SYNful KnockïŒããã¯äœã§ãäœãšäžç·ã«é£ã¹ãŸããïŒ
2015幎9æãFireEyeã®äžéšã§ããç±³åœã®äŒæ¥Mandiantã¯ãäžåœã®ããã«ãŒã掻åãæžãããããã«æ©åšã®è²©å£²ã®æžå°ãæè¿æ£åœåãããããã«ãŒã¿ãŒã§Cisco IOSãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®æ€åºãããåœã®ãã¡ãŒã ãŠã§ã¢ã«é¢ããäºä»¶ã®è©³çŽ°ãªèª¿æ»ã«é¢ããã¡ã¢ã圌ã®ããã°ã«å ¬éããŸããäžçã®ããã€ãã®åœã Mandiantã¯åœŒå¥³ã®ã¡ã¢ããSYNful Knock-Ciscoã«ãŒã¿ãŒã€ã³ãã©ã³ãããšåŒã³ããããã¯ãŒã¯æ©åšã®è©°ãç©ãšãã®å®å šæ§ã«ã€ããŠãåã ã®ç 究è ã®è¡šé¢çãªç解ãããã«å®èšŒããŸããã ç¹ã«ãMandiantã®èª¿æ»ã«ã€ããŠãããã·ã¢ã®å€§æã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ãããšèªç§°ããŠãããã·ã¢ã®äŒæ¥Digital Securityã®CEOã§ããIlya Medvedovskyã¯ã次ã®ããã«è¿°ã¹ãŠããŸããã ã·ã¹ã³èªäœã¯ãã¯ã©ã€ã¢ã³ããããããã€ã³ãã©ã³ããå®éã«çºèŠãããšããäºå®ãèªããããåŸãªãã£ããNSAã®ã¹ã¿ã€ã«ããŸãã¯ãããã¯ãŒã¯æ©åšã®ããŒããŠã§ã¢ã«ãŒãããã ãã ããããMedvedovskyæ°ã«ããåŒçšã§èšåãããã€ã³ãã©ã³ãã®ãªãããšãããã«ã¯ããŒããŠã§ã¢ã®ããšã«ã€ããŠã¯ãMandiantã®ç 究ã§ã¯è©±ããããŸããã§ããã Mandiantã¯äœãæãåºããŸãããïŒ
ãããã¯ãŒã¯æ©åšã®è匱æ§ã«çãã®äœå°ã¯ãªããšããã«èšããªããã°ãªããŸããïŒ å®è£ ãæåãããã«ã¯ãæ»æè ãCiscoã«ãŒã¿ãŒç®¡çè ã¢ã«ãŠã³ãïŒäžéšã®ã¡ãã£ã¢ãæžããããã«ã¹ã€ããã§ã¯ãªãïŒãŸãã¯æ©åšãžã®ç©ççã¢ã¯ã»ã¹ãå¿ èŠã§ãã ã·ã¹ã³ã¯ãããã«ã€ããŠMandiantç 究ã®1ãæåã®8æã«æžãã èŠåãçºè¡šããŸããã
PC管çè ã®ãã°ã€ã³åãšãã¹ã¯ãŒããååŸãã誰ããOSãåã€ã³ã¹ããŒã«ãããããã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ãããšèšã£ãããé©ãã§ãããã ã»ãšãã©ãªãã§ãããã ããã¯ããªãæçœãªè åšã§ãããå®éã«å®è£ ãããããšããããããŸãã ãããŠã管çè ãã¹ã¯ãŒããç§å¯ã«ããŠãããšããæšå¥šäºé ã¯ãæããæ¶ããªãå€å žã§ãã ã§ã¯ããããã¯ãŒã¯æ©åšã«é¢ããŠãåæ§ã®è åšãèæ ®ãããŠãããã管çè ãã¹ã¯ãŒããä¿æããããšãæšå¥šããããšã§çåãçããã®ã¯ãªãã§ããïŒ ã«ãŒã¿ãŒãŸãã¯ã¹ã€ããã¯ãã¢ãã€ã«ããã€ã¹ãŸãã¯ããŒãœãã«ã³ã³ãã¥ãŒã¿ãŒããã»ãã¥ãªãã£ã確ä¿ãããšããååã®ç¹ã§ã©ã®ããã«ç°ãªããŸããïŒ
Mandiantã«ãã£ãŠæ€åºãããã€ã³ã·ãã³ã/æªæã®ããã³ãŒãã®ååã§ããSYNful Knockã®å Žåãæ»æè ã¯äºåã«æºåããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã€ã¡ãŒãžãã«ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ã§ããŸããïŒããã¯ããŒããŠã§ã¢ã€ã³ãã©ã³ããšåŒã°ããŸããïŒïŒïŒã
- æ»æè ãèšå®ããç¹å®ã®æ¡ä»¶ãæºãããã©ãã£ãã¯ããªãã€ã¬ã¯ãããŸãã ãããSYNful Knockã®äž»èŠãªããã€ããŒããã§ããã
- å éšã«èšçœ®ããããããã¯ãŒã¯æ©åšãžã®å€éšã¢ã¯ã»ã¹çšã®NATãæäŸããŸãã
- ããšãã°ãããã»ã¹ãªã¹ãã§æªæã®ããã¢ã¯ãã£ããã£ãé衚瀺ã«ããããšã«ããé£èªåã
- ãµã€ããŒç¯çœªè ããã®ã³ãã³ããšããããžã®å¿çããã«ãŒã¿ãŒã€ã³ã¿ãŒãã§ã€ã¹ã«éä¿¡ãããç¹å¥ãªåœ¢åŒã®TCPãã±ããã«ã«ãã»ã«åããŸãã
SYNful Knockãèå¥ããããã®ããã€ãã®éåžžã«åçŽãªã¡ã«ããºã ãšæšå¥šäºé ãææ¡ãããŠããŸãã
- ã³ãã³ããshow platform | ã«ãŒã¿ã«ROãValidãå«ããŸãã ææããã«ãŒã¿ãŒã¯ãçµæãçæãããã次ã®ãããªãã®ãçæãããããããšã¯ãããŸããã
16M 0x40000000ïŒ0x41FFFFFF 0x00000000ïŒ0x01FFFFFF CacheMode = 3ãROãæå¹
1M 0x42000000ïŒ0x421FFFFF 0x02000000ïŒ0x021FFFFF CacheMode = 3ãROãæå¹
1M 0x42200000ïŒ0x423FFFFF 0x02200000ïŒ0x023FFFFF CacheMode = 3ãROãæå¹
1M 0x42400000ïŒ0x425FFFFF 0x02400000ïŒ0x025FFFFF CacheMode = 3ãROãæå¹
