããã¯ãŒã¯å
ã«èªåçã«æ¡æ£ããããšããæªæã®ããã¢ã¯ãã£ããã£ãæ€åºããŸãã Malware Mobile ThreatSignaturesMalwareMobile â Google AndroidãApple iOS ãªã©ã®ã¢ãã€ã«ããã³ã¿ãã¬ãã OS ã«é¢é£ãããã«ãŠã§ã¢ã瀺ãã·ã°ãã㣠Malware Web ThreatSignaturesMalwareWeb â HTTP ãš TLS ãããã³ã«ã®æªæã®ããã³ãŒããæ€åºããã·ã°ãã㣠Phishing ThreatSignaturesPhishing â ã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°æŽ»åãæ€åºããã·ã°ãã㣠Scanners ThreatSignaturesScanners â NessusãNiktoããã®ä»ã®ããŒãã¹ãã£ã³ããŒã«ãªã©ã®ããŒã«ããã®åµå¯ããããŒãã³ã°ãæ€åºããã·ã°ããã£ããŠãŒã¶ãŒãšãŒãžã§ã³ã â äžå¯©ãªãŠãŒã¶ãŒãšãŒãžã§ã³ããç°åžžãªãŠãŒã¶ãŒãšãŒãžã§ã³ããæ€åºããã·ã°ãã㣠Web Attacks ThreatSignaturesWeb â ãŠã§ãã¯ã©ã€ã¢ã³ã â ãŠã§ããã©ãŠã¶ã CURLãWGET ãªã©ã®ã¯ã©ã€ã¢ã³ãåŽã¢ããªã±ãŒã·ã§ã³ãªã©ã®ãŠã§ãã¯ã©ã€ã¢ã³ãã«é¢ããæ»æãè匱æ§ãæ€åºããã·ã°ããã£ããŠã§ããµãŒã㌠â APACHEãTOMCATãNGINXãMicrosoft Internet Information ServicesïŒIISïŒããã®ä»ã®ãŠã§ããµãŒããŒãœãããŠã§ã¢ãªã©ã®ãŠã§ããµãŒããŒã€ã³ãã©ã¹ãã©ã¯ãã£ã«å¯Ÿããæ»æãæ€åºããã·ã°ããã£ãWeb Specific Apps â ç¹å®ã®Web ã¢ããªã±ãŒã·ã§ã³ã®æ»æãè匱æ§ãæ€åºããã·ã°ããã£ã AWS ãããŒãžãã«ãŒã«ã«ãã AWS Network Firewall ã®ãã¹ã AWS ãããŒãžãã«ãŒã«ãå®è£
ããåŸãã«ãŒã«ã®æ€èšŒãè¡ãããå ŽåããããŸãã以äžã®ãããªããšãã§ããŸãïŒ â ThreatSignaturesWeb â ã«ãŒã«ãäŸã«ããŠã¿ãŸãããã AWS Network Firewall ã«ãã£ãŠãã©ãã£ãã¯ãæ€æ»ããã Fiori ãæäŸãã SAP ãµãŒããŒãããå Žåã curl ã metasploit ãªã©ã®ããŒã«ã䜿ã£ãŠããŠã§ããµãŒããŒã®ã¯ãšãªã»ã°ã¡ã³ãã«ãã€ããŒããæ³šå
¥ããŠã¿ãããšãã§ããŸãã ãã®ããã° ã®äŸãåèã«ããŠãã ããã CloudWatch Logs Log Group ã§ã¢ã©ãŒãã® Log Destination ã«ããããããã®ã衚瀺ããå§ããŸãã æ¬¡ã«ãã·ã°ããã£ãèå¥åãšããŠäœ¿çšããããšã§ãäžèŽãã AWS Network Firewall ãããŒãžãã«ãŒã«ãæ€çŽ¢ããããšãã§ããŸãã以äžã«äŸã瀺ããŸãïŒ "alert": { "action": "blocked", "signature_id": 2811788, "rev": 7, "signature": "ipTIME firmware < 9.58 RCE", "category": "Web Application Attack", "severity": 1, "metadata": { "created_at": [ "2015_07_03" ], "updated_at": [ "2020_10_01" ] } }, "http": { "hostname": "54.179.180.129", "http_port": 