この記事では、Cato XOps セキュリティ調査レポートの生成方法を説明します。これらのレポートは、XOps ストーリー調査を強調し、セキュリティイベントのデータを要約し、アカウントの全体的なセキュリティ状態に関する洞察を提供します。
注: XOpsはCatoのセキュリティおよび運用のための統一されたアナリティクス層であり、インサイトおよびガイド付き是正を提供します。 XOps は XDR に取って代わりました。詳細は XOps FAQ を参照してください。
概要
Cato は、アカウントのために調査された XOps(以前は XDR) ストーリーに関連するデータを要約する、定義済みレポートテンプレートを提供します。 これにより、すべてのストーリー調査の概要を示す XOps レポートを生成することができ、悪意のあるストーリーや疑わしいストーリーなど、最も重要なものに焦点を当てた内訳も含まれます。
定期的なレポートまたはワンタイムレポートのテンプレートを作成し、レポートの時間範囲を定義します。 デフォルトでは、XOps 調査レポート用の定義済みレポートテンプレートは、過去の 1 週間のストーリーデータを表示します。
レポートに関連する作業の詳細については、Cato Reportsを参照してください。

知られている制限事項
XOps セキュリティ調査レポートは、サイトまたはSDPユーザーごとにフィルタリングをサポートしていません。 フィルターが設定されている場合、それらはレポートには反映されず、全てのサイトと SDP ユーザーのデータを表示します。
定期的なXOps セキュリティ調査レポートの作成
Create a new recurring report by defining the Filters for the items included in the report, as well as the Schedule which defines how often the report is generated - every two minutes, daily, weekly, or monthly. Generated reports are stored in the Cato Cloud, and they can be automatically emailed or downloaded. The Schedule also defines the time range that is covered by each report.
You can select a mailing list of email addresses for the recipients, which can include Cato Management Application admins, and external users.
For more information about Mailing Lists, see Working with Mailing Lists.
To create a recurring report:
From the navigation pane, select Home > Reports.
From the Catalog tab, find and select the template you want to use to generate the report.
Click Generate > Create Schedule.
Enter a Report Name.
(Optional) In Filters, select specific sites or users for the predefined report.
By default, the predefined report includes all sites and users.
Define when the report will be generated and sent:
Select the Frequency.
For Weekly and Monthly scheduled reports, in Every select the day that the report is sent.
Select the timezone.
Select the export format: PDF or CSV.
In Subscriptions, select the Mailing List that receives the report.
You can click New to create a new mailing list.
Click Save Schedule. The report is added to the Saved Reports tab.
Generating a Recurring Report On Demand
Recurring reports are automatically generated based on their schedule settings. For example, a weekly report configured for Monday, is generated every Monday. You can also choose to manually generate a recurring report on demand, in which case the generated report uses the defined time range based on the current day. If an admin manually generates a weekly report on a Tuesday, the time range for the report is the previous 7 days starting from that Tuesday, regardless of the starting day of the recurring report. For more information about the time range of recurring reports, see Cato Reports.
To generate a recurring report on demand:
From the navigation pane, select Home > Reports.
From the Saved Reports tab, find the recurring report and click Generate Now.
From the Generated PDFs tab, find the report and click Download.
ワンタイムXOps調査レポートの作成
XOps セキュリティ調査テンプレートに基づいて一度限りのレポートを作成できます。 レポートに含まれる項目のフィルターを定義します。
To create a one-time report:
From the navigation pane, select Home > Reports.
From the Catalog tab, select the template you want to use to generate the report.
Select Generate > Generate Now.
Enter a Report Name.
Define the relevant Filters for your report.
These are specific to the report type.Define the Timeframe and Timezone of the report.
Select the Format: PDF or CSV.
Click Generate.
The report is generated, and you can download it from the Generated tab.
XOps セキュリティ調査レポートを理解する
これらは XOps セキュリティ調査レポートのセクションです:
エグゼクティブ概要
選択された時間範囲のイベントとストーリーの全体的な合計、以下を含む:
すべてのイベント: アカウントのイベント総数
セキュリティイベント: アカウントに対して有効なCatoセキュリティエンジンによって生成されたイベントの数
調査されたストーリー: ストーリー・ワークベンチで調査され、判定がなされた検出&レスポンス・ストーリーの総数。詳細はストーリー・ワークベンチを参照してください。
疑わしいおよび悪意のあるストーリー: ストーリー・ワークベンチで調査され、疑わしいまたは悪意のあると判定されたストーリーの数
判定による調査されたストーリー: すべて調査されたストーリーの判定による内訳
時間経過による調査されたストーリー: 脅威の種類(例: 疑わしい活動、評判、ポリシー違反、マルウェア)ごとの内訳を含むグラフ
悪意のあるおよび疑わしいストーリー
悪意があるまたは疑わしいと判定されたストーリーの情報を表示します。これには以下が含まれます:
悪意および疑わしいストーリーの脅威タイプ: 脅威タイプ(例えば、不審な活動、評判、ポリシー違反、マルウェア)による悪意のあるまたは疑わしいストーリーの数
悪意あるおよび疑わしいストーリーのサイト別分類: ストーリーを生成したトラフィックのサイトによる悪意あるまたは疑わしいストーリーの数
悪意のあるストーリーの重大度別: 重大度(高、中、低)による悪意のあるストーリーの数を示すチャート
悪意のあるおよび疑わしいストーリーのロケーション別: 脅威の場所に基づく悪意または疑わしいストーリーの数を示すグラフ ロケーションはストーリー内のターゲットとソースに基づいており、そのため 1 つのストーリーには複数の脅威の場所がある場合があります。
一般的なセキュリティ姿勢
トップブロックアプリケーションインターネットファイアウォール: インターネットファイアウォールでブロックされたトップアプリケーションおよびヒット数
トップブロックカテゴリインターネットファイアウォール: インターネットファイアウォールでブロックされたトップカテゴリおよびヒット数
トップブロックアプリケーションWANファイアウォール: WANファイアウォールでブロックされたトップアプリケーションおよびヒット数
トップブロックカテゴリWANファイアウォール: WANファイアウォールでブロックされたトップカテゴリおよびヒット数
リスクレベルによるIPSイベント: リスクレベルによるIPSブロックイベントの内訳を示すチャート
アンチマルウェアブロックイベント: レポートの時間範囲中におけるアンチマルウェアサービスのすべてのブロックイベントを示すグラフ
調査監査
このセクションでは、レポート時間範囲中に判定に達したすべての XOps ストーリー調査をすばやく確認できます。 監査テーブルの情報は、レポートが生成された時点での調査の状態を反映しています。
これらはテーブルの列です:
ストーリーへのリンク: クリックして、ストーリーワークベンチのストーリードリルダウンページを開きます。詳細はストーリー・ワークベンチを参照してください。
作成日: ストーリー作成の日時
表示: ストーリーでの攻撃の指標。 表示についての詳細は、Indications Catalog を参照してください。
タイプ: ストーリーを作成したXOps エンジン。
脅威タイプの分類。 例: 疑わしいターゲット, C&C, 疑わしいブラウザ拡張機能, スキャナー
判決:アナリストによって決定されたストーリーの判決
重大度:アナリストによって決定されたストーリーの重大度(可能な値: 低、中、高)
サイト:ネットワーク上のストーリーを生成したトラフィックがあるサイト
ソース:ストーリーに関与したネットワーク上のIPアドレス、デバイス名、またはSDPユーザー
ステータス:ストーリー調査の状況 考えられる値には以下が含まれます:オープン、クローズ、詳細待ち(待ち日数を含む)