แสดงบทความที่มีป้ายกำกับ cyber security แสดงบทความทั้งหมด
แสดงบทความที่มีป้ายกำกับ cyber security แสดงบทความทั้งหมด

"Security Information & Event Management (SIEM): พื้นฐานสำคัญของระบบความปลอดภัยองค์กร"

SIEM: คำย่อของ Security Information & Event Management แนวทางการรักษาความปลอดภัยข้อมูลข่าวสารขององค์กร ที่ต้องการประสิทธิภาพ และความเชื่อถือได้ของระบบและเครื่องมือช่วยตรวจจับภัยคุกคามทางไซเบอร์ การสอบสวน การตอบโต้ต่อภัยคุกคาม SIEM จะเป็นเทคโนโลยีที่จะมาช่วยให้การรักษาความปลอดภัยไซเบอร์ขององค์กรมีแนวทางที่ชัดเจนจนก้าวนำหน้าภัยคุกคาม

ด้วยการทำงานแบบ real time ที่จะมอนิเตอร์กิจกรรมต่างๆ ขององค์กรตลอดเวลา และการวิเคราะห์ข้อมูลประวัติการใช้งาน รวมทั้งการเพิ่มการอยู่รอดขององค์กรจากภัยคุกคาม




การตรวจจับภัยคุกคามและความผิดปกติอื่นๆ SIEM จะประมวลผลข้อมูลจำนวนมากแล้วตรวจจับข้อมูลที่ผิดปกติได้อย่างรวดเร็ว รวมทั้งการจับภาพกิจกรรมที่ผิดปกติของแผนผังข้อมูลข่าวสารตามช่วงเวลาที่กำหนด รวมทั้งแอพพลิเคชั่นทำงานด้านเครือข่าย อุปกรณ์ระบบ ระบบคลาวด์ และการแก้ปัญหาแบบ SaaS ซึ่งจะช่วยให้องค์กรมีความก้าวหน้าล้ำไปข้างหน้าภัยคุกคามทั้งภายในและภายนอก

สำหรับบทความนี้ผมจะพาท่านผู้อ่านให้รู้จักกับเทคโนโลยี SIEM และวิธีการเลือกเครื่องมือ SIEM มาใช้งานกับหน่วยงานหรือองค์กร



แนวโน้มของ SIEM ในปี 2024-2025

SIEM เทคโนโลยีถูกแนะนำครั้งแรกในปี 2005 และพัฒนารูปแบบการใช้งานตามลำดับ สำหรับเครื่องมือช่วยในการตรวจจับภัยคุกคาม การสอบสวน และตอบโต้ภัยคุกคาม (TDIR) โดย SIEM เป็นคำประสมของ SIM การจัดการความปลอดภัยของข้อมูลข่าวสาร และ SEM การจัดการความปลอดภัยแบบองค์รวม และระบบการรักษาความปลอดภัยในทุกระดับขององค์กร


มาดูว่า SIEM ทำงานอย่างไร ?

มีหน้าที่ในการรวบรวม ดาต้า หรือ ข้อมูลการใช้งานอินเตอร์เน็ต ของหน่วยงานหรือองค์กร รวมทั้งการให้บริการข้อมูลต่างๆ เครื่องมือ และแอพพลิเคชั่นการใช้งานของทุกส่วน ทุกคนในองค์กร




ด้วยเทคโนโลยี SIEM จะเป็นศูนย์กลางมุมมอง เกี่ยวกับผู้ใช้งานไอทีขององค์กร ทำหน้าที่เป็นผู้รวมรวมข้อมูลและวิเคราะห์ข้อมูล ที่ผิดปกติ และแจ้งเตือนส่วนที่เกี่ยวข้องในการจัดการ

อุปกรณ์ระบบเครือข่าย เช่น สวิทซ์ฮับ เร้าเตอร์ สะพานเชื่อมต่อ อุปกรณ์ไร้สาย ฯลฯ

ระบบให้บริการข้อมูล เวบไซต์ ดาต้าเซนเตอร์ FTP เป็นต้น

อุปกรณ์รักษาความปลอดภัย IPS ไฟร์วอล โปรแกรมป้องกันไวรัส IDS

การให้บริการบนคลาด์

การวิเคราะห์ของ SIEM เช่น กิจกรรมของผู้ใช้งาน หมายเลขเครื่องใช้งาน หน่วยความจำ และอื่นๆ

