ãã®ãããªåé¡ã®è§£æ±ºçã¯ãçµç¹ã®å¢çã宿çã«èª¿ã¹ãããšã§ãããã®åé¡ã®è§£æ±ºã«ã¯ããããã¯ãŒã¯ã¹ãã£ããŒãIoTæ€çŽ¢ãšã³ãžã³ãè匱æ§ã¹ãã£ããŒãã»ãã¥ãªãã£åæãµãŒãã¹ãé©ããŠããŸããããã«ãã®èšäºã§ã¯ãã¹ãã£ã³ã®ã¿ã€ããšãã©ã¡ãŒã¿ãŒããããã®é·æãšçæãé »ç¹ã«äœ¿çšãããããŒã«ãããã³çµæãåŠçããæ¹æ³ã«ã€ããŠæ€èšããŸãã
pingã¹ãã£ã³
èæ ®ãã¹ãæåã®ã¹ãã£ã³ã¯pingã¹ãã£ã³ã§ããäž»ãªã¿ã¹ã¯ã¯ããããã¯ãŒã¯å ã®ãã©ã€ããããŒããæ€åºããããšã§ããpingã¹ãã£ã³ãšã¯ãICMPãã±ããã®ãããŒããã£ã¹ããæããŸããã¹ãã£ããŒã¯ãæå®ãããIPã¢ãã¬ã¹ã«Echo REQUESTãã±ãããéä¿¡ããå¿çãšããŠEchoREPLYãã±ãããæåŸ ããŸããå¿çãåä¿¡ããå Žåããã¹ãã¯ãããã¯ãŒã¯äžã®æå®ãããIPã¢ãã¬ã¹ã«ååšãããšèŠãªãããŸãã
ICMPã¯ã蚺æã®ããã«ãããã¯ãŒã¯ç®¡çè ã«ãã£ãŠåºã䜿çšãããŠãããããããŒãã«é¢ããæ å ±ã®é瀺ãåé¿ããã«ã¯ãå¢çä¿è·ãæ£ããæ§æããããšãéèŠã§ããã»ãšãã©ã®ã»ãã¥ãªãã£ããŒã«ã¯ããã©ã«ãã§ICMPãŸãã¯ICMPå¿çããããã¯ãããããäŒæ¥ãããã¯ãŒã¯ã®å Žåããã®ã¿ã€ãã®ã¹ãã£ã³ã¯å€éšã¹ãã£ã³ã«ã¯é¢ä¿ãããŸãããäŒæ¥ãããã¯ãŒã¯ã«éæšæºã¿ã¹ã¯ããªãå Žåãéåžžãæ¬¡ã®ã¿ã€ãã®ICMPã¡ãã»ãŒãžã®çµäºãèš±å¯ãããŸãïŒDestination UnreachableãEcho REQUESTãBad IPããããŒãããã³Echo REPLYãDestination UnreachableãSource QuenchãTime ExceededãBadIPããããŒã®å ¥åãèš±å¯ãããŸããããŒã«ã«ãããã¯ãŒã¯ã«ã¯ãã®ãããªå³æ Œãªã»ãã¥ãªãã£ããªã·ãŒããªããæ»æè ã¯ãã§ã«ãããã¯ãŒã¯ã«äŸµå ¥ããŠãããšãã«ãã®æ¹æ³ã䜿çšã§ããŸãããããã¯ç°¡åã«æ€åºãããŸãã
ããŒãã¹ãã£ã³
TCPã¹ãã£ã³ãšUDPã¹ãã£ã³ãäžè¬åïŒããŒãã¹ãã£ã³ïŒã§çµã¿åãããŠã¿ãŸãããããããã®æ¹æ³ã§ã¹ãã£ã³ãããšãããŒãã§äœ¿çšå¯èœãªããŒããæ±ºå®ãããååŸãããããŒã¿ã«åºã¥ããŠã䜿çšãããŠãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã¿ã€ãããŸãã¯ã¿ãŒã²ããããŒãã§å®è¡ãããŠããç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ãæ³å®ãããŸããããŒãã¹ãã£ã³ãšã¯ãå€éšãã¹ãã«æ¥ç¶ããããã®ãã¹ã詊è¡ãæããŸããèªåãããã¯ãŒã¯ã¹ãã£ããŒã«å®è£ ãããŠããäž»ãªæ¹æ³ãèããŠã¿ãŸãããã
- TCP SYNã
- TCP CONNECTã
- UDPã¹ãã£ã³ã
TCP SYNæ¹åŒãæãäžè¬çã§ã95ïŒ ã®ã±ãŒã¹ã§äœ¿çšãããŠããŸããæ¥ç¶ãå®å šã«ç¢ºç«ãããŠããªããããããã¯ããŒããªãŒãã³ã¹ãã£ã³ãšåŒã°ããŸãã調æ»äžã®ããŒãã«SYNã¡ãã»ãŒãžãéä¿¡ãããå¿çãæåŸ ãããŸããããã«åºã¥ããŠãããŒãã®ã¹ããŒã¿ã¹ã決å®ãããŸãã SYN / ACKå¿çã¯ãããŒãããªãã¹ã³ããŠããïŒéããŠããïŒããšã瀺ããRSTå¿çã¯ãããŒãããªãã¹ã³ããŠããªãããšã瀺ããŸãã
ããã€ãã®èŠæ±ã®åŸã§å¿çãåä¿¡ãããªãå Žåãå®å ããŒããžã®ãããã¯ãŒã¯ãã©ãã£ãã¯ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠãã£ã«ã¿ãªã³ã°ãããŸãïŒä»¥äžããããŒãã¯ãã£ã«ã¿ãªã³ã°ãããŸãããšããçšèªã䜿çšããŸãïŒã ICMPã¡ãã»ãŒãžãDestinationUnreachableã¡ãã»ãŒãžãšç¹å®ã®ã³ãŒãããã³ãã©ã°ãšãšãã«è¿ãããå ŽåãããŒãããã£ã«ã¿ãŒæžã¿ãšããŠããŒã¯ãããŸãã
TCPCONNECTã¡ãœããã¯TCPSYNã»ã©äžè¬çã§ã¯ãããŸããããå®éã«ã¯ãŸã äžè¬çã§ãã TCP CONNECTã¡ãœãããå®è£ ããå Žåããã³ãã·ã§ã€ã¯æé ã䜿çšããŠç®çã®ããŒããžã®TCPæ¥ç¶ã確ç«ããããšããŸãããã®æé ã¯ãæ¥ç¶ãã©ã¡ãŒã¿ãŒãããŽã·ãšãŒãããããã®ã¡ãã»ãŒãžãã€ãŸããããŒãéã§ã®SYNãSYN / ACKãACKãµãŒãã¹ã¡ãã»ãŒãžã®äº€æã§æ§æãããŸããæ¥ç¶ã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¬ãã«ã§ç¢ºç«ããããããä¿è·ããŒã«ã«ãã£ãŠãããã¯ãããã€ãã³ããã°ã«èšé²ãããå¯èœæ§ããããŸãã
