Panda Securityã®ãŠã€ã«ã¹å¯Ÿçã©ãã§ããPandaLabsã¯ã2015幎ã®ã¬ããŒããå ¬éããŸããã
æšå¹Žãäœæãããæªæã®ããããã°ã©ã ã®æ°ã«æ°ããèšé²ãããã8,400äžã®éžæè¢ãè¶ ããŸããã åæã«ã倧äŒæ¥ãšããŸããŸãªã¿ã€ãã®Webãµã€ãã®äž¡æ¹ã1幎ã®éã«æ»æããããŠãŒã¶ãŒãšé¡§å®¢ã«é¢ããããŒã¿ããããã®äžéšããçãŸããŸããã ãã®çµæãäžçäžã®äœçŸäžäººãã®ãŠãŒã¶ãŒããµã€ããŒç¯çœªã®åœ±é¿ãåããŠããŸãã ããã«ãã§ãŒã³ã«ã¯å¥ã®èšåããããŸããã 圌ãã¯ãéè¡ã«ãŒãã®ããŒã¿ãªã©ãèšå€§ãªéã®æ å ±ã管çããŠãããããç¯çœªè ã®äž»ãªæšçã«ãªããŸããã
Cryptolockerã¯äŒæ¥ã®äžçã«ææãäžããŸããããå€ãã®è¢«å®³è ãæ å ±ã®åŸ©å ã«åãã§æ¯æã£ãŠãããšããäºå®ã®çµæãšããŠãäŒæ¥ã«å¯Ÿããæ»æã®æ°ãå€§å¹ ã«å¢å ããŸããã ã¢ãã®ã€ã³ã¿ãŒãããïŒIoTïŒã¯ããã®ãããªããã€ã¹ã®ã»ãã¥ãªãã£ãçåèŠãããŠãããããåé¢ã«åºå§ããŠããŸãã 2015幎ã«ãããŸããŸãªå°é家ãã©ã®ããã«è»ããããã³ã°ãããããããªã¢ãŒãã³ã³ãããŒã«ããããšãã§ããããèŠãŸããã
ãã ããæªããã¥ãŒã¹ã ãã§ã¯ãããŸããã ã æ°éäŒæ¥ãšæ³å·è¡æ©é¢ã¯ãŸããŸãååããŠããã ãã£ãããšãããã確å®ã«ã圌ãã¯ã€ã³ã¿ãŒãããäžã§ãµã€ããŒç¯çœªè ã«éå£ã眮ããŸãããããŠãŸã ããã¹ã倧ããªåç·ããããŸããã圌ãã®ç¯çœªã眰ããããªãããšã¯è¯ãããšã§ãã
Adobe Flashã¯ãäžçäžã®äœçŸäžäººãã®ãŠãŒã¶ãŒã«ææããããã«äœ¿çšãããè匱æ§ã®ãããã»ãã¥ãªãã£ã®äžçã«ãšã£ãŠãæªå€¢ãã§ãã 圌ã¯æåŸã®æ¥ã ãçããŠããããã§ãã ãŸããŸãå€ãã®ã·ã¹ãã ããã®äœ¿çšãçŠæ¢ããŠããŸãã
Googleã¯ãChromeãã©ãŠã¶ã§FlashããµããŒãããªãããšã決å®ããå¥ã®äŒç€Ÿã§ããäžæ¹ãWebãµã€ãäžã®Amazonã¯ããã®åœ¢åŒã䜿çšããåºåèŠçŽ ã®å ¬éãèš±å¯ããŸããã
æšå¹ŽããŸããäœæãããæªæã®ããããã°ã©ã ã®æ°ã®èšé²ã§ããã åèšã§ã2015幎ã«PandaLabsã¢ã³ããŠã€ã«ã¹ç 究æã«ãã£ãŠ8400äžãè¶ ããæ°ãããµã³ãã«ãæ€åºãããäžåãããŸãããããã¯ãæ¯æ¥å¹³åçŽ23äžä»¶ã®æ°ããè åšã§ãã
çŸåšãçŽ3å400äžã®æªæã®ããããã°ã©ã ãç 究æã«ç»é²ãããŠããŸããã€ãŸãããããŸã§ã«äœæããããã«ãŠã§ã¢ã®4åã®1以äžã2015幎ã«ç»é²ãããŸããïŒ27.36ïŒ ïŒã ãã«ãŠã§ã¢ã®äž»ãªçš®é¡ã§ããããã€ã®æšéŠ¬ã«å ããŠãæšå¹ŽãPNPãšããŸããŸãªCryptolockerã®äºçš®ãæåãªãã¬ãŒã€ãŒã§ãããäžçäžã§å€§æ··ä¹±ãåŒãèµ·ããã身代éã®æ¯æããšåŒãæãã«æ å ±ãçã¿ãŸããã
2015幎ã«åºçŸããæ°ããè åšã®æŠèŠ
ãã€ãã®ããã«ãéå»1幎éã«äœæãããè åšã®ç·æ°ã®50ïŒ ä»¥äžãå ããããã€ã®æšéŠ¬ãè©äŸ¡ã®ãããã«ããŸãã
ãã ããä»ã®ã«ããŽãªãç¹ã«ãŠã€ã«ã¹ïŒ22.79ïŒ ïŒãã¯ãŒã ïŒ13.22ïŒ ïŒãPUPïŒ10.71ïŒ ïŒãšæ¯èŒãããšãããã€ã®æšéŠ¬ã®ã·ã§ã¢ã¯æšå¹Žãããäœããªã£ãŠããŸãã äžçäžã®ãã«ãŠã§ã¢ã«ãã£ãŠåŒãèµ·ããããææãåæãããšãCollective Intelligenceã®ããŒã¿ã®ãããã§ãããã€ã®æšéŠ¬ãã»ãšãã©ã®ææã®åå ã§ããããšãããããŸãïŒææç·æ°ã®60.30ïŒ ïŒã
ææååž
