
2015幎4æã®NATOã®ãšã¹ããã¢ã®ãµã€ããŒæ³šæã§ãã¢ã©ã€ã¢ã³ã¹ã®äž»èŠãªãµã€ããŒéšéã¯Androidããã€ã¹ããŠã§ãã«ã¡ã©ã«ããã»ã©é¢å¿ããªãããšãå€æããŸãããè»äºããã«ãŒã®çŠç¹ã¯WindowsãšSCADAã·ã¹ãã ã«ç§»ããŸããã
1ãæåãDellã®ç 究è ã¯ã2014幎ã«ã¹ãã¢POSã·ã¹ãã ãšSCADAã·ã¹ãã ãæ»æããããã«èšèšããããã«ãŠã§ã¢ã®æ°ã2åã«å¢å ããããšãææããŸãããéå»3幎éã«å°é家ã«ãã£ãŠåéãããŸããã
è¿å¹Žã®ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã¯ãæ å ±æè¡ãšã€ã³ã¿ãŒãããã®çºå±ã«ãããæ ¹æ¬çã«æ°ããã¬ãã«ã«éããŸããã ãã ããèªååã®æ°ããã©ãŠã³ãã«ã¯ç¬èªã®åé¡ããããŸããä¿è·ããã³ããŒã¿åŠçæè¡ã®äžé©åãªäœ¿çšã¯æ·±å»ãªè匱æ§ã«ã€ãªãããŸãã
ãã®ç¹ã§ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã¯æ»æè ãšãµã€ããŒè»ã®æšçã«ãªãã€ã€ãããŸãã åã ã®ã¯ãŒã ã§ããStuxnetïŒ2010ïŒãšFlameïŒ2012ïŒã¯ãããé«åºŠãªãã«ãã¹ããŒãžæ»æã¹ããŒã ã«çœ®ãæããããŸããã ãã®ããã2014幎ã«Havexããã€ã®æšéŠ¬ãé åžããããã«ãããã«ãŒã¯ç£æ¥çšãšã³ã¿ãŒãã©ã€ãºç®¡çãœãããŠã§ã¢ïŒSCADAïŒã®è£œé å ã®ãµã€ãããããã³ã°ããSCADAã·ã¹ãã ã®å ¬åŒé åžã«ææããŸããããã®åŸãäŒæ¥ã«ã€ã³ã¹ããŒã«ãããæ»æè ããšãŒãããã®ããã€ãã®åœã§å¶åŸ¡ã·ã¹ãã ãå¶åŸ¡ã§ããããã«ãªããŸããã
2012幎ãPositive Technologiesã®å°é家ã¯åæã¬ããŒããIndustrial Systems Security in Numbersããçºè¡šããŸããã 以äžã¯ã2012幎ãã2015幎ã«çºçããå€æŽãè©äŸ¡ããããšãã§ããæ°ãã調æ»ã®çµæã§ãã
ããã»ã¹å¶åŸ¡ã·ã¹ãã ã®ã»ãã¥ãªãã£ãåæããããã»ã¹ã§èŠ³å¯ãããäžè¬çãªåŸåã®ãã¡ã次ã®ç¹ã«æ³šæããããšãã§ããŸãã
éããã㢠ã çç£ã茞éã絊氎ããšãã«ã®ãŒã管çããå€ãã®ã·ã¹ãã ã¯ãå ¬éãããŠããæ€çŽ¢ãšã³ãžã³ã䜿çšããŠã€ã³ã¿ãŒãããäžã§èŠã€ããããšãã§ããŸãã 2015幎1æçŸåšãPositive Technologiesã®ç 究è ã¯ãããã»ã¹å¶åŸ¡ã·ã¹ãã ã®140,000以äžã®ç°ãªãã³ã³ããŒãã³ããçºèŠããŠããŸãã ããã«ããã®ãããªã·ã¹ãã ã®ææè ã¯ããªãœãŒã¹ããå€éšããèŠãããããšãèªèããŠããŸããã ããªã¹ã¯ã¢ãŒããšã¯ã©ãŠããµãŒãã¹ãã»ã³ãµãŒãšç©çããŒããç£æ¥çšWi-Fiããã³ãã®ä»ã®çš®é¡ã®ã¢ã¯ã»ã¹ãä»ããç£æ¥çšå¶åŸ¡ã·ã¹ãã ãžã®æ»æã®æ©äŒãèŠã€ããŸãã