UDPã¹ãã£ã³ã¯TCPã¹ãã£ã³ãããé ããè€éã§ããã»ãšãã©ã®èªåã¹ãã£ããŒã§ã¯ãããŒãããšã«æšæºãã©ã¡ãŒã¿ãŒã䜿çšããŠ65,535åã®UDPããŒããã¹ãã£ã³ããããã®åèšæéãæå€§18æéããããããUDPããŒãã®ã¹ãã£ã³ã®è©³çްã«ãããå¿ããããã¡ã§ãããã®æéã¯ãã¹ãã£ã³ããã»ã¹ã䞊ååãããªã©ãããŸããŸãªæ¹æ³ã§ççž®ã§ããŸãã UDPãµãŒãã¹ã¯ãéåžžæ»æè ãé¢å¿ãæã€å€æ°ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãµãŒãã¹ãšéä¿¡ãããããUDPãµãŒãã¹ã®æ€çŽ¢ãæ€èšããå¿ èŠããããŸãã
UDPãµãŒãã¹DNSïŒ53ïŒãNTPïŒ123ïŒãSNMPïŒ161ïŒãVPNïŒ500ã1194ã4500ïŒãRDGïŒ3391ïŒã¯ãå€ãã®å Žåããããã¯ãŒã¯å¢çã«ãããŸãã echoïŒ7ïŒãdiscardïŒ9ïŒãchargenïŒ19ïŒãDAYTIMEïŒ13ïŒãTFTPïŒ69ïŒãSIPïŒ5060ïŒãNFSïŒ2049ïŒãRPCïŒ111ã137-139ïŒãªã©ã®ããŸãäžè¬çã§ã¯ãªããµãŒãã¹ã761ãªã©ïŒãDBMSïŒ1434ïŒã
空ã®UDPããããŒãéä¿¡ãããããŒãã®ã¹ããŒã¿ã¹ãå€å¥ãããŸããå®å ããŒãå°éäžèœã³ãŒããå«ãICMPå®å å°éäžèœå°éå¯èœæ§ãšã©ãŒãè¿ãããå Žåãããã¯ããŒããéããŠããããšãæå³ããŸãããã®ä»ã®ICMPå°éå¯èœæ§ãšã©ãŒïŒå®å ãã¹ãã«å°éã§ããªããå®å ãããã³ã«ã«å°éã§ããªãããããã¯ãŒã¯ã管çäžçŠæ¢ãããŠããããã¹ãã管çäžçŠæ¢ãããŠãããéä¿¡ã管çäžçŠæ¢ãããŠããïŒã¯ãããŒãããã£ã«ã¿ãªã³ã°ãããŠããããšã瀺ããŸããããŒããUDPãã±ããã§å¿çããå ŽåãããŒãã¯éããŠããŸãã UDPãšãã±ããæå€±ã®è©³çްã«ãããèŠæ±ã¯æ°åãéåžžã¯3å以äžç¹°ãè¿ãããŸããéåžžãå¿çãåä¿¡ãããªãå Žåããã©ãã£ãã¯ã®åå ãæç¢ºã§ãªããããããŒãã¹ããŒã¿ã¹ã¯ããªãŒãã³ããŸãã¯ããã£ã«ã¿ãªã³ã°æžã¿ããšå€æãããŸããã€ãŸããä¿è·ããŒã«ãŸãã¯ãã±ããæå€±ã«ãã£ãŠãã©ãã£ãã¯ããããã¯ãããŸãã
ããŒãã®ã¹ããŒã¿ã¹ãšUDPããŒãã§å®è¡ãããŠãããµãŒãã¹èªäœãæ£ç¢ºã«å€æããããã«ãç¹å¥ãªãã€ããŒãã䜿çšãããŸãããã®ååšã«ããã調æ»äžã®ã¢ããªã±ãŒã·ã§ã³ã§ç¹å®ã®åå¿ãçºçããã¯ãã§ãã
ãŸããªã¹ãã£ã³æ¹æ³
å®éã«äœ¿çšãããŠããªãæ¹æ³ïŒ
- TCP ACKã
- TCP NULLãFINãXmasã
- ã¬ã€ãžãŒã¹ãã£ã³ã
ACKã¹ãã£ã³æ¹åŒã®çŽæ¥ã®ç®çã¯ãä¿è·ã«ãŒã«ãèå¥ãããã£ã«ã¿ãªã³ã°ãããããŒããèå¥ããããšã§ãããã®ã¿ã€ãã®ã¹ãã£ã³ã®èŠæ±ãã±ããã«ã¯ãACKãã©ã°ã®ã¿ãèšå®ãããŠããŸããããŒãã¯ACKãã±ããã§å°éå¯èœã§ãããããéããŠããããŒããšéããŠããããŒãã¯RSTãã±ãããè¿ããŸãããã¹ããŒã¿ã¹ã¯äžæã§ããç¹å®ã®ã³ãŒããå«ãICMPDestination Unreachableã¡ãã»ãŒãžã§å¿çãŸãã¯å¿çããªãããŒãã¯ããã£ã«ã¿ãªã³ã°ããããšèŠãªãããŸãã
TCP NULLãFINãXmasã¡ãœããã¯ãTCPããããŒã«ç¡å¹ãªãã©ã°ãå«ãŸãããã±ãããéä¿¡ããŸãã NULLã¹ãã£ã³ã¯ããããèšå®ãããFINã¹ãã£ã³ã¯TCP FINããããèšå®ããXmasã¹ãã£ã³ã¯FINãPSHãããã³URGãã©ã°ãèšå®ããŸãããã®æ¹æ³ã¯ãRFC 793仿§ã®æ©èœã«åºã¥ããŠãããããŒããéãããããšãRSTãå«ãŸãªãçä¿¡ã»ã°ã¡ã³ãã«ãããå¿çãšããŠRSTãéä¿¡ãããŸããããŒããéããŠããå Žåãå¿çã¯ãããŸããã ICMPå°éå¯èœãšã©ãŒã¯ãããŒãããã£ã«ã¿ãªã³ã°ãããŠããããšãæå³ããŸãããããã®æ¹æ³ã¯SYNã¹ãã£ã³ãããç§å¯ã§ãããšèŠãªãããŸããããã¹ãŠã®ã·ã¹ãã ãRFC 793ã«æºæ ããŠããããã§ã¯ãªãããã粟床ã¯äœããªããŸãã
ã¬ã€ãžãŒã¹ãã£ã³ã¯ããŸã³ããã¹ããšåŒã°ããå¥ã®ãã¹ãã䜿çšããŠã¹ãã£ã³ãããããæãã¹ãã«ã¹ãªæ¹æ³ã§ãããã®æ¹æ³ã¯ãäŸµå ¥è ãã€ã³ããªãžã§ã³ã¹ã®ããã«äœ¿çšããŸãããã®ã¹ãã£ã³ã®å©ç¹ã¯ããŸã³ããã¹ãã®ããŒãã¹ããŒã¿ã¹ã決å®ããããããããŸããŸãªãã¹ãã䜿çšããŠããã¹ãéã®ä¿¡é Œé¢ä¿ã確ç«ã§ããããšã§ããã¡ãœããã®å®å šãªèª¬æã¯ãããã«ãããŸãã