PUPã2äœã«ãªããææã®çŽ3åã®1ãåŒãèµ·ãããã¹ãã€ãŠã§ã¢ãšã¢ããŠã§ã¢ïŒ5.19ïŒ ïŒãã¯ãŒã 2.98ïŒ ïŒããŠã€ã«ã¹ïŒ2.55ïŒ ïŒãäžåããŸããã PUPã䜿çšããç©æ¥µçãªé åžæè¡ãšããã°ã©ã ã¯ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«é«åºŠãªã€ã³ã¹ããŒã«ãè¡ãããããšãæå³ããŸãã
32.13ïŒ ã§ããææããã³ã³ãã¥ãŒã¿ãŒã®ã°ããŒãã«ã¬ãã«ãèŠããšãäž»ã«PUPã«ãã£ãŠéå»1幎éã§å¢å ããŠããããšãããããŸãã
ãã ãããã®æ°å€ã¯ãããããçš®é¡ã®ãã«ãŠã§ã¢ãååšããã³ã³ãã¥ãŒã¿ãŒã®å²åãæå³ããŸãããææããããšãæå³ãããã®ã§ã¯ãªãããšã«æ³šæããŠãã ããã
ææã¬ãã«ãæãé«ãåœïŒäžåœïŒ57.24ïŒ ïŒãå°æ¹ŸïŒ49.15ïŒ ïŒããã«ã³ïŒ42.52ïŒ ïŒã
ã¢ãžã¢ãšã©ãã³ã¢ã¡ãªã«ã¯ãææçãæãé«ãå°åã§ãã ããã10ã«å«ãŸããŠããªãããäžçã®å¹³åææçãè¶ ããŠããä»ã®åœïŒã³ãã³ãã¢ïŒ33.17ïŒ ïŒããŠã«ã°ã¢ã€ïŒ32.98ïŒ ïŒãããªïŒ32.54ïŒ ïŒãã¹ãã€ã³ïŒ32.15ïŒ ïŒã
ææã¬ãã«ãæãäœãåœã®ããŒã¿ãåæãããšãäžäœ10ãåœã®ãã¡9ãåœããšãŒãããã§ãããæ¥æ¬ã®ã¿ããšãŒããã以å€ã®å¯äžã®åœã§ããããšãããããŸãã ã¹ã«ã³ãžããã¢è«žåœããªãŒãããŠããŸãïŒãã£ã³ã©ã³ãïŒ20.32ïŒ ïŒããã«ãŠã§ãŒïŒ20.51ïŒ ïŒãã¹ãŠã§ãŒãã³ïŒ20.88ïŒ ïŒ
ããã10ã«å ¥ã£ãŠããªãã£ãããåæã«äžçå¹³åãäžåãææã¬ãã«ã瀺ããä»ã®åœïŒãªãŒã¹ãã©ãªã¢ïŒ26.87ïŒ ïŒããã©ã³ã¹ïŒ27.02ïŒ ïŒããã«ãã¬ã«ïŒ27.74ïŒ ïŒããªãŒã¹ããªã¢ïŒ28.96ïŒ ïŒãã«ããïŒ29.03ïŒ ïŒãã¢ã¡ãªã«ïŒ29.48ïŒ ïŒããããºãšã©ïŒ30.11ïŒ ïŒããã³ã¬ãªãŒïŒ30.23ïŒ ïŒãã€ã¿ãªã¢ïŒ31.84ïŒ ïŒãã³ã¹ã¿ãªã«ïŒ32.10ïŒ ïŒã
ãµã€ããŒç¯çœª
2015幎ã®ç¬¬1ååæã«æãå±éºãªãµã€ããŒæ»æãç¹å®ããå¿ èŠãããå Žåããã¡ããããããã¯ãæå·åããç¹ã«CryptoLockerã«ãªããŸãã ãã®ã¿ã€ãã®æ»æã¯ããããã¿ã€ãã®ãŠãŒã¶ãŒã«åœ±é¿ãåãŒããŸããããäŒæ¥ã¯ããæãŸãããšæãããŸãã 身代éãæ¯æãããšãã䟡å€ã®ããæ å ±ãä¿åããŸãã
äžéšã®äŒæ¥ãç¹ã«ããŒã¿ãä¿è·ããããã®ããã¯ã¢ããã·ã¹ãã ãæããªãäŒæ¥ã¯ãæçµçã«ãã®ã¿ã€ãã®æeventuallyã«å±ããããšãç¥ãããŠããŸãã 2æãã€ãªãã€å·èŠå¯ãã©ã³ãµã ãŠã§ã¢ã«ææããåŸãã³ã³ãã¥ãŒã¿ãŒã®ããã¯ã解é€ããããã«500ãã«ã®èº«ä»£éãæ¯æã£ãããšãå€æããŸããã ãµã€ããŒç¯çœªè ã¯ãããŸããŸãªçš®é¡ã®æè¡ã䜿çšããŠã·ã¹ãã ã«ææãããŠãŒã¶ãŒæ å ±ãçã¿ãŸãã æãäžè¬çãªææææ³ã®1ã€ã¯ããšã¯ã¹ããã€ãã®äœ¿çšã§ãã 被害è ã®ã³ã³ãã¥ãŒã¿ãŒã®è匱æ§ãæªçšããããã°ã©ã ã
1æããµã€ããŒè©æ¬ºåž«ãFlash Playerã®ç©Žãç©æ¥µçã«æªçšããŠããããšãå€æããŸããã ãã®å Žåãã»ãã¥ãªãã£ããŒã«ã¯ãŒããã€è匱æ§ã§ããããããŸã§ç¥ãããŠããªãã£ããããå©çšå¯èœãªãããã¯ãããŸããã§ããã Javaãããã«ãŒã«ãã£ãŠæãé »ç¹ã«ãããã³ã°ãããå¥ã®ãœãããŠã§ã¢ã§ããããã«ãFlashã¯ãµã€ããŒç¯çœªè ã®äž»ãªç®æšã§ãã
ãµã€ããŒç¯çœªè ããŠãŒã¶ãŒãã ãŸããŠãæå·åãã«ææãããããã«äœ¿çšãããããã®ãæ°ãããææ³ïŒéå»ã®æ»æã¯20幎åã ã£ãããïŒã¯ãOfficeããã¥ã¡ã³ãïŒç¹ã«WordïŒã§ãã¯ãã䜿çšããããšã§ãã ã