80, "url": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh", "http_user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36", "http_method": "POST", "protocol": "HTTP/1.1", "length": 0 }, "files": [ { "filename": "/bin/sh", "sid": [], "gaps": false, "state": "CLOSED", "stored": false, "size": 33, "tx_id": 0 } ], "app_proto": "http" } ã«ã¹ã¿ã ãã¡ã€ã¢ãŒãŠã©ãŒã« ã«ãŒã« AWS Network Firewall ã¯ã 2ã€ã®ã«ãŒã«ãšã³ãžã³ ã䜿çšããŠãã±ãããæ€æ»ããŸãããšã³ãžã³ã¯ããã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒã§èšå®ãããã«ãŒã«ã«åŸã£ãŠãã±ãããæ€æ»ããŸãã ã¹ããŒãã¬ã¹ ã«ãŒã«ãšã³ãžã³ â ãã©ãã£ãã¯ã®æ¹åãããã±ãããæ¢åã®æ¿èªãããæ¥ç¶ã®äžéšã§ãããã©ãããªã©ã®èŠçŽ ãèæ
®ããããšãªããåãã±ãããåå¥ã«æ€æ»ããŸãããããã¯ãŒã¯ãã¡ã€ã¢ãŠã©ãŒã«ã®ã¹ããŒãã¬ã¹ã«ãŒã«ã¯ãAmazon VPC ã®ãããã¯ãŒã¯ã¢ã¯ã»ã¹ã³ã³ãããŒã«ãªã¹ãïŒ ACL ïŒãšåäœãäœ¿ãæ¹ã䌌ãŠããŸãã ã¹ããŒããã« ã«ãŒã«ãšã³ãžã³ â ãã±ããããã©ãã£ãã¯ãããŒã®ã³ã³ããã¹ãã§æ€æ»ããããè€éãªã«ãŒã«ã䜿çšããããšãã§ãããããã¯ãŒã¯ãã©ãã£ãã¯ãèšé²ãããã©ãã£ãã¯ã«é¢ãã Network Firewall ã¢ã©ãŒããèšé²ããããšãã§ããŸããã¹ããŒããã«ã«ãŒã«ã¯ãã©ãã£ãã¯ã®æ¹åãèæ
®ããŸããã¹ããŒããã«ãšã³ãžã³ã¯ããªãŒãã³ãœãŒã¹ã®äŸµå
¥é²åŸ¡ã·ã¹ãã ïŒIPSïŒã§ãã Suricata ãšäºææ§ã®ããã«ãŒã«ã䜿çšããŸãã詳现ã«ã€ããŠã¯ã AWS Network Firewall ã®ã¹ããŒããã« ã«ãŒã«ã°ã«ãŒãã䜿çšãã ãåç
§ããŠãã ããã 以äžã®ããã°ãåèã«ãç¬èªã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãäœæããããšãã§ããŸãïŒ Hands on walkthrough of the AWS Network Flexible rules engine part-1 Hands on walkthrough of the AWS Network Flexible rules engine part-2 SAP ã¢ããªã±ãŒã·ã§ã³ã«é¢é£ããã«ãŒã«ã®äŸïŒ #These example Firewall Rules will alert SQL injection attempts to SAP MaxDB Sybase database as well as SAP Netweaver AS Java Use Case #alert http $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET ATTACK_RESPONSE SAP MaxDB error in HTTP response, possible SQL injection point"; flow:from_server,established; file_data; content:"SQL error"; fast_pattern; content:"POS("; distance:0; pcre:"/SQL error.