¡°UEBAÖ®±Ê¡±»³öÒµÎñϵͳÎå´óÍþв
°ä²¼¹¦·ò 2018-12-11ºÏ¶àLASϵͳ¿ÉÒÔΪÓû§½»¸¶ÒµÎñÍþв»ÏñµÄÄÜÁ¦£¬ÓÐЧÌáÉýÓû§¶ÔÓÚÒµÎñϵͳµÄÒì³£ÐÐΪµÄÍþв¼ø±ðÕýÈ·¶ÈºÍËÝÔ´ÕæÕýÍþвÐÐΪµÄÄÜÁ¦£¬Æðµ½³ÁÒªµÄƽ̨×÷Óá£
Ó×ÌùÊ¿£º¾ßÌåÄÚÈÝÄܹ»²Î¿´¡¶ºÏ¶àLASϵͳʹÓÃUEBA¼¼Êõ½øÐÐÒµÎñÍþв»ÏñµÄ»ã±¨¡·¡£
UEBA¼¼Êõ£¨User and Entity Behaviours Analytics£©¡ª¡ªÓû§ÊµÌåÐÐΪ·ÖÎö£¬ÊÇÍøÂ簲ȫÁìÓòÀï·¢ÏÖÒì³£ÐÐΪÊÇÒ»ÖÖ³ÁÒªµÄÄÜÁ¦¡£ºÃ¶àʱ³½£¬Òì³£ÊÂÎñÎÞÊýÊÇÒ»¸öÓ׸ÅÂÊÊÂÎñ£¬ÓÉÓÚÓû§¶ÔÕâÀàÊÂÎñµÄ¾«×¼¶ÈÒªÇó¸ß£¬³Ö¾ÃÒÔÀ´²»×ãÓÐЧµÄ¼ì²â»úÔì×÷Ϊ±£ÏÕ¡£ÔÚ´«Í³¼ì²â»úÔìÖУ¬ÎÒÃǹý¶ÈÒÀÀµÒÑÖªÍþв¼ì²â£¨Æ©ÈçIDS¡¢IPS¡¢NGIDS¡¢NGIPS¡¢FW¡¢NGFWµÈ£©µÄÒÑÖª¹æ¶¨À´×ö¼ì²â£¬¼ì²âÒýÇæÀïÄÚÖù涨»ò¾Ñ飬µ«Í¨¹ýÒÑÖª¹æ¶¨µÄ»úÔ죬¹æ¶¨ãÐÖµ²»×ã½Ã½ÝÐÔÈÝÒ×ÒýÆðÎóÅУ¬ÕýÈ·¶È²»¹»¡£¶øUEBA¼¿Á©ÔòÊÇ´ÓÊý¾Ý·ÖÎöµÄÊÓ½ÇÈ¥·¢ÏֹؼüÎÊÌ⣬ÎÒÃÇ´Ó¾Û½¹Êý¾ÝÄÚÈÝ×ÔÉíµ½ÄÚÈݸߵÍÎĹØÏµ¡¢ÐÐΪ·ÖÎöµÈ£¬´Óµ¥µãµ¥Ìõ¼ì²âµ½¶àά¶È´óÊý¾Ý·ÖÎöÀ´·¢ÏÖ¸ü¶à¸üÕýÈ·µÄÓмÛÖµÐÅÏ¢¡£±¾°¸ÖУ¬ÎÒÃÇʹÓÃÁËÎå¸öÒµÎñÍþв»ÏñµÄÄÜÁ¦£¬Ô®ÊÖÓû§ÕýÈ·¶¨Î»ÁËÒµÎñϵͳµÄ°²È«Íþв£¬´ó´óÌáÉýÁËÓû§µÄ°²È«·À»¤ÄÜÁ¦£º
¡¾Íþв»ÏñÒ»¡¿£ºÀûÓÃÀëȺ·ÖÎö£¬ÍÚ¾òÐÐΪÒì³£¸ö±ð
ºÏ¶àLASϵͳÎÞÐè¶ÔÓû§ÀûÓÃϵͳҵÎñ½øÐÐÈκÎÖ±½Ó²Ù×÷µÄǰÌáÏ£¬×Ô¶¯°Îȡһ°´¹¦·ò¶ÎÄÚµÄÈÕÖ¾Êý¾Ý£¬¶ÔÈËÔ±µÄ×÷Ï¢¹¦·ò¡¢¹¤×÷µØÖ·¡¢ÐÐΪ¸öÐÔ£¨²Ù×÷Ƶ¶È¼°¹¤×÷ÈÈÇø¹¦·ò¶Î£©¡¢Ó×ÎÒÌØµã£¨´ºÇï¼°ËùÊô»ú¹¹£©µÈ¶à¸öά¶È½øÐÐÀëȺ·ÖÎö£¬´Ó¶øÍÚ¾ò³ö´æÔÚÒì³£ÐÐΪµÄÈËÔ±£¬¼´Óû§»òÕ˺ţ¬ÈçÏÂͼËùʾ£º