ã»ãšãã©ã®ãŠãŒã¶ãŒã¯ãããã¹ãããã¥ã¡ã³ãã«è åšãå«ããããšã¯ã§ããªããšèããŠã誀ã£ãã»ãã¥ãªãã£æèãæã£ãŠããŸãã ãããç¥ã£ãŠãããå¢çäžã®ãã£ã«ã¿ãŒããã®ãããªãã¡ã€ã«ãšæŠããªãããšãç解ããŠãããã«ãŒã¯ãã®æ¹æ³ã䜿çšããŠæ»æã®æ°ãæ¥æ¿ã«å¢ãããŸããã
ãã®æ»æã®åŒ±ç¹ã¯ããŠãŒã¶ãŒããã¯ããæå¹ã«ããå¿ èŠãããããšã§ããããµã€ããŒç¯çœªè ã¯ãããååã«èªèããŠããããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®ããŸããŸãªå·§åŠãªææ³ãããŸãé©çšããŠããŸãã PandaLabsã§é瀺ãããŠãããã®ãããªäŸã®1ã€ã¯ããŒãããç»åãå«ãWordææžã§ããã ããã¥ã¡ã³ãã®äžéšã«ã¯ãã»ãã¥ãªãã£äžã®çç±ã§ç»åããŒãããŠãããšããã¡ãã»ãŒãžã倪åã§æžãããŠããŸãã ãŠãŒã¶ãŒãæ å ±ã«ã¢ã¯ã»ã¹ãããå Žåã¯ãç¢å°ã§ç€ºããããã¿ã³ãã¯ãªãã¯ããŠãã¯ããå®è¡ããå¿ èŠããããŸããã ãã¯ããæå¹ã«ããåŸãç»åã¯æ確ã«ãªããŸããããåæã«ã³ã³ãã¥ãŒã¿ãŒã¯Cryptolockerã®äºçš®ã®1ã€ã«ææããŸããã
ç¹ã«ãªãŒã¹ãã©ãªã¢ã§äººæ°ã®ããå¥ã®æå·äœæè ã¯ãä»ã®å€ãã®åœã§èŠãããŸãããã人æ°ã®ããBreaking Badã·ãªãŒãºã®åçã䜿çšããŸããã ãã£ãã·ã³ã°ã«ã€ããŠè©±ããšããç§ãã¡ã¯ãã°ãã°éè¡ããéããããšæãããé»åã¡ãŒã«ã¡ãã»ãŒãžã«ã€ããŠèããŸãã ãã¡ããããã£ãã·ã³ã°æ»æã¯ãã®æ¹æ³ã§å®è¡ããããšãã§ãããã®ææ³ã¯äŸç¶ãšããŠå€ãã®å Žåã«äœ¿çšãããŠããŸãããçŸåšã§ã¯ãã£ãã·ã³ã°è©æ¬ºåž«ã¯éè¡ã®é¡§å®¢ã決æžãµãŒãã¹ã ãã§ã¯ãããŸããã
1æãããã«ãŒã®ã°ã«ãŒããAppleã«ä»£ãã£ãŠãã£ãã·ã³ã°æ»æãéå§ãããšèšãããŠããŸãã AppleãµããŒãã®æè¡ãµããŒãããæªæã®ããã¡ãã»ãŒãžãéä¿¡ãããäžè¬çãªææ³ã䜿çšãããŸããã ãã®æçŽã®èè ã¯ããŠãŒã¶ãŒãåã«æããããããã®ã»ãã¥ãªãã£åé¡ã«ã€ããŠèšåããŸããïŒãããªãã®Apple IDã¯åæ¢ãããŸãããã
ãã®ã¡ãã»ãŒãžã¯ãèš±å¯ãããŠããªã人ããŠãŒã¶ãŒã®ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ããããšãããã®çµæã¢ã«ãŠã³ããåæãããããšããŠãŒã¶ãŒã«èŠåããŸããã ãã®æçŽã«ã¯ããŠãŒã¶ãŒãApple Webãµã€ãã®ãã¶ã€ã³ã®ããŒãžã«å°ããªã³ã¯ãå«ãŸããŠããŸããããã®ããŒãžã§ã¯ãååãäœæãé»è©±çªå·ãéè¡ã«ãŒãæ å ±ãªã©ãå€ãã®æ å ±ãèŠæ±ãããŸããã
2æãã¢ã¡ãªã«ã®äŒç€ŸAnthemã¯ã8000äžäººã®ãŠãŒã¶ãŒããã®ããŒã¿ã®çé£ããããããæ»æã®ç ç²è ã§ããããšãèªããŸããã ãã®å Žåãããã«ãŒã¯çãŸãããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããŠäŒæ¥ããŒã¿ããŒã¹ã®1ã€ã«ã¢ã¯ã»ã¹ããããšãã§ããŸããã Anthemã«ã¯1åãã«ä»¥äžã®è²»çšãããããšæšå®ãããŠããŸãã
3æãSlackïŒUSAïŒã¯ãã¹ãŠã®ãŠãŒã¶ãŒã«ã¡ãã»ãŒãžãéä¿¡ãããŠãŒã¶ãŒæ å ±ãä¿åãããŠããããŒã¿ããŒã¹ãžã®äžæ£ã¢ã¯ã»ã¹ãèŠã€ãã£ãããšãéç¥ããŸããã éèŠãªæ å ±ã¯çãŸããŸããã§ãããïŒå®éãSlackã¯ç»é²ããŒã¿ãå€æŽããå¿ èŠããªãããšããŠãŒã¶ãŒã«éç¥ããŸããïŒãäŒç€Ÿã¯å³åº§ã«2段éèªèšŒã·ã¹ãã ããªã³ã«ãããŠãŒã¶ãŒã«è¿œå ã®ã»ãã¥ãªãã£æ©èœã䜿çšããŠä¿è·ã¬ãã«ãé«ããŸããã