64K 0x42600000ïŒ0x4261FFFF 0x02600000ïŒ0x0261FFFF CacheMode = 3ãROãæå¹
64K 0x42620000ïŒ0x4263FFFF 0x02620000ïŒ0x0263FFFF CacheMode = 3ãROãæå¹
- Cisco TalosãªãµãŒããŠãããã«ãã£ãŠPythonã¹ã¯ãªãããšããŠèšè¿°ãããå®å šã«ç¡æã§é åžãããç¹å¥ãªSYNfulKnockã¹ãã£ããŒã
- SIDã36054ã® Snortæ»ææ€åºã·ã¹ãã ã®ã·ã°ãã㣠ã Cisco ASAãCisco ISRãCisco FirePOWERã¢ãã©ã€ã¢ã³ã¹ãCisco Firepower 9300ããã³ä»®æ³å®è¡ã®FirePOWERãµãŒãã¹ã®äžéšã§ããCisco NGIPSäŸµå ¥æ€ç¥ã·ã¹ãã ã«ããåæ§ã®ã·ã°ããã£ãè£ åãããŠããŸãã
ãã®ãããªçœ²åã®çµæã以äžã«ç€ºããŸãã
çŸåšå ¥æå¯èœãªæ å ±ã«ãããšãSYNful Knockã¯æ·±å»ãªæ害ãåŒãèµ·ããããShadowserverã«ãããšããã®é ä¿¡ç¯å²ïŒåœ±é¿ãåãããããã¯ãŒã¯ããã€ã¹ã®æ°ïŒã¯2015幎9æ20æ¥ã«163å°ã«å¶éãããŸããïŒãã®äžä»£ã®1,000äžå°ã®è²©å£²ããã€ã¹ã®ãã¡ïŒã
ã·ã¹ã³ããŒããŠã§ã¢ã€ã³ã·ãã³ãå±¥æŽ
ãã ããSYNful Knockã¯ãã·ã¹ã³ã®ãããã¯ãŒã¯è£œåã«é¢ããæåã®æ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã§ã¯ãããŸããã§ããã åèšã§ãéå»4幎éã«ãæ©åšã®ãã«ãŠã§ã¢ææã䌎ã6ã€ã®ã€ã³ã·ãã³ããç¹å®ããŸããã ãããã¯ãã¹ãŠãããŸããŸãªæ¹æ³ã§ããŸããŸãªã·ã¹ã³ãã©ãããã©ãŒã ãæ»æããããšããæ·±å»ãªäŸµå ¥è ã®åªåãåæ ããŠããŸãã
ããã...ãããã®ã€ã³ã·ãã³ããããå°ã詳ãã説æããåã«ãSYNful Knockã§ã€ã³ã·ãã³ãã説æãããšãã«ãã§ã«è¿°ã¹ãéèŠãªãã€ã³ããäœããããšæããŸãã èšåãããã±ãŒã¹ã®ãããã«ãããŠãã䜿çšãããã·ã¹ã³ãœãããŠã§ã¢ã®æ¢ç¥ãŸãã¯æªç¥ã®è匱æ§ã¯ãããŸããã§ããã åŒç€ŸãŸãã¯åŒç€Ÿã®ã客æ§ãèšé²ãããã¹ãŠã®ã±ãŒã¹ã§ãæ»æãåããã®ã¯ããããã¯ãŒã¯æ©åšã®ç®¡çè ã¢ã«ãŠã³ãã®äŸµå®³/çé£ããŸãã¯Cisco IOSãåããæ©åšãžã®ç©ççã¢ã¯ã»ã¹ã®ããããã§ãã
äžã®è¡šã¯ãéå»4幎éã«èšé²ãããæ©åšã§çºçãã6件ã®ã€ã³ã·ãã³ããã¹ãŠããŸãšãããã®ã§ãã è²ã¯å®è£ ã®è€éããåæ ããŠããŸãïŒç·-äœãèµ€-é«ïŒã ãéçãªãæææ¹æ³ãšã¯ãããã€ã¹ã«ä¿åãããŠããIOSã€ã¡ãŒãžã®å€æŽã§ããããšãæå³ããŸãã ãå®è¡ããã»ã¹ããšã¯ãã¡ã¢ãªå ã®ã³ãŒããå€æŽããããšãæå³ããŸãïŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã èªäœã®ã€ã¡ãŒãžã¯å€æŽãããŸããïŒã ããªã¢ãŒãæ€åºããšã¯ãäžèšã®SYNful Knockã»ã¯ã·ã§ã³ã§èª¬æããããã«ããããã¯ãŒã¯æ©åšãŸãã¯ãã®ãããã¯ãŒã¯ãã©ãã£ãã¯ãã¹ãã£ã³ããããšã«ããããããã¯ãŒã¯æ©åšäžã®æªæã®ããã³ãŒãããªã¢ãŒãã§èå¥ããæ©èœãæå³ããŸãã
æŽå²çã«ãæåã®2ã€ã®ã€ã³ã·ãã³ãïŒãªãã·ã§ã³0ããã³1ïŒã¯ãæè¡çãªèŠ³ç¹ããæãåçŽã§ããããšãå€æããŸããã 5幎åã«æ¬çªç°å¢ããåé€ãããCisco ISR 2800ã3825ãããã³3845ã«ãŒã¿ãŒã䜿çšããŠããç¹å®ã®é¡§å®¢ã察象ãšããŠãããæ»æè ã¯ããã€ã¹ã«ããŠã³ããŒãããIOSã€ã¡ãŒãžãåçŽã«çœ®ãæããŸããã åæ§ã®ã€ã³ã·ãã³ããšã®æŠãã¯ç°¡åã§ã-ãããã¯ãŒã¯æ©åšã«ããŠã³ããŒããããIOSã³ãŒãã確èªããã ãã§ãããããã«ã€ããŠã¯åŸã§èª¬æããŸãã
ãªãã·ã§ã³2ããã³3ã¯æè¡çã«è€éã§ããããšãå€æããŸãããæ»æè ã¯ã䟵害ããã管çè ã¢ã«ãŠã³ãã䜿çšããŠãæ©åšã®ãããã°æ©èœã䜿çšããŠãCisco 7600ã«ãŒã¿ãŒã®ã¡ã¢ãªå ã®IOSã³ãŒãã®äžéšãå€æŽã§ããŸããã åã蟌ã¿ã³ãŒãã®äž»ãªç®æšã¯ãæ»æè ãèšå®ããåºæºã«åŸã£ãŠIPv4ãã±ããããã£ããã£ããŠãªãã€ã¬ã¯ãããããšã§ããã æªæã®ããã³ãŒãã®2çªç®ã®ç®æšã¯ãã€ã³ã¿ãŒãããããå€éšããäŸµå ¥è ãå éšãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããã®NATãå®è£ ããããšã§ããã ãã®å ŽåãããŠã³ããŒããããIOSã³ãŒãã®æ€èšŒã¯ãããã€ã¹ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯å€æŽãããªãããã圹ã«ç«ããªããªããŸãããæªæã®ããã³ãŒãã¯å®è¡äžã«ã¡ã¢ãªå ã§ã®ã¿æ©èœããŸãã äžæ¹ãããã€ã¹ãåèµ·åãããšãã¡ã¢ãªå ã§å€æŽãããã³ãŒãã¯æ©èœããªããªããŸãã äž¡æ¹ã®ã€ã³ã·ãã³ãã§ãåŸæ¥ã®æ段ã䜿çšããŠæ©åšãžã®ç®¡çã¢ã¯ã»ã¹ãä¿è·ããç¹æš©ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ãèš±å¯ããããšã«ãããåé¡ã®ç¹°ãè¿ããäžåããããšãã§ããŸãããŸããã¡ã¢ãªå ã®ç°åžžãªåäœã®ç£èŠæ©èœã䜿çšããããšãã§ããŸãã