โดย SIEM จะจัดหมวดหมู่ค่าเบี่ยงเบนการใช้าน เช่น ความพยายามในการ Log in ของผู้ใช้งาน การเปลี่ยนบัญชีผู้ใช้งาน หรือมัลแวร์ที่เป็นอันตราย โดยอ่อนตัวในการตั้งค่า และกำหนดการป้องกันและการแจ้งเตือน




โดย SIEM จะเลือกรูปแบบหรือพฤติกรรมที่เป็นอันตราย แม้ว่าจะมีไฟล์ต้องสงสัย ที่อาจจะไม่เข้าข่ายธงแดง แต่ว่า SIEM ก็จะยังสามารถตรวจจับได้ในที่สุดด้วย ชุดคำสั่งในการตรวจจับความสัมพันธ์ที่เชื่อมโยงหรือเกี่ยวข้องกัน




สุดท้าย SIEM จะเก็บข้อมูลในระบบฐานข้อมูล ที่เราจะใช้ในการวิเคราะห์ และตรวจสอบภายหลัง และแน่ใจว่าสอดคล้องกับกฏองค์กรด้านไซเบอร์



ด้วย SIEM จะช่วยให้องค์กรมีเครื่องมือเป็นศูนย์กลางการทำงาน ด้านรักษาความปลอดภัยไซเบอร์ ทำให้เจ้าหน้าที่ด้านรักษาความปลอดภัยไซเบอร์ของหน่วยงาน หรือองค์กร มีระบบตรวจสอบ และวิเคราะห์ภัยคุกคาม การป้องกัน การแจ้งเตือนส่วนที่เกี่ยวข้องได้สะดวกและรวดเร็ว

ประสิทธิภาพของการมองเห็นภัยคุกคามที่พุ่งเข้ามายังระบบของหน่วยงานหรือองค์กร

ลดเวลาในการตรวจสอบแก้ไขการแจ้งเตือนที่ผิดพลาด false alert ด้วยระบบฐานข้อมูลและรูปแบบการวิเคราะห์ภัยคุกคามที่ทันสมัยตามเวลาจริง

อ่อนตัวในการปรับแต่งและใช้งาน เพื่อให้สอดคล้องกับโปรแกรมและระบบงานต่างๆ ของหน่วยงานและองค์กร ที่อาจจะมีอยู่แล้ว
✅ ขั้นตอนการทดสอบใช้งาน SIEM

ขั้นตอนที่ 1: เลือกเครื่องมือ SIEM ที่ต้องการทดสอบ

คุณสามารถเริ่มจากเครื่องมือ SIEM ที่เป็นที่นิยมและมี Free Trial หรือโอเพ่นซอร์ส เช่น:
ชื่อเครื่องมือ ประเภท จุดเด่น
Splunk เวอร์ชันทดลอง แสดงผลข้อมูลแบบ Interactive, มี Marketplace เสริม
Elastic SIEM (Elastic Security) โอเพ่นซอร์ส รวม Log + SIEM + Endpoint เข้าไว้ในระบบเดียว
Microsoft Sentinel Cloud-based ผสานกับ Microsoft 365 และ Azure ได้ดี
Wazuh โอเพ่นซอร์ส ติดตั้งได้เอง, รวม SIEM + XDR ในตัว
IBM QRadar มี Free Trial ใช้ในองค์กรใหญ่, รองรับการวิเคราะห์เชิงลึก

ขั้นตอนที่ 2: เตรียมเครื่องมือและระบบสำหรับทดสอบ

  1. เตรียมเครื่อง VM หรือ Cloud (เช่น AWS EC2, Azure VM)

  2. ติดตั้ง OS เช่น Ubuntu, CentOS (ขึ้นอยู่กับเครื่องมือที่เลือก)

  3. ติดตั้งระบบ SIEM หรือใช้งานผ่าน Cloud

ตัวอย่าง:
สำหรับ Wazuh บน Ubuntu:

curl -s https://packages.wazuh.com/4.x/bash/wazuh-install.sh | bash -s -- -i


ขั้นตอนที่ 3: ส่งข้อมูล Log เข้าไปในระบบ SIEM

  • ติดตั้ง Agent หรือ Forwarder ที่เครื่องปลายทาง (เช่น Filebeat, Wazuh Agent)

  • กำหนดแหล่ง Log เช่น syslog, firewall log, Windows event log

  • ตรวจสอบว่า SIEM รับข้อมูลและแสดงผลแล้ว


ขั้นตอนที่ 4: ทดสอบการแจ้งเตือนเหตุการณ์ (Alert Test)

ตัวอย่างการทดสอบ:

