Abnormal Security 로그 수집

파서 버전: 6.0

다음에서 지원:

이 문서에서는 Abnormal Security 로그를 Google Security Operations에 수집하는 방법을 설명합니다. 파서는 JSON 및 Syslog 형식의 이메일 로그를 모두 처리합니다. 먼저 입력을 JSON으로 처리하려고 시도하고 실패하면 Grok 패턴을 사용하여 Syslog 형식에서 데이터를 추출합니다. 그런 다음 추출된 필드가 통합 데이터 모델 (UDM)에 매핑되어 관련 보안 컨텍스트로 데이터를 보강하고 추가 분석을 위해 형식을 표준화합니다.

시작하기 전에

다음 기본 요건이 충족되었는지 확인합니다.

  • Google SecOps 인스턴스
  • Abnormal Security에 대한 권한 있는 액세스

Google SecOps 고객 ID 가져오기

  1. Google SecOps 콘솔에 로그인합니다.
  2. SIEM 설정 > 프로필 로 이동합니다.
  3. 조직 세부정보 섹션에서 고객 ID 를 복사하여 저장합니다.

Google SecOps 수집 인증 파일 가져오기

  1. Google SecOps 콘솔에 로그인합니다.
  2. SIEM 설정 > 수집 에이전트 로 이동합니다.
  3. 수집 인증 파일 을 다운로드합니다.

로그를 Google SecOps로 전송하도록 Abnormal Security 구성

  1. Abnormal Security 웹 UI에 로그인합니다.
  2. 설정 > 통합 을 클릭합니다.
  3. Google Chronicle 아이콘을 찾아 연결 을 클릭합니다.
  4. Google SecOps 고객 ID 를 입력합니다.
  5. Google SecOps 인스턴스 엔드포인트 주소 를 입력합니다.
  6. 이전에 다운로드한 수집 인증 파일 을 Google 서비스 계정으로 업로드합니다.
  7. 저장 > 확인 을 클릭합니다.

지원되는 Abnormal Security 로그 형식

Abnormal Security 파서는 SYSLOG 및 JSON 형식의 로그를 지원합니다.