äœã³ã¹ãèªç©ºäŒç€Ÿã®ã©ã€ã¢ã³ãšã¢ã¯ãäŒç€Ÿã«500äžãã«ã®æ倱ããããããæ»æã®ç ç²è ã§ããã æ»æã®è©³çŽ°ãæããã«ãããŠããªããšããäºå®ã«ãããããããäžåœã®éè¡ã®1ã€ã«è»¢éãè¡ãããããšãç¥ãããŠããŸãã äŒç€Ÿã¯ç¯çœªãå ±åããçãŸãããéã§å£åº§ãåçµããããšãã§ããè¿ãå°æ¥ã«æ害ãè£åããã€ããã§ãããšè¿°ã¹ãŸããã
å¥åº·ä¿éºäŒç€Ÿã§ããCareFirst BlueCross BlueShieldã¯ã110äžäººã®ãŠãŒã¶ãŒãçãã ãµã€ããŒæ»æã®è¢«å®³è ã§ããã æ¯æ¥ããã®ãããªç¯çœªè ããã®æ»æã®è åšã¯å¢å€§ãç¶ããŠãããããã¯äžçäžã§çºçããŠããæ°çŸä»¶ã®æ å ±çé£äºä»¶ã®ã»ãã®1ã€ã§ãã
ãªã³ã©ã€ã³ããŒããµãŒãã¹ã§ããAdultFriendFinderãæ»æãåãããã®çµæããŠãŒã¶ãŒã®å人æ å ±ãçãŸããŸããã ããã«ãŒã¯ãçãŸããæ å ±ã70ãããã³ã€ã³ã§è²©å£²ããããšãç³ãåºãŸãããããã®æç¹ã§ã®éé¡ã¯17,000ç±³ãã«ã§ããã ãŸããªãããã®ããŒã¿ããŒã¹å šäœãã€ã³ã¿ãŒãããã§å ¬éãããŸããã
倧æãã¹ã¯ãŒã管çäŒç€ŸLastPassã¯ãæ å ±çé£ã®ãã1ã€ã®è¢«å®³è ã§ãã 幞ããªããšã«ãããã«ãŒã¯ãã¹ã¯ãŒããååŸã§ããããŠãŒã¶ãŒã®ãã¹ã¿ãŒãã¹ã¯ãŒãã®ããã·ã¥ã®ã¿ãååŸã§ããããã§ãã ãããã®ããã·ã¥ã®è€éãïŒæ··åšããç解ãã«ããïŒã«ãããããã«ãŒãå®éã®ãã¹ã¯ãŒããååŸããããšã¯éåžžã«å°é£ã«ãªããŸãã ããããããã«ãããããããããŸãè€éã§ãªãå Žåã¯ãã¹ã¯ãŒããå€æŽããããšããå§ãããŸããã
ã©ã¹ãã¬ã¹ã®ã«ãžãã«ããããŒãããã¯ããã«ã¢ã³ãã«ãžã㯠ãããã«ãŒã顧客æ å ±ïŒååãéè¡ã«ãŒãçªå·ãCVVã³ãŒãïŒãçã¿å§ããŠãã8ãæã§ã»ãã¥ãªãã£ã䟵害ãããããšãç¥ããŸããã
ãã®è€åæœèšã®ã¬ã¹ãã©ã³ãããŒãã·ã§ããã§ã«ãŒãã䜿çšãã顧客ã¯èŠããã§ããŸããããããã«ãã«ãžãã§æ³šæãã顧客ã¯èŠãã¿ãŸããã§ããã ãã®æ»æã¯ã顧客ã®éè¡ã«ãŒãã«é¢ããæ å ±ãçãããã«ç«¯æ«ãæ»æããããšãã«éå»ã«èŠãä»ã®æ»æïŒã¿ãŒã²ãããããŒã ãããUPSãããŒãã³ããŒã«ã¹ïŒãé£æ³ãããŸãã
ãŠãŒã¶ãŒãã¢ã«ãŠã³ãã®ç°åžžãªã¢ã¯ãã£ããã£ã«æ°ä»ããããã Uberãæ»æã®è¢«å®³è ã§ãã£ããšåãããŠããŸããã ããããã ãŸããããŠãŒã¶ãŒãIDãããã«ãŒã«æäŸãããšããããã¯ãã£ãã·ã³ã°ã®äºäŸã§ãã£ãããã§ãã
6ææ«ãããŒã©ã³ãã®èªç©ºäŒç€ŸLOTã® 1,400人ã®ä¹å®¢ããé£è¡èšç»ã«äœ¿çšãããã·ã¹ãã ãæ»æããåŸããã¬ããªãã¯ã·ã§ãã³ç©ºæž¯ïŒããŒã©ã³ããã¯ã«ã·ã£ã¯ïŒã«ææãããŸããã
æšå¹Žã®æ倧ã®æ»æã®1ã€ã¯ãééããªãã¢ã·ã¥ãªãŒããã£ãœã³ã«å¯Ÿããæ»æã§ããã Impact TeamãšããŠç¥ãããããã«ãŒã¯ããã®åºäŒãç³»ãµãŒãã¹ã®ééãèŠæ±ããã¡ãã»ãŒãžãWebãµã€ãã«æçš¿ããŸãããããããªããšãçãŸããæ å ±ããã¹ãŠå ¬éããããšã«ãªããŸãã ã¢ã¡ãªã«ã®äŒç€ŸãèŠä»¶ãéµå®ããªãã£ãã»ãŒçŽåŸã«ãããã«ãŒã¯çãŸããæ å ±10 GBã®ãã¬ã³ããå ¬éããŸããã å ¬éãããæ å ±ã«ã¯ãå®è¡ãããæäœãé»åã¡ãŒã«ã¢ãã¬ã¹ãæ§çå奜ãªã©ã3,700äžäººã®é¡§å®¢ã«é¢ããããŒã¿ãå«ãŸããŠããŸãããããã«ã瀟å ææžãå ¬éãããŸããã