  • พยายามเข้าสู่ระบบ (Login Fail) หลายครั้งติดกัน

  • สร้างไฟล์ต้องสงสัยบนเครื่อง Agent

  • เปลี่ยนค่าระบบผิดปกติ (เช่น การปิด Antivirus)

ดูว่า SIEM แจ้งเตือนและวิเคราะห์เหตุการณ์อย่างไร เช่น:

  • ตรวจจับความพยายาม Brute Force

  • การเข้าถึงไฟล์สำคัญโดยไม่ได้รับอนุญาต


ขั้นตอนที่ 5: วิเคราะห์ Dashboard และจัดการ Alert

  • เข้าไปดู Dashboard ที่แสดงพฤติกรรมผู้ใช้งาน, กราฟภัยคุกคาม

  • ตรวจสอบ Alert และจำแนกเป็น High, Medium, Low

  • กำหนด Action เช่น ปิดพอร์ต, ส่งอีเมล, แจ้งเตือนผ่าน Slack/MS Teams

  
เครื่องมือ ลิงก์
Splunk Free Trial https://www.splunk.com/en_us/download/splunk-enterprise.html
Elastic SIEM https://www.elastic.co/security
Microsoft Sentinel (Azure) https://azure.microsoft.com/en-us/products/microsoft-sentinel/
Wazuh (Open Source) https://wazuh.com/
IBM QRadar Free Trial https://www.ibm.com/products/qradar-siem

Thai house keeper was shocked 2.2 Million Baht was scam by Call Center Gang

 Latest cyber attack report in Thailand on yesterday 28 Fab 2024 .Thai cyber police was reported from 57 years old woman whose husband was a retired from ordnance department Army and passed away. 

The scammer was calling on her husband phone number while she was doing the house work as usually day life.

The Scammer: Hello ,this is the   ordnance department Army pension and welfare from BKK.

The victim: Yes ,and do you have anything about my pass away husband?

The Scammer: Yes ,we have some pension about 1650USD left and we wanted to transfer to  you bank account so, take another from and follow me instruction how to do ,so stay on your phone.

The victim : Okay I was on my smartphone now click the link vis  SMS  from the scammer to install the application .

The cyber police came to investigate the case and believed the SMS installed the remote access control application and gained control the victim phone moreover ,asked the victim to open bank account app which is involved password enter and face scan to transfer the 2.2 million Thai Bath from her account to the scammer. 

This sad news was happened series action which is no ending sooner or later.

what do you think and comment and suggest to prevent this threat in Thailand and also in other countries across the globe.

 


Cryptocurrency Wallets was hacked and lost 40 ETW in Thailand

 On 24th Feb 2024 Cryptocurrency Wallets fraud when a news was revealed from the victim of personal crypto digital  currency wallet was hacked and lost about 40 ETW which is converted into Thai bath is about  ฿106,318.89 THB, so total amount was 40 x 106,318.89 = 4252755.6 THB or about 118,362.25 USD 

The victim of the recently case is a famous actor and good knowledge of crypto currency trade and exchange ,moreover high education profile PH.D Science of education and Art from USA as well as a guest speaker about money investment on many university.

The incident happened in a night when he stayed up late to read article from website about the trade and exchange bitcoin ,with intend to find how much the total fee for his wallet transaction from beginning up to so far, he then now fall in phishing links in the article which is link over and across like normal website.
until to the last click link which said that this will let you know about how much you pay for your transaction fee  in sum up.

His device is iPhone11 with the face security login when screen off (I guess)  
for more detail I will add more in the next time.
I would like to tell all you guys that even high profile of education and knowledge of IT and cybersecurity is still became the victim of this hacked ,so we have to learn and careful about this simple phishing.
A lesson learn from my point of view.
1. Face login convenient ,but somehow be aware of this things also.
2.When Log in your bank account or digital wallet don't forget to log out too.



  
any comment and suggest would happy to welcome! 

Source : Thailand news on youtube and TV channel 

What is Pegasus spyware?

I would say that Pegasus is a high profile person such as the head of the country or senior officer in military forces or police and political. Pegasus spyware is zero-click mobile surveillance software designed to infiltrate iOS and Android devices to secretly collect sensitive information and send it to the NSO group server in cloud.

The dreaded Pegasus is its zero-click surveillance capabilities, meaning it can spread and infect devices without a victim having to do anything at all.

if your are a normal people I would say you will be more safe from this spyware which is believe that Pegasus is a state sponsor threat and very expensive one per licensed so the target of them would be the most value target such as leader in political ,military ,police officer for instance.