4çªç®ã®ãªãã·ã§ã³ã¯ãã«ãŒã¿ãŒã«ãããããæ¹æ³ãåã®2ã€ã«äŒŒãŠããŸããïŒCisco 1800ã3800ãããã³7200ã圱é¿ãåããŸãïŒã ãã ããæªæã®ããã³ãŒããããã€ã¹ã®åèµ·åãšãœãããŠã§ã¢ã®æŽæ°ã«èæ§ãããããšãçºèŠããã®ã¯ãããæåã§ããããããŸã§ã®ãšããïŒä¿®æ£ãããROMMONæŽæ°ã³ãŒãã§æªæã®ããã³ãŒããèŠã€ããããïŒã æªæã®ããã³ãŒãã®äžéšã¯ã以åã®ã€ã³ã·ãã³ããšåæ§ã«ãICMPã«ã«ãã»ã«åãããŠãããããé¢å¿ã®ãããã©ãã£ãã¯ãæ»æè ã«ãªãã€ã¬ã¯ãããŠããŸããããã³ãŒãã®ãã®ä»ã®éšåã¯ãŸã£ããæ°ãããã®ã§ããã ã¢ãžã¥ã©ãŒã¢ãŒããã¯ãã£äžã«æ§ç¯ãããå¿ èŠã«å¿ããŠæ°ããæ©èœéšåãèªã¿èŸŒãããšãã§ããŸããã ããã€ã¹ãåèµ·åãããããããã®ã¢ãžã¥ãŒã«ããªããŒãããå¿ èŠããããŸããããã®ããã«ãå€æŽãããROMMONã¢ããããŒãã«ã座ã£ãŠãããæªæã®ããã³ãŒãã®åºæ¬çãªéšåãåå ã§ããã æªæã®ããã³ãŒãã®ãã®å€çš®ããèªåèªèº«ãå®ãã«ã¯ãå€çš®0ãã3ã«ã€ããŠèª¬æãã察çã䜿çšããããå®æçãªæŽæ°ãã€ã³ã¹ããŒã«ããããšã§å€æŽããROMMONæŽæ°ãç¡ååããã ãã§ãïŒã·ã¹ã³ãROMMONæŽæ°ãšIOSã€ã¡ãŒãžçšã®ããžã¿ã«çœ²åã¡ã«ããºã ãå°å ¥ããã®ã¯ç¡é§ã§ã¯ãããŸããã§ãããã以åã®ãã©ãããã©ãŒã ã§ã¯äžä»£ã®æ€èšŒã¯æåã§ã¢ã¯ãã£ãã«ããå¿ èŠããããŸãïŒã
æåŸã«ãæåŸã®5çªç®ã®ãªãã·ã§ã³ïŒSYNful KnockãšãåŒã°ããïŒã¯ãã€ã³ã·ãã³ã0ã1ã2ãããã³3ã«äŒŒãŠããŸãããéãã¯ã管çãµãŒããŒãšã®éä¿¡ã«ICMPã§ã¯ãªãTCPã䜿çšããããšã§ãã ãªãããã®çç±ã§ããããæãé£ãããªãã·ã§ã³ã§ã¯ãªããåºãå ±éãããã®ã¯ããã§ããã ææããã«ãŒã¿ãŒã®æ°ïŒCisco 1841ã2811ãããã³3825ã¢ãã«ã®ã¿ã圱é¿ãåããŸããïŒã¯ããã®äžä»£ãååšããé販売ããã1,000äžå°ã®ãã¡çŽ150å°ã®ããã€ã¹ã§ããã ããã¯ããããã§ããïŒ å®éã«ã¯ããã§ã¯ãããŸããã ããšãã°ãCisco 40åå°ã®ã«ãŒã¿ãŒãããªãå°ççã«åæ£ãããããã¯ãŒã¯ã 2ã3ããŒã¹ã®åœã«ãªãã£ã¹ãæã€äŒç€Ÿã«ã¯ãçŽ1ã200ã®ã«ãŒã¿ãŒããããŸãã åœå ã®ãå°é家ããæžããããã«ãSYNful Knockã¯ã»ããã§ã¯ãªãã1人ã®é¡§å®¢ã§ããèŠã€ãããŸããã§ããã åããªãã·ã§ã³No. 3ã§ã¯1人ã®é¡§å®¢ã®ã¿ãèŠããã ãããããã¯éåžžã«åççãªä»®å®ã§ãã
çé¢ç®ãªäŒè©±ãå§ããåã®ç°¡åãªæè²ããã°ã©ã
ãããŠãããããå°ãé¢ããŠãä»æ¥ã®ã·ã¹ã³ã®ãããã¯ãŒã¯æ©åšã«ã€ããŠç°¡åã«èª¬æããŸãã ãMicrosoftãç¥ã£ãŠãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯äœã§ããïŒããšãã質åããå§ããŸãããããWindowsããšçãããšãããªãã¯ééã£ãŠããã§ãããã MS DOSãèæ ®ã«å ¥ããªãå ŽåãMicrosoftã«ãããã€ãã®WindowsããããŸãã Windows 3.11ãWindows 95ãWindows NTãWindows 2000ãWindows 7ãWindows 8ãWindows 8ãWindows CEãWindows EmbeddedãæåŸã«Windows 10ããããŸãïŒããã¯ãã¹ãŠã®Windowsã§ã¯ãããŸããïŒã ãããŠãããã¯åãOSã§ã¯ãããŸãã-ãããã¯éåžžã«å€§ããç°ãªããŸãïŒã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ãŒã¹ã ãã§ãªãïŒã ããã¯ã·ã¹ã³ã®å Žåã§ã-ããã€ãã®ãªãã¬ãŒãã£ã³ã°ãããã¯ãŒã¯ã·ã¹ãã ããããŸãã iOSãCatOSãAsyncOSãFirepower OSãNX OSããããŸãã ãããŠIOSã§ãããç°ãªããŸã-IOSãIOS XEãIOS XRã ãããŠããã¯å®å šã«ç°ãªã£ãŠããŸãã åãiOS XRã¯ãååã«å ±éãã3æåããããŸãããéåžžã®iOSãšã¯ã»ãšãã©é¢ä¿ããããŸããã IOS XRã¯QNXã«åºã¥ããŠãããIOS XEã¯Linuxã«åºã¥ããŠãããIOSã¯BSDiã«åºã¥ããŠããŸãã ã¡ãªã¿ã«ãSYNful Knockãå«ãäžèšã®ãã¹ãŠã®ã€ã³ã·ãã³ãã§ã¯ããããŸã§ã®ãšããCisco IOSã®ã¿ãæ»æãããŠããŸããIOSXEãIOS XRãNX-OSãããã³ãã®ä»ã®ãã©ãããã©ãŒã ã«é¢ããŠã¯ãã€ã³ã·ãã³ããèšé²ããŠããŸããã