è匱æ§ã®ç¹å®ããã»ã¹
è匱æ§ãšã¯ãæ»æãå®è£ ããããã«äœ¿çšã§ãããããŒãå šäœãŸãã¯ãã®åã ã®ãœãããŠã§ã¢ã³ã³ããŒãã³ãã®åŒ±ç¹ãæå³ããŸããæšæºçãªç¶æ³ã§ã¯ãè匱æ§ã®ååšã¯ã䜿çšãããŠããããã°ã©ã ã³ãŒããŸãã¯ã©ã€ãã©ãªã®ãšã©ãŒãããã³æ§æãšã©ãŒã«ãã£ãŠèª¬æãããŸãã
è匱æ§ã¯MITRECVEã«æåºããã詳现ã¯NVDã§å ¬éãããŠããŸããè匱æ§ã«ã¯ãCVEèå¥åãšå šäœçãªCVSSè匱æ§ã¹ã³ã¢ãå²ãåœãŠãããŸããããã¯ãè匱æ§ããšã³ãã·ã¹ãã ã«ãããããªã¹ã¯ã®ã¬ãã«ãåæ ããŠããŸããè匱æ§ã®è©äŸ¡ã®è©³çްã«ã€ããŠã¯ãèšäºãåç §ããŠãã ãããã¹ãã£ã³ã®ã¿ã¹ã¯ã¯è匱ãªãœãããŠã§ã¢ãæ€åºããããšã§ãããããäžå åãããMITRECVEãªã¹ãã¯è匱æ§ã¹ãã£ããŒã®åç §ãã€ã³ãã§ãã
æ§æãšã©ãŒãè匱æ§ã§ããããã®ãããªè匱æ§ãMITREããŒã¿ããŒã¹ã§èŠã€ããããšã¯ãã£ãã«ãããŸããããã ãããããã¯äŸç¶ãšããŠå éšèå¥åãæã€ã¹ãã£ããŒã®ãã¬ããžããŒã¹ã«ãªããŸããMITER CVEã«ãªãä»ã®ã¿ã€ãã®è匱æ§ã¯ã¹ãã£ããŒã®ç¥èããŒã¹ã«åé¡ããããããã¹ãã£ã³çšã®ããŒã«ãéžæãããšãã¯ãéçºè ã®å°éç¥èã«æ³šæãæãããšãéèŠã§ããVulnerability Scannerã¯ããŒããããŒãªã³ã°ããåéããæ å ±ãè匱æ§ããŒã¿ããŒã¹ãŸãã¯æ¢ç¥ã®è匱æ§ã®ãªã¹ããšæ¯èŒããŸããã¹ãã£ããŒãæã€æ å ±ãå€ããã°å€ãã»ã©ãçµæã¯ããæ£ç¢ºã«ãªããŸãã
ã¹ãã£ã³ãã©ã¡ãŒã¿ãã¹ãã£ã³ã®çš®é¡ãããã³è匱æ§ã¹ãã£ããŒã䜿çšããŠè匱æ§ãæ€åºããåçãèŠãŠã¿ãŸãããã
ã¹ãã£ã³ãªãã·ã§ã³
1ãæä»¥å ã«ãçµç¹ã®å¢çã¯ç¹°ãè¿ãå€åããå¯èœæ§ããããŸããé¡ã®åšå²ã®ã¹ãã£ã³ãå®è¡ãããšãçµæãç¡é¢ä¿ã«ãªãæéãç¡é§ã«ããå¯èœæ§ããããŸããã¹ãã£ã³é床ãå€§å¹ ã«åäžãããšããµãŒãã¹ãããããããããå¯èœæ§ããããŸãããã©ã³ã¹ãèŠã€ããŠãé©åãªã¹ãã£ã³ãã©ã¡ãŒã¿ãéžæããå¿ èŠããããŸããè²»ãããæéãçµæã®æ£ç¢ºæ§ãšé¢é£æ§ã¯ãéžæã«ãã£ãŠç°ãªããŸããåèš65,535åã®TCPããŒããšåãæ°ã®UDPããŒããã¹ãã£ã³ã§ããŸããç§ãã¡ã®çµéšã§ã¯ãã¹ãã£ã³ããŒã«ã«åé¡ãããäŒæ¥ã®å¹³åçµ±èšå¢çã¯ããã¹ã¯ã24ã®2ã€ã®å®å šãªCã¯ã©ã¹ãããã¯ãŒã¯ã§ãã
åºæ¬ãã©ã¡ãŒã¿ïŒ
- ããŒãã®æ°ã
- ã¹ãã£ã³æ·±åºŠã
- ã¹ãã£ã³é床ã
- è匱æ§ã倿ããããã®ãã©ã¡ãŒã¿ã
ããŒãã®æ°ã«ãã£ãŠãã¹ãã£ã³ã¯3ã€ã®ã¿ã€ãã«åããããšãã§ããŸã-TCPããã³UDPããŒãã®ãªã¹ãå šäœã®ã¹ãã£ã³ãTCPããŒãããã³äžè¬çãªUDPããŒãã®ãªã¹ãå šäœã®ã¹ãã£ã³ãäžè¬çãªTCPããã³UDPããŒãã®ã¹ãã£ã³ãããŒãã®äººæ°ã倿ããæ¹æ³ã¯ïŒ nmapãŠãŒãã£ãªãã£ã§ã¯ããŠãŒãã£ãªãã£éçºè ãåéããçµ±èšã«åºã¥ããŠãæã人æ°ã®ãã1000åã®ããŒããæ§æãã¡ã€ã«ã§å®çŸ©ãããŠããŸããåžè²©ã®ã¹ãã£ããŒã«ããæå€§3500ããŒããäºåæ§æãããŠããŸãã
ãããã¯ãŒã¯ãéæšæºããŒãã§ãµãŒãã¹ã䜿çšããŠããå Žåã¯ãããããã¹ãã£ã³ãªã¹ãã«è¿œå ããå¿ èŠããããŸããéåžžã®ã¹ãã£ã³ã§ã¯ããã¹ãŠã®TCPããŒããšäžè¬çãªUDPããŒããã¹ãã£ã³ããäžå€®ã®ãªãã·ã§ã³ã䜿çšããããšããå§ãããŸãããã®ãªãã·ã§ã³ã¯ãçµæã®æéãšç²ŸåºŠã®ç¹ã§æããã©ã³ã¹ãåããŠããŸããäŸµå ¥ãã¹ããŸãã¯å®å šãªãããã¯ãŒã¯å¢çç£æ»ãå®è¡ãããšãã¯ããã¹ãŠã®TCPããã³UDPããŒããã¹ãã£ã³ããããšããå§ãããŸãã
éèŠãªæ³šæïŒå éšãããã¯ãŒã¯ããã®ãã©ãã£ãã¯ã«å¯Ÿãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãã¹ãã£ããŒã«é©çšããããããããŒã«ã«ãããã¯ãŒã¯ããã¹ãã£ã³ããå Žåãå¢çã®å®éã®ç»åã衚瀺ããããšã¯ã§ããŸãããåšèŸºã¹ãã£ã³ã¯ã1ã€ä»¥äžã®å€éšãµã€ãããå®è¡ããå¿ èŠããããŸããç°ãªãåœã«ããå Žåã«ã®ã¿ãç°ãªããµã€ãã䜿çšããããšã¯çã«ããªã£ãŠããŸãã