Initially, Pegasus spread through phishing attacks via email or SMS ,Now, Pegasus spyware has zero-click surveillance capabilities.

I would say that if your phone android /iOS not connect to the internet it would be tough for Pegasus to infect ,but possible when connect the phone with the trap Access point Wi-Fi by hacker team.

Not easy ,but possible anything can happens with anyone ,so be alert and precaution whenever you have to connect to the internet and Free public WIFI network.

if you are a high profile person normally they will have a baseline to prevent themselves from  risk and vulnerability, however things can happens if lack of awareness and carefulness.

From my own experience is that the malware infected in your device can be seen from slow running process task on devices ,but unique Pegasus capability is that it won't show any sign or symptom of any slow performance at all on the target devices.

How Pegasus is dreadful threat?

1.Ability to infect itself into the target device with a zero click.

2.No slow performance on the infected devices.



Best 10 tips to avoid malware attack

 I would like to share with your guys my 20 years on computer working both hardware and software system in order to review and go over the baseline of the principle virus computer hack in your computer and other devices.

this practical is not only for Windows OS ,but also Mac and LINUX as well.

1.Make sure your OS is copy right or genuine licensed either  licenses: Retail, OEM, or Volume.

2.Always update your OS to make sure for the latest software update this can help prevent malware and other threat in proactive way.

3.Regularly conduct scan for virus and threats using Windows defender and follow the instruction base on the threat be detected and respond.

4.Do not download and install other software or application from dark web or underground website which is most of them offer hack or crack the serial number.

5.If you need to download and install software or application try to do from the official website or portal  of software product company or organization such as Microsoft download ,Linux download for instances.

 6.Porn website and gambling website is the heaven of hackers to hide malware and spyware for those human who can not resist to that ,so keep away from this mentioned.

7.Some Freeware are good ,however strong recommend to use shareware or trial would be safer.

8.when install any software or application avoid click next next and next without to read and precaution for every click or else you will be more then 60% of install malware or spyware on your computer.

9.Try install Antivirus and malware product in order to detect and hunt for some threat that might compromise in your computer, such as  MacAfee or Trend Micro.

10.Back up your sensitive data in Flash drive or external disk in case of compromise you will have ability to recover and continue work as normal.




ทำความรู้จักกับ EDR

 คำว่า EDR ย่อมาจากคำว่า Endpoint Detection and Response แปลตรงตัวคือ จุดสุดท้ายการตรวจจับและการตอบโต้ 

ในทางการรักษาความปลอดภัยไซเบอร์แล้ว เทคโนโลยี EDR มีความสำคัญและจำเป็นต่อทุกๆ หน่วยงานหรือองค์กร เนื่องจากจะช่วยในการป้องกันการเจาะข้อมูล หรือโจมตีองค์กรจากนักเจาะระบบหรือ Hacker นั้นเอง แบบตามเวลาจริงหรือ Real time

การทำงานอย่างมีประสิทธิภาพของ EDR จำเป็นต้องทำหน้าที่ 4 อย่างนี้อย่างดี คือ

1. การรวบรวมข้อมูลการโจมตีทางไซเบอร์และข้อมูลอื่นๆที่อาจจะเกี่ยวข้อง โดยใช้คำสั่งขนาดเล็ก Agents ที่ทำงานอยู่ภายใต้อุปกรณ์แต่ละอย่างเช่น คอมพิวเตอร์ หรือมือถือ เป็นต้น

ตัวอย่างของข้อมูลที่รวบรวม ได้แก่ 

กระบวนการงานอะไรที่กำลังดำเนินอยู่

เครือข่ายอะไรที่ทำการเชื่อมต่อ

ข้อมูลอะไรที่กำลังเปิดดู เป็นต้น 

2. การตรวจจับและตอบโต้ภัยคุกคาม หรือ (Threat)

เป็นการทำงานแบบ Real time หรือตามเวลาจริงและตอบโต้กลับแบบอัตโนมัติ คือผู้ใช้งานไม่จำเป็นต้องมาตอบโต้เอง 

ซึ่งรูปแบบของ Threat หรือภัยคุกคามก็จะมี 2 แบบคือ แบบที่เรารู้จักแล้ว กับแบบใหม่ที่เราไม่รู็จักมาก่อน 