지원되는 Abnormal Security 샘플 로그

  • JSON
{
  "threatId": "3fd4ed1a-9237-7e6f-d434-eacdcc41f47b",
  "messages": [
    {
      "abxMessageId": 3405268390454580698,
      "abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/3405268390454580698",
      "attachmentCount": 0,
      "attachmentNames": [],
      "attackStrategy": "Unknown Sender",
      "attackType": "Spam",
      "attackVector": "Link",
      "attackedParty": "VIP",
      "autoRemediated": true,
      "fromAddress": "masked.from@example.com",
      "fromName": "Masked User Name",
      "impersonatedParty": "None / Others",
      "internetMessageId": "<20eb9e7c1c3046fda97f6564c81ced64@530566577>",
      "isRead": false,
      "postRemediated": false,
      "receivedTime": "2023-08-28T14:09:31Z",
      "recipientAddress": "masked.recipient@example.com",
      "remediationStatus": "Auto-Remediated",
      "remediationTimestamp": "2023-08-28T14:09:35.618Z",
      "sentTime": "2023-08-28T14:08:44Z",
      "subject": "Banking Insights | A deep dive into the global M&A landscape",
      "threatId": "3fd4ed1a-9237-7e6f-d434-eacdcc41f47b",
      "toAddresses": [
        "masked.to@example.com"
      ],
      "ccEmails": [],
      "replyToEmails": [
        "masked.reply@example.com"
      ],
      "returnPath": "masked.returnPath@example.com",
      "senderDomain": "masked.sender.domain",
      "senderIpAddress": null,
      "summaryInsights": [
        "Suspicious Link",
        "Unusual Sender",
        "Abnormal Email Body HTML",
        "Invisible characters found in Email",
        "Unusual Sender Domain",
        "Suspicious Financial Request",
        "Unusual Reply To"
      ],
      "urlCount": 19,
      "urls": [
        "https://masked.comm.link/e/es?s=530566577&e=2595782&elqTrackId=MASKEDID&elq=MASKEDID&elqaid=119820&elqat=1",
        "https://www.masked.group/en/simplifying-the-brand?utm_source=Eloqua&utm_medium=email&utm_campaign=MASKED_CAMPAIGN&elqCampaignId=20995&elq=MASKEDID",
        "https://masked.group.link/e/er?utm_source=Eloqua&utm_medium=email&utm_campaign=MASKED_CAMPAIGN&elqCampaignId=20995&s=530566577&lid=192730&elqTrackId=MASKEDID&elq=MASKEDID&elqaid=119820&elqat=1"
        // ... (16 additional masked URLs omitted for brevity)
      ]
    }
  ]
}
  • SYSLOG + JSON
<14> {
  "threatId": "83da593b-3778-9d2f-da8c-e305dc1425e1",
  "messages": [
    {
      "abxMessageId": 8274341447487143770,
      "abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/8274341447487143770",
      "attackType": "Spam",
      "fromAddress": "masked.from.1@example.com",
      "fromName": "Masked User Name",
      "internetMessageId": "<PUZPR06MB45764FCED76739D0BC8A1B69E3DFA@masked.server.prod.outlook.com>",
      "recipientAddress": "masked.recipient.1@example.com",
      "remediationStatus": "Auto-Remediated",
      "subject": "Freightview, FreightPOP Users List",
      "toAddresses": [
        "masked.to.1@example.com"
      ],
      "returnPath": "masked.returnPath.1@example.com",
      "senderDomain": "outlook.com",
      "senderIpAddress": null,
      "urlCount": 0,
      "urls": []
    },
    {
      "abxMessageId": -4495524442058864563,
      "abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/-4495524442058864563",
      "attackType": "Spam",
      "fromAddress": "masked.user.2@outlook.com",
      "fromName": "Masked User Name",
      "internetMessageId": "<PUZPR06MB4576BF221988D780C8412731E3DFA@masked.server.prod.outlook.com>",
      "recipientAddress": "masked.recipient.2@example.com",
      "remediationStatus": "Auto-Remediated",
      "subject": "Freightview, FreightPOP Users List",
      "toAddresses": [
        "masked.to.2@example.com"
      ],
      "returnPath": "masked.user.2@outlook.com",
