CISOïŒ ã€ãŽãŒã«ã誰ãã
ã€ãŽãŒã«ïŒ @@@ïŒ
CISOïŒ ãããçè§£ããŠãã ããããã¹ãŠã®ã«ã¡ã©ããã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã®æ§æã確èªããŠãã ããã
ã€ãŽãŒã«ïŒ ã§ãã100,500以äžããã®ã§ãããªãæéãããããŸãïŒ
CISOïŒ ç§ãã¡ã®é»æ°æåž«ã§ãããããªããåäŸã®é ã«é£ããŠè¡ã£ãŠãã ããã圌ã¯åäŸã®é ã«ã©ãžãªãµãŒã¯ã«ã蚪ããŸããã
IgorïŒ SCAPã詊ããŠã¿ãã»ãããããããããŸããã
CISOïŒ ãããŠäœ...
åæžã
å€ãã®ããã¥ã¡ã³ãïŒæšæºã泚æãæšå¥šäºé ïŒã¯ãæ å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£èšå®ã®èŠä»¶ãå®çŸ©ããè匱æ§ãæ€çŽ¢ãã管çãæŽæ°ããŸããæå€§ã®äŒæ¥ã®1ã€ã§æè¿çºèŠããã åé¡ã¯ãè匱æ§ãšæ§æã管çããå¿ èŠæ§ãåã³ç€ºããŠããŸãã
ååãšããŠãæ å ±ã·ã¹ãã ã¯è€éã§åçãªãªããžã§ã¯ãã§ãããããèŠä»¶ã«æºæ ããã«ã¯ããã®ç¶æ ïŒç£æ»ïŒãåžžã«ç£èŠããå¿ èŠããããŸãã
ã»ãã¥ãªãã£ç£æ»ãèªååããããã®äºå®äžã®æ¹æ³ã¯ãNISTã«ãã£ãŠææ¡ãããSCAPïŒã»ãã¥ãªãã£ã³ã³ãã³ãèªååãããã³ã«ïŒä»æ§ã§èª¬æ ãããŠããã¢ãããŒã ã§ãã
SCAPã䜿çšããæ å ±ã·ã¹ãã ã®èªåã»ãã¥ãªãã£ç£æ»ããã»ã¹ã®æ§é å³
次ã«ãç£æ»èªååããã»ã¹ã®ãã¹ãŠã®ãã€ã³ãããã詳现ã«çè§£ããããšããå§ãããŸããè¡ãïŒ
èŠä»¶
ç£æ»ã®ãœãŒã¹ããã®æ ¹æ ããã³çç±ã¯ãèŠå¶åœå±ã«ãã£ãŠèª²ãããæ å ±ã·ã¹ãã ã®é«ã¬ãã«ã®çŽã®èŠä»¶ã§ããããã¹ããã©ã¯ãã£ã¹ãç¬èªã®ããªã·ãŒããŸãã¯ããŒãããŒã®ããªã·ãŒã§å®çŸ©ãããŠããŸãã
ããšãã°ãPCI DSSæšæºã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«æ§æã®ãµããŒããããã°ã©ã ã®æŽæ°ãã»ãã¥ãªãã£ã·ã¹ãã ã®å®æçãªãã¹ããããã³æ å ±ã»ãã¥ãªãã£ããªã·ãŒã®ãµããŒãã«é¢ããèŠä»¶ã説æãããŠããŸãã
CISã³ã³ãããŒã«ã®æšå¥šäºé vã 7.1ã¯ãç¶ç¶çãªè匱æ§ç®¡çïŒCIS Control 3ïŒãããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®å®å šãªæ§æïŒCIS Control 5ïŒã®èŠä»¶ã瀺ããŠããŸãã
ãŸããFSTEC泚æçªå·17ã¯ãå·ã®æ å ±ã·ã¹ãã ã«å«ãŸããæ å ±ã®ä¿è·ã«é¢ããèŠä»¶ãå®çŸ©ããŠããŸãã