第3ååæã«ã¯ã被害è ãžã®ã¢ã¯ã»ã¹æ段ãšããŠãµã€ããŒç¯çœªè ã«ãã£ãŠäœ¿çšãããå€ãã®æ°ããè匱æ§ã確èªãããŸããã å žåçãªFlashãŸãã¯Javaæ»æã«å ããŠãApple Mac OS Xãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ããã€ãã®ã€ã³ã·ãã³ããçºçããŸãããæåã®ã€ã³ã·ãã³ãã¯Stefan Esserã«ãã£ãŠçºèŠãããã«ãŒãã¢ã¯ã»ã¹ãèš±å¯ããMacã®æ»æã«äœ¿çšãããã¢ããŠã§ã¢ã«é¢é£ããŠããŸããã 2çªç®ã®ã€ã³ã·ãã³ãã¯MyKã®å°é家ã«ãã£ãŠçºèŠãããŸããã ããã«ã¯ããã¹ã¯ãŒã管çã·ã¹ãã ã«è匱æ§ãå«ãŸããŠãããããããã«ãŒã¯ä¿åãããŠãããã¹ãŠã®æ å ±ãååŸã§ããŸããã
æ¥éã«äººæ°ãåããŠããæ»ææ¹æ³ã®1ã€ã¯ãããŒã ã«ãŒã¿ãŒãŸãã¯äŒæ¥ã«ãŒã¿ãŒã®ååã§ãã ãã®å Žåãã«ãŒã¿ãŒã¯ããã«ãŒã®å¶åŸ¡äžã«ãããŸãã ã«ãŒã¿ãŒASUSãDIGICOMãbservaTelecomãPLDTãããã³ZTEã«ã¯äºåã«å®çŸ©ãããã¢ã¯ã»ã¹ã³ãŒããããããšãå€æããŸããã ããã«ãããããã«ãŒã¯èšçœ®ãããéšå±ã«å ¥ããã«ããã«ãŒãå¶åŸ¡ã§ããŸããã
ã¯ãªã¹ãã¹ã«ããã«ãŒãXbox LiveãšPSNã«å¯ŸããŠDDoSã䜿çšãããšãã«ãåæ§ã®æ»æãçºèŠãããŸããã å€ãã®ã»ãã¥ãªãã£åé¡ã§ç¥ãããŠããAdobe Flashã¯ããŸããªãæ¶æ» ããå¯èœæ§ããããŸãã iOSã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã®Flashã®äœ¿çšãçŠæ¢ããŠããŸãã ãã®åŸãAndroidãåãããã«é²ã¿ãŸããã Googleã¯ãChromeãã©ãŠã¶ã§Flashãç¡å¹ã«ããŠããæåŸã®çªãcoã®èã«å ¥ãããçªã§ãã ãŸããAmazonã¯ããã®ãã¯ãããžãŒã«åºã¥ããŠäœæãããåºåããµã€ãã§çŠæ¢ããããšãçºè¡šããŸããã
FBIã¯ã2014幎ã«JPMorganã®æ»æã«é¢äžãã5人ãææããŸãã ã ãã®æ»æã®äžç°ãšããŠãããã«ãŒã¯åŸæ¥å¡ç»é²ããŒã¿ãååŸããŸããããã®ããŒã¿ã¯åŸã§90ã®äŒæ¥ãµãŒããŒã«ã¢ã¯ã»ã¹ããŠãäŒæ¥é¡§å®¢ã§ãã7,600äžäººãš700äžã®æ³äººã«é¢ããæ å ±ãçã¿ãŸããã
ãã€ã¯ããœãã㯠ã補åããã³ãœãªã¥ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã¬ãã«ãäžããããšã決å®ã ããœãªã¥ãŒã·ã§ã³ã®æ°ããªé倧ãªãšã©ãŒãçºèŠã§ããã¹ãã·ã£ãªã¹ãã®å ±é ¬ã2åã«ããŸããïŒ5ã10äžç±³ãã«ïŒã ãã®æ £è¡ã¯ITäŒæ¥ã®éã§äžè¬çã«ãªããŸãããããŸã ãã¹ãŠã®ã»ã¯ã¿ãŒãã«ããŒããŠããŸããã ãããããšã©ãŒã«é¢ããæ å ±ãããµã€ãã«ã販売ããããããæ©ãå°éããããšãæåŸ ããŠãå€ãã®äŒæ¥ãå ±é ¬ãæäŸããŠããŸãã
ããšãã°ããã€ã«ãå ±é ¬ãšããŠæäŸãããŠãã€ãããèªç©ºã¯ ããšã©ãŒãèŠã€ããŠå ±åãã人ã«æ倧100äžãã€ã«ãæäŸããããšã決å®ããŸããã FBIã¯ãŸããã€ã³ã»ã³ãã£ãããã°ã©ã ãå°å ¥ããããšã決å®ããŸãããããã®å Žåã¯ç¯çœªè ãé ãããšã«é¢ããæ å ±ãæäŸãã人ã察象ãšããŠããŸãã
æ倧ã®è³éã§ãã300äžãã«ã¯ãGameover ZeuSããããããã®ã€ããªãã®ãŒçåºæ¿è ã§ããEvgeni Mikhailovich Bogachevã®ææãæ¯æŽã§ãã人ã«æäŸãããŸããã