      "senderDomain": "outlook.com",
      "senderIpAddress": null,
      "urlCount": 0,
      "urls": []
    }
  ]
}
  • JSON (threat_log) 스키마
{
  "event": {
    "abx_message_id": -3325933065721657641,
    "abx_portal_url": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/-3325933065721657641",
    "threat_id": "1c3736ab-9e3a-883f-62b5-6fe36ac9672c",
    "subject": "[EXTERNAL] RE: Masked Name PUP094439581",
    "from_address": "masked.sender@maskeddomain.xyz",
    "from_name": "masked.sender@maskeddomain.xyz",
    "to_addresses": "masked.recipient@maskedcorp.com",
    "recipient_address": "masked.recipient@maskedcorp.com",
    "internet_message_id": "<MASKEDID@masked-insurance-group.com>",
    "attack_type": "Phishing: Credential",
    "return_path": "masked.sender@maskeddomain.xyz",
    "sender_ip_address": "",
    "urls": [
      "www.masked-insurance-group.com",
      "http://www.masked-insurance-group.com/"
    ],
    "sender_domain": "masked-insurance-group.com",
    "tenant": "Auto Club Group"
  },
  "sourcetype": "threat_log"
}
  • JSON (abuse_mailbox) 스키마
{
  "event": {
    "abx_metadata": {
      "event_type": "ABUSE_MAILBOX",
      "timestamp": "2024-04-27T15:25:53.374227319Z",
      "trace_id": "00bc67b5-eb26-41c2-9f95-021eb435fc49"
    },
    "abx_body": {
      "campaign_id": "28b9c99f-f4a4-3032-bd99-3b7bac532471",
      "subject": "[EXTERNAL] News you might have missed",
      "recipient_name": "Masked PII Name",
      "recipient_address": "masked.abuse.recipient@secops.com",
      "internet_message_id": "<AutoNewsDigest-MASKED@odspnotify>",
      "email_label_or_location": "inbox"
    }
  },
  "sourcetype": "abuse_mailbox"
}
  • JSON (audit_log) 스키마
{
  "event": {
    "abx_metadata": {
      "event_type": "AUDIT_LOG",
      "timestamp": "2024-04-01T17:50:55.194231924Z",
      "trace_id": "6f95188c-cba2-4e86-a3ae-3eaf22c869e4"
    },
    "abx_body": {
      "category": "login",
      "details": {
        "request_url": "/api-token-auth/"
      },
      "source_ip": "0.0.0.0",
      "status": "SUCCESS",
      "tenant_name": "masked_secops_tenant",
      "timestamp": "2024-04-01T17:50:54.632Z",
      "user": {
        "email": "masked.audit.user@secops.net"
      }
    }
  },
  "sourcetype": "audit_log"
}
  • JSON (case) 스키마
{
  "event": {
    "abx_metadata": {
      "event_type": "CASE",
      "timestamp": "2024-08-08T12:42:45.104485389Z",
      "trace_id": "e4ad638f-439a-4c5f-839d-b650ecab9156"
    },
    "abx_body": {
      "schema_version": "1.0.0",
      "case_id": 11188520,
      "tenant": "masked name",
      "entity": {
        "entity_type": "USER_ACCOUNT",
        "identifier": "masked.case.user@secops.com"
      },
      "description": "Account Compromised",
      "event_timeline": [
        {
          "timestamp": "2024-09-07T20:17:25+00:00",
          "event_type": "SIGN_IN",
          "platform": "AZURE_AD",
          "insights": [
            {
              "signal": "Risky Browser",
              "description": "The browser associated with this sign-in, None, is considered risky and has been blocklisted by Abnormal or your organization."
            }
          ],
          "ip_address": "0.0.0.0 ",
          "operating_system": "ios 17.6",
          "isp": "verizon wireless",
          "location": {
            "city": "Huntley",
            "state": "Illinois",
            "country": "United States"
          }
        },
        {
          "timestamp": "2024-09-07T20:17:25+00:00",
          "event_type": "SIGN_IN",
          "platform": "AZURE_AD",
          "ip_address": "0.0.0.0 ",
          "operating_system": "ios 15.6"
        }
      ],
      "event_type": "CASE"
    }
  },
  "sourcetype": "case"
}