ã¹ãã£ã³æ·±åºŠãšã¯ãã¹ãã£ã³ã¿ãŒã²ããã«é¢ããŠåéãããããŒã¿ã®éãæããŸããããã«ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããœãããŠã§ã¢ããŒãžã§ã³ãããŸããŸãªãããã³ã«ã«äœ¿çšãããæå·åã«é¢ããæ å ±ãWebã¢ããªã±ãŒã·ã§ã³ã«é¢ããæ å ±ãå«ãŸããŸããåæã«ãçŽæ¥çãªé¢ä¿ããããŸããç¥ãããããšãå€ãã»ã©ãã¹ãã£ããŒãåäœããããŒãã«é¢ããæ å ±ãåéããæéãé·ããªããŸãã
é床ãéžæãããšãã¯ãã¹ãã£ã³ãè¡ããããã£ãã«ã®åž¯åå¹ ãã¹ãã£ã³ããããã£ãã«ã®åž¯åå¹ ãããã³ã¹ãã£ããŒã®æ©èœã«ãã£ãŠã¬ã€ããããå¿ èŠããããŸãããããå€ããããŸããããããè¶ ãããšãçµæã®æ£ç¢ºæ§ãã¹ãã£ã³ãããããŒãããã³åã ã®ãµãŒãã¹ã®æäœæ§ã®ç¶æãä¿èšŒãããŸãããã¹ãã£ã³ãå®äºããã®ã«ãããæéãèæ ®ããããšãå¿ããªãã§ãã ããã
èåŒ±æ§æ€åºãªãã·ã§ã³ã¯ãã¹ãã£ã³ãªãã·ã§ã³ã®æãåºç¯ãªã»ã¯ã·ã§ã³ã§ãããã¹ãã£ã³ã®éåºŠãšæ€åºã§ããè匱æ§ã®éãæ±ºå®ããŸããããšãã°ããããŒãã§ãã¯ã¯é·ãã¯ããããŸãããæ»æã®ã·ãã¥ã¬ãŒã·ã§ã³ã¯ç¹å®ã®ãµãŒãã¹ã«å¯ŸããŠã®ã¿å®è¡ãããæéãããããŸãããæãé·ããã¥ãŒã¯Webã¯ããŒã«ã§ãã
䜿çšããèªåœããã§ãã¯ããå¿ èŠã®ããã¢ããªã±ãŒã·ã§ã³ãšã³ããªãã€ã³ãã®æ°ã«ãã£ãŠã¯ãæ°çŸã®Webã¢ããªã±ãŒã·ã§ã³ã®ãã«ã¹ãã£ã³ã«æ°é±éãããå ŽåããããŸãã Webã¢ãžã¥ãŒã«ãšWebã¯ããŒã©ãŒãå®è£ ãããŠãããããWebã®è匱æ§ãæ©åšã§æ€èšŒããŠãã100ïŒ ã®ç²ŸåºŠã¯åŸãããŸããããããã»ã¹å šäœã®é床ãå€§å¹ ã«äœäžããå¯èœæ§ãããããšãçè§£ããããšãéèŠã§ãã
ã¹ãã£ã³ããã¢ããªã±ãŒã·ã§ã³ãæ éã«éžæããŠãéåžžã®ã¹ãã£ã³ãšã¯å¥ã«Webã¯ããŒã«ãå®è¡ããããšããå§ãããŸãã詳现ãªåæã«ã¯ãéçããã³åçãªã¢ããªã±ãŒã·ã§ã³åæããŒã«ãŸãã¯äŸµå ¥ãã¹ããµãŒãã¹ã䜿çšããŸãããµãŒãã¹ãäžæãããªã¹ã¯ãããããã宿çãªã¹ãã£ã³ãå®è¡ãããšãã«å±éºãªã¹ãã£ã³ã䜿çšããããšã¯ãå§ãããŸããããã§ãã¯ã®è©³çްã«ã€ããŠã¯ã以äžã®ã¹ãã£ããŒã®æäœã«é¢ããã»ã¯ã·ã§ã³ãåç §ããŠãã ããã
ããŒã«
ãµã€ãã®ã»ãã¥ãªãã£ãã°ã調ã¹ãããšãããã°ãã€ã³ã¿ãŒãããã倿°ã®ç ç©¶è ããªã³ã©ã€ã³ãµãŒãã¹ãããã³ããããããã«ãã£ãŠã¹ãã£ã³ãããŠããããšã«æ°ä»ãããšæããŸãããã¹ãŠã®ããŒã«ã詳现ã«èª¬æããããšã¯æå³ããããŸããããããã¯ãŒã¯å¢çãšã€ã³ã¿ãŒããããã¹ãã£ã³ããããã«äœ¿çšãããããã€ãã®ã¹ãã£ããŒãšãµãŒãã¹ããªã¹ãããŸããã¹ãã£ã³ããŒã«ã¯ããããç°ãªãç®çãæãããããããŒã«ãéžæãããšãã¯ããã®ããŒã«ã䜿çšãããŠããçç±ãçè§£ããå¿ èŠããããŸããå®å šã§æ£ç¢ºãªçµæãåŸãããã«ãè€æ°ã®ã¹ãã£ããŒã䜿çšããããšãæ£ããå ŽåããããŸãã
ãããã¯ãŒã¯ã¹ãã£ããŒïŒMasscanãZmapãnmap..ãå®éããããã¯ãŒã¯ãã¹ãã£ã³ããããã®ãŠãŒãã£ãªãã£ã¯ä»ã«ããããããããŸãããå¢çãã¹ãã£ã³ããããã«ä»ã®ãŠãŒãã£ãªãã£ãå¿ èŠã«ãªãããšã¯ã»ãšãã©ãããŸããããããã®ãŠãŒãã£ãªãã£ã¯ãããŒããšãµãŒãã¹ã®ã¹ãã£ã³ã«é¢é£ããã»ãšãã©ã®ã¿ã¹ã¯ã解決ããŸãã
Internet of Thingsã®æ€çŽ¢ãšã³ãžã³ããŸãã¯ãªã³ã©ã€ã³ã¯ããŒã©ãŒã¯ãã€ã³ã¿ãŒãããå šè¬ã«é¢ããæ å ±ãåéããããã®éèŠãªããŒã«ã§ãããããã¯ããµã€ãã¡ã³ããŒã·ãããèšŒææžãã¢ã¯ãã£ããªãµãŒãã¹ãããã³ãã®ä»ã®æ å ±ã®èŠçŽãæäŸããŸãããã®ã¿ã€ãã®ã¹ãã£ããŒã®éçºè ã«åæããŠãã¹ãã£ã³ãªã¹ããããªãœãŒã¹ãé€å€ããããäŒæ¥ã§ã®äœ¿çšã®ã¿ãç®çãšããŠãªãœãŒã¹ã«é¢ããæ å ±ãä¿æãããããããšãã§ããŸããæãæåãªæ€çŽ¢ãšã³ãžã³ïŒå段ãCensysãFofaã