ããã«ãã§ãŒã³ããµã€ããŒç¯çœªè ã®æšçã«ãªãã€ã€ãããŸãã ã©ã¹ãã¬ã¹ã®ããŒãããã¯ããã«ã¢ã³ãã«ãžããžã®æ»æã«å ããŠã ãã«ãã³ãããã¯ãŒã¯ãã¹ã¿ãŒãŠãããããã¯ãŒã¯ ïŒãŠã§ã¹ãã£ã³ãã·ã§ã©ãã£ã³ãªã©ïŒãã©ã¹ãã¬ã¹ãµã³ãºã«ãžãããã©ã³ãããã«ãºããã³ããªã³ãªãªãšã³ã¿ã«ããã¡ã€ã¢ããŒããŒãºã«ãžãã¢ã³ãããã«ãªã©ããããŸããã ããã¯ç¢ºãã«æé·ããé·ããªã¹ãã§ãã ããã«ã«ã¯ãã²ã¹ãã®äœçŸäžãã®éè¡ã«ãŒãã«é¢é£ããæ å ±ãå«ãŸããŠããŸãã ååãšããŠãããã«ã¯ã²ã¹ãã«ã¯ã¬ãžããã«ãŒãã§ã®æ¯æããæäŸããŸããããã¯ãPOS端æ«ã«å¯Ÿããæ»æã®æ°ãå¢ããããšãæå³ããŸãïŒéå»ã«ã¯ãããã«ãŒãæ å ±ãçãããšãã§ããã¿ãŒã²ããã®å Žåã®ããã«ããµã€ããŒç¯çœªè ã®éã§éåžžã«è¯ãããšãå€æããŸãã販売æç¹ã§ãã«ãŠã§ã¢ã䜿çšãã4,600äžã®éè¡ã«ãŒãïŒã
ç©å ·ã¡ãŒã«ãŒã®VTechãã»ãã¥ãªãã£ããŒã«ã«æ©ãŸãããŠããã499äžäººã®èŠªãš637äžäººã®åäŸã被害ãåããŸããã æ»æã®æ°é±éåŸãè±åœèŠå¯ã¯æ»æã®å®¹çè ãé®æããŸããã
ãœãŒã·ã£ã«ãããã¯ãŒã¯
1æãç±³åœå€§çµ±é ãã©ã¯ã»ãªããã«ãã声æãšãšãã«ããµã€ããŒç¯çœªè ãšæŠãããã®å¯Ÿçããã°ã©ã ãå°å ¥ããŸãããããã¯ãISISãšããŠèªå·±çŽ¹ä»ããã°ã«ãŒãããœãŒã·ã£ã«ãããã¯ãŒã¯ã®ãã³ã¿ãŽã³ã¢ã«ãŠã³ãããããã³ã°ããŸããã
ãŸããæè¿Facebookã§æãäžè¬çãªè©æ¬ºã®1ã€ãæåãªäŒç€Ÿã®ã®ããã«ãŒããæäŸããæ¶ç©ºã®æçš¿ã«æ³šæãæã䟡å€ããããŸãã 1æãè©æ¬ºã°ã«ãŒããFacebookãã£ã³ããŒã³ãéå§ãã430 $ 500ã®Zaraã®ããã«ãŒãã®é åžãçŽæããŸããã åå ããã«ã¯ããŠãŒã¶ãŒã¯ãã®ã¢ã¯ã·ã§ã³ã«åå ããå£ã«ãThank you ZaraããšæžããŠãåãããšããã¹ãä»ã®50人ãæåŸ ããå¿ èŠããããŸããã è©æ¬ºã¯éç«ã®ããã«åºãããŸããã ãããæ°æéã§ã5,000人以äžãåå ãã124,000ãè¶ ããæåŸ ç¶ãéä¿¡ããŸããã
éåä¿¡ãããã¡ãã»ãŒãžãå«ãFacebookãµãŒããŒãžã®ãã¹ãŠã®ãŠãŒã¶ãŒæ¥ç¶ã¯ãå®å šãªHTTPSãããã³ã«ãä»ããŠéä¿¡ãããŸãã ããã ãã§ã¯äžååã ã£ãããããã®ãœãŒã·ã£ã«ãããã¯ãŒã¯ã¯Torãããã¯ãŒã¯äžã«ãµãŒãã¹ãäœæãããŠãŒã¶ãŒã¯ãªã³ã©ã€ã³ãã©ã€ãã·ãŒã«ããã«èªä¿¡ãæã€ããšãã§ããããã«ãªããŸããã ãã ãããŠãŒã¶ãŒãç¬èªã®ãµãŒãã¹ãä»ããŠç¢ºç«ããæ¥ç¶ã«å ããŠãFacebookãæäŸããéæ¥çãªé信圢åŒïŒé»åã¡ãŒã«ãªã©ïŒããããŸãã å人ãããªãã«å人çãªã¡ãã»ãŒãžãéä¿¡ããå Žåã«åä¿¡ããéç¥ã«ã€ããŠè©±ããŸãïŒãã®æ©èœãç¡å¹ã«ããŠããªãå ŽåïŒã ãã®ãããªã¡ãã»ãŒãžã¯ã»ãã¥ãªãã£ãäœããããFacebookã¯ã人æ°ã®ããæå·åããã°ã©ã Pretty Good PrivacyïŒPGPïŒã§ä¿è·ãããïŒå¿ èŠã«å¿ããŠïŒãã¹ãŠã®ãŠãŒã¶ãŒãã¡ãã»ãŒãžãåãåãããã«ãªã£ãããšãçºè¡šããŸããã PGPã¯ããªãŒãã³ããŒïŒã¡ãã»ãŒãžã®éä¿¡è ã«ããå¿ èŠããããŸãïŒãšç§å¯ããŒïŒåä¿¡è ã«ã®ã¿ããå¿ èŠããããŸãïŒã«åºã¥ãã·ã¹ãã ã䜿çšããŠãæœåšçãªããã«ãŒããã®æçŽãé ããŸãã
WhatsAppã¯ããŠãŒã¶ãŒãåŒãä»ããŠææããããã1ã€ã®äžè¬çãªæ¹æ³ã§ãã äžæ£è¡çºãããæ¹æ³ãèŠã€ããŸãããããã«ãããç¯çœªè ã¯WhatsApp Trendy BlueãšåŒã°ããåœã®ãµãŒãã¹ã§ãŠãŒã¶ãŒãã ãŸãããšããŸãã ããã¯è¿œå æ©èœãåããã¢ããªã±ãŒã·ã§ã³ã®ãæ°ããããŒãžã§ã³ããšããŠåœè£ ããŸãããå®éã«ã¯ããŠãŒã¶ãŒã«é«äŸ¡ãªãµãŒãã¹ã®çœ²åãããã ãã§ãã ãã®åœã®ããã°ã©ã ã§ã¯ãå°ãªããšã10人ã®å人ãæåŸ ããŠããµãŒãã¹ã«ç»é²ããããã«æ±ããŠããŸãã