¡¾Íþв»Ïñ¶þ¡¿£º¹¹½¨ÐÐΪ»ùÏߣ¬Åû¶¸ö±ðÒÉÄÑÐÐΪ
ºÏ¶àLASϵͳ»áƾ¾ÝÓû§×ÔÉíÐèÒª£¬½áºÏÓû§»òÕ˺ʹ½¨ÐÐΪ»ùÏߣ¬Æ©È磬ϵͳÄܹ»»®¶¨ÄÄЩÕ˺ÅÔÚʲô¹¦·òÄÚÄܹ»½Ó¼ûÒµÎñϵͳ£»Õ˺ŵĽӼûȨÏÞÓÐÄÄЩµÈµÈ¡£ÎÒÃÇ·¢ÏÖÁ˸ÃÓû§µÄÈÕ½Ó¼ûÁ¿Í»±ä£¬´Ó¶øÅж¨Á˸ö±ðÒÉÄÑÐÐΪ¡£ÈçÏÂͼËùʾ£º
ͼÖÐÄܹ»¿´³ö£¬ÆäÈÕ½Ó¼ûÁ¿Í»±äÇ÷ÏòÔÚijһ¸ö¹¦·òµã²úÉúÏÔÖøµÄ±ä¶¯£¬ÓâÔ½ÈÕ¾ùÖµÊý±¶Ö®¶à¡£
¡¾Íþв»ÏñÈý¡¿£º»ùÓÚÒÉÄÑÐÐΪ£¬Åж¨¸ö±ðÒì³£ÐÔÖÊ
±¾°¸ÖУ¬ºÏ¶àLASϵͳÌáÈ¡µ½ÁËÕË»§×÷Ï¢¹¦·òµÄÒì³£ÐÐΪÐÅÏ¢£¬ÈçÏÂͼËùʾ£º
´ÓÁ˾ÖչʾÄܹ»¿´³ö£¬¸ÃÓû§»òÕ˺ŶÔÒµÎñϵͳµÄ²Ù×÷ÐÐΪ£¬ÖØÒª¼¯ÖÐÔÚÉÏÎç10µã×óÓÒ¡¢ÍíÉÏ7µãÖÁ8µãÕâÁ½¸ö¹¦·ò¶ÎÄÚ£¬Çҷǹ¤×÷¹¦·ò½Ó¼ûÕ¼±ÈÁ¦¸ß¡£
¡¾Íþв»ÏñËÄ¡¿£ºÀûÓùØÏµÍ¼Æ×£¬ËÝÔ´¿ÉÒɹØÁªÈËÔ±
ƾ¾ÝºÏ¶àLASϵͳÌṩµÄ¹ØÏµÍ¼Æ×Ö°ÄÜ£¬¿É¶Ô¿ÉÒÉÈËÔ±¡¢Õ˺š¢Óû§½øÐйØÁª·ÖÎö£¬´Ó¶à¸öά¶È£¨»ú¹¹¡¢ÀûÓá¢ÄÚÈݵȣ©·ÖÎöÓëÆä´æÔÚ¹ØÁªµÄÈËÔ±¡£
¡¾Íþв»ÏñÎå¡¿£º»¹ÔÈÕÖ¾ÐÅÏ¢£¬ÁоٿÉÒÉÈËÔ±²Ù×÷
ƾ¾ÝɸѡµÄ¿ÉÒÉÈËÔ±Ãûµ¥£¬ÀûÓÃLASµÄÈÕÖ¾ËÑË÷¶ÔÆä²éÎʲÙ×÷½øÐÐÁË»ØËÝ£¬×îÖÕÈ·ÈÏÆäÍþвÐÐΪ¡£
ͨ¹ýÉÏÊöÒµÎñÍþв»ÏñÄܹ»¿´³ö£¬Ä³Ê¡»á¼¶³ÇÊеĹ«°²ÐÐÒµÓû§Í¨¹ý°²Éóƽ̨µÄ»ù´¡½¨É裬ʵÏÖÁ˺£Á¿ÀûÓÃϵͳÈÕÖ¾µÄ²É¼¯¡¢´æ´¢ºÍ·ÖÎöÀûÓã¬Éî¶ÈÍÚ¾ò·ÖÎö¡¢Ô¤¾¯µÈʵսÀûÓ㬻ùÓÚ´óÊý¾Ý¼¼ÊõµÄ³ÉÊìʹÓã¬ÊµÊ±·¢Ïֺʹ¦ÖÃÒµÎñϵͳÖеÄԽȨ½Ó¼û¡¢Êý¾ÝµÁÈ¡µÈÒì³£²Ù×÷ÐÐΪ£¬½«º£Á¿Éó¼ÆÊý¾ÝÕæÕýÀûÓÃÆðÀ´£¬ÇÐʵ½â¾öÐÅÏ¢×ÊԴʹÓÃÖÎÀíÖеݲȫÎÊÌâ¡£