ãã®åé¡ã解決ããããã«ã倿°ã®ãã§ãã¯ãåããè€éãªåçšããŒã«ã䜿çšããå¿ èŠã¯ãããŸãããããã€ãã®ã軜ããã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ãã¹ãã£ã³ããå¿ èŠã¯ãããŸããããã®ãããªå Žåãç¡æã®ã¹ãã£ããŒã§ååã§ããç¡æã®Webã¯ããŒã©ãŒã¯ãããããããæã广çãªãã®ãéžæããã®ã¯å°é£ã§ããããã§ã¯ãéžæã¯ããã奜ã¿ã®åé¡ã§ããæãæåãªãã®ïŒSkipfishãNiktoãZAPãAcunetixãSQLmapã
æå°éã®ã¹ãã£ã³ã¿ã¹ã¯ãå®è¡ãããçŽãã®ã»ãã¥ãªãã£ã確ä¿ããã«ã¯ãè匱æ§ã«é¢ããç¥èããŒã¹ãåžžã«æŽæ°ãããã³ããŒããã®ãµããŒããšå°éç¥èãåããåçšã¹ãã£ããŒã®äºç®ãç«ãŠãFSTECèšŒææžãé©ããŠããå ŽåããããŸããæãæåãªãã®ïŒXSpiderãRedCheckãScanner-VSã
æ³šææ·±ãæåã§åæããã«ã¯ãBurp SuiteãMetasploitãOpenVASããŒã«ã䟿å©ã§ããGoogleã®Tsunamiã¹ãã£ããŒãæè¿ãªãªãŒã¹ãããŸããã
èšåãã䟡å€ã®ããå¥ã®è¡ã¯ããªã³ã©ã€ã³èåŒ±æ§æ€çŽ¢ãšã³ãžã³Vulnersã§ãã..ãããã¯ã倿°ã®ãœãŒã¹ããè匱æ§ã«é¢ããæ å ±ãåéããæ å ±ã»ãã¥ãªãã£ã³ã³ãã³ãã®å€§èŠæš¡ãªããŒã¿ããŒã¹ã§ãããæšæºã®ããŒã¿ããŒã¹ã«å ããŠããã³ããŒã®ã»ãã¥ãªãã£æ å ±ããã°å ±å¥šéããã°ã©ã ãããã³ãã®ä»ã®ããŒãå¥ãªãœãŒã¹ãå«ãŸããŸãããã®ãªãœãŒã¹ã¯ãçµæãååŸããããã®APIãæäŸãããããããã§å®éã«ã¹ãã£ã³ããªããŠããã·ã¹ãã ã«ãããŒãã§ãã¯ãå®è£ ã§ããŸãããŸãã¯ãVulnersè匱æ§ã¹ãã£ããŒã䜿çšããŸããããã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã€ã³ã¹ããŒã«ãããããã±ãŒãžã«é¢ããæ å ±ãåéããVulnersAPIãä»ããŠè匱æ§ããã§ãã¯ããŸãããªãœãŒã¹ã®æ©èœã®äžéšã¯ææã§ãã
ã»ãã¥ãªãã£åæããŒã«
ãã¹ãŠã®åçšã»ãã¥ãªãã£ã·ã¹ãã ã¯ã以äžã§èª¬æããåºæ¬çãªã¹ãã£ã³ã¢ãŒããSIEMã·ã¹ãã ãããã管çã·ã¹ãã ãCMBDããã±ããã·ã¹ãã ãªã©ã®ããŸããŸãªå€éšã·ã¹ãã ãšã®çµ±åããµããŒãããŠããŸããåçšã®è匱æ§åæã·ã¹ãã ã¯ãããŸããŸãªåºæºã«åºã¥ããŠã¢ã©ãŒããéä¿¡ããããŸããŸãªåœ¢åŒãšã¿ã€ãã®ã¬ããŒãããµããŒãã§ããŸãããã¹ãŠã®ã·ã¹ãã éçºè ã¯ãå ±éã®è匱æ§ããŒã¿ããŒã¹ãšã調æ»ã«åºã¥ããŠçµ¶ããæŽæ°ãããç¬èªã®ãã¬ããžããŒã¹ã䜿çšããŠããŸãã
åçšã»ãã¥ãªãã£åæããŒã«ã®äž»ãªéãã¯ããµããŒããããŠããæšæºãæ¿åºæ©é¢ã®ã©ã€ã»ã³ã¹ãå®è¡ããããã§ãã¯ã®æ°ãšå質ãããã³åœå ãœãããŠã§ã¢ã®ã¹ãã£ã³ã®ãµããŒããªã©ã1ã€ãŸãã¯å¥ã®è²©å£²åžå Žãžã®çŠç¹ã§ãããã®èšäºã¯ãè匱æ§åæã·ã¹ãã ã®å®æ§çãªæ¯èŒãæäŸããããšãç®çãšããŠããŸãããç§ãã¡ã®æèŠã§ã¯ãåã·ã¹ãã ã«ã¯ç¬èªã®é·æãšçæããããŸããïŒãªã¹ããããŠããããŒã«ã䜿çšãããšããããã®çµã¿åããã䜿çšããããšãã§ããã»ãã¥ãªãã£åæã«é©ããŠããã®QualysãMaxPatrol 8ãæ¥é7 InsightVMãTenable瀟ã®SecurityCenterãã
ã»ãã¥ãªãã£åæã·ã¹ãã ã®ããã¿
ã¹ãã£ã³ã¢ãŒãã¯ã次ã®3ã€ã®åæ§ã®ååã«åŸã£ãŠå®è£ ãããŸãã
- ç£æ»ããŸãã¯ãã¯ã€ãããã¯ã¹ã¢ãŒãã
- ã³ã³ãã©ã€ã¢ã³ã¹ããŸãã¯æè¡æšæºãžã®ã³ã³ãã©ã€ã¢ã³ã¹ã®æ€èšŒã
- ãã³ãã¹ãããŸãã¯ãã©ãã¯ããã¯ã¹ã¢ãŒãã
å¢çã¹ãã£ã³ã®äž»ãªé¢å¿ã¯ãã¹ãã£ã³ãããããŒãã«ã€ããŠäœãç¥ããªãå€éšã®æ»æè ã®ã¢ã¯ã·ã§ã³ãã·ãã¥ã¬ãŒãããããããã©ãã¯ããã¯ã¹ã¢ãŒãã§ãã以äžã¯ããã¹ãŠã®ã¢ãŒãã®ã¯ã€ãã¯ãªãã¡ã¬ã³ã¹ã§ãã
ç£æ»ã¯ãã¯ã€ãããã¯ã¹ã¢ãŒãã§ããããããã¯ãŒã¯ã®å®å šãªã€ã³ãã³ããªãå®è¡ãããã¹ãŠã®ãœãããŠã§ã¢ãæ€åºãããã®ããŒãžã§ã³ãšãã©ã¡ãŒã¿ã決å®ããããã«åºã¥ããŠãã·ã¹ãã ã®è匱æ§ã«ã€ããŠè©³çްãªã¬ãã«ã§çµè«ãå°ãåºãã匱ããã¹ã¯ãŒãã®äœ¿çšã«ã€ããŠã·ã¹ãã ããã§ãã¯ã§ããŸããã¹ãã£ã³ããã»ã¹ã«ã¯ãäŒæ¥ãããã¯ãŒã¯ãšã®ããçšåºŠã®çµ±åãå¿ èŠã§ããç¹ã«ãããŒããæ¿èªããã«ã¯ã¢ã«ãŠã³ããå¿ èŠã§ãã