*POS\([0-9]+\)/m"; threshold:type both,track by_src,count 1,seconds 60; classtype:web-application-attack; sid:2020545; rev:2;) #alert http $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET ATTACK_RESPONSE SAP MaxDB error in HTTP response, possible SQL injection point"; flow:from_server,established; file_data; content:"Warning"; content:"maxdb"; fast_pattern; distance:0; pcre:"/Warning.*maxdb/m"; threshold:type both,track by_src,count 1,seconds 60; classtype:web-application-attack; sid:2020546; rev:2;) #alert http $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET ATTACK_RESPONSE Sybase error in HTTP response, possible SQL injection point"; flow:from_server,established; file_data; content:"Warning"; content:"sybase"; fast_pattern; distance:0; pcre:"/i?Warning.*sybase/m"; threshold:type both,track by_src,count 1,seconds 60; classtype:web-application-attack; sid:2020547; rev:3;) #alert http $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET ATTACK_RESPONSE Sybase error in HTTP response, possible SQL injection point"; flow:from_server,established; file_data; content:"Sybase message"; fast_pattern:only; threshold:type both,track by_src,count 1,seconds 60; classtype:web-application-attack; sid:2020548; rev:2;) #alert http $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET ATTACK_RESPONSE Sybase error in HTTP response, possible SQL injection point"; flow:from_server,established; file_data; content:"Sybase Server message"; fast_pattern:only; threshold:type both,track by_src,count 1,seconds 60; classtype:web-application-attack; sid:2020549; rev:2;) alert http any any -> $HOME_NET any (msg: "ATTACK [PTsecurity] SAP NetWeaver AS Java UDDI 7.11-7.50 SQL Injection (CVE-2016-2386)"; flow: established, to_server; content: "POST"; http_method; content: "/UDDISecurityService/UDDISecurityImplBean"; http_uri; fast_pattern; content: "permissionId"; http_client_body; content: "|27|"; http_client_body; distance: 0; pcre: "/permissionId\s*>[^<]+?\x27/Pi"; reference: cve, 2016-2386; reference: url, github.com/vah13/SAP_exploit; classtype: attempted-recon; reference: url, github.com/ptresearch/AttackDetection; sid: 10002408; rev: 1; ) ããŒãã㌠ãããŒãžã ã«ãŒã« ã»ãã¥ãªãã£ã®ããŒãºãããã«å©çšã§ãã AWS ãããŒãžãã«ãŒã«ãè¶