ãããã£ãŠãç 究è ãäŒæ¥ããiOSããããã³ã°ããããšæåºãšããŠå®£èšããå Žåãããã¯éãããã§ãã·ã§ããªãºã ã®å åã§ãããåºæ¬çãªãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ããŸããŸãªå€æŽãå ããããŠããããšãç解ããŠããªãããã¹ããŒã«ãŒãè£ é£ŸããŠäœããããšããå¹³å¡ãªæ¬²æ±ã§ããã¥ãŒã¹ã ãã ããããŸããŸãªIOSã«å ããŠãæ©èœãç°ãªãããŸããŸãªæ§æããããŸãïŒIPããŒã¹ãIPãµãŒãã¹ãIPé³å£°ãé«åºŠãªã»ãã¥ãªãã£ããµãŒãã¹ãããã€ããŒãµãŒãã¹ãªã©ïŒã ããŠãiOSããŒãžã§ã³ããããããããŸãã ããšãã°ã誰ããIOS 15.1ã®è匱æ§ã«ã€ããŠåœŒã®ç 究ã§æžããŠããå Žåãè«ççãªè³ªåããããŸã-ã©ã®ç¹å®ã®ããŒãžã§ã³15.1ã§ããïŒ 15.1ïŒ1ïŒSY5.27ãŸãã¯15.1ïŒ1ïŒSY6ãŸãã¯15.1ïŒ2ïŒSY5.32ãŸãã¯15.1ïŒ4ïŒM11ïŒ ããã¯ãã¹ãŠç°ãªããœãããŠã§ã¢ã§ãããiOS 15.1ã«é©çšãããŸãã ã·ã¹ã³ã¯ã補åãã補åãžããã©ãããã©ãŒã ãããã©ãããã©ãŒã ãžãããŒãžã§ã³ããããŒãžã§ã³ãžç§»è¡ããåã ã®ã³ãŒãã®çµ±åããããã䜿çšããŠãããšèããããšãã§ããŸãã ã¯ãããã®ãããªæçããããŸãã ããããããã«ããããããããã¹ãŠã®ã·ã¹ã³ãœãããŠã§ã¢ã«æ®éçãªæªæã®ããã³ãŒããè匱æ§ã¯çºèŠãããŠããŸããã
ããŠã誰ãããã·ã¹ã³ããããã³ã°ããŸããããšèšã£ãããæ£ç¢ºã«äœããããã³ã°ãããã®ãããããæ¬åœã«ã·ã¹ã³ãªã®ããéãã«å°ãã䟡å€ããããŸãã ãããŠãããšãã°ãåè¿°ã®ãã·ã¢ã®äŒç€ŸDigital Securityã¯ã2014幎ç§ã«ãéä¿¡ãããã¯ãŒã¯ã®å å ¥è æ©åšã®ã»ãã¥ãªãã£ããšããã¬ããŒããçºè¡ããäœããã®çç±ã§Linksysæ©åšãCiscoæ©åšãšåŒã³ããããã®éã«çå·ãä»ããŸããã ãã ããLinksyséšéã¯2013幎ã®æ¥ãã€ãŸããã·ã¢ã®ãç 究è ãã®å ±åæžã®çºè¡ã®1幎ååã«Belkinã«å£²åŽãããã·ã¹ã³ã¯æ£åŒãªé¢ä¿ãæã¡ãŸããã§ããã ã·ã¹ã³ãLinksysãè²·åããå®éã®èŠ³ç¹ããèŠããšãã·ã¹ã³ã¯ãããèªç€Ÿã®ããžãã¹ã«çµ±åããããšã¯ãªããå€ç«ããŠããŒã ãŠãŒã¶ãŒã®ã¿ã察象ãšããŠããŸããã ã·ã¹ã³ãšLinksysã®éçºããŒã ãšéçºããã»ã¹ã§ãããç°ãªã£ãŠããŸããã ãããããããããããDigital Securityã®ããã«ããããšã¯ã§ããŸããã ããã§ããã·ã¹ã³ã®æ©åšã®å®å šæ§ã«é¢ããèšäºã¯ãã·ã¹ã³ä»¥å€ã®äŒç€Ÿã§ããLinksysã«ã€ããŠã®èšäºãããæ Œæ®µã«ã¯ãŒã«ã§ãã
ãããã¯ãŒã¯æ©åšãæ»æããã®ã¯ç°¡åã§ããïŒ
ã·ã¹ã³ã®ãããã¯ãŒã¯æ©åšã¯ãããŸããŸãªçš®é¡ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããã®ã¢ã»ã³ããªãããã³ããŒãžã§ã³ãåããéåžžã«ç°è³ªãªç°å¢ã§ããããšã«æ°ä»ããã®ã§ãæåã®æ®µèœã§ç€ºããå ã®ã¿ã¹ã¯ã«æ»ããããããã¯ãŒã¯æ©åšã¯ã©ã®çšåºŠè匱/ä¿è·ãããŠãããããå°ãã䟡å€ããããŸãïŒã
2000幎ãæãåºããŠå§ããŸãããã 次ã«ãã·ã¹ã³ã¯ã»ãã¥ã¢ãšã³ã¿ãŒãã©ã€ãºãããã¯ãŒã¯åãã®Cisco SAFE ïŒãšã³ã¿ãŒãã©ã€ãºåãã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ïŒèšèšã¬ã€ãã®æåã®ããŒãžã§ã³ããªãªãŒã¹ããŸãããããã¯ãã·ã¹ã³ã®ã»ãã¥ã¢ãããã¯ãŒã¯ã¢ãŒããã¯ãã£ãæ¯ããäž»èŠãªèšèšååãšåºæ¬åçã説æããŠããŸãã
ãããã®å ¬çã®1ã€ã¯ãã ãã¹ãŠã®IPããã€ã¹ãæ»æè ã®æšçã«ãªãå¯èœæ§ãããã ããšã§ããã ã¡ãªã¿ã«ããã§ã«Cisco SAFEã®æåã®ããŒãžã§ã³ã§ã¯ããã·ã¢èªã«ç¿»èš³ãããŠãããã«ãŒã¿ãŒãšã¹ã€ããã®ã»ãã¥ãªãã£ã«çŽ°å¿ã®æ³šæãæãå¿ èŠãããããšãè¿°ã¹ãããŠããŸãã
ãã®å Žåã§ããããµãŒãã¹æåŠãæ»æããã©ãã£ãã¯ã®ååããç¹æš©ãäžæ£ã¢ã¯ã»ã¹ãžã®ããŸããŸãªäžæ£ã¢ã¯ã·ã§ã³ã®å®è£ ã®æœåšçãªã¿ãŒã²ãããšããŠããããã¯ãŒã¯æ©åšãçå£ã«æ€èšããããšããå§ãããŸãã