ã¹ãã£ããŒã§ããèš±å¯ããããŠãŒã¶ãŒããããŒãããã®ãœãããŠã§ã¢ãããã³æ§æãã©ã¡ãŒã¿ãŒã«é¢ãã詳现æ å ±ãåãåãã®ã¯ã¯ããã«ç°¡åã§ããã¹ãã£ã³äžãããŒã¿ãåéãããã·ã¹ãã ã®è©³çްã«å¿ããŠããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŸããŸãªã¡ã«ããºã ãšãã©ã³ã¹ããŒããããŒã¿ã®åéã«äœ¿çšãããŸãããã©ã³ã¹ããŒãã®ãªã¹ãã«ã¯ãWMIãNetBiosãLDAPãSSHãTelnetãOracleãMS SQLãSAP DIAGãSAP RFCãé©åãªãããã³ã«ãšããŒãã䜿çšãããªã¢ãŒããšã³ãžã³ãå«ãŸããŸããããããã«éå®ãããŸããã
ã³ã³ãã©ã€ã¢ã³ã¹ã¯ãã»ãã¥ãªãã£æšæºãèŠä»¶ããŸãã¯ããªã·ãŒãžã®ã³ã³ãã©ã€ã¢ã³ã¹ã確èªããã¢ãŒãã§ãããã®ã¢ãŒãã¯ãç£æ»ãšåæ§ã®ã¡ã«ããºã ãšãã©ã³ã¹ããŒãã䜿çšããŸãããã®ã¢ãŒãã®æ©èœã¯ãã»ãã¥ãªãã£ã¹ãã£ããŒã«çµã¿èŸŒãŸããŠããæšæºã«æºæ ããŠãããã©ããäŒæ¥ã·ã¹ãã ããã§ãã¯ããæ©èœã§ããæšæºã®äŸãšããŠã¯ãæ¯æãã·ã¹ãã ãšåŠççšã®PCI DSSããã·ã¢ã®éè¡çšã®STO BR IBBSãEUèŠä»¶ã«æºæ ããããã®GDPRããããŸãããã1ã€ã®äŸã¯ãå éšã»ãã¥ãªãã£ããªã·ãŒã§ããããã¯ãæšæºã§æå®ãããŠããèŠä»¶ãããé«ãèŠä»¶ãæã€å ŽåããããŸããããã«ãã¢ããããŒãã®ã€ã³ã¹ããŒã«ãã§ãã¯ããã®ä»ã®ã«ã¹ã¿ã ãã§ãã¯ããããŸãã
Pentestã¯ãã¹ãã£ããŒãã¿ãŒã²ããã¢ãã¬ã¹ãŸãã¯ãã¡ã€ã³å以å€ã®ããŒã¿ãæããªããã©ãã¯ããã¯ã¹ã¢ãŒãã§ããã¢ãŒãã§äœ¿çšããããã§ãã¯ã®ã¿ã€ããèããŠã¿ãŸãããã
- ãããŒãã§ãã¯ã
- æ»æã®æš¡å£ã
- ãŠã§ããã§ãã¯ã
- æ§æã®ç¢ºèªã
- å±éºãªãã§ãã¯ã
ãããŒãã§ãã¯ã¯ãã¹ãã£ããŒã䜿çšãããŠãããœãããŠã§ã¢ãšãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã§ã³ãå€å¥ããå éšã®è匱æ§ããŒã¿ããŒã¹ã«å¯ŸããŠãããã®ããŒãžã§ã³ãæ€èšŒãããšããäºå®ã«åºã¥ããŠããŸãããããŒãšããŒãžã§ã³ãæ€çŽ¢ããããã«ãããŸããŸãªãœãŒã¹ã䜿çšãããŸããããã®ä¿¡é Œæ§ãç°ãªããã¹ãã£ããŒã®å éšããžãã¯ã«ãã£ãŠèæ ®ãããŸãããœãŒã¹ã«ã¯ããµãŒãã¹ãããŒããã°ãã¢ããªã±ãŒã·ã§ã³ã®å¿çãããã³ãããã®ãã©ã¡ãŒã¿ãŒãšåœ¢åŒãæå®ã§ããŸããWebãµãŒããŒãšã¢ããªã±ãŒã·ã§ã³ãåæããå Žåããšã©ãŒããŒãžãšã¢ã¯ã»ã¹æåŠããŒãžããã®æ å ±ããã§ãã¯ããããããã®ãµãŒããŒãšã¢ããªã±ãŒã·ã§ã³ã®å¿çãããã³ãã®ä»ã®èããããæ å ±æºãåæãããŸããã¹ãã£ããŒã¯ããããŒã¹ãã£ã³ã«ãã£ãŠæ€åºãããè匱æ§ããçãããè匱æ§ãŸãã¯æªç¢ºèªã®è匱æ§ãšããŠããŒã¯ããŸãã
æš¡æ¬æ»æã¯ããã¹ãã®è匱æ§ãæªçšããå®å šãªè©Šã¿ã§ããã·ãã¥ã¬ãŒããããæ»æã¯èª€æ€ç¥ã®å¯èœæ§ãäœãã培åºçã«ãã¹ããããŠããŸããã¹ãã£ããŒãã¹ãã£ã³ã¿ãŒã²ããã§è匱æ§ã·ã°ããã£ãæ€åºãããšãè匱æ§ãæªçšãããŸãããã§ãã¯ã§ã¯ãè匱æ§ãæ€åºããããã«å¿ èŠãªæ¹æ³ã䜿çšããŸããããšãã°ãéå®åã®èŠæ±ã¯ããµãŒãã¹ã®æåŠãåŒãèµ·ãããªãã¢ããªã±ãŒã·ã§ã³ã«éä¿¡ãããè匱æ§ã®ååšã¯ãè匱ãªã¢ããªã±ãŒã·ã§ã³ã«å žåçãªå¿çã«ãã£ãŠæ±ºå®ãããŸãã
å¥ã®æ¹æ³ïŒã³ãŒãã®å®è¡ãå¯èœã«ããè匱æ§ã®æªçšã«æåãããšãã¹ãã£ããŒã¯è匱ãªãã¹ãããããèªäœã«çºä¿¡PINGãŸãã¯DNSèŠæ±ãéä¿¡ã§ããŸããè匱æ§ãå®å šã«ãã§ãã¯ã§ãããšã¯éããªãããšãçè§£ããããšãéèŠã§ãããããã£ãŠããã³ãã¹ãã¢ãŒãã§ã¯ããã§ãã¯ãä»ã®ã¹ãã£ã³ã¢ãŒããããé ã衚瀺ãããããšããããããŸãã
Webãã§ãã¯ã¯ãæ€åºãããWebã¢ããªã±ãŒã·ã§ã³ãå®è¡ã§ããæãåºç¯å²ã§æéã®ãããã¿ã€ãã®ãã§ãã¯ã§ããæåã®æ®µéã§ã¯ãWebã¢ããªã±ãŒã·ã§ã³ã®ãã£ã¬ã¯ããªãã¹ãã£ã³ãããæœåšçãªè匱æ§ãããå¯èœæ§ã®ãããã©ã¡ãŒã¿ãšãã£ãŒã«ããæ€åºãããŸãããã®ãããªã¹ãã£ã³ã®é床ã¯ããã£ã¬ã¯ããªã®æ€çŽ¢ã«äœ¿çšãããèŸæžãšWebã¢ããªã±ãŒã·ã§ã³ã®ãµã€ãºã«ãã£ãŠç°ãªããŸãã