ããŠããå Žåã ããŒãããŒã®æäŸãããœãªã¥ãŒã·ã§ã³ ãæŽ»çšããããšãã§ããŸãããã®ããã°ã§ã¯ãAWS ããŒãããŒã§ãã Fortinet ã®ãããŒãžã IDS ãš IPS ã«ãŒã«ãåãäžããŸãã Fortinet Managed IPS Rules for AWS Firewall ã¯ãAWS Network Firewall ã®ããã®èšå®æžã¿ã®ã«ãŒã«ã»ãããæäŸããæ§ã
ãªãããã¯ãŒã¯æ»æãæ€ç¥ã鲿¢ããããã«èšèšãããŠããŸãããããã®ã«ãŒã«ã¯ãæ¢ç¥ã®è匱æ§ããšã¯ã¹ããã€ããWeb ã¢ããªã±ãŒã·ã§ã³æ»æã ãã§ãªããåŸæ¥ã®ã»ãã¥ãªãã£å¯Ÿçã§ã¯æ€åºãå°é£ãªæªç¥ã®ãšã¯ã¹ããã€ãã§ãããŒããã€æ»æãããä¿è·ããããã«äœ¿çšã§ããŸãã Fortinet ã®ãããŒãžã IPS ã«ãŒã«ã¯ãFortiGuard Labs ãæäŸããææ°ã®è
åšã€ã³ããªãžã§ã³ã¹ããŒã¿ã«åºã¥ããŠå®æçã«ã¡ã³ããã³ã¹ãããææ°ã®è
åšããã客æ§ã®ç°å¢ã確å®ã«ä¿è·ããŸããããã¯ãæ©å¯ããŒã¿ãä¿åãããŠããããæ»æè
ã®æšçã«ãªãããã SAP ã©ã³ãã¹ã±ãŒãã«ãšã£ãŠç¹ã«éèŠã§ãã ã客æ§ã®å°å
¥èŠä»¶ãæºããããã«ã è€æ°ã®ã°ã«ãŒãã»ãã ãçšæãããŠããŸãããããã®ã«ãŒã«ã»ããã¯ä»¥äžã®éãã§ãïŒ Name Technical Name ã¯ã©ã€ã¢ã³ãã®èåŒ±æ§ Fortinet-ips-client-enable-rulegroup1 Fortinet-ids-client-alert-rulegroup1 ãã«ãŠã§ã¢æ€åº Fortinet-ips-malware-enable-rulegroup1 Fortinet-ids-malware-alert-rulegroup1 ãµãŒãããã³OSã®èåŒ±æ§ Fortinet-ips-serveros-enable-rulegroup1 Fortinet-ips-serveros-enable-rulegroup2 Fortinet-ids-serveros-alert-rulegroup1 Fortinet-ids-serveros-alert-rulegroup2 Web ã¯ã©ã€ã¢ã³ãã®èåŒ±æ§ Fortinet-ips-webclient-enable-rulegroup1 Fortinet-ids-webclient-alert-rulegroup1 Webã¢ããªã±ãŒã·ã§ã³ã®èåŒ±æ§ Fortinet-ips-webapp-enable-rulegroup1 Fortinet-ids-webapp-alert-rulegroup1 WebãµãŒãã®èåŒ±æ§ Fortinet-ips-webserver-enable-rulegroup1 Fortinet-ids-webserver-alert-rulegroup1 ã«ãŒã«ã®åã»ããã¯ã䟵å
¥æ€ç¥ã·ã°ããã£ãšäŸµå
¥é²æ¢ã·ã°ããã£ã®2ã€ã®ãµãã»ããã§æ§æãããŸãïŒ äŸµå
¥é²åŸ¡ã·ã°ããã£ïŒIPSïŒã¯ DROP ãŸã㯠ALERT ã¢ã¯ã·ã§ã³ãå®è¡ã§ãã 䟵å
¥æ€ç¥ã·ã°ããã£ïŒIDSïŒã¯ ALERT ã¢ã¯ã·ã§ã³ããå®è¡ã§ããªãã å