ã«ãŒã¿ãŒãã¹ã€ãããæ»æããã®ã¯ç°¡åã§ããïŒ ã¯ããæãäžè¬çãªWindowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã¯åäœããŸããã ãããã圌ãã®ä»äºã®åçã¯ã7ã€ã®ã¢ã¶ã©ã·ã®èåŸã«ããç§å¯ãšã¯èšããŸããã äžèšã§æžããããšãæãåºããŠãã ããã ããŸããŸãªIOSãªãã·ã§ã³ã®äžå¿ã«ããã®ã¯ãBSDiãLinuxãQNXã§ãã å®å šã«ç¡æµã§ãããæ¬ é¥ããªããšèŠãªãããšãã§ããŸããïŒ æ²ããããªãããã¯äžå¯èœã§ãã OSããŒã¿ã«åºã¥ããŠæ§ç¯ããããããã¯ãŒã¯æ©åšïŒè¿å¹Žå€§å¹ ã«å€æŽãããŠããã«ããããããïŒãå®éã®ã€ã³ã·ãã³ãã«ã€ãªããå¯èœæ§ã®ããåé¡ãæ±ããŠããããšã¯é©ãã¹ãããšã§ããããïŒ ãã®ãããªã€ã³ã·ãã³ãã®æ°ã¯ãè¥å€§åããæèŠãããæ¯èŒã«ãªããªãã»ã©å°ãªããCisco PSIRTã«ãã£ãŠå ¬éãããã ãã§ãïŒãããŠããããäœã§ãããã以äžã«èšè¿°ããŸãïŒè匱æ§éå ±ã
ã·ã¹ã³ã®æ©åšã«ãããã·ã§ã«ã³ãŒããã«ãŒãããããããã³ãã®ä»ã®åé¡ã«é¢ãããæèŠãã®æŽå²
äžèšã®ã·ã¹ã³ã®ããŒããŠã§ã¢ã€ã³ã·ãã³ãã«é¢ããéèŠãªãã€ã³ããèŠããŠããŸããïŒ ãããã¯ãæ©åšãžã®ç©ççã¢ã¯ã»ã¹ãŸãã¯ç®¡çè ã¢ã«ãŠã³ãã®çé£ã§ã®ã¿å¯èœã§ããã å®çšçãªèŠ³ç¹ããã¯ãããã¯éèŠã§ãããªããªãããä»»æã®ã·ã¹ã³ããããã³ã°æ¹æ³ãçºæããç 究è ããŸãã¯ã·ã¹ã³æ©åšã®ã«ãŒãããããäœæããçè«çå¯èœæ§ã«ã€ããŠèª¬æããç 究è ããŸãã¯éåžžæ¢ã«ç¡é¢ä¿ãªããŒãžã§ã³ã®IOSã®ã·ã§ã«ã³ãŒãã瀺ããç 究è ã«é¢ããå€ãã®èšäºãå ¬éãããŠããããã§ã
ãããå®éã«ã¯ãããããã¹ãŠã®ã¹ããŒãªãŒã«ã¯å€ãã®é¡äŒŒããæ©èœããããšããäºå®ã«çŽé¢ããå¿ èŠããããŸãã
- ãããã¯ãã·ã¹ã³ã®Webãµã€ãã§ãã§ã«å ¬éãããŠããè匱æ§ã«é¢ããå ¬éæ å ±ã«åºã¥ããŠããŸãã
- ãããã¯éåžžãCiscoãããã¯ãŒã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ç¡é¢ä¿ãªããŒãžã§ã³ã«é©çšã§ããŸãã
- ãããã¯ãäž»ã«IOS XEãIOS XRããŸãã¯NX-OSã§ã¯ãªããCisco IOSã«é¢é£ããŠããŸãã
- ãããã¯ãå®éã®ç掻ãå®éã®ç°å¢ãšã¯ã»ã©é ãå®éšå®€ç 究ã«åºã¥ããŠããŸãã
- ã·ã¹ã³ã®æ©åšã§å©çšå¯èœãªãœãããŠã§ã¢ããã³ããŒããŠã§ã¢ã®ã»ãã¥ãªãã£ã¡ã«ããºã ã¯èæ ®ãããŠããŸããã
ãããã®ç©èªã¯å®çšçãªèŠ³ç¹ããèå³æ·±ãã§ããïŒ ç 究è -ã¯ãã ã¡ãã£ã¢-ã¯ãã ãã®ãããªåºçç©ãå ¬éããããŸã§ã«ã補é æ¥è ã¯ãã®ãããªè åšããä¿è·ããããã®æšå¥šäºé ãçºè¡ããå¿ èŠã«å¿ããŠãœãããŠã§ã¢ãä¿®æ£ããããããåä¿¡ããããã«ãµã€ã³ã¢ãããããã¹ãŠã®é¡§å®¢ã«éç¥ãéä¿¡ããŠããããã補é æ¥è ã¯ãã¯ãååšããŸããã ãšããã§ã誰ã§ã賌èªã§ããŸãã æ¶è²»è ã«ãšã£ãŠã¯ãååãšããŠããã»ã©ã§ã¯ãããŸãããå®éã®äžçã§ã¯ãå ¬éãããŠããè匱æ§ãæªçšããæ¹æ³ã®å€ãã¯åäœããªãããåäœæ¡ä»¶ã«ãã£ãŠéåžžã«å¶éãããŠããããã§ãã ããã¯å€ãã®å Žåãã楜ããããããPRã®ããããŸãã¯åã«æ¥œãã¿ã®ããã«ã誀ã£ãŠæã«èœã¡ãæ©åšãç 究ããããšããããŸããŸãªæ奜家ã«ãã£ãŠå¿ããããŸãããããã®æ©åšã¯ãCisco IOSã®ææ°ããŒãžã§ã³ãé©åã«èšå®ããæ¹æ³ããç 究ã®ããã«ãã¢ããããŒããããæ¹æ³ããç¥ããŸããã¡ãŒã«ãŒã«ãšã£ãŠãé¢é£æ§ãé«ããèå³æ·±ããã®ã§ããã
ããšãã°ãç 究è ã¯ãCatalyst 6500ã«ãŒãã«ã¹ã€ããäžã®IOSããŒãžã§ã³15.1ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®Tclã€ã³ã¿ãŒããªã¿ãŒã®è匱æ§ã®æªçšã«é¢ããæ å ±ãå ¬éããŠããŸãããã®è匱æ§ã«ãããæ»æè ã¯ç¹æš©ãŠãŒã¶ãŒïŒç®¡çè ïŒæš©éãååŸããç¹æš©ã³ãã³ããå®è¡ã§ããŸãã äœæ¥ã³ãŒããåãåã£ãç 究è ãŸãã¯åœŒã®äŒç€Ÿã¯ããããã¯ãŒã¯æ©åšã®è£œé å ã«é£çµ¡ããããšããããã«ããæ¯èŠããããç¥å床ã®é«ã声æã§èªåèªèº«ã®ååãä»ããã®ã«ãã§ã«æ £ããŠãããããæ¥ãã§ã¡ãã£ã¢ã«ãæãäºå®ããæãå ¥ããã€ã³ã¿ãŒãããã§æŽ»çºã«è°è«ãããåºãŸãå§ããŸãã ãããã¯ãŒã¯æ©åšã®ç 究ã«çµéšã®ãªãå€ãã®å°é家ã¯ããããã声æãæ€èšŒã§ãããããã·ã¢åãã®äŒç€Ÿã®æèŠãä¿¡é ŒããŠããããããã®ãããªå£°æãä¿¡é ŒããŸããç 究è ã¯ãæ·±å»ãªäŒæ¥ããªãã¬ãŒã¿ãŒã®ãããã¯ãŒã¯æ©åšããã©ãžãªåžå Žã§ã®ç 究ã®ããã«è³Œå ¥ã§ããäžåœã®ã¢ãã ããã®ä»ã®æ¶è²»è²¡ãåžžã«ç解ããŠããããã§ã¯ãããŸããïŒã