ãã¹ãŠã®èŠä»¶ãšæšå¥šäºé ã®äž»ãªåé¡ã¯ããããã®é«ã¬ãã«ã®é圢åŒåãããèšè¿°ã§ãããèªååããã»ã¹ã§ã®äœ¿çšãèš±å¯ããŠããŸããããã®ãœãªã¥ãŒã·ã§ã³ã¯ãSCAP仿§ã®éçºãšãšãã«2009幎ã«NISTã«ãã£ãŠææ¡ãããŸããã
SCAP
SCAPïŒSecurity Content Automation ProtocolïŒã¯ãæ å ±ã·ã¹ãã ãèªåçã«æ§æããè匱æ§ãæ€çŽ¢ããŠä¿®æ£ããã»ãã¥ãªãã£ã®ã¬ãã«ãè©äŸ¡ã§ããããã«ããé局仿§ã§ãã
SCAPã«ã¯ãçžäºæ¥ç¶ããã倿°ã®ã³ã³ããŒãã³ããå«ãŸããŠããããã®æ£åŒãªèª¬æã¯XMLã«åºã¥ããŠããŸããXCCDFã OVALã OCILã ARFèšèª ãèå¥ã¹ããŒã CCEã CPEã SWIDã CVE ;ã¡ããªã㯠CVSSã CCSS..ã
仿§ã®ä»ã®ã³ã³ããŒãã³ããéèŠã§ãããã³ã¢èšèªã¯XCCDFãšOVALã§ãã
XCCDFïŒExtensible Configuration Checklist Description FormatïŒã¯ãæ å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£èšå®ã®ãªã¹ããèšè¿°ããä»ã®SCAPã³ã³ããŒãã³ãã®çžäºæ¥ç¶ãå®çŸ©ããèšèªã§ãããã®èšèªã¯ãæ å ±äº€æãããã¥ã¡ã³ãçæãèªåãã¹ããããã³æå®ãããèŠä»¶ãžã®é©åæ§è©äŸ¡ãæäŸããããã«èšèšãããŠããŸããã¹ãã£ã³ãå®è¡ããã³ãã³ãã¯å«ãŸããŠããŸããã
OVALïŒOpen Vulnerability and Assessment LanguageïŒã¯ãã·ã¹ãã ã®ç¶æ ã«é¢ããè«çã¹ããŒãã¡ã³ãã®å®£èšèšèªã§ããããã¯SCAPæšæºã®äž»èŠã³ã³ããŒãã³ãã§ãããè匱æ§ãšå¿ èŠãªã·ã¹ãã æ§æã説æããããã«äœ¿çšãããŸãã
ãããã£ãŠãSCAPã³ã³ãã³ãã¯æ å ±ã·ã¹ãã ã®èŠä»¶ã§ãããæ£åŒãªåœ¢åŒã«å€æãããŸããããã«ãããã·ã¹ãã ãèŠä»¶ã«æºæ ããŠãããã©ãããèªåçã«ãã§ãã¯ããè匱æ§ãæ€çŽ¢ã§ããŸãã
XCCDFãšOVALã«ã€ããŠã¯æ¬¡ã®èšäºã§è©³ããåæããããã«ãªã³ã¯ãæ®ããŸãã
質åãSCAPã³ã³ãã³ãã¯ã©ãã§å ¥æã§ããŸããïŒ
- èªåã§äœæããŸããããã¯éåžžã«é¢åã§ã仿§ãçè§£ããå¿ èŠããããŸãã人çã容æã«ãªããªãŒãã³ãœãŒã¹ã§SCAPãšãã£ã¿ããªãã䜿ããããã°ã©ãã£ã«ã«ã€ã³ã¿ãã§ãŒã¹ã§XCCDFãšOVALææžãäœæããããšãã§ããŸãã
- ãªãŒãã³ãªãœãŒã¹ã䜿çšããŸããããšãã°ãOVALã®ããŒã¹-FSTECããã®èª¬æãUSGCBèŠä»¶ããŸãã¯MITREããã®ãªããžããªã
- è³Œå ¥ãããã€ãã®åçšè£œåãè³Œå ¥ãããšãã¡ãŒã«ãŒã®ããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã
éèš³