šäœãšããŠãAWS Firewall çš ã® Fortinet Managed IPS Rules ã¯ãSAP ã©ã³ãã¹ã±ãŒãã«è¿œå ã®ã»ãã¥ãªãã£ã¬ã€ã€ãŒãæäŸããããžãã¹ã¯ãªãã£ã«ã«ãªããŒã¿ãšã¢ããªã±ãŒã·ã§ã³ã®ä¿è·ã«åœ¹ç«ã¡ãŸãã Fortinet Managed Rules for AWS Firewall ã®ã»ããã¢ãããšæ€èšŒæ¹æ³ã®è©³çްã«ã€ããŠã¯ã 管çã¬ã€ã ãåç
§ããŠãã ããã SAP å°çšã®äŸµå
¥é²åŸ¡ã·ã°ããã£ã«ãŒã« Fortinet ã¯ãSAP å°çšã«ã«ã¹ã¿ãã€ãºããããããŒãžã AWS ãããã¯ãŒã¯ãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã®ã»ãããã¡ã€ã¢ãŠã©ãŒã«ããšã³ããã€ã³ããããã¯ã·ã§ã³ãã¯ã©ãŠãã»ãã¥ãªãã£ãµãŒãã¹ãªã©ãããŸããŸãªã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãæäŸããŠããŸãããããã®ãœãªã¥ãŒã·ã§ã³ã¯é«åºŠãªè
åšã®æ€ç¥ãšé²æ¢æ©èœãæäŸããæ¢ç¥ã®è
åšããæ°ããªè
åšãŸã§ãå¹
åºãè
åšãã SAP ã·ã¹ãã ãä¿è·ããŸãã Fortinet ã¯ãSAP ã¢ããªã±ãŒã·ã§ã³ã«ç¹åããæ»æãæªæã®ããåäœã鲿¢ããããã«ã60 çš®é¡ä»¥äžïŒããã«å¢å äžïŒã®ã·ã°ããã£ãæäŸããŠããŸãããããã®ã·ã°ããã£ã¯ãFortinet ãæäŸãããããŒãžã IPS ã«ãŒã«ã®äžéšã§ãã Signature Name Severity Area SAP.Netweaver.publicinfo.HTTP.Request.Smuggling Server SAP.Netweaver.Visual.Composer.Unrestricted.File.Upload Server SAP.Netweaver.LM.Configuration.Wizard.Authentication.Bypass Server SAP.Netweaver.SOAP.Query.Directory.Traversal Server SAP.Solution.Manager.SMDAgent.Remote.Code.Execution Server SAP.Netweaver.Log.Injection.Remote.Command.Injection Server SAP.Netweaver.DIAG.Request.DoS Server SAPGUI.Regsver32.Rule.Security.Policy.Bypass Client SAP.Netweaver.CrashFileDownloadServlet.Directory.Traversal Server SAP.Netweaver.UDDI.Server.SQL.Injection Server SAP.SQL.Anywhere.NET.Data.Provider.Column.Alias.Buffer.Overflow Server SAP.Sybase.Event.Stream.Processor.DoS Server SAP.Sybase.Event.Stream.Processor.Code.Execution Server Figure 1. Fortinet ãããŒãžã IPS ã«ãŒã«ã«ããã SAP åºæã®ã·ã°ããã£ã®äŸ è€éããé¿ããããããããã®çœ²åã¯æäŸãããã«ãŒã«ã°ã«ãŒãã«åæ£ãããŸããSAP å°å
¥ã®å®å
šæ§ã確ä¿ããã«ã¯ã以äžã®ã«ãŒã«ã°ã«ãŒããéåžžã«éèŠã§ãããŸãã ãµãŒãããã³OSã®èåŒ±æ§ Webã¢ããªã±ãŒã·ã§ã³ã®èåŒ±æ§ WebãµãŒãã®èåŒ±æ§ ã¯ã©ã€ã¢ã³ãã®èåŒ±æ§ ãã«ãŠã§ã¢æ€åº ã©ã®ã«ãŒã«ã°ã«ãŒããããªãã®ãŠãŒã¹ã±ãŒã¹ã«é¢é£ãããã確èªããã«ã¯ã 管çã¬ã€ãã®ãŠãŒã¹ã±ãŒã¹ã®ã»ã¯ã·ã§ã³ ãåç