å€ãã®ããã¯ã®1ã€ã®ã㌠ã éãããæ°ã®ã¡ãŒã«ãŒã§ç£æ¥çšå¶åŸ¡ã·ã¹ãã ãå®è£ ããçµç¹ã®æ°ãæ¥éã«å¢å ããŠãããããããŸããŸãªç£æ¥ã§éèŠãªæœèšã管çããããã«åãSCADAãã©ãããã©ãŒã ã䜿çšãããŠããŸãã ããšãã°ãåœç€Ÿã®å°é家ã¯ã倧åãããã³è¡çªåå éåšããšãŒãããã®ããã€ãã®ç©ºæž¯ãã€ã©ã³ã®åååçºé»æãããŸããŸãªåœã§æ倧ã®ãã€ãã©ã€ã³ãšçµŠæ°Žã·ã¹ãã ããã·ã¢ã®åè»ãšååŠãã©ã³ãã管çããã·ã¹ãã ã®è匱æ§ãç¹å®ããŸããã äžåºŠçºèŠããããšãåæ§ã®è匱æ§ã«ãããæ»æè ã¯äžçäžã®ããŸããŸãªãªããžã§ã¯ããæ»æã§ããŸãã
è åšã¯ä¿è·ãããéãçºçããŸã ã ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®è€éãªçµç¹ãšæè¡çããã»ã¹ç¶ç¶æ§ã®èŠä»¶ã«ãããå¶åŸ¡ã·ã¹ãã ã®åºæ¬ã³ã³ããŒãã³ãïŒç£æ¥çšãããã³ã«ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãDBMSïŒã¯å€ããªã£ãŠãããæŽæ°ãããŠãããããã®è匱æ§ã¯äœå¹Žã解æ¶ãããŠããŸããã äžæ¹ãèªååããŒã«ã®éçºã«ãããããã«ãŒã®é床ãå€§å¹ ã«åäžããŸãã PHDays IVãã©ãŒã©ã ã§ã®Critical Infrastructure Attackã³ã³ãã¹ãã®æ çµã¿ã®äžã§ãç£æ¥äŒæ¥ã§äœ¿çšãããŠããããã€ãã®ææ°ã®SCADAãã©ãããã©ãŒã ã2æ¥éã«ããã£ãŠãããã³ã°ãããŸãã ã
ãã¯ã¬ã€ãžãŒããŠã¹ ã ã ç£æ¥å¶åŸ¡ã·ã¹ãã ïŒèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ïŒãšããçšèªã¯ãèªååã®äž»ãªå¯Ÿè±¡ã倧èŠæš¡ãªç£æ¥äŒæ¥ã§ãã£ã80幎代ã«ç»å ŽããŸããã ããããæè¡ã®äœäŸ¡æ Œåãšå°ååã«ããã建ç©ã®çåœç¶æãç£èŠã·ã¹ãã ãé é»ã管çããã³ã³ãã¥ãŒã¿ãŒåãããããã€ã¹ãæ¥åžžç掻ã«ç©æ¥µçã«é¢äžããããã«ãªããŸããã åæã«ã補é æ¥è ãæ¶è²»è ãããããã®ã·ã¹ãã ã®å®å šæ§ã«ååãªæ³šæãæã£ãŠããŸããããã®èª¿æ»ã§ã¯ããã®ãããªããã€ã¹ãã€ã³ã¿ãŒãããçµç±ã§å©çšã§ããããšã瀺ããŠããŸãã
調æ»æ¹æ³
è匱æ§ã«é¢ããæ å ±ãåéããããã«ãè匱æ§ããŒã¿ããŒã¹ïŒICS-CERTãNVD / CVEãSCADA StrangeloveãSiemens Product CERTãªã©ïŒããšã¯ã¹ããã€ãã³ã¬ã¯ã·ã§ã³ïŒSAINTexploitãMetasploit FrameworkãImmunity Canvasãªã©ïŒããã³ããŒéç¥ãããã³ç§åŠã¬ããŒãã䜿çšãããŸãããå°éãµã€ãã§ã®äŒè°ãåºçç©ã
è匱æ§ã¯CVSS vã«åºã¥ããŠæ±ºå®ãããŸããã 2.çµ±èšã¯ãè匱æ§ã®å žåçãªèª¬æã®æ¬ åŠãé瀺ããªã·ãŒãªã©ã®èŠå ã®åœ±é¿ãåããããšã«çæããå¿ èŠããããŸãã ãããã£ãŠãICSã®å®éã®ã»ãã¥ãªãã£ç¶æ³ã¯ãçµ±èšã瀺ããããããã«æªåããå¯èœæ§ããããŸãã