Facebookã¯ããã®ãããã¯ãŒã¯ãWebãµã€ãã«ãå«ããªããã¿ã³ãè¿œå ããããšãæ€èšããŠããããšãçºè¡šããŸããã äºæ³éãããµã€ããŒç¯çœªè ã¯ãã®æ©äŒãå©çšããããšã«ããŸããã ãã®çºè¡šã®æ°æéåŸãããŸããŸãªçš®é¡ã®ãå«ããªãåœã®ãªã³ã¯ãçŸããŸããã å®éããããã¯ãŠãŒã¶ãŒãtrickããŠå人æ å ±ãå ±æãããtrapã§ããããšãå€æããŸããã
ã¢ãã€ã«ã®è åš
2015幎ã¯ãé»åã¡ãŒã«ã®å€ãã¯ãŒã ãšSMSã¡ãã»ãŒãžã§äœ¿çšããããã«è¿ä»£åããããã¡ãã»ã³ãžã£ãŒããæãåºãããè åšããå§ãŸããŸããã 被害è ãèªåã®å®¹çè ã®ç»åãžã®ãªã³ã¯ãå«ãSMSã¡ãã»ãŒãžãåä¿¡ãããšãæ»æãéå§ãããŸãã åé¡ã¯ããªã³ã¯ãã¯ãªãã¯ãããšãAPKãã¡ã€ã«ïŒAndroidã¢ããªã±ãŒã·ã§ã³ããã±ãŒãžïŒãå®éã«ããŠã³ããŒããããããšã§ãã 被害è ããããã€ã³ã¹ããŒã«ãããšããã®ã¯ãŒã ã¯è¢«å®³è ã®ãã¹ãŠã®é£çµ¡å ã«åæ§ã®SMSã¡ãã»ãŒãžãéä¿¡ããŸãã å¯å£«éã¯ãæ¥æ¬ã®éä¿¡äºæ¥è ã§ããNTTãã³ã¢ãšå ±åã§ãã»ãã¥ãªãã£æ©èœã®1ã€ãšããŠè¹åœ©ã¹ãã£ããŒãæäŸããæåã®Androidã¢ãã€ã«ããã€ã¹ã§ããArrows NX F-04GããªãªãŒã¹ããŸããã ãã®æ¹æ³ã¯ãApple iPhone 6ãSamsung Galaxy S6ãªã©ã®ã¡ãŒã«ãŒã®éã§éåžžã«äººæ°ã®ããæçŽã¹ãã£ã³æ¹æ³ãããã¯ããã«å®å šã§ãã
6æã«ããã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®å ¬åŒã¢ããªã¹ãã¢ã§ããGoogle Playã§è£œåãå ¬éããAndroidéçºè ã察象ãšãããã£ãã·ã³ã°ãã£ã³ããŒã³ãçºèŠããŸããã Play Developer SupportãšããäŒç€Ÿããããã¢ã«ãŠã³ãæ å ±ã®æŽæ°ããšããèŠåºãã®ã¡ãã»ãŒãžãéä¿¡ãããã¢ã«ãŠã³ãã®æ å ±ãæŽæ°ããããã«èŠæ±ãããŸããã
ãªã³ã¯ãã¯ãªãã¯ãããšããŠãŒã¶ãŒã¯Googleã«äŒŒãããŒãžã«ãªãã€ã¬ã¯ããããããã§ããŒã¿ãå ¥åããå¿ èŠããããŸããã
ãã®ã±ãŒã¹ã¯ãããã«ãŒã被害è ã®éè¡å£åº§ã空ã«ããã®ã§ã¯ãªãããã®å£åº§ã䜿çšããŠGoogle Playã¹ãã¢ãä»ããŠè åšãæ¡æ£ããããšããç¹ã§ç°ãªããŸãã æãå¿é ãªã®ã¯ãç¯çœªè ãããã»ã¹å šäœãç°¡åã«èªååã§ããããšã§ãã
ããã«ã¯ä»¥äžãå¿ èŠã§ãã
â¢Google Playã§å ¬éãããŠãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã«é¢ããæ å ±ãããŠã³ããŒãããããã«ãã¹ãã€ããŒãŸãã¯ã¯ããŒã©ãŒãäœæããŸãïŒããã«ã¯ããŸããŸãªãªãŒãã³ãœãŒã¹ãããžã§ã¯ãããããŸãïŒã
â¢æ å ±ãåæããŠãããŸããŸãªéçºè ã®é»åã¡ãŒã«ã¢ãã¬ã¹ãååŸããŸãã
â¢WebããŒãžã§ããéçºè åãã«èšå®ãããã«ã¹ã¿ã ãã£ãã·ã³ã°ãã£ã³ããŒã³ãéå§ããŸãã ãã®å Žåã欺ceptionã¯ããã«ä¿¡ãããããããªãããã³ã³ããŒãžã§ã³çããé«ããã®ã«åœ¹ç«ã¡ãŸãã
â¢ãªããªã ããã«ãŒã¯åéçºè ã«ãã£ãŠå ¬éããããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã«é¢ããæ å ±ãæã£ãŠããããã人æ°ã®ããã¢ããªã±ãŒã·ã§ã³ïŒäœçŸäžãã®ããŠã³ããŒãïŒã®éçºè ããã©ããã«é¥ããã³ã«åœŒã«èŠåããã·ã¹ãã ãäœæã§ããŸãã