§ããŠãã ãããäŸãã° AWS äžã® SAP S/4 HANA ãããã€ã¡ã³ãã®å Žåã以äžã®ã«ãŒã«ã°ã«ãŒãã該åœããŸãïŒ ãµãŒããŒãš OS ã®è匱æ§ãWeb ãµãŒããŒã®è匱æ§ãWeb ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ã ãµãŒãããã³OSã®èåŒ±æ§ ã«ãŒã«ã°ã«ãŒãã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãš SAP Web DispatcherãRFC (Remote Function Call) Gateway ãªã©ã® SAP ãµãŒãã¹ã«å¯Ÿããæ»æãé²ããŸãã SAP ã SAP Web ããŒã¹ã®ããã³ããšã³ã Fiori ã«ç§»è¡ããã«ã€ããŠãHTTP(s) ãªã¯ãšã¹ã㯠OWASP Top 10 (Open Web Application Security Project) ã«å¯ŸããŠä¿è·ãããå¿
èŠããããŸãããã®ãã㪠HTTP(s) ãªã¯ãšã¹ããä¿è·ããããã«ãAWS WAF ã Forti Web ã®ãã㪠Web Application Firewall ãå®è£
ããããšãåŒ·ãæšå¥šããŸãããã®ãã㪠Web Application Firewall ã¯ãSQL ã€ã³ãžã§ã¯ã·ã§ã³ãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ãç¹å®ããããã«ãHTTP ããããŒãHTTP ããã£ãURI æååããã€ããŒããªã©ã OSI ã¢ãã« ã®ã¬ã€ã€ãŒ 7 ã®æ
å ±ãåæããããã«èšèšãããŠããŸããåè¿°ã® Web ãµãŒãã®èåŒ±æ§ ããã³ Web ã¢ããªã±ãŒã·ã§ã³ã®èåŒ±æ§ ç®¡çã«ãŒã«ã°ã«ãŒãã¯ããã®ãããªã·ããªãªã«ãããŠåºæ¬ç㪠Web ä¿è·ãæäŸããŸãã AWS äžã® SAP S/4HANA ãããã€ã¡ã³ããä¿è·ããã³ã³ããã¹ãã§ã¯ã ã¯ã©ã€ã¢ã³ãã®èåŒ±æ§ ã«ãŒã«ã°ã«ãŒãã¯äœ¿çšãããŸããããã®ã«ãŒã«ã°ã«ãŒãã¯ãChrome ãã©ãŠã¶ã SAP GUI ã®ãããªã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ã«å¯Ÿããæ»æããããã¯ããããšã«ã®ã¿æå¹ã§ããããµãŒããŒã³ã³ããŒãã³ãã«å¯Ÿããæ»æãé²ãããšã¯ã§ããŸãããSAP ãããã€ãã¯ã©ã€ã¢ã³ããšããŠæ©èœããå Žåãããšãã°ãéä¿¡ãã©ãã£ãã¯ïŒ ãšã°ã¬ã¹ ãã©ãã£ãã¯ïŒã®ä¿è·ãšãã£ã«ã¿ãªã³ã°ãè¡ãå Žåã¯ã ã¯ã©ã€ã¢ã³ãã®èåŒ±æ§ ããã³ ãã«ãŠã§ã¢æ€åº ã«ãŒã«ã°ã«ãŒããé¢é£ããŸãã ãããã®ã«ãŒã«ã»ããã¯ã FortiGuard Labs ã®è
åšã€ã³ããªãžã§ã³ã¹ãã宿çã«æŽæ°ããããããå«ãŸããã·ã°ããã£ã®æ°ã¯æéã®çµéãšãšãã«å¢å ããæ°ããæ»æããããã¯ããã«ãŒã«ãå«ãŸããããã«ãªããŸãã SAP ç°å¢ã§ AWS Network Firewall ã䜿çšããéã®èšèšãšäœ¿çšäžã®èæ
®ç¹ AWS äžã® SAP ãããã€ã¡ã³ãã« AWS Network Firewall ãå®è£
ããåã«ãããã€ãã®èŠå ãèæ