SCAPã³ã³ãã³ãã®åœ¢åŒã§åœ¢åŒåãããèŠä»¶ã¯ãããããã€ã³ã¿ãŒããªã¿ãŒãŸãã¯ã¹ãã£ããŒã®å ¥åããŒã¿ã§ããããã®äžã«ã¯éåžžã«å€ãã®ãã®ããããŸããMITERã¯ããæ¿èªããããçµç¹ããã®è£œåãããã³OVALãªããžããªã®èšé²ãä¿æããŠã ãŸãã
ããã€ãã®ç¡æã®éèš³ãæ€èšããŠãã ããïŒ OVALdiã OpenSCAPã ScanOVALã
OVALdi
éèš³ã¯MITREã«ãã£ãŠéçºãããŸãããããã¯ãéçºãããOVALããã¥ã¡ã³ãã®è©äŸ¡ãšæ§æãã§ãã¯ã瀺ãããšã®ã¿ãç®çãšããŠããŸããæ å ±ã·ã¹ãã ãè©äŸ¡ããããã®æå°éã®æ©èœããããŸããWindowsãšLinuxã®äž¡æ¹ã§å©çšã§ããŸããBSDã©ã€ã»ã³ã¹ã®äžã§é åžãããŸãã
OVALdiã¯ãã³ãã³ãã©ã€ã³ããã®ã¿ãããŒã«ã«ã§ã®ã¿å¶åŸ¡ã§ããŸãããã®ããã«ã¯ã管çè æš©éã§ã³ãã³ããå ¥åããå¿ èŠããããŸãã
ovaldi.exe -m -o "definitions.xml"
ãã
m
ã§ã-OVALããã¥ã¡ã³ãã®æŽåæ§ããã§ãã¯ããŸãã
o
ãã¯OVALããã¥ã¡ã³ããžã®ãã¹ã§ãã
ãªãŒãã³ãã£ãã
OpenSCAP BaseïŒCLIããŒã¹ã®ãªãŒãã³ãœãŒã¹ã¹ãã£ããŒïŒãSCAP WorkbenchïŒGUIããŒã¹ã®ã¹ãã£ããŒïŒãªã©ãå€ãã®è£œåã«ä»£è¡šãããRedHatã®ãããžã§ã¯ãã
次ã®èšäºã§ã¯ãRed Hatã®ç¡æã®èªåç£æ»ã·ã¹ãã ã®å±éãšäœ¿çšã«ã€ããŠè©³ãã説æããããã«ãªã³ã¯ãæ®ããŸãã
SCAP Workbenchã€ã³ã¿ãŒãã§ã€ã¹
OpenSCAPããŒã«ãWindowsã«é©ããŠãããšããäºå®ã«ãããããããunixã®ãããªã·ã¹ãã ã«ã¯ããå€ãã®å¯èœæ§ãæç€ºãããŸããåœåããããžã§ã¯ãã¯åœŒãã®è©äŸ¡ã®ã¿ãç®çãšããŠããŸããã
ã¿ãŒããã«ã®ã³ãã³ãã€ã³ã¿ãŒããªã¿ãŒãããªã¬ãŒãããŸãïŒ
oscap oval eval "D:\definitions.xml" --report "D:\results.html"
ã
ãã®åŸãããã¥ã¡ã³ãOVAL-ã®æç€ºã«åŸã£ãŠã·ã¹ãã ããã§ãã¯ããŸãã
«D:\definitions.xml»
çµæããã¡ã€ã«ã«ä¿åããŸã
«D:\results.html»
ã
SvanOVAL
ãã·ã¢ã®ããäŒç€ŸãFSTECçšã«éçºããããŒã«ããã®ããŒã«ã¯ç¡æã§ãWindowsãšLinuxïŒAstraïŒã®äž¡æ¹ã«é©ããŠããŸãã
ScanOVALã€ã³ã¿ãŒãã§ã€ã¹
äž»ãªæ¬ ç¹ã¯ãããŒã«ã®æ©èœãFSTEKããŒã¿ããŒã¹ã«è¡šç€ºãããè匱æ§ã«ã€ããŠã·ã¹ãã ããã§ãã¯ããããšã«ãã£ãŠã®ã¿å¶éãããOVALããã¥ã¡ã³ãã®ããžã¿ã«çœ²åããã§ãã¯ããããããã«ã¹ã¿ã ãã¡ã€ã«ããã£ãŒãã§ããªãããšã§ããããã«ãããããããScanOVALã¯ããŒããŒã¬ã¹ã»ãã¥ãªãã£ã«åããFSTECã®å€§ããªäžæ©ã§ãã
SCAPããžãã¯
ç°¡åã«ããããã«ãå€ãã®ãã¥ã¢ã³ã¹ã¯èæ ®ãããŠããŸãããããã¯ãäžè¬ã«SCAPã®ååã«éåããŸããããã¢ãããŒãèªäœãããããçè§£ããããšãå¯èœã«ããŸãã
SCAPã®åºæ¬çãªè«ç
å³XCCDFããã¥ã¡ã³ãã«ã¯ãããã¡ã€ã«ãå«ãŸããŠããããã®ãã¡ã®1ã€ããã¹ãçšã«éžæã§ããŸããããšãã°ãWindows 10ã®è匱æ§ãæ€çŽ¢ããããç¹å®ã®èŠä»¶ãæºããããããŸããå®éããããã¡ã€ã«ã«ã¯ãã·ã¹ãã ããã®ãããã¡ã€ã«ãæºãããŠãããã©ããã倿ããããã«ãã§ãã¯ããå¿ èŠã®ãããã§ãã¯ãªã¹ããå«ãŸããŠããŸãã
ãã§ãã¯ãªã¹ãã«ã¯ã説æçãªæ å ±ïŒå£é ã§ã®èŠä»¶ãäžæŽåã解決ããããã®æšå¥šäºé ãè©äŸ¡ææšãªã©ïŒãå«ãŸããŠããŸããããã¯ãã¹ãŠãæ€èšŒçµæã®èª¬æã衚瀺ããããã«äœ¿çšãããŸãã
ãã ãããã§ãã¯ãªã¹ãã®åé ç®ã«å«ãŸããäž»ãªãã®ã¯ãé¢é£ããOVALããã¥ã¡ã³ãã®ç¹å®ã®å®çŸ©ãžã®ãªã³ã¯ ã§ãã OVALå®çŸ©ãåŠçããåŸãã€ã³ã¿ãŒããªã¿ãŒã¯ããŒã«çµæïŒ
true
ãŸãã¯
false
ïŒãè¿ããŸãã ããã«åºã¥ããŠããã§ãã¯ãªã¹ãããã®èŠæ±ãæºããããŠãããšçµè«ä»ããŸãã
OVALããã¥ã¡ã³ãã§ã¯ãå®çŸ©ã¯åæ Œãããã¹ãã®è«çãã³ãã«ã圢æ ããŸããåãã¹ãã§ã¯ãè«çæŒç®åã䜿çšããŠãªããžã§ã¯ããš ç¶æ ãé¢é£ä»ã ãŸãã
ãã¹ãããªããžã§ã¯ããããã³ç¶æ ã«ã¯ããŸããŸãªã¿ã€ãããã ãŸãããã®å€ãããããŸãã SCAP仿§ã®å¹ åºãæ©èœã決å®ããã®ã¯ããããã®å€æ§æ§ã§ãã
ããšãã°ãWindowsçšããšããããã¿ã€ãããã
group_sid
ïŒ
group_sid_test
ã
group_sid_object
ãããŠ
group_sid_state
ããªããSIDèå¥åã«ãã£ãŠããŠãŒã¶ãŒããã³ãµãã°ã«ãŒããè©äŸ¡ããããšãã§ããŸãïŒããŸãã
dpkginfo
Linuxã¿ã€ãã§ ã¯ãç¹å®ã®DPKGããã±ãŒãžã«é¢ããæ å ±ã確èªã§ããŸããã¿ã€ã
textfilecontent
ã¯ã·ã¹ãã ã«äŸåãããæ§æãã¡ã€ã«ãªã©ã®ããã¹ããã¡ã€ã«ã®å å®¹ã®æ€èšŒãæäŸããŸãã
OVALããã¥ã¡ã³ãã®ç¶æ ã¯ããªããžã§ã¯ããç¹åŸŽä»ãããã©ã¡ãŒã¿ã®å¿ èŠãªå€ãæå®ããŸãã
ãã¹ããåŠçãããšããã€ã³ã¿ãŒããªã¿ãŒã¯ãªããžã§ã¯ãã®çŸåšã®ç¶æ ãç¹åŸŽä»ãããã©ã¡ãŒã¿ãŒã®å€ã決å®ãããã¹ãã§æå®ãããããžãã¯ã«åŸã£ãŠãæå®ãããå€ãšæ¯èŒããŸããããã«åºã¥ããŠãããŒã«ãã¹ãçµæãçæãããŸãã
å®çŸ©ã¯ãŸããæå®ã®ããžãã¯ã«åŸã£ãŠåãªã³ã¯ããããã¹ãã®çµæãæ¯èŒãããã§ãã¯ãªã¹ãããã®ç¹å®ã®èŠä»¶ã®éæã衚ãæçµçµæããããããŸãã
ããšãã°ãå®è¡å¯èœãã¡ã€ã«ã®äžå€æ§ãä¿èšŒããå¿ èŠãããå Žåããªããžã§ã¯ããšããŠSCAPã³ã³ãã³ãã«å€æã ãããšããã«ããŒã ã§æ±ºå®ãããç¹å®ã®å®è¡å¯èœãã¡ã€ã«ãäžããããŸã
.../example.exe
ã ã¹ããŒã¿ã¹ã¯ã次ã®ããã·ã¥åèšã®ç®çã®å€ã«èšå®ãããŸã
D41...27E
ã ãã¹ãã¯æ¯èŒæäœã決å®ããŸãïŒ
equal
-çããããã®å Žåãã€ã³ã¿ããªã¿ã¯ãã¡ã€ã«ã®ããã·ã¥åèšãèšç®ãã
.../example.exe
ãããæå®ããããã®ãšæ¯èŒã ãŸã
D41...27E
ãããããäžèŽããå Žåãããã¯è¯å®çãªçµæãè¿ããŸãã
çµæ
SCAP仿§ã«ããã°ãç£æ»çµæã¯ARFïŒAsset Reporting FormatïŒã§è¡šç€ºãããŸãã
ARFã¬ããŒãã¯XMLããã¥ã¡ã³ãã«å«ãŸããŠããããããã¡ã€ã«ã®èª¬æããã§ãã¯ãªã¹ãã®èŠä»¶ãããã³åãã§ãã¯ãªã¹ãé ç®ã®èŠçŽçµæãå«ãŸããŠããŸãã
éåžžãã¹ãã£ã³çµæã¯äººéãèªã¿åãã圢åŒã«å€æãããŸãã
OVALdiã€ã³ã¿ãŒããªã¿ãŒã䜿çšããŠWindows10ã®è匱æ§ããã§ãã¯ããçµæã®ãµã³ãã«
è£æ£
SCAPãããã³ã«ã®æ©èœã¯ãæ€åºãããäžæŽåã®èªåä¿®æ£ãšè匱æ§ã®æé€ãæäŸããŸãïŒæ©èœã¯èªåç£æ»ã·ã¹ãã ã«ãã£ãŠãµããŒããããŠããå¿ èŠããããŸãïŒã
ããã¯è¯ããªãã·ã§ã³ã®ããã«æããŸãããèªåä¿®æ£ã«ãã£ãŠã·ã¹ãã ãç Žæããå¯èœæ§ãããããããããã®æ©èœã¯æ éã«äœ¿çšããŠãã ããã
æãäžè¬çãªããªãšãŒã·ã§ã³ã¯ããã§ãã¯ã®çµæãæºããããŠããªãèŠä»¶ã®ãªã¹ããšãããããä¿®æ£ããããã«å®è¡ããå¿ èŠã®ããã¢ã¯ã·ã§ã³ã®ããã¹ãã«ãã説æãšããŠè¡šç€ºãããå Žåã§ããããšãã°ãCIS-CATã®ç¡æããŒãžã§ã³ã®ããã«ã
CIS-CATLiteã€ã³ã¿ãŒããªã¿ãŒã®çµæã®äŸãšåé€ã®æšå¥šäºé
çµè«
ç£æ»ã®èªååã¯æ å ±ã»ãã¥ãªãã£ã®æãéèŠãªã¿ã¹ã¯ã§ããããã®é¢é£æ§ã¯ãç¹å®ã®èŠä»¶ãæºããå¿ èŠãããã·ã¹ãã ã®æ°ãè€éããããã³ãã€ããã¯ã¹ã«ãããã®ã§ãã
SCAPã¯ãæè»ã§å€é¢çãªèªååææ³ãæäŸããŸãããæ¬¡ã®ãããªæ¬ ç¹ããããŸãã
- é«ã¬ãã«ã®å£é èŠä»¶ã圢åŒåãããSCAPã³ã³ãã³ãã«å€æããããšã®è€éãã
- SCAP仿§ã®å¯èœæ§ãæå€§éã«æŽ»çšã§ããããã«ããã€ã³ã¿ãŒããªã¿ãŒã®äœæã®è€éãã
äžæ¹ããšã³ããŠãŒã¶ãŒã®èгç¹ããã¯ãSCAPã¯ã管çãããã€ã³ãã©ã¹ãã©ã¯ãã£ã®æéãççž®ããã»ãã¥ãªãã£ãåäžãããã®ã«åœ¹ç«ã€ã·ã³ãã«ã§å¹æçãªããŒã«ã§ãã