ซึ่งทีม รปภ.ไซเบอร์ จะสามารถรวบรวมสิ่งที่เรียกว่า สิ่งบอกเหตุการโจมตีของภัยคุกคาม หรือ IOC ย่อมาจากคำว่า Indicator of compromise  ถ้าเราตรวจจับและเจอมาแล้ว ก็จะนำไปสร้างสิ่งที่เรียกว่าลายนิ้วมือของการโจมตี หรือ Finger prints ไว้ในระบบเพื่อป้องกันการโจมตีของมัลแวร์หรือ Ransomware นั้นได้ เปรียบเทียบกับคนที่เคยมาเที่ยวผับ แล้วทะเลาะหรือสร้างความเดือดร้อนให้คนที่มาเที่ยวปกติ จนท.รปภ.ก็จะจดจำใบหน้า และพฤติกรรมของคนดังกล่าว และนำไปพรินแปะไว้ที่หน้าประตูทางเข้าผับเป็นต้น ถ้าคนนั้นมาเที่ยวอีกก็จะถูกตรวจจับและห้ามเข้าข้างใน เป็นต้น ซึ่งรูปแบบนี้ก็จะคล้ายกับการทำงานของโปรแกรม Antivirus ที่เรารู้จักและคุ้นเคยกันอยู่แล้ว 

แต่ทางกลับกันถ้าคนร้ายหรือคนไม่ดีที่เราไม่เคยรู้จักมาก่อนแฝงตัวเข้ามา เราจะรับมืออย่างไร 

การพัฒนา Advance Logarithms ในการตรวจสอบพฤติกรรมของภัยคุกคามที่เราไม่เคยพบมาก่อน ยกตัวอย่างการซ่อนมัลแวร์ ในโปรแกรมสำนักงานของ Microsoft Office ในชุดคำสั่งขนาดเล็กอย่างแมโคร 

ของโปรแกรม Ms Excel เป็นต้น ซึ่งเทคโนโลยี EDR จะสามารถสังเกตุเห็นความผิดปกติของมัลแวร์ที่จะแก้ไขหรือตบตาระบบรักษาความปลอดภัย ดังนั้น EDR ก็จะช่วยป้องกันมัลแวร์ไม่ให้ทำงานต่อไปได้ 

3. การทำหน้าที่สืบสวนพิสูจน์หลักฐานและการตามล่าภัยคุกคาม (Forensic investigation and threat hunting  ) ไม่มีใครรับประกันได้ว่า EDR จะสามารถปิดกั้นภัยคุกคามได้ 100% ดังนั้นการรวบรวมข้อมูลและพฤติกรรมของมัลแวร์ที่เกิดขึ้นใหม่ๆ ก็จะช่วยทำให้กระบวนการทำ Fingers print ของภัยคุกคามมีมากขึ้นในอนาคต รวมทั้งทีมนักล่าภัยคุกคามจะสามารถใช้ข้อมูลในการตามล่าภัยคุกคามได้ แบบการป้องกันเชิงรูก (Proactive defense) ทั้งนี้จะต้องใช้การตรวจสอบและตอบโต้แบบ manual หรือไม่ใช่แบบอัตโนมัตินั้นเอง 

4.การสนธิและการรายงาน (Integrate and report) สำหรับนักวิเคราะห์ระบบการรักษาความปลอดภัยแล้ว การสนธิข้อมูลเข้าด้วยกันเพื่อหาความเชื่อมโยงเป็นสิ่งจำเป็นในขั้นตอนการทำงานของกระบวนการดังกล่าว เพราะปกติพวกเขาจะได้รับการแจ้งเตือนภัยคุกคาม (Alerts) จำนวนมาก พวกเขาจำเป็นต้องเลือกและคัดแยกในส่วนที่เกี่ยวข้องและจำเป็น ซึ่ง EDR ควรจะมีส่วนช่วยในการทำงานของพวกเขา ในการจัดเรียงลำดับและความเร่งด่วนของภัยคุกคาม


สำหรับทีมรักษาความปลอดภัยไซเบอร์แล้ว EDR จำเป็นต้องผนวกหรือทำงานร่วมกับระบบหรือเครื่องมือเดิมขององค์กรที่มีอยู่แล้ว โดยการส่งรายงานภัยคุกคามไปที่ SIEM ,XDR หรือ SOAR เป็นต้น 

สิ่งที่ดีที่สุดของ EDR คือการช่วยให้องค์กรหรือหน่วยงานมีเทคโนโลยีในการตรวจจับภัยคุกคามที่ยืดหยุ่นและอ่อนตัวที่สุด ในการประกันผลสำเร็จของการโจมตีต่อระบบแล้ว จะสามารถตรวจจับภักคุกคาม กู้คืนระบบให้กลับมาใช้งานได้ตามปกติในเวลาที่เร็วที่สุด