®ããããšãäžå¯æ¬ ã§ãããŸãã ãŠãŒã¹ã±ãŒã¹ã«å¿ããŠã AWS WAFãAWS Network FirewallãAmazon VPC ã»ãã¥ãªãã£ã°ã«ãŒãã®çµã¿åããã䜿çšããããšãæ€èšããŠãã ããã AWS Web Application Firewall (WAF) ã¯ãApplication Load Balancer (ALB)ãAmazon API GatewayããŸã㯠Amazon CloudFront ã«ãã£ãŠããã³ãããã HTTP ããŒã¹ã®ãã©ãã£ãã¯ã«å¯ŸããŠã¬ã€ã€ãŒ 7 ã®ä¿è·ãæäŸããŸãã AWS Firewall Manager ã¯ãAWS çµç¹å
ã® AWS ãªãŒãžã§ã³ãã¢ã«ãŠã³ãããªãœãŒã¹ã«ãŸããããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®èšå®ãšãããã€ãè¡ãããã®äžå¿çãªå ŽæãšããŠæ©èœããã»ãã¥ãªãã£ç®¡çãµãŒãã¹ã§ã ãFirewall Manager ã¯ãæ°ããã¢ã«ãŠã³ãããªãœãŒã¹ãäœæãããå Žåã§ãããã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãäžè²«ããŠé©çšãããããã«ããŸããFirewall Manager ã¯ãAWS Network FirewallãAmazon Route 53 Resolver DNS FirewallãAWS WAFãAWS Shield AdvancedãAmazon VPC ã»ãã¥ãªãã£ã°ã«ãŒããšçµ±åãããŠããŸãã æ£åœãªãã©ãã£ãã¯ããããã¯ããªãããã«ãåžžã«ãã¹ãã宿œããŠãã ããã AWS ãããŒãžã ã«ãŒã« ã°ã«ãŒããã«ã¹ã¿ã ãããŒãžã ã«ãŒã« ã°ã«ãŒãã«ã³ããŒãã å«ãŸããã«ãŒã«ã®ã©ã€ããµã€ã¯ã«ãã«ã¹ã¿ãã€ãºãŸãã¯å¶åŸ¡ããããšãã§ããŸãããã¹ããã©ã¯ãã£ã¹ãšããŠãæ¬çªç°å¢ã«é©çšããåã«ããŸãã¹ããŒãžã³ã°ç°å¢ã« AWS ããã³ããŒãã㌠ãããŒãžã ã«ãŒã«ãå®è£
ããŠãã¹ãããããšããå§ãããŸããããã«ããããããã®æ°ããã«ãŒã«ã SAP ç°å¢ã«è¿œå ããå Žåã®åœ±é¿ãçè§£ããé©åã«ã«ã¹ã¿ãã€ãºããããšãã§ããŸããAWS Network Firewall ã¯ãâalert mode â ãä»ããŠã«ãŒã«ãšãã©ãã£ãã¯éã®çžäºäœçšã®èŠ³æž¬å¯èœæ§ãæäŸããŸããããã«ãããã«ãŒã«ãåé€ãã代ããã«ãã«ãŒã«ã®äžèŽãã¢ã©ãŒãããããšã§ãã«ãŒã«ããã¹ãããããšãã§ããŸããAWS ãããŒãžã ã«ãŒã« ã°ã«ãŒãã«ã€ããŠã¯ããããå®è£
ããããã®ã¹ããããã€ã¹ãããã®æé ã ãã ã«ãããŸããFortinet ãããŒãžãã«ãŒã«ã«ã¯ãIPS ãš IDS ã®ããŒãžã§ã³ããããŸããIDS ã«ãŒã«ã¯ãã«ãŒã«ã®äžèŽã«å¯ŸããŠã¢ã©ãŒããçºããããããã¹ãã«äœ¿çšã§ããŸãã ãããã¯ãŒã¯ãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ãš IPS ã·ã°ããã£ã¯ãããã©ãŒãã³ã¹ã«æªåœ±é¿ãåãŒãå¯èœæ§ããããŸã ãAWS ãããã¯ãŒã¯ãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã®æ°ã¯ãæ€æ»ã®ããã©ãŒãã³ã¹ã«åœ±é¿ãäžããŸãããããã®ã«ãŒã«ã¯ããããã¯ãŒã¯ãã©ãã£ãã¯ããªã¢ã«ã¿ã€ã ã§åæããŠåäœããããããããã¯ãŒã¯ãã©ãã£ãã¯ã®åŠçãé