ããããããã«çŽé¢ããŸãããã Tclã€ã³ã¿ãŒããªã¿ãŒã®è匱æ§èªäœã¯å€ãããç¥ãããŠãããç¬èªã®CVEèå¥åããæã£ãŠããŸãã ã€ãŸããçºèŠãããè匱æ§ã«ã€ããŠã®å£°æã¯ãããèªäœã®PRã®ããã ãã«äœãããé²éªšãªåã§ãã ããã¯æ·±å»ãªè匱æ§ã§ããïŒãŸããç 究è ãæžããŠããããã«ããããã¯ãŒã¯ããã€ã¹ãå®å šã«å¶åŸ¡ã§ããããã«ãªããŸããïŒ Cisco PSIRTã¯ãäžçšåºŠã®å±éºæ§ãšããŠåé¡ããŸãã æ»æè ã¯ãããå©çšã§ããŸããïŒ ãã å°ãªããšããç 究ã®å ¬éæç¹ã§ã®iOS 15.1ã®æå®ãããããŒãžã§ã³ã«ããããã®è匱æ§ã¯æ¢ã«ä¿®æ£ãããŠããããã§ãïŒä»ã®åœ±é¿ãåããå Žåãšåæ§ïŒã ãŸããããŒãžã§ã³15.1èªäœïŒç¹å®ã®ããŒãžã§ã³15.1ãåé¡ã§ãããã©ããã¯ããããŸãããïŒã¯ããã¯ãé¢ä¿ãããŸããã
ããŸããŸãªãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³ã䜿çšããããšã¯ããã»ã©é£ãããªããããããŸããããCatalyst 6500ã¹ã€ãããã€ã³ã¹ããŒã«ãããŠããäŒæ¥ã®å éšãããã¯ãŒã¯ã®ã³ã¢ã«å ¥ãå¿ èŠæ§ã«ã€ããŠã¯æžããŸãããèšåããïŒã ãã ãããã®è匱æ§ããŸã£ãã䜿çšã§ããªãæéå¶éãããããšã«æ³šæããŠãã ããã ã©ã®æç¹ã§ãããã®è匱æ§ãæªçšãããããšã¯ãããŸãããããã«ãããã¢ããªã±ãŒã·ã§ã³ã®ç¯å²ãçãŸããŸãã
ãã1ã€ã®äŸã¯ã2008幎5æã®EUSecWestäŒè°ã§ã®Sebastien Munizã«ãããã»ã³ã»ãŒã·ã§ãã«ãªãã¬ããŒãã§ãã·ã¹ã³æ©åšã®ã«ãŒãããããçºè¡šãããŸãã ã äžè¬ã«ãiOSçšã®ã«ãŒããããã¯é·ãéè°è«ãããŠããŸããããMunitzã¯ãããã¿ã€ããéçºããæåã®1ã€ã§ãã ãã¹ãŠã¯åé¡ãããŸããããè匱æ§ã䜿çšããŠè¡ãããã®ã§ã¯ãªãããããã¯ãŒã¯ããã€ã¹ã«ããŠã³ããŒããããIOSã€ã¡ãŒãžãå€æŽããããšã§è¡ãããŸããã ã¯ããã·ã¹ã³ãŸãã¯ã客æ§ãçºèŠããäžèšã®ã€ã³ã·ãã³ããšåããªãã·ã§ã³ã ãŸãããã®æ©äŒã¯ã Munitsaã®ããªãåã«ã FXãšããæåãªã·ã¹ã³ã®æ©åšç 究è ã«ãã£ãŠå®èšŒãããŸãã ïŒããšãã°ã2003幎ã®BlackHatã§ïŒã ããã«å¯ŸããŠãIOSã€ã¡ãŒãžæ€èšŒãªã©ã®åçŽãªäžåã¡ã«ããºã ããããŸããããããã¯ãªãã©ã€ã³ïŒããã€ã¹èªäœã®å€éšïŒãšããã€ã¹èªäœïŒæ€èšŒã³ãã³ãã䜿çšïŒã®äž¡æ¹ã§å®è¡ã§ããŸããã æ¬è³ªçã«ãããã¯Cisco PSIRTããã¥ãŒã¹ã¬ã¿ãŒã§æžããè匱æ§ã«é¢ãããã®ã§ã¯ãªããã·ã¹ã³ã®ãããã¯ãŒã¯æ©åšãä¿è·ããããã®æ確ãªæšå¥šäºé ã«åŸããªãå Žåã«å®éã«å®è£ ã§ããèå³æ·±ãæ©äŒã«é¢ãããã®ã§ãã
äžè¬ã«ãããã¯åå¿è ã®ç 究è ã®æãäžè¬çãªæ¬ ç¹ã®1ã€ã§ãã è匱æ§ããçºèŠãããïŒããããããã§ã«é·ãéã·ã¹ã³ã®Webãµã€ãã«å ¬éãããŠããïŒãããç 究è ã¯æèçãŸãã¯ç¡æèã®ãã¡ã«ãçºèŠãŸãã¯æªçšãããåæããŒã¿ã®æ確åãå¿ããŠããŸãã ããããããã¯å®éã«ãã®å®éšãç¹°ãè¿ãããšãå¯èœãã©ããããŸãã¯å®éšå®€ã®æ¡ä»¶ã決ããŠè¶ ããªããã©ããã«å€§ããäŸåããŸãã
ãããŠæåŸã«ãäžéšã®æªçãªç 究è ã¯ããåæã¬ãã«ã®ã»ãã¥ãªãã£ãã®æŠå¿µãå¿ããŠããŸããã€ãŸãããããã¯ãŒã¯æ©åšã§ããªãã®æ°ã®ä¿è·ã¡ã«ããºã ããäžãããæ»æè ã®èœåãããã«å¶éããŸããèšãæããã°ããã®è匱æ§ã¯ä»¥åããç¥ãããŠããããã§ã«æé€ãããŠããã枩宀æ¡ä»¶ã®ç 究è ã¯ãŸã ãããæªçšããããšããŠããã®ã§ãç 究ãäžè¬ã«å ¬éãããŠããŒã¯ã§åŸ æã®äœããšããŠæ瀺ããŠããŸããå®éã®ã»ãã¥ãªãã£ã®èŠ³ç¹ããèŠããšãè匱æ§ã¯ãã¯ãå±éºã䌎ããŸããããPRã¯PRã§ããæã«ã¯ãç 究è ãäŒç€Ÿã®ããšãå¿ããªãããã«ããã®ãããªç 究ã¯çŸããã©ãããŒã«å ãŸããŸãããäœããããŸããã
èšãæããã°ãäŒæ¥ã§åããŠããã圌ã®ãããã¯ãŒã¯æ©åšã®ã»ãã¥ãªãã£ã«é¢ããæ å ±ã«é¢å¿ãããã»ãã¥ãªãã£å°é家ã®èŠ³ç¹ãããç 究è ã®ãã¬ã¹ãªãªãŒã¹ã ãã§ãªãã補é æ¥è ãæäŸããç©Žãšãã®äœ¿çšã®å¶éã«é¢ããæ å ±ãç 究ãã䟡å€ããããŸãã
Cisco PSIRTã·ã¹ã³
補åã»ãã¥ãªãã£ã€ã³ã·ãã³ã察å¿ããŒã ã§ããã·ã¹ã³è£œåã»ãã¥ãªãã£ã€ã³ã·ãã³ã察å¿ããŒã ã¯ãå°çšãµã€ãwww.cisco.com/securityã§ããŸããŸãªã·ã¹ã³ãœãªã¥ãŒã·ã§ã³ã§èŠã€ãã£ããã¹ãŠã®åé¡ã«é¢ããæ å ±ãå®æçã«å ¬éããŠããŸãã