åãæ®µéã§ãCMSã®ãããŒãšã¢ããªã±ãŒã·ã§ã³ãã©ã°ã€ã³ãåéãããæ¢ç¥ã®è匱æ§ã®ãããŒãã§ãã¯ã«äœ¿çšãããŸããæ¬¡ã®æ®µéã¯ãåºæ¬çãªWebãã§ãã¯ã§ããããŸããŸãªã¿ã€ãã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã®æ€çŽ¢ãèªèšŒããã³ã»ãã·ã§ã³ã¹ãã¬ãŒãžã·ã¹ãã ã®ãšã©ãŒã®æ€çŽ¢ãæ©å¯ããŒã¿ãšä¿è·ãããŠããªãæ§æã®æ€çŽ¢ãXXEã€ã³ãžã§ã¯ã·ã§ã³ã®ãã§ãã¯ãã¯ãã¹ãµã€ãã¹ã¯ãªãããå®å šã§ãªãéã·ãªã¢ã«åãä»»æã®ãã¡ã€ã«ã®ããŒãããªã¢ãŒãã³ãŒãã®å®è¡ããã¹ãã©ããŒãµã«..ããªã¹ãã¯ãã¹ãã£ã³ãã©ã¡ãŒã¿ãšã¹ãã£ããŒæ©èœã«å¿ããŠåºããªãå¯èœæ§ããããŸããéåžžãæå€§ãã©ã¡ãŒã¿ãŒã§ã¯ãOWASPããã10ãªã¹ãã«åŸã£ãŠãã§ãã¯ãå®è¡ãããŸãã
æ§æãã§ãã¯ã¯ããœãããŠã§ã¢æ§æãšã©ãŒã®æ€åºãç®çãšããŠããŸããããã©ã«ãã®ãã¹ã¯ãŒããèå¥ããããç°ãªãã¢ã«ãŠã³ãã®çããã¹ã¯ãŒãã»ããã䜿çšããŠãã¹ã¯ãŒãã詊ãããããŸãã管çèªèšŒããã«ãšå¶åŸ¡ã€ã³ã¿ãŒãã§ãŒã¹ã䜿çšå¯èœãªããªã³ã¿ãŒã匱ãæå·åã¢ã«ãŽãªãºã ãã¢ã¯ã»ã¹æš©ã®ãšã©ãŒãããã³æšæºãã¹ã«æ²¿ã£ãæ©å¯æ å ±ã®é瀺ãæããã«ããŸããããŠã³ããŒãããã¯ã¢ããããITã·ã¹ãã ããã³æ å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®ç®¡çè ã«ãããã®ä»ã®åæ§ã®ãšã©ãŒã«äœ¿çšã§ããŸãã
å±éºãªãã§ãã¯ã®äžã«ã¯ããããã䜿çšãããšãããŒã¿ã®æŽåæ§ãŸãã¯å¯çšæ§ã®éåã«ã€ãªããå¯èœæ§ããããã®ããããŸããããã«ã¯ããµãŒãã¹æåŠã®ãã§ãã¯ãããŒã¿ã®åé€ãŸãã¯å€æŽãè¡ãããã®ãã©ã¡ãŒã¿ãŒã䜿çšããSQLã€ã³ãžã§ã¯ã·ã§ã³ãªãã·ã§ã³ãå«ãŸããŸããã¢ã«ãŠã³ãã®ãããã¯ã«ã€ãªãããã«ãŒããã©ãŒã¹ã®è©Šã¿ã«å¶éã®ãªããã«ãŒããã©ãŒã¹æ»æãå±éºãªãã§ãã¯ã¯ãèµ·ããããçµæã®ããã«äœ¿çšãããããšã¯ãã£ãã«ãããŸããããããŒã¿ã®å®å šæ§ãå¿é ããªãæ»æè ã®ã¢ã¯ã·ã§ã³ããšãã¥ã¬ãŒãããææ®µãšããŠãã»ãã¥ãªãã£ã¹ãã£ããŒã«ãã£ãŠãµããŒããããŠããŸãã
ã¹ãã£ã³ãšçµæ
åºæ¬çãªã¹ãã£ã³æ¹æ³ãšããŒã«ã確èªããŸããããã®ç¥èãå®éã«ã©ã®ããã«äœ¿çšããããšãã質åã«ç§»ããŸãããããŸããäœãã©ã®ããã«ã¹ãã£ã³ããããšãã質åã«çããå¿ èŠããããŸãããã®è³ªåã«çããã«ã¯ãçµç¹ã«å±ããå€éšIPã¢ãã¬ã¹ãšãã¡ã€ã³åã«é¢ããæ å ±ãåéããå¿ èŠããããŸããç§ãã¡ã®çµéšã§ã¯ãã¹ãã£ã³ã¿ãŒã²ãããã€ã³ãã³ããªãšè匱æ§ã®èå¥ã«åããæ¹ãè¯ãã§ãããã
ã€ã³ãã³ããªã¹ãã£ã³ã¯ãè匱æ§ã¹ãã£ã³ãããã¯ããã«é »ç¹ã«å®è¡ã§ããŸããã€ã³ãã³ããªã§ã¯ããµãŒãã¹ç®¡çè ãNATã䜿çšãããŠããå Žåã¯ãµãŒãã¹ã®å éšIPã¢ãã¬ã¹ãããã³ãµãŒãã¹ã®éèŠæ§ãšãã®ç®çã«é¢ããæ å ±ã§çµæãå å®ãããããšããå§ãããŸããå°æ¥çã«ã¯ãæ å ±ã¯ãäžèŠãŸãã¯è匱ãªãµãŒãã¹ã®æ€åºã«é¢é£ããã€ã³ã·ãã³ããè¿ éã«æé€ããã®ã«åœ¹ç«ã¡ãŸããçæ³çã«ã¯ãäŒæ¥ã«ã¯ãITããã³æ å ±ã»ãã¥ãªãã£ãµãŒãã¹ãé¢äžããããããã¯ãŒã¯å¢çã«ãµãŒãã¹ãé 眮ããããã®ããã»ã¹ãšããªã·ãŒããããŸãã
ãã®ã¢ãããŒãã䜿çšããŠãã人çèŠå ãããŸããŸãªæè¡çé害ã«ãããšã©ãŒãçºçããå¢çã«äžèŠãªãµãŒãã¹ã衚瀺ãããå¯èœæ§ããããŸããç°¡åãªäŸïŒå éšãããã¯ãŒã¯ããå¢çã«ããŒã443ããããŒããã£ã¹ããããã§ãã¯ãã€ã³ããããã¯ãŒã¯ã¢ãã©ã€ã¢ã³ã¹ã«ã«ãŒã«ãèšè¿°ãããŠããŸããããã«ãã£ããµãŒãã¹ã¯å€ãããµãŒãã¹ã忢ããŠããŸãã ITãµãŒãã¹ã¯ããã«ã€ããŠç¥ããããŠããªãã£ãã®ã§ãã«ãŒã«ã¯æ®ããŸããããã®å Žåãå¢çã¯ããã§ãã¯ãã€ã³ãã¢ãã©ã€ã¢ã³ã¹ã®ç®¡çããã«ãŸãã¯ããã§ãã¹ããããããã«èšç»ãããŠããªãã£ãä»ã®å éšãµãŒãã¹ãžã®èªèšŒã§çµããå¯èœæ§ããããŸããåæã«ãå¢çç·ã®ç»åã¯æ£åŒã«å€æŽãããŠããããããŒãã䜿çšå¯èœã§ãã
