במסמך הזה מתואר סוג של ממצא איום ב-Security Command Center. ממצאי האיומים נוצרים על ידי מזהי איומים כשהם מזהים איום פוטנציאלי במשאבי הענן שלכם. רשימה מלאה של ממצאי האיומים הזמינים מופיעה באינדקס של ממצאי האיומים.
סקירה כללית
Security Command Center בודק יומני ביקורת כדי לזהות מחיקה חריגה של תוכנית גיבוי של שירות Backup and DR, שמשמשת להחלת מדיניות גיבוי על אפליקציה.
המקור של הממצא הזה הוא Event Threat Detection.
איך מגיבים
כדי להגיב לממצא הזה:
שלב 1: בדיקת פרטי הממצא
- פותחים את
Impact: Google Cloud Backup and DR remove planהממצא, כמו שמתואר במאמר בדיקת הממצאים. חלונית הפרטים של הממצא נפתחת בכרטיסייה סיכום. - בכרטיסייה סיכום, בודקים את המידע בקטעים הבאים:
- מה זוהה, במיוחד השדות הבאים:
- שם האפליקציה: השם של מסד נתונים או מכונה וירטואלית שמחוברים ל-Backup and DR
- שם הפרופיל: מציין את יעד האחסון לגיבויים של נתוני אפליקציות ומכונות וירטואליות
- שם התבנית: השם של קבוצת מדיניות שמגדירה את תדירות הגיבוי, לוח הזמנים וזמן השמירה
- מקור המידע שהושפע
- השם המוצג של המשאב: הפרויקט שבו התוכנית נמחקה
- קישורים קשורים, במיוחד השדות הבאים:
- שיטת MITRE ATTACK: קישור למסמכי התיעוד של MITRE ATT&CK
- Logging URI: קישור לפתיחת Logs Explorer
- מה זוהה, במיוחד השדות הבאים:
שלב 2: מחקר על שיטות התקפה ותגובה
פונים לבעלים של חשבון השירות בשדה Principal email (כתובת האימייל של חשבון המשתמש). בודקים אם הבעלים החוקי ביצע את הפעולה.
שלב 3: מיישמים את התגובה
- בפרויקט שבו בוצעה הפעולה, עוברים למסוף הניהול.
- בכרטיסייה App Manager (ניהול אפליקציות), מאתרים את האפליקציות המושפעות שכבר לא מוגנות ובודקים את מדיניות הגיבוי של כל אחת מהן.
דוגמה למציאת JSON
הנה דוגמה ל-JSON של הממצא.
{ "finding": { "access": { "principalEmail": "USER_EMAIL", "callerIp": "IP_ADDRESS", "callerIpGeo": { "regionCode": "REGION_CODE" }, "serviceName": "backupdr.googleapis.com", "methodName": "deleteSla", "principalSubject": "user:USER_EMAIL" }, "attackExposure": {}, "backupDisasterRecovery": { "applications": [ "HOST_NAME" ], "backupCreateTime": "EVENT_TIMESTAMP" }, "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/locations/FINDING_LOCATION/findings/FINDING_ID", "category": "Inhibit System Recovery: Google Cloud Backup and DR remove plan", "cloudDlpDataProfile": {}, "cloudDlpInspection": {}, "createTime": "EVENT_TIMESTAMP", "database": {}, "description": "A backup plan with multiple policies for an application was deleted from the Google Cloud Backup and DR Service. The deletion of a backup plan can prevent future backups.", "eventTime": "EVENT_TIMESTAMP", "exfiltration": {}, "findingClass": "THREAT", "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/etd", "indicator": {}, "kernelRootkit": {}, "kubernetes": {}, "mitreAttack": { "primaryTactic": "IMPACT", "primaryTechniques": [ "INHIBIT_SYSTEM_RECOVERY" ] }, "mute": "UNDEFINED", "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID", "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID", "parentDisplayName": "Event Threat Detection", "resourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER", "severity": "HIGH", "state": "ACTIVE", "vulnerability": {}, "externalSystems": {} }, "resource": { "name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER", "display_name": "PROJECT_ID", "type": "google.cloud.resourcemanager.Project", "project_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER", "project_display_name": "PROJECT_ID", "parent_name": "//cloudresourcemanager.googleapis.com/organizations/ORGANIZATION_ID", "parent_display_name": "FOLDER_NAME", "folders": [] }, "sourceProperties": { "sourceId": { "projectNumber": "PROJECT_NUMBER", "customerOrganizationNumber": "ORGANIZATION_ID" }, "detectionCategory": { "ruleName": "backup_remove_plan" }, "detectionPriority": "MEDIUM", "affectedResources": [ { "gcpResourceName": "//backupdr.googleapis.com/projects/PROJECT_NUMBER" }, { "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER" } ], "evidence": [ { "sourceLogId": { "projectId": "PROJECT_ID", "resourceContainer": "projects/PROJECT_ID", "timestamp": { "seconds": "0", "nanos": 0.0 }, "insertId": "INSERT_ID" } } ], "properties": {}, "findingId": "FINDING_ID", "contextUris": { "mitreUri": { "displayName": "MITRE Link", "url": "https://attack.mitre.org/techniques/T1490/" }, "cloudLoggingQueryUri": [ { "displayName": "Cloud Logging Query Link", "url": "LINK_TO_LOG_QUERY" } ], "relatedFindingUri": {} }, "description": "A backup plan with multiple policies for an application was deleted from the Google Cloud Backup and DR Service. The deletion of a backup plan can prevent future backups.", "backupDisasterRecovery": { "applications": [ "HOST_NAME" ] } } }
המאמרים הבאים
- איך עובדים עם ממצאי איומים ב-Security Command Center
- אפשר לעיין באינדקס של ממצאי איומים.
- איך בודקים ממצא דרך מסוף Google Cloud .
- מידע על השירותים שמפיקים ממצאים לגבי איומים