ºÏ¶àLASϵͳµÄÖ÷ÌâÊÇ»ùÓÚUEBA¼¼Êõ£¬Í¨¹ý¶ÈÎöÍÚ¾òÓë¡°Õý³£¡±Ä£Ê½´æÔÚÎó²îµÄÒì³£ÐÐΪ£¬À´¼ì²âÓµÓÐÍþвµÄÓû§ºÍʵÌ壬ʹÓûúе½ø½¨¡¢Ëã·¨ºÍͳ¼Æ·ÖÎöµÈ¼¿Á©À´ÏàʶºÎʱÓëÒѳÉÁ¢µÄģʽ´æÔÚÎó²î£¬Í¨¹ýÓë×ÔÉíÕ˺ÅÔÐÐΪģÐͽøÐбÈÁ¦£¬½áºÏÆäËûά¶ÈµÄÒì³£ÐÐΪģÐͽøÐзÖÎö£¬·¢ÏÖÄÄЩÕË»§¿ÉÄܱ»ºÚ¿ÍµÁÈ¡½ÚÔ죬»¹Äܹ»¶ÔÉæ¼°µÄÒì³£ÀàÐÍ£¬Òì³£Çé¿öÃ÷ϸ¡¢¹ì¼£É¢²¼µÈÐÅÏ¢½øÐз¢ÏÖ£¬ÏÔʾÄÄЩÒì³£¿ÉÄܵ¼ÖÂDZÔÚµÄÕæÊµÍþв£¬ÊǼì²âÄÚ²¿Óû§µÄÒì³£ÐÐΪ¡¢·ÖÎöÕç±ðÍþвµÄÒ»¼þÀûÆ÷¡£ºÏ¶àLASϵͳ³ýÁËÉÏÊö½»¸¶ÄÜÁ¦Ö®±í£¬»¹Äܹ»¾ÛºÏ»ã±¨ºÍÈÕÖ¾ÖеÄÊý¾Ý£¬ÒÔ¼°¹ØÁªÎļþ¡¢Á÷ºÍÊý¾Ý°üÐÅÏ¢£¬ÔÚº£Á¿ÈÕÖ¾Êý¾ÝµÄÔëÉùÖУ¬ÓÐЧ½µµÍ°²È«ÊÂÎñ·ÖÎöµÄ¹¤×÷Á¿£¬Ìá¸ß¸æ¾¯µÄÕë¶ÔÐÔºÍÕýÈ·ÂÊ¡£Í¨¹ýÓëSIEMÀàÆ½Ì¨£¬Æ©ÈçSOCºÍÌ¬ÊÆ¸Ð֪ƽ̨µÄ½áºÏ£¬¿É²ûÑï¸ü¶àÓÐЧ¼ÛÖµ¡£
²Î¿¼Îļþ:
1.https://mp.weixin.qq.com/s/yLiQbpoI6TyOc-R0bUeuqA
2.https://mp.weixin.qq.com/s/OftrYdfSudSP_gPdYa6kmA
3.https://mp.weixin.qq.com/s/oWRkuYfh3TNfV61ssv8rTg
4.https://baike.www.alibaba-yz.com/item/%E7%9B%97%E6%A2%A6%E7%A9%BA%E9%97%B4/31288?fr=aladdin
ÍùÆÚÓйØÔĶÁ
ÈÃÊý¾Ý¿ÉÊÓ»¯±äµÃµ¥Ò» ¡ªTSOC°²È«¿ÉÊÓ»¯×¨°æÕýʽ°ä²¼
https://mp.weixin.qq.com/s/oWRkuYfh3TNfV61ssv8rTg
½â¶Á¡ª¹ùÆôÈ«×ܹ¤¹ØÓڵȱ£2.0µÈÎåÏ×÷ÄÚÈݵijÁÒª½²»°
https://mp.weixin.qq.com/s/OftrYdfSudSP_gPdYa6kmA
Ê¢¿ªÈںϣ¬Èð²È«Êý¾Ý¿ÉÊÓ»¯±äµÃµ¥Ò»¡ª¡ªº¼ÖÝרÏî°ä²¼»á²à¼Ç
https://mp.weixin.qq.com/s/_1rhIxFgF79eCcT8S9xwkg
°²·ÀÁìÓòµÄÌ¬ÊÆ¸ÐÖªÔÀ´ÊÇÕâÑùµÄ
https://mp.weixin.qq.com/s/f-LU3aPmOLYN11EQTDvj9g


¾©¹«Íø°²±¸11010802024551ºÅ