UDM 매핑 표

로그 필드 UDM 매핑 논리
attachmentCount additional.fields.attachmentCount.value.number_value 직접 매핑됨
attachmentNames additional.fields.attachmentNames.value 쉼표로 구분된 문자열로 연결됨
attackStrategy security_result.detection_fields.attackStrategy.value 직접 매핑됨
attackType security_result.threat_name 직접 매핑됨
attackVector security_result.detection_fields.attackVector.value 직접 매핑됨
attackedParty security_result.detection_fields.attackedParty.value 직접 매핑됨
autoRemediated IDM 객체에 매핑되지 않음
ccEmails network.email.cc 각 이메일 주소가 추출되어 배열에 추가됨
fromAddress network.email.from 이메일 주소가 추출되어 직접 매핑됨
fromName principal.user.user_display_name 직접 매핑됨
impersonatedParty security_result.detection_fields.impersonatedParty.value 직접 매핑됨
internetMessageId additional.fields.internetMessageId.value.string_value 직접 매핑됨
isRead additional.fields.isRead.value.bool_value 직접 매핑됨
postRemediated additional.fields.postRemediated.value.bool_value 직접 매핑됨
receivedTime additional.fields.mailReceivedTime.value.string_value 직접 매핑됨
remediationStatus additional.fields.remediationStatus.value.string_value 직접 매핑됨
remediationTimestamp additional.fields.mailRemediationTimestamp.value.string_value 직접 매핑됨
replyToEmails network.email.reply_to 첫 번째 이메일 주소가 추출되어 직접 매핑됨
returnPath additional.fields.returnPath.value.string_value 직접 매핑됨
senderDomain principal.administrative_domain 직접 매핑됨
senderIpAddress principal.ip, principal.asset.ip IP 주소가 추출되어 두 필드 모두에 매핑됨
sentTime additional.fields.mailSentTime.value.string_value 직접 매핑됨
subject network.email.subject 직접 매핑됨
summaryInsights security_result.summary 쉼표로 구분된 문자열로 연결됨
threatId security_result.threat_id 직접 매핑됨
toAddresses network.email.to 각 이메일 주소가 추출되어 배열에 추가됨
urlCount additional.fields.urlCount.value.number_value 직접 매핑됨
URLs additional.fields.detectedUrls.value 쉼표로 구분된 문자열로 연결됨
additional.fields.campaign_id.value.string_value event_data.abx_body.campaign_id가 있는 경우 매핑됨
additional.fields.trace_id.value.string_value event_data.abx_metadata.trace_id가 있는 경우 매핑됨
additional.fields.messageReportedTime.value.string_value event_data.abx_body.message_reported_time이 있는 경우 매핑됨
metadata.event_type messages 배열이 있는 경우 EMAIL_TRANSACTION으로 설정되고, 그렇지 않으면 다른 필드를 기반으로 결정되며 USER_LOGIN, STATUS_UPDATE 또는 GENERIC_EVENT일 수 있음
metadata.product_name 항상 ABNORMAL_SECURITY로 설정됨
metadata.vendor_name 항상 ABNORMAL_SECURITY로 설정됨
metadata.product_event_type event_data.abx_metadata.event_type이 있는 경우 매핑됨
extensions.auth.type event_type이 USER_LOGIN인 경우 AUTHTYPE_UNSPECIFIED로 설정됨
security_result.category messages 배열이 있는 경우 MAIL_SPAMMAIL_PHISHING으로 설정되고, 그렇지 않으면 다른 필드를 기반으로 MAIL_PHISHING 또는 MAIL_SPAM으로 설정됨
security_result.category_details abx_metadata.event_type이 ABUSE_MAILBOX인 경우 ABUSE_MAILBOX로 설정되고, 그렇지 않으면 abx_body.category가 login인 경우 login으로 설정됨
security_result.detection_fields.reported.value event_data.abx_body.reported가 있는 경우 매핑됨
security_result.detection_fields.judgement.value event_data.abx_body.judgement가 있는 경우 매핑됨
target.url event_data.abx_body.details.request_url이 있는 경우 매핑됨
target.user.userid event_data.abx_body.user.email이 있는 경우 매핑됨
target.user.email_addresses event_data.abx_body.user.email이 있는 경우 매핑됨
event.abx_body.abnormal_message_id event.idm.read_only_udm.metadata.product_log_id 변경 로그에서 매핑됨
event.abx_body.email_label_or_location event.idm.read_only_udm.additional.fields 변경 로그에서 매핑됨
event.abx_body.not_analyzed event.idm.read_only_udm.security_result.detection_fields 변경 로그에서 매핑됨
event_data.message_sources", "event_data.sender_auth_results.spf", "event_data.sender_auth_results.dkim", "event_data.sender_auth_results.dmarc", "event_data.tenant", and "event_data.attack_score additional.fields 변경 로그에서 매핑됨
event_data.abx_body.severity security_result.severity 변경 로그에서 매핑됨
event_data.abx_body.trigger_event" and "event_data.abx_body.entity.entity_type additional.fields 변경 로그에서 매핑됨
event_data.abx_body.entity.identifier principal.user.email_addresses 변경 로그에서 매핑됨
event_data.abx_body.case_id metadata.product_log_id 변경 로그에서 매핑됨
sourcetype", "event.folder_locations additional.fields 변경 로그에서 매핑됨
event.abx_message_id metadata.product_log_id 변경 로그에서 매핑됨

변경 로그

이 파서의 변경 로그 보기

도움이 더 필요하신가요? 커뮤니티 회원 및 Google SecOps 전문가에게 문의하여 답변을 받으세요.