ããã«ã¢ã¯ã»ã¹ãããšãããŸããŸãªããŒãžã§ã³ã®ããŸããŸãªè£œåã®ããŸããŸãªè匱æ§ã«é¢ãã絶ããæŽæ°ãããæ å ±ãèŠãããšãã§ããŸããåæã«ãããšãã°ããã®è匱æ§ãå®è£ ã§ããæ¡ä»¶ããœãããŠã§ã¢ã®ããŒãžã§ã³ãä¿®æ£ããããããŠã³ããŒãããå Žæãäžå ·åã®ããŒã¿ããŒã¹ãžã®ãªã³ã¯ïŒãã°ïŒãªã©ã«é¢ããå€ãã®é¢é£æ å ±ã瀺ãããŸãã
ãããŠãã¡ããããããæé€ããæ¹æ³ã«é¢ããæ å ±ã¯ãåè匱æ§ã«å¯ŸããŠæäŸãããŸãããœãªã¥ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã¯ããã®è匱æ§ã®æ°ã§ã¯ãªãããã®é€å»ã®ããã®çµã¿èŸŒã¿ããã»ã¹ã«ãã£ãŠæ±ºå®ãããããšãå¿ããªãã§ãã ããã
ãšããã§ãè匱æ§ãä¿®æ£ããããã»ã¹ã«ã€ããŠã PRãè¿œæ±ããã ãã§ãªããå®éã®å®å šæ§ã宣èšããŠããªãç 究è ã®éã§ã¯ãç¹å®ã®åé¡ãååšããæ©åšã¡ãŒã«ãŒãšå¯Ÿè©±ããç¿æ £ããããŸããã·ã¹ã³ã«ã¯ãã®ãããªæ £è¡ããããŸããç§ãã¡ã«ãããšãããªã·ãŒæ å ±æŒããã®è匱æ§ã®ãæã ã¯æã ã®æ©åšã®è匱æ§ãçºèŠããä»»æã®ç 究è ãäŒæ¥ããšååããæºåãæŽããŸãããåãFXã¯ç©æ¥µçã«ç§ãã¡ãšããåãããPSIRTãšéä¿¡ããåã«ãæèŠããå ¬éããŸããã
ãã·ã¢ã®äŒç€Ÿã®äžã§ãç§ã¯ããžãã£ããã¯ãããžãŒãºã«ååãä»ããããšãã§ããŸããããžãã£ããã¯ãããžãŒãºã¯ãåœç€Ÿã®ã³ã³ãµã«ãã£ã³ã°ãµãŒãã¹ãæäŸããããŸããŸãªè£œåã®è匱æ§ã«é¢ããæ å ±ãéä¿¡ããéçšã§é·ãååããŠãããŸãããæè¿ãPositive Technologiesãããã®ãããªéç¥ãçŽ15件åãåããŸãããé倧床ã¯äœããé«ãŸã§ããŸããŸã§ãããã®ã³ã³ããã¹ãã§ã®ããžãã£ããã¯ãããžãŒã¯ããœãããŠã§ã¢ã®è匱æ§ã調æ»ããæçããã¢ãããŒãã®äŸã§ãããã¡ãŒã«ãŒã®ã¿ã«é瀺ãããè匱æ§ãå«ããœãããŠã§ã¢ã®ãŠãŒã¶ãŒã«å¯Ÿãã責任ããæ 床ã§ãããããã2床èšåããåœå ã®ããžã¿ã«ã»ãã¥ãªãã£ã¯ãäžåºŠã Cisco PSIRTã«æ¥ç¶ããããšã¯ãããŸããã圌女ãçºèŠããè匱æ§ãç§ãã¡ã®æ©åšã®ä»ã®åé¡ã«ã€ããŠïŒããã«ãç¬èªã®ã€ãã·ã¢ããã®Cisco PSIRTã®å°é家ããCiscoæ©åšã§çºèŠãããè匱æ§ã«é¢ããZeroNightsã®æè¿ã®å ±åã«ã€ããŠDigital Securityã«é£çµ¡ãããšããDigital Securityã®ä»£è¡šè ã¯å¿çã§ãããç 究ã®è©³çŽ°ãæäŸã§ããŸããã§ããã
ã·ã¹ã³ã¯äœãããŠããŸããïŒ
Cisco PSIRTã«ã€ããŠè©±ããŠããå Žåããããã¯ãŒã¯æ©åšã®ã»ãã¥ãªãã£ã確ä¿ããããã®ä»ã®ã€ãã·ã¢ããã«ã€ããŠã¯èšããŸãããããããæåã«åã³æè²ããã°ã©ã ã«æ»ãããã§ãã
IOSã®ã¿ã€ããã¢ã»ã³ããªãããã³ããŒãžã§ã³ã«é¢ããã¹ããŒãªãŒã«ããCiscoã«ãŒã¿ãŒããªã©ã®äžè¬çãªæŠå¿µããªãããšãè¿œå ããå¿ èŠããããŸãïŒåãããšãã¹ã€ããã«ãåœãŠã¯ãŸããŸãïŒãç 究ã«é¢ããã¬ããŒããèªããšãã¯ããããã¯ãŒã¯æ©åšã®ã©ã®ç¹å®ã®ã©ã€ã³ãšã¢ãã«ãé¢ä¿ããŠããããæ©åšã®æ§æã¯äœãã圱é¿ã¯ã©ã®ããã§ãã£ãããåžžã«æ確ã«ããå¿ èŠããããŸãã ISRãASRãGSRãCSRãCRSããããŸããæã人æ°ã®ããã©ã€ã³ã¯ãäºæãã¬ããšã«ãç°ãªãäžä»£ã§ãæäŸãããIntegrated Services RouterïŒISRïŒã§ããæè¿ãç§ãã¡ã¯ã客æ§ã«ç¬¬3äžä»£ã®Cisco ISRã«ãŒã¿ãŒã§ããISR 4kïŒå¥åISR 4000ïŒãæäŸããŠããŸãã第1äžä»£ã®Cisco ISRïŒã¢ãã«1800ã2800ãããã³3800ïŒã®çç£ãã€ãŸããSYNful Knockãå«ãäžèšã®ãã¹ãŠã®ã€ã³ã·ãã³ãã§çŽ¹ä»ããã補åã¯ã5幎åã®2010幎ã«å®æããŸãããããããå®å šã«è«ççãã€è«ççãªçµè«ãå°ãåºãããŸã-çŸåšè³Œå ¥ãããŠããã·ã¹ã³ã®æ©åšã§ã¯ãåè¿°ã®ã€ã³ã·ãã³ãã®å€ãã¯ååãšããŠäžå¯èœã§ãããªããã®ãããªçµè«ãäžãã®ã§ããïŒ
ãã¹ãŠãéåžžã«ç°¡åã§ããCisco ISRã«ãŒã¿ãŒã®ç¬¬1äžä»£ã¯ã2004幎ã«ç»å Žããèªç€Ÿè£œåã®ã»ãã¥ãªãã£ã確ä¿ããããã®å¯Ÿçãäžæçã§éäœç³»çã§ãããããã§ããç»åã«çœ²åããæ©èœïŒDigital Image SigningïŒã䜿çšããŠãäžæ£ãªå€æŽã眮æããç»åãä¿è·ããŸããããã©ãã§ãã§ã¯ãããŸããã§ãããçŸåšããã®æ©èœã¯560çš®é¡ã®ã·ã¹ã³è£œåã«ååšããŠããŸãã