ããã念é ã«çœ®ããŠãæãåçŽã§è€éã§ãªãæ»æã®1ã€ããã®ã¢ã«ãŠã³ãããã¢ããªã±ãŒã·ã§ã³ãå ¬éããŸãã 誰ããéçºè Candy Crushã®ããŒã¿ãçãããšããåãã¢ã«ãŠã³ãããCandy Crush 2ãå ¬éãããšæ³åããŠãã ããã ããã«ãŒãããè³¢ããç§å¯éµïŒå人æ å ±ã®çé£ã§ã¯ååŸã§ããªãïŒã䜿çšããã«ã¢ããªã±ãŒã·ã§ã³ãå€æŽããæ¹æ³ãèŠã€ããå Žåãããã«ãŒã¯å¿ èŠãªã¢ããªã±ãŒã·ã§ã³ãå ¬éããã³æŽæ°ã§ããŸãã
åã®äŸã«æ»ã£ãŠãããã«ãŒããã£ã³ãã£ã¯ã©ãã·ã¥ã®æŽæ°ããŒãžã§ã³ãäœæããããã€ã®æšéŠ¬ãå«ãŸããŠããããšãæ³åããŠãã ãããäœçŸäžäººãã®äººã ãè åšãèããã«ããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããŸãã
Google Android Security Awards, , Android.
: 2000 , 1000 500 . , 38000 .
Zimperium Android 950 , . , , , . MMS, â . MMS, .. Android . , MMS.
, , . Google (Sony, LG, Motorola ) , Samsung , , , .
IBM XForce , , . Google , .
" , Android. , . : PIN- 500 . , Android PIN- - , , 500 . Apple .
Appthority Quicksand, , MDM, . Apple iOS 8.4.1.
, , â Ims0mnia. Apple , .
Apple Apple Store , XcodeGhost. iOS, , , .
Apple 225 000 iCloud. , «» , App Store, iOS.
HP Fortify -. , 100% , , « ». , - , .
, . Wired Jeep Cherokee, . , : , , , ⊠, , . , .
, , BlackHat .
Land Rover 65 000 , 2013 . . BlackHat , Tesla Model S. , 6 , , . .
, , , Toyota Corolla . , , . , ( ), â - .
-
-. , Sony Pictures «», .
, . Der Spiegel , () F-35, , ..
, , , IT-. CNN , , . , , , . , , «
».
, (OPM, ), , 4 . , , . , , , , , , , .
TV5MONDE, . , «» Facebook -.
« » , .
, . , , , . , Stuxnet, . , , Stuxnet ().
Hacking Team â - - . . Hacking Team Twitter, . Hacked Team .
( , ). , Hacking Team, , , , , , . - , , Hacking Team.
« » Adobe Flash , Hacking Team.
, , , - . , , , , .
25 , . , , , .
DGI 78020 - . , , Naikon - , . , , , , , , , , , , - .
Anonymous , - .
IT- 2016
1.
- -, .. . , . , , .
2.
. PE- (https://ru.wikipedia.org/wiki/ Portable_Executable), PE-, . java-, , , Powershell, Windows 10, . , Fileless-,
, , .
3.
. , . , , .. , . , ( , .) .
4. Android
, Android, .. . . , .
5.
, 2016 , , -, .. . - « » , .
6.
, 2016 , , , , , . 2015 , , .
7.
-, - , . , Stuxnet.
8.
. , , , . , , , .
ãããã«
2015 , , 2016 . , , - 12 , , , Cryptolocker.
, .. , , - , . , , , - . , , , . , , , , , . , .