ããªããSAP ã¢ããªã±ãŒã·ã§ã³ã®ããã©ãŒãã³ã¹ã«æªåœ±é¿ãåãŒãå¯èœæ§ããããŸãããã®ãããSAP Application ãš Database ã³ã³ããŒãã³ãéã®ãããã¯ãŒã¯ãã©ãã£ãã¯ãæ€æ»ããããšã¯æšå¥šãããŸããã ã€ã³ã°ã¬ã¹ ãã©ãã£ã㯠ã€ã³ã¹ãã¯ã·ã§ã³ãšãšã°ã¬ã¹ ãã©ãã£ã㯠ã€ã³ã¹ãã¯ã·ã§ã³ã ãããã¯ãŒã¯ãã¡ã€ã¢ãŠã©ãŒã«ã«ããã€ã³ã°ã¬ã¹ ãã©ãã£ã㯠ãã£ã«ã¿ãªã³ã°ã¯ãå€éšãããããã¯ãŒã¯ã«äŸµå
¥ããè
åšã®æ€åºãšé²æ¢ã«éç¹ã眮ããŠããŸããäžæ¹ããšã°ã¬ã¹ ãã©ãã£ã 㯠ãã£ã«ã¿ãªã³ã°ã¯ãããŒã¿ã®çé£/æµåºããã®ä»ã®æªæã®ããè¡çºãªã©ããããã¯ãŒã¯ããåºãããšããè
åšã®æ€åºãšé²æ¢ã«é¢ä¿ããŸããSAP ã·ã¹ãã ã¯ã¯ã©ã€ã¢ã³ããšããŠæ©èœããããšãã§ãïŒäŸïŒã¢ãŠãããŠã³ã Web ã€ã³ã¿ãŒãã§ãŒã¹ïŒãé¢é£ãã ãšã°ã¬ã¹ãã©ãã£ãã¯æ€æ»ãé©çšãããããšã«çæããŠãã ããã ãŸãšã AWS Network Firewall çšã®ããã«äœ¿ãã AWS ãããŒãžãã«ãŒã«ããããç¥ãããæ»æãã SAP ç°å¢ãä¿è·ããã®ã«åœ¹ç«ã€ããšã説æããŸãããããã¯ãã«ã¹ã¿ã ãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ãå®è£
ããç¶æããããã®ãªãŒããŒããããåæžããªããããã®ä¿è·ãæäŸããŸããã»ãã¥ãªãã£ã®ããŒãºãæ¢åã® AWS ãããŒãžãã«ãŒã«ã§ã«ããŒã§ããªãå Žåã¯ãFortinet ãªã©ã® AWS ããŒãããŒã«ãããœãªã¥ãŒã·ã§ã³ã§è£å®ããããšãã§ããŸãã Fortinet ã¯ãAWS äžã®SAP ãããã€ã¡ã³ããä¿è·ããããã«ç¹å¥ã«èšèšãããããŸããŸãª Fortinet Managed IPS ã«ãŒã«ãªã©ãSAP ãããã€ã¡ã³ãå°çšã®ã»ãã¥ãªãã£ãµãŒãã¹ãšãµããŒããæäŸããŠããŸãããããã® IPS ã«ãŒã«ã¯ãã¿ãŒã²ãããçµã£ãè
åšã®æ€åºãšé²æ¢æ©èœãæäŸããæ¢ç¥ã®è
åšãæ°ããªè
åšãã SAP ã·ã¹ãã ãä¿è·ããŸããSAP ã»ãã¥ãªãã£ã«å¯Ÿãã Fortinet ã®åãçµã¿ã¯ãéèŠãªããžãã¹ã·ã¹ãã ãä¿è·ããããšã®éèŠæ§ã匷調ããSAP ç°å¢ç¹æã®ããŒãºã«åãããå°çšã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®å¿
èŠæ§ãæµ®ã圫ãã«ããŠããŸãã èŠçŽãããšãAWS Network Firewall ã¯ãäžå¯©ãªãããã¯ãŒã¯ãã©ãã£ãã¯ãæ€æ»ããŠé®æããããšã§ãAWS äžã® SAP ã¯ãŒã¯ããŒãã®å®å
šã確ä¿ããæè»ãªã¹ããŒãã¬ã¹ããã³ã¹ããŒããã« ã«ãŒã«ãšã³ãžã³ãæäŸããããšã§ãæ°ããªè
åšãã SAP ã·ã¹ãã ãä¿è·ããããšãã§ããŸããAWS äžã®å®å
šã§ããã©ãŒãã³ã¹ã®é«ã SAP ãããã€ã¡ã³ãã«ãããSAP ãŠãŒã¶ãŒã¯ããã·ã§ã³ã¯ãªãã£ã«ã«ãªããžãã¹ããã»ã¹ãå®äºããããšãã§ããŸãã SAP on AWS ãš AWS Network Firewall ã®è©³çްã«ã€ããŠã¯ã AWS 補åã®ããã¥ã¡ã³ã ãã芧ãã ããã Fortinet ã®è©³çްã«ã€ããŠã¯ã Fortinet ã® SAP ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ ãšã Fortinet ãéèŠãª SAP ãšã³ã¿ãŒãã©ã€ãºç°å¢ã®ä¿è·ã«ã©ã®ããã«åœ¹ç«ã€ã ãã芧ãã ããã 翻蚳㯠Specialist SA è
è°·ãæ
åœããŸãããåæã¯ ãã¡ã ã§ãã