2007幎ã«ã¯ãæ©åšã®å®å šæ§ãå¶åŸ¡ãã極æ±ãèµ·æºãšããåžå Žã«ç»å Žããããšãããåœé 補åããä¿è·ããããã«èšèšãããACTããŒããŠã§ã¢ã¢ãžã¥ãŒã«ã®æåã®å®è£ ããããŸããã 2008幎ã«ãCisco Secure Development LifecycleïŒCSDLïŒããã»ã¹ãã·ã¹ã³ã«å°å ¥ããŸãããïŒãããã³1幎åŸã第2äžä»£ã®Cisco ISR G2ã«ãŒã¿ãŒïŒ1900ã2900ãããã³3900ïŒãèªçããŸãããããã«ã¯ãç¬èªã®ä¿è·ã®ããã®æ©èœãã¯ããã«å€ããããŸããããã«ãããŒããŠã§ã¢ã¬ãã«ã§ããç¹ã«ãACTã¢ãžã¥ãŒã«ã¯ãããããã©ã¹ãã¢ã³ã«ãŒã¢ãžã¥ãŒã«ïŒããã©ã¹ãã¢ã³ã«ãŒãïŒã«å€æãããçŸåšã§ã¯çŽ300ã®ã·ã¹ã³è£œåã«å®è£ ãããŠããŸããããã€ã¹ã®ãœãããŠã§ã¢ã®æŽåæ§ã確èªã§ããã»ãã¥ã¢ããŒãæ©èœã¯ã2010幎ã«åããŠå®è£ ãããä»æ¥ã§ã¯ã»ãšãã©ã®ã·ã¹ã³è£œåã®éçºããã»ã¹ã«äžå¯æ¬ ãªéšåã§ãã
ã»ãã¥ãªãã£ã«é¢ããŠåæ§ã®å€æŽããœãããŠã§ã¢ã«åœ±é¿ãåãŒããŠããŸããããšãã°ãIOSã®10çªç®ãš12çªç®ã®ããŒãžã§ã³ïŒããã³çŸåšã®ããŒãžã§ã³ã¯æ¢ã«15ã§å§ãŸãïŒã®éã§ã®ã¿ãæ°åïŒïŒïŒã®ãããã¯ãŒã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®äžéããŒãžã§ã³ããªãªãŒã¹ããããã¹ãäžã«èŠã€ãã£ããšã©ãŒãä¿®æ£ããã ãã§ãªããæªæã®ããã³ãŒãã®æ§è³ªã®å€åãšæ»æè ã®è¡åãèæ ®ããŠãä¿è·æ©èœãæ¡åŒµããŸããããšãã°ãæ€èšŒã¡ã«ããºã ãšã»ãã¥ã¢ããŒããéçãªIOSã€ã¡ãŒãžã®çœ®æãé²ãã®ã«ååãªå Žåããããã¯ãŒã¯ããã€ã¹ã®ã¡ã¢ãªå ã®çãããç°åžžãªã¢ã¯ãã£ããã£ãç£èŠããŠã¡ã¢ãªã§å®è¡ãããæªæã®ããã³ãŒããšæŠãããã®ç¹å¥ãªã¢ãã¿ãéçºããŸããããŸããã¡ã¢ãªã§å®è¡ãããŠããæªæã®ããã³ãŒããšæŠãããã«ãããã€ã¹ã®éåžžã®æ©èœã«ã¯äžèŠãªå€ãã®ãããã°ã³ãã³ããé€å€ããŸããããæ»æè ã«æ±ãè¡çºãå®è¡ããè¿œå ã®æ©äŒãäžããŸããããšããã§ãããããã¹ãŠã®ä¿è·æ©èœã®ç 究ã¯å¿ é ã§ããããã§ã«èª¬æããCisco Security Ninjaããã°ã©ã ã®äžéšã§ãã
éçºã®éçšã§ãæ©åšã®ä¿è·èœåã匷åã§ããã ãã§ãªããã·ã¹ã³æ©åšã®ãµããŒãã«é¢é£ããä»ã®ããã»ã¹ã«æ©èœãè¿œå ããããšãã§ããŸããããããã«ã¯ä»¥äžãå«ãŸããŸãã
- ãããã¯ãŒã¯æ©åšã®ã€ã³ã·ãã³ãã調æ»ãããæ害æ§ãããã§ãã¯ããããã®ç¹å¥ãªããŒã«ã®éçºïŒã€ã³ã¹ããŒã«ããæ©åšã«ã€ããŠäœãæªãããšãçãããã客æ§ãæ¯æŽããã¢ããªã¹ãã®ã¿ãå©çšå¯èœïŒã
- ãããã¯ãŒã¯æ©åšã®ä¿è·ã匷åãããã®æŽåæ§ãå¶åŸ¡ããããã®æšå¥šäºé ã®éçºã
- 顧客ãšã®éä¿¡æã«Cisco TACãã¯ãã«ã«ãµããŒãããŒã ã䜿çšããç¹å¥ãªããŒã«ã®éçºã顧客ãéä¿¡ãããã³ããåæããŠããããã¯ãŒã¯OSã€ã¡ãŒãžã®ãªãããŸããæ€åºã§ããŸãã
- ã·ã¹ã³ã®æ©åšã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ã€ã¡ãŒãžãæ€èšŒããããã®ç¹å¥ãªãµãŒãã¹ãéå§ããŸãã
- ãããŠãä»ã®å€ãã®ã
ãŸããã·ã¹ã³ã®æ©åšã«åºã¥ããŠã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããã«ã¯ã©ãããã°ããã§ããïŒ
ãããããã®è³ªåãžã®çãã¯ãç§ã¯è¿ãå°æ¥ã«å¥ã®ããŒããæ§ããã ãã...
èŠçŽãããš
ãã®çãã¡ã¢ã䜿çšããŠããããã¯ãŒã¯æ©åšã®å®å šæ§ãã©ã®ããã«èª¿æŽãããããã©ã®ããã«åäžããããã«é¢ããäžé£ã®åºçç©ãéããŸããã次ã®èšäºã§ã¯ããã®èšäºã«èšèŒãããŠããåé¡ãåé¿ããããã«ã·ã¹ã³ã®æ©åšã®ãŠãŒã¶ãŒãå®è¡ã§ããã¢ã¯ã·ã§ã³ã詳ããèŠãŠãããŸãããããŸã§ã®éã次ã®ã¹ããŒãã¡ã³ãã§èŠçŽããããšæããŸããã¿ãŒã²ããã¯ãã«ãŒã¿ãŒãåããã¹ã€ãããªã©ãäœã§ãããŸããŸããããããã®ä¿è·ãä¿èšŒããããšãæ ããªãã§ãã ããããã®å¯èœæ§ã®èª¬æã¯ã¡ãŒã«ãŒã§èŠã€ããããšãã§ããŸããããŠãç 究è ã«ãšã£ãŠã¯ããããã¯ãŒã¯æ©åšã®è匱æ§ã«é¢ããæ å ±ãå ¬éããããšã«ã€ããŠããã責任ãããããšããå§ãããŸãããããã¯ãŒã¯æ©åšã¯ãæ»æè ããŠãŒã¶ãŒã«å±å®³ãå ããããã«äœ¿çšã§ããŸãã
è¿œå æ å ±ïŒ
- Cisco SYNful Knock ( )
- - Cisco SYNful Knock
- Cisco SYNful Knock
- Cisco Cisco
- Cisco IOS
- Cisco IOS XR
- Cisco NX-OS
- Cisco
- Cisco
- Cisco IOS IOS XE
- Cisco IOSæŽåæ§ç®¡çã¬ã€ã
- ã·ã¹ã³ã®ã»ãã¥ãªãã£éå ±ã賌èªãã