ã€ã³ã¿ãŒãããã§ã®ICSã®å¯çšæ§ã«é¢ããããŒã¿ã¯ãå ¬éãããŠããæ€çŽ¢ãšã³ãžã³ïŒShodanãProject SonarãGoogleãBingïŒããã³ããŒãã¹ãã£ã³çµæã䜿çšããååçãªæ¹æ³ã䜿çšããŠåéãããŸããã ããŒã¿åæã¯ã740件ã®ãšã³ããªã§æ§æãããæçŽããŒã¿ããŒã¹ã䜿çšããŠå®è¡ãããŸãããããã«ããããããŒã«åºã¥ããŠè£œåã®è£œé å ãšããŒãžã§ã³ã«ã€ããŠçµè«ãåºãããšãã§ããŸãã ã»ãšãã©ã®ãã£ã³ã¬ãŒããªã³ãã¯SNMPïŒ240ïŒããã³HTTPïŒ113ïŒãããã³ã«ã«é¢é£ããŠãããçŽ3åã®1ãããŸããŸãªç£æ¥çšãããã³ã«ïŒModbusãDNP3ãS7ãªã©ïŒã«é¢é£ããŠããŸãã
è匱æ§ã®æ°
åèšã§ããã®èª¿æ»ã§ã¯ICSã®ã³ã³ããŒãã³ãã«691ã®è匱æ§ã確èªãããŸããã 2009幎以éãæ¥æ¿ã«å¢å ããŸãããä»åŸ3幎éïŒ2010ã2012ïŒã«ãèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã®è匱æ§ã®æ°ã¯20åã«å¢å ããŸãã ïŒ9ãã192ïŒã ãã®åŸãæ€åºãããè匱æ§ã®å¹Žéå¹³åæ°ã¯å®å®ããŸããïŒ2014幎ã«181ïŒã

ICSã®è匱æ§ã®æ°
è匱æ§åæ
èå¥ãããè匱æ§ã®é倧床ã¬ãã«ã2012幎ã®åŸåãä¿æããŠããŸãã 倧éšåã®è匱æ§ã®å±éºåºŠã¯é«ïŒ58ïŒ ïŒããã³äžïŒ39ïŒ ïŒã§ãã
CVSSãã¯ãã«ãèŠããšãè匱æ§ã®åæ°ä»¥äžã¯ã ã¢ã¯ã»ã·ããªãã£ãªã©ã®éèŠãªææšã«å¯ŸããŠé«ãã¡ããªãã¯ãæã£ãŠããŸã ã ãªã¢ãŒãããã®æªçšã®å²åãé«ããããã¯åŒ±ãèªèšŒã¡ã«ããºã ãšçµã¿åããããŠãæ»æã®ãªã¹ã¯ãé«ããŸãã
è匱æ§ãé€å»ããããã»ã¹ã«é¢ããæ å ±ãžã®ãªãŒãã³ã¢ã¯ã»ã¹ã¯å ¬éãããŠããªãããããã®ç 究ã§ã¯ã¡ãŒã«ãŒã®Positive Technologiesã®å°é家ãååŸããããŒã¿ã䜿çšããŸããã ç¶æ³ã¯ãã»ãšãã©ã®ã»ãã¥ãªãã£æ¬ é¥ïŒçŽ81ïŒ ïŒãåºãç¥ãããããã«ãªãåããŸãã¯æ å ±ã®èª¿æŽãããŠããªãé瀺ãã30æ¥ä»¥å ã«ã¡ãŒã«ãŒã«ãã£ãŠå³åº§ã«æé€ããã2012幎ãããæ鬱ã«èŠããŸãã 2015幎第1ååæã®ããŒã¿ã«ãããšã3ãæ以å ã«ä¿®æ£ãããè匱æ§ã¯ããã14ïŒ ã3ãæ以äžã§ä¿®æ£ããã34ïŒ ãããã³ãšã©ãŒã®æ®ãã®52ïŒ ã¯åã«ä¿®æ£ãããªãã£ãããã¡ãŒã«ãŒãä¿®æ£ããæéãå ±åããŸããã§ããã

èªååãããããã»ã¹å¶åŸ¡ã®è匱æ§ã®é€å»
ã¡ãŒã«ãŒå¥ã®è匱æ§
補åã®è匱æ§ã®æ°ããªãŒãããã¡ãŒã«ãŒã®ãªã¹ãã¯å€æŽãããŠããŸããïŒ ã·ãŒã¡ã³ã¹ ïŒ124ã®è匱æ§ïŒã ã·ã¥ãã€ããŒãšã¬ã¯ããªãã¯ãšInvensys ïŒ96ïŒã ã¢ããã³ãã㯠ïŒ51ïŒã ãŒãã©ã«ãšã¬ã¯ããªã㯠ïŒ31ïŒãè²·åããŸããã åæã«ãç¹å®ãããè匱æ§ãæã€ã¡ãŒã«ãŒã®äžè¬çãªãªã¹ããå¢ããŠããŸãã 以äžã®å³ã¯ãæãè匱æ§ã®é«ãäŒæ¥ã瀺ããŠããŸãã æ®ãã®88ã®ã¡ãŒã«ãŒã¯ãããã®ä»ãã®è¡ã«ãŸãšããããŠããŸãã