ãã®ãããªå€åãæ€åºããã«ã¯ã宿çã«ã¹ãã£ã³ããŠçµæã®å·®åæ¯èŒãé©çšããå¿ èŠããããŸãããããããšããµãŒãã¹ãããŒã«é¡èãªå€åãçããæ³šç®ãéããŠã€ã³ã·ãã³ãã®åæã«ã€ãªãããŸãã
è匱æ§ã®æé€
è匱æ§é€å»ããã»ã¹ãæ£ããæè¡çã«å®è£ ããããã®æåã®ã¹ãããã¯ãæäœããå¿ èŠã®ããã¹ãã£ã³çµæãæ£ãã衚瀺ããããšã§ããè€æ°ã®ç°ãªãã¹ãã£ããŒã䜿çšããå Žåã¯ãããŒãã®æ å ±ã1ãæã§åæããŠçµã¿åãããæ¹ãé©åã§ãããã®ãããåšåº«ã«é¢ãããã¹ãŠã®æ å ±ãä¿åããåæã·ã¹ãã ã䜿çšããããšããå§ãããŸãã
è匱æ§ãä¿®æ£ããåºæ¬çãªæ¹æ³ã¯ãã¢ããããŒããã€ã³ã¹ããŒã«ããããšã§ããå¥ã®æ¹æ³ã䜿çšããããšãã§ããŸã-å¢çãããµãŒãã¹ãåãåºããŸãïŒã»ãã¥ãªãã£æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ããå¿ èŠããããŸãïŒã
代åçãªèª¿æŽææ®µãé©çšã§ããŸããã€ãŸããè匱ãªã³ã³ããŒãã³ããŸãã¯ã¢ããªã±ãŒã·ã§ã³ã®äœ¿çšãé€å€ã§ããŸãããã1ã€ã®ãªãã·ã§ã³ã¯ãIPSãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ãªã©ã®ç¹æ®ãªã»ãã¥ãªãã£ããŒã«ã䜿çšããããšã§ãããã¡ããããããã¯ãŒã¯å¢çã«äžèŠãªãµãŒãã¹ã衚瀺ãããªãããã«ããæ¹ãæ£ããã§ãããããŸããŸãªç¶æ³ãç¹ã«ããžãã¹èŠä»¶ã®ããã«ããã®ã¢ãããŒããåžžã«å¯èœã§ãããšã¯éããŸããã
èåŒ±æ§æé€ã®åªå é äœ
è匱æ§ãä¿®æ£ããåªå é äœã¯ãçµç¹ã®å éšããã»ã¹ã«ãã£ãŠç°ãªããŸãããããã¯ãŒã¯å¢çã®è匱æ§ãæé€ããããã«äœæ¥ãããšãã¯ããµãŒãã¹ãå¢çã«é 眮ãããŠããçç±ããµãŒãã¹ã管çããŠãããŠãŒã¶ãŒãããã³ãµãŒãã¹ãææããŠãããŠãŒã¶ãŒãæç¢ºã«çè§£ããããšãéèŠã§ãããŸããäŒç€Ÿã®éèŠãªããžãã¹æ©èœãæ åœããããŒãã®è匱æ§ãæé€ã§ããŸããåœç¶ããã®ãããªãµãŒãã¹ãå¢çããåé€ããããšã¯ã§ããŸããããè£åæªçœ®ãŸãã¯è¿œå ã®ã»ãã¥ãªãã£æªçœ®ãé©çšããããšã¯ã§ããŸããéèŠåºŠã®äœããµãŒãã¹ã䜿çšãããšãç°¡åã«ãªããŸããäžæçã«å¢çããåé€ãããã£ãããšæŽæ°ããŠãµãŒãã¹ã«æ»ãããšãã§ããŸãã
ãã1ã€ã®æ¹æ³ã¯ãããŒãã®è匱æ§ã®é倧床ãŸãã¯æ°ã«å¿ããé€å»ã®åªå é äœã§ããããŒãããããŒã¹ãã£ã³ã®è匱æ§ã®çãã10ã40æ€åºããå Žåããããããã¹ãŠããã«ååšãããã©ããã確èªããŠãæå³ããããŸããããŸããããã¯ããã®ããŒãã®ãœãããŠã§ã¢ãæŽæ°ããææã§ãããšããã·ã°ãã«ã§ããæŽæ°ã®æ©äŒããªãå Žåã¯ãè£åæªçœ®ãè¬ããå¿ èŠããããŸããçµç¹ã«ãæŽæ°ããªãè匱ãªãœãããŠã§ã¢ã³ã³ããŒãã³ããèŠã€ãã£ãããŒãã倿°ããå Žåã¯ãæŽæ°ïŒãµããŒãïŒãµã€ã¯ã«ã«ãããœãããŠã§ã¢ãžã®åãæ¿ããæ€èšãããšããæ¥ãŸããããœãããŠã§ã¢ãæŽæ°ããã«ã¯ãæåã«ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãæŽæ°ããå¿ èŠãããå¯èœæ§ããããŸãã
çµæ
ãããã¯ãŒã¯å¢çäžã®ãµãŒãã¹ããã³ãµãŒãã¹ã«é¢ãããã¹ãŠã®æ å ±ã¯ãããªãã ãã§ãªããã€ã³ã¿ãŒãããã®èª°ããååŸã§ããŸããã¹ãã£ã³ããªããŠããã·ã¹ãã ã®è匱æ§ãäžå®ã®ç²ŸåºŠã§ç¹å®ããããšãã§ããŸããæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®ãªã¹ã¯ã軜æžããã«ã¯ããããã¯ãŒã¯å¢çãç£èŠããäžèŠãªãµãŒãã¹ãæéå ã«é衚瀺ãŸãã¯ä¿è·ããæŽæ°ãã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã
ããã»ã¹ã瀟å ã§çµç¹ãããŠããããå¢çå¶åŸ¡ãŸãã¯ã»ãã¥ãªãã£åæã®ããã®ãµãŒãã¹ãæäŸãããµãŒãããŒãã£ã®å°éå®¶ãé¢äžããŠçµç¹ãããŠãããã¯é¢ä¿ãããŸãããæãéèŠãªããšã¯ãå¢çå¶åŸ¡ãšè匱æ§ã®ä¿®åŸ©ã宿çã«ç¢ºå®ã«ããããšã§ãã
æçš¿è MaximFedotovãã·ãã¢ã¹ãã·ã£ãªã¹ãããªã³ã©ã€ã³ãµãŒãã¹éšéãPTãšãã¹ããŒãã»ãã¥ãªãã£ã»ã³ã¿ãŒãPositive Technologies