ããŸããŸãªã¡ãŒã«ãŒã®ICSã®è匱æ§ïŒãªã¹ã¯å¥ïŒ
ICSã®ã¢ã¯ã»ã·ããªãã£ãšè匱æ§ã®å°ç
å šäœãšããŠã調æ»ã®æ çµã¿å ã§ã 146 137ã®ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®ã³ã³ããŒãã³ããç¹å®ãããã€ã³ã¿ãŒãããçµç±ã§ã¢ã¯ã»ã¹ã§ããŸãã æãäžè¬çãªãã®ã¯ã ããªãžãŠã ãã«ãã£ã³ã°ãªãŒãã¡ãŒã·ã§ã³ã·ã¹ãã ïŒHoneywellïŒãš ããœãŒã©ãŒãã¯ãããžãŒïŒ SMA Solar Technology ïŒã«åºã¥ããã®ãå«ããšãã«ã®ãŒç£èŠããã³å¶åŸ¡ã·ã¹ãã ã§ãã å©çšå¯èœãªã³ã³ããŒãã³ãã®æ倧æ°ã¯ã PLC / RTUã§ãã ããã®åŸã«ã€ã³ããŒã¿ç£èŠããã³å¶åŸ¡ã·ã¹ãã ãç¶ããŸãã 以äžã¯ããããã¯ãŒã¯ããã€ã¹ãšHMI / SCADAã³ã³ããŒãã³ãã§ãã
åœ-æè¡çãªãŒããŒãé«åºŠãªèªååãè¡ã£ãŠããã®ã¯åœç¶ã®ããšã§ãããããã£ãŠããããã®åœã®ç£æ¥ã·ã¹ãã ã®ã€ã³ã¿ãŒããããžã®éäžåºŠã¯éåžžã«é«ãã§ãã åãšåãããã«ã ç±³åœãéŠäœïŒ33ïŒ ïŒã®ãŸãŸã§ããã2äœã¯ã€ã¿ãªã¢ã§ã¯ãªããã€ãã§ããã倧ããªããŒãžã³ïŒ 19ïŒ ïŒãæã£ãŠããŸãã äžè¬ã«ã欧å·å°åã§ã¯ãç£æ¥ã·ã¹ãã ã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹æ§ãèããåäžããŠããŸãã äžæ¹ãã¢ãžã¢å°åã§ã¯ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®ã»ãšãã©ç¥ãããŠããªãã³ã³ããŒãã³ããäžçåžå Žã§ç¥ãããŠãããåžžã«ç¹å®ã§ãããšã¯éããŸããã

å©çšå¯èœãªããã»ã¹å¶åŸ¡ã·ã¹ãã ã®é åž
䜿çšå¯èœãªICSã³ã³ããŒãã³ãã®ããŒãžã§ã³ãåæããããšã«ããã15,000以äžã®è匱ãªã³ã³ããŒãã³ããç¹å®ãããŸããã æãå€ãã®ã¯ç±³åœã§ã次ã«ãã©ã³ã¹ãã€ã¿ãªã¢ããã€ããç¶ããŸããããã¯ããããã®ã·ã¹ãã ã®pre延ã®å šäœåãšäžèŽããŠããŸãã äžæ¹ãã€ã³ã¿ãŒãããäžã§æãäžè¬çãªã³ã³ããŒãã³ãã§ã¯ãã»ãšãã©ã®è匱æ§ãæããã«ãããŠããªãããšã«æ³šæããå¿ èŠããããŸãã äžè¬ã«ãå©çšå¯èœãªããã»ã¹å¶åŸ¡ã·ã¹ãã ã®10ïŒ ä»¥äžãè匱ã§ããã

åœããšã®è匱ãªICSã³ã³ããŒãã³ãã®ååž

åœããšã®è匱ãªICSã³ã³ããŒãã³ãã®ååž
Positive Hack Daysã®æ å ±ã»ãã¥ãªãã£ã«é¢ãããã©ãŒã©ã ïŒã¢ã¹ã¯ã¯ã§5æ26ã27æ¥ã«éå¬ïŒã§ãPositive Technologiesã®å°é家ã¯ã2014幎ã®ç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®è匱æ§ã®èª¿æ»çµæã«é¢ãã詳现ãªã¬ããŒããæ瀺ããŸãã ããã§ãèªååãããããã»ã¹å¶åŸ¡ã·ã¹ãã ããããã³ã°ããããã®ã³ã³ãã¹ãã«åå ããããšãå¯èœã